DPDP Readiness Scorecard

Last updated: 9 September 2026

Twelve questions to gauge where your organisation stands under India's Digital Personal Data Protection Act, 2023 — answer honestly, no legal background needed. This is a general self-check, not legal advice, and it is not a complete assessment of your obligations.

The scorecard runs entirely in your browser. Your answers are not stored, collected, or sent anywhere — the result is shown only to you on this page.

Data mapping

1. Do you know which systems, vendors, and third parties currently hold your customers' personal data?
2. Can you produce a list of what personal data you collect and why, without asking several different departments?

Consent

3. Is your consent request written in plain language, separate from your general terms and conditions?
4. Can a person withdraw consent as easily as they gave it?

Data-principal rights

Access, correction, and erasure.

5. If a person asked you today to erase their data, could your systems actually do it — including backups and vendor copies?
6. Do you have a defined process to respond to a request to access or correct personal data?

Vendors & processors

7. Do your vendor and processor contracts address responsibility if a vendor causes a personal data breach?
8. Do you know which of your vendors are outside India, and what happens to personal data when it leaves the country?

Breach readiness

9. If a breach happened, do you know who must be notified, and within what timeframe?
10. Do you have a named person responsible for data-protection decisions, rather than "the IT team" generally?

Children's data

11. If your product could plausibly be used by anyone under 18, do you have age-verification or parental-consent mechanisms in place?

Governance

12. Has someone in your leadership actually read the DPDP Act and Rules, rather than compliance being an assumption?

Please answer all 12 questions to see your result.

0 / 12 “yes”