The DPDPA penalty clock is already running. Find out exactly where you stand.
Twenty questions across the six obligations that carry real penalties. An instant 0 to 100 readiness score, your risk band, and where you stand against your sector. Before the Board asks, and before the regulator does.
Every month of delay is a month of exposure you cannot retroactively fix. Penalties under Section 33 reach up to Rs 250 Cr per instance.
SaaS company · 200 to 1000 people
DevelopingStatute-anchored to the DPDPA 2023 and the DPDP Rules 2025. Every question cites its section.
BFSI · Healthcare · SaaS · E-commerce / D2C · Manufacturing · Education
Enforcement timeline
The scoring model
Six pillars. The obligations that carry the penalties.
Notice and Transparency
Whether people are told, in clear