Skip to main content
DPDP Tools: Penalty Calculator, SDF Classifier, Templates — page loaded
Free tools

Free DPDP Compliance Tools, Calculators and Templates

Working tools that turn the law into decisions you can make today.

Interactive calculators

Compute it. Don’t guess it.

Penalty exposure estimator
Toggle applicable contraventions
Severity multiplier (DPBI discretion under Section 33(2))100%
Estimated maximum exposure
₹0Cr
Toggle contraventions to compute.
Read the methodology behind the penalty estimator
Are you a Significant Data Fiduciary?

Answer seven yes/no questions based on the factors in Section 10(1). The classifier estimates your likelihood of SDF designation.

Do you process personal data of more than 10 lakh Indian Data Principals?
Do you process sensitive data (health, financial, biometric, location)?
Do you make automated decisions affecting Data Principals (credit, insurance, hiring)?
Are you in a critical sector (telecom, banking, payments, healthcare)?
Do you operate cross-border data flows at scale?
Do you deploy AI/ML on personal data at scale?
Could your processing materially impact electoral processes or public discourse?
0 of 7 answered — answer all to see the result.
Read the methodology behind the SDF classifier
Cross-border transfer checker

India runs a default-permitted regime under Section 16. Select a destination to see its status and sectoral overlays.

Do you need a DPIA?

A Data Protection Impact Assessment is mandatory for SDFs and for high-risk processing (Rule 13). Toggle the factors that apply to your processing.

Toggle factors to see whether a DPIA is required.
Template library

Starter artefacts. Production-grade.

01Notice

Privacy Notice Template

Standalone, itemised privacy notice satisfying Section 5 and Rule 3. Includes layered short and long versions.

Download
02Notice

Cookie & Tracking Notice

Cookie and tracking-technology notice with category-level consent and a preference centre pattern.

Download
03Consent

Consent Capture UX Spec

UX specification for granular consent flows with withdrawal-parity and audit trails. Includes 22-language fallback patterns.

Download
04Breach

72-Hour Breach Response Runbook

Hour-by-hour incident runbook from detection through DPBI intimation and post-incident review.

Download
05Breach

Breach Intimation Templates

Two pre-drafted notices: (i) DPBI intimation matching Rule 7(2); (ii) Data Principal notice in plain language.

Download
06Security

Rule 6 Security Controls Checklist

Control-by-control checklist mapped to the seven Rule 6 safeguard categories with evidence prompts.

Download
07Vendor

Data Processing Addendum (DPA)

Master DPA clauses for processor contracts. Aligned to Section 8(2) Fiduciary-Processor obligations and Rule 6.

Download
08Vendor

Vendor Due Diligence Questionnaire

Scored DDQ with Red/Amber/Green output to triage processor risk and drive remediation.

Download
09Grievance

Grievance Officer SOP

Standard operating procedure for the grievance function with escalation and 90-day SLA tracking.

Download
10Rights

DSAR Handling SOP & Tracker

Workflow for DSAR intake, identity verification, data assembly and timely response. Includes SLA tracker.

Download
11Governance

Record of Processing Activities

RoPA register template capturing purpose, basis, categories, processors and retention per activity.

Download
12DPIA

DPIA Template (Rule 13)

Data Protection Impact Assessment template for high-risk processing with residual-risk and Board sign-off.

Download
13Governance

DPO Job Description & KRAs

Section 10(2)(a)-compliant DPO role description with India-residency, board-reporting and quarterly KRAs.

Download
14Children

Verifiable Parental Consent Flow

Reference flow for age verification and verifiable parental consent under Section 9 and Rule 10.

Download
15Governance

Retention & Erasure Schedule

Master retention schedule mapping each data category to the strictest applicable retention obligation.

Download
16Board Reports

Board-Level DPDP Risk Report

Board-pack format presenting maximum vs residual penalty exposure and programme progress by quarter.

Download
Quick reference

One-page cheatsheets for fast lookup.

Detect → contain → triage severity → intimate DPBI without delay → detailed Rule 7 report within 72 hours → notify affected Principals in plain language → forensic review and root-cause analysis.

Necessary for the requested service? → Section 7(a) voluntary provision. Required by a specific law/order? → Section 7(c). Asking the user to opt into something beyond the core service? → Section 6 consent. None of these? → reassess whether you should process at all.

₹250 Cr security (8(5)) · ₹200 Cr breach notice (8(6)) · ₹200 Cr children (9) · ₹150 Cr SDF (10) · ₹50 Cr any other provision · ₹10K Data Principal duties (15). Penalties apply per contravention and can cumulate.

India-resident DPO reporting to the Board · annual DPIA on high-risk processing · annual independent audit by an empanelled auditor · periodic risk assessment · algorithmic transparency where automated decisions affect principals.

A principal can request: a summary of personal data held, the processing activities, and the list of Data Processors. Respond in writing with complete disclosure within 90 days. Rights: access (Section 11), correction & erasure (Section 12), grievance (Section 13), nomination (Section 14).

Verifiable parental consent before processing data of anyone under 18. Absolute prohibitions on tracking, behavioural monitoring and targeted advertising of children — not curable by consent. Self-declared age gates are insufficient.

Default-permitted under Section 16 unless the destination is on a Government blacklist (none as of May 2026). Then check sectoral overlays (RBI payment localisation, health, KYC retention). Map the flow, record the basis, apply SCCs as best practice.
Interactive checklist

DPDP Compliance Readiness Checklist.

Your progress saves automatically in this browser.

0 / 40
Notice & Consent
Data Principal Rights
Data Fiduciary Obligations
Security Safeguards (Rule 6)
Breach Response
Processor & Vendor Governance
Children's Data (Section 9)
Cross-Border Data Transfers
SDF — Additional Obligations
Phase 3 — Full Enforcement (13 May 2027)

Tools you’ve used. Now make them work.

Get a tailored gap report mapped to every tool on this page.