Would your handling of personal data stand up to India’s DPDP Act?
The five duties the Digital Personal Data Protection Act, 2023 is built around — notice and consent, the rights of Data Principals, security and breach response, the data lifecycle, and governance — as fifteen plain-language questions. Scored on screen, with the Act’s sections beside every answer and a branded PDF report to keep.
Your level, five-dimension profile and recommendations appear on screen the moment you finish — no email, and the branded PDF report is yours to keep.
01Notice & Consent
02Rights & Grievance
03Security & Breach Response
04Data Lifecycle
05Governance & Readiness
Scored in this browser — nothing is sent unless you choose to.
This checklist is an educational self-assessment built from the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 as notified. It is not legal advice, an audit or a certification — engage qualified counsel for compliance determinations, and confirm the commencement dates that apply to you.
Who this is for
Founders and product owners of Indian consumer platforms with the Rules' commencement ahead of them
UK and EU companies serving Indian users, mapping GDPR work onto the DPDP Act
Compliance and operations leads who need an engineering backlog, not another memo
The flow
How it works
01Answer quick multiple-choice questions about how personal data is actually handled today — options, not essays — with an optional industry lens.
02Get your readiness level and a five-dimension profile, scored against the published rubric, with the Act’s sections beside each recommendation.
03Keep the branded PDF report, then take the DPDP Build Plan to turn the gaps into a prioritised engineering backlog.
Every result is one level and five dimension scores — an example profile.
The framework
Five duties, scored in the open
Every answer carries zero to three points by the maturity it describes. Three questions per dimension give a dimension score out of nine; the five together map to one of four readiness levels. The rubric is published because a score you cannot inspect is not worth acting on.
0–3 per answer→3 questions per dimension→dimension score out of 9→5 dimensions→your result out of 45
No gate. Full results on screen — email is never required to see them.
Nothing stored. Answers are scored in your browser and never leave this page unless you choose to send them.
No invented benchmarks. Every number derives from the published rubric and your own answers; every legal reference is to a section of the Act or a Rule you can read.
All five dimensions weigh equally in v1 — deliberately, until real-world results earn differentiated weights. Framework v1 · September 2026.
How you ask: whether each purpose has a plain-language notice and a free, specific, informed, unambiguous yes behind it — and whether under-18s are handled the way the Act demands.
Why this matters
Consent is the Act's default ground for processing, and the burden of proving that notice was given and consent obtained sits with you (s.6(10)). Bundled tick-boxes and pre-ticked defaults are exactly what the definition in s.6 rules out — and children's data carries its own penalty tier.
How do you obtain consent for the personal data your product collects?
What does the notice say, and in which languages can a user read it?
How do you handle users who may be under 18?
02
Rights & Grievance
Whether a user can actually get what the Act gives them — a summary of their data, correction, erasure, a nominee — and whether a grievance reaches someone who answers in the time you publish.
Why this matters
Sections 11 to 14 turn privacy into service requests, and s.8(10) makes a grievance redressal mechanism a duty. A right that takes a week of emails to honour is a complaint waiting to reach the Data Protection Board — and the Board is where every unresolved grievance goes.
If a user asked for a summary of their personal data and who it was shared with, what would happen?
Who handles grievances, and is the route published?
Could you correct or erase one person's data everywhere it lives, including at your vendors?
03
Security & Breach Response
The safeguards the Rules name as the minimum — encryption or masking, access control, logs and monitoring, backups — and whether a breach would reach affected users and the Board on the Rules' clock.
Why this matters
Failing to take reasonable security safeguards carries the Act's highest penalty tier, up to ₹250 crore, and failing to notify a breach the next, up to ₹200 crore. Rule 7 asks for plain-language intimation to every affected user without delay and a detailed report to the Board within 72 hours.
Which of the Rules' minimum safeguards are in place for personal data?
If personal data were breached tonight, what would happen in the first 72 hours?
How are the vendors that process personal data for you bound?
04
Data Lifecycle
Whether you know what personal data you hold, why, for how long and where it goes — and whether it is erased when the purpose is served, including at your processors and across borders.
Why this matters
Section 8(7) requires erasure once consent is withdrawn or the purpose is no longer served, and Rule 8 adds hard inactivity clocks for the largest platforms. Section 16 lets the Government restrict transfers to notified countries — you cannot comply with a restriction on data whose location you cannot name.
Do you have a current inventory of the personal data you hold?
What happens to personal data once its purpose is served or consent is withdrawn?
