Skip to main content
DPDP Readiness Assessment: Free 28-Question Self-Check — page loaded
DPDP Self-Assessment Diagnostic

DPDP Readiness Assessment: Score Your Organisation in Minutes

How ready are you for DPDP enforcement?

Live diagnostic

What you'll get

An honest read of where your DPDP programme stands today — plus a tailored set of priority actions to close the gaps that will hurt you most when enforcement bites.

0–100
Maturity score
Top 5
Priority actions
Free
No sign-up
28 Questions·7 Workstreams·~12 min

28 Questions · 7 Workstreams

An honest read of where your DPDP programme stands today — plus a tailored set of priority actions to close the gaps that will hurt you most when enforcement bites.

Notice & Consent

  1. 1Have you published a DPDP-compliant Privacy Notice covering the items required under Section 5 of the Act?
  2. 2Is your Privacy Notice available in English plus the 22 Eighth Schedule languages, with parity of content?
  3. 3Where you rely on consent (Section 6), is consent capture granular, purpose-specific, and freely revocable?
  4. 4Do you maintain a tamper-evident audit trail of every consent event with policy version, timestamp and channel?

Data Principal Rights

  1. 5Do Data Principals have a clearly published mechanism to exercise rights under Sections 11–14?
  2. 6Do you have a documented SOP that processes DSARs within the 90-day cap under Rule 14(3)?
  3. 7Have you appointed a Grievance Officer (or DPO acting in that capacity) with name and contact details published?
  4. 8Have you tested your DSAR fulfilment end-to-end at least once in the last 12 months?

Security Safeguards

  1. 9Is personal data encrypted at rest AND in transit using current industry-standard algorithms?
  2. 10Are role-based access controls enforced with least-privilege, and reviewed at least annually?
  3. 11Are security and access logs retained for at least 1 year and reviewed regularly?
  4. 12Do you conduct independent security testing (VAPT, SOC2, ISO 27001 audit) at least annually?

Breach Response

  1. 13Do you have a documented Personal Data Breach Response Plan with clear roles and timelines?
  2. 14Have you mapped notification templates aligned to Rule 7 (DPBI report format + Data Principal intimation)?
  3. 15Have you run a breach tabletop exercise in the last 12 months covering at least 2 scenarios?
  4. 16Is there a documented post-incident review process that captures root cause and remediation tracking?

Processor & Vendor Governance

  1. 17Have you signed DPDP-aligned Data Processing Agreements with all material processors?
  2. 18Do you maintain an up-to-date inventory of all sub-processors with the categories of personal data they receive?
  3. 19Is there a documented vendor onboarding due-diligence process, including a privacy-and-security questionnaire?

Children, Cross-Border & SDF

  1. 20Have you mapped which of your services may process the personal data of children under 18?
  2. 21If you process children's data, do you have a Verifiable Parental Consent flow per Rule 10?
  3. 22Have you assessed whether your processing impacts persons with disabilities (lawful guardians)?
  4. 23Have you mapped all cross-border personal data flows (which categories go where, by what mechanism)?
  5. 24Have you assessed whether you might qualify as a Significant Data Fiduciary under Section 10?
  6. 25If you are likely to be classified an SDF, have you started the Rule 13 obligations (DPIA, annual audit, India-resident DPO)?

Governance & Accountability

  1. 26Is there a named senior owner accountable for the DPDP programme, with a budget and a roadmap?
  2. 27Is DPDP risk on the agenda of your Board / Risk Committee at least quarterly?
  3. 28Do you maintain a Record of Processing Activities (RoPA) covering every system that touches personal data?

Maturity score

  • Not started0
  • Planned25
  • In progress50
  • Implemented80
  • Optimised100

Your maturity score

0+ You're at the foundational stage
Core obligations are largely unaddressed. Prioritise the Phase-1 essentials — notice, consent, security and breach response — before enforcement bites.
20+ You're developing your DPDP capability
Foundations are forming but inconsistent. Close the gaps in your weakest workstreams and formalise SOPs.
40+ You're at the established stage
A real programme exists. Focus now on evidence, testing and vendor flow-down to make it defensible.
60+ You're operating at an advanced level
Most obligations are operational. Tighten the long-tail — tabletop tests, sub-processor inventory, board cadence.
80+ You're at a leading-practice level
Mature and well-evidenced. Maintain the discipline, keep your RoPA live, and prepare for SDF-grade scrutiny.