DPDP Self-Assessment Diagnostic
DPDP Readiness Assessment: Score Your Organisation in Minutes
How ready are you for DPDP enforcement?
Live diagnostic
What you'll get
An honest read of where your DPDP programme stands today — plus a tailored set of priority actions to close the gaps that will hurt you most when enforcement bites.
0–100
Maturity score
Top 5
Priority actions
Free
No sign-up
28 Questions·7 Workstreams·~12 min
28 Questions · 7 Workstreams
An honest read of where your DPDP programme stands today — plus a tailored set of priority actions to close the gaps that will hurt you most when enforcement bites.
Notice & Consent
- 1Have you published a DPDP-compliant Privacy Notice covering the items required under Section 5 of the Act?
- 2Is your Privacy Notice available in English plus the 22 Eighth Schedule languages, with parity of content?
- 3Where you rely on consent (Section 6), is consent capture granular, purpose-specific, and freely revocable?
- 4Do you maintain a tamper-evident audit trail of every consent event with policy version, timestamp and channel?
Data Principal Rights
- 5Do Data Principals have a clearly published mechanism to exercise rights under Sections 11–14?
- 6Do you have a documented SOP that processes DSARs within the 90-day cap under Rule 14(3)?
- 7Have you appointed a Grievance Officer (or DPO acting in that capacity) with name and contact details published?
- 8Have you tested your DSAR fulfilment end-to-end at least once in the last 12 months?
Security Safeguards
- 9Is personal data encrypted at rest AND in transit using current industry-standard algorithms?
- 10Are role-based access controls enforced with least-privilege, and reviewed at least annually?
- 11Are security and access logs retained for at least 1 year and reviewed regularly?
- 12Do you conduct independent security testing (VAPT, SOC2, ISO 27001 audit) at least annually?
Breach Response
- 13Do you have a documented Personal Data Breach Response Plan with clear roles and timelines?
- 14Have you mapped notification templates aligned to Rule 7 (DPBI report format + Data Principal intimation)?
- 15Have you run a breach tabletop exercise in the last 12 months covering at least 2 scenarios?
- 16Is there a documented post-incident review process that captures root cause and remediation tracking?
Processor & Vendor Governance
- 17Have you signed DPDP-aligned Data Processing Agreements with all material processors?
- 18Do you maintain an up-to-date inventory of all sub-processors with the categories of personal data they receive?
- 19Is there a documented vendor onboarding due-diligence process, including a privacy-and-security questionnaire?
Children, Cross-Border & SDF
- 20Have you mapped which of your services may process the personal data of children under 18?
- 21If you process children's data, do you have a Verifiable Parental Consent flow per Rule 10?
- 22Have you assessed whether your processing impacts persons with disabilities (lawful guardians)?
- 23Have you mapped all cross-border personal data flows (which categories go where, by what mechanism)?
- 24Have you assessed whether you might qualify as a Significant Data Fiduciary under Section 10?
- 25If you are likely to be classified an SDF, have you started the Rule 13 obligations (DPIA, annual audit, India-resident DPO)?
Governance & Accountability
- 26Is there a named senior owner accountable for the DPDP programme, with a budget and a roadmap?
- 27Is DPDP risk on the agenda of your Board / Risk Committee at least quarterly?
- 28Do you maintain a Record of Processing Activities (RoPA) covering every system that touches personal data?
Maturity score
- Not started0
- Planned25
- In progress50
- Implemented80
- Optimised100
Your maturity score
- 0+ You're at the foundational stage
- Core obligations are largely unaddressed. Prioritise the Phase-1 essentials — notice, consent, security and breach response — before enforcement bites.
- 20+ You're developing your DPDP capability
- Foundations are forming but inconsistent. Close the gaps in your weakest workstreams and formalise SOPs.
- 40+ You're at the established stage
- A real programme exists. Focus now on evidence, testing and vendor flow-down to make it defensible.
- 60+ You're operating at an advanced level
- Most obligations are operational. Tighten the long-tail — tabletop tests, sub-processor inventory, board cadence.
- 80+ You're at a leading-practice level
- Mature and well-evidenced. Maintain the discipline, keep your RoPA live, and prepare for SDF-grade scrutiny.