Do you know where personal data is processed and which third parties receive it?
05
Governance & Readiness
Whether someone owns the programme with authority, whether you have assessed your exposure to the Significant Data Fiduciary duties, and whether there is a dated plan to the Rules' commencement.
Why this matters
The Rules notified in November 2025 put most duties on an 18-month clock, and a Significant Data Fiduciary must additionally appoint a Data Protection Officer based in India, run an annual impact assessment and audit, and may face data localisation. Governance decides whether the other four dimensions ever get finished.
Who owns DPDP compliance in your organisation?
Have you assessed whether you could be notified as a Significant Data Fiduciary?
Is there a plan that reaches the Rules' commencement dates?
What your score means
Exposed0–13 of 45
Personal data is being processed without the structure the Act presumes — consent that is not consent, rights with no route, a breach that would be improvised. The good news is the order of work is clear: an inventory, a purpose register and a named owner come first, and each closes several gaps at once.
Patchwork14–24 of 45
Real safeguards exist — what is missing is the system holding them together, and patchwork fails exactly where the pieces meet: the SDK nobody reviewed, the vendor without terms, the erasure that never reached a processor. Pick each dimension's recommendation and finish it; completion, not sophistication, is this level's work.
Structured25–35 of 45
Your programme is genuinely organised — the remaining distance is between 'we have it' and 'we can prove it': consent records that would satisfy s.6(10), a breach runbook that has actually run, erasure verified rather than assumed. With the Rules' clock ahead, this is a strong position to finish from.
Ready by Design36–45 of 45
This posture would stand up to the Board's questions, and it compounds: enterprise buyers clear vendor review faster, new products inherit consent and rights machinery instead of retrofitting it, and a notification as a Significant Data Fiduciary would be an adjustment, not a crisis. The work now is keeping it true through change.
FAQ
About this checklist
Short answers to what people ask before they take it — including when the Act's duties apply and what a self-assessment can and cannot tell you.
01What is a DPDP compliance checklist?
A DPDP compliance checklist is a structured way to assess how an organisation handles digital personal data against the duties India's Digital Personal Data Protection Act, 2023 and its Rules impose — notice and consent, the rights of Data Principals, security safeguards and breach intimation, retention and erasure, and governance. It turns the Act into questions you can answer.
02Who should use this checklist?
Anyone responsible for a product or organisation that processes the personal data of people in India: founders and product owners of consumer platforms, marketplaces, SaaS, fintech, healthtech and edtech products, operations and compliance leads, and companies outside India that serve Indian users. The questions are in plain language — you need working knowledge of your systems, not a legal background.
03Is this checklist legal advice or a certification?
No. It is an educational self-assessment built from the Act's own duties and the Rules' published requirements, with section and rule references so you can check them. It shows where your posture likely stands and what typically closes each gap, but it is not legal advice, an audit or a certification — engage qualified counsel for compliance determinations.
04When do the DPDP obligations actually apply?
The Act passed in August 2023; the DPDP Rules were notified in November 2025 with phased commencement — the Data Protection Board provisions immediately, consent-manager registration after twelve months, and most duties on Data Fiduciaries (notice, consent, security, breach intimation, erasure, children's data, rights) after eighteen months, landing in May 2027 as notified. Confirm your dates with counsel.
05Do I need to share my email address to see the results?
No. Your level, the five-dimension profile and every recommendation appear on screen the moment you finish, and the branded PDF report is generated locally in your browser. Your answers never leave the page unless you choose to send your results to our team, and the contact form that follows only asks for what a reply needs.
06What should we do after a low score?
Start with the dimension that scored lowest — its recommendation names the first step — then take the DPDP Build Plan, which turns ten answers about your product into a prioritised engineering backlog with the Act's sections beside each item. If you are building software that processes personal data, send your results and we will walk the gaps with you.
Building software that processes personal data in India?
Send your results through and we'll walk the engineering gaps with you — consent capture, rights workflows, erasure automation, audit trails and the architecture choices that make compliance a property of the system rather than a policy. A working conversation, not a pitch.
One click opens the assistant you already use with a question that points it at this page, so the answer comes from what we publish, not a guess.
The question it opens withRead https://digiwagon.com/tools/dpdp-compliance-checklist and tell me what "DPDP Compliance Checklist" helps me decide, what inputs I should gather before using it, and how DigiWagon suggests acting on the result. Stick to what the page says and mark anything you are not sure about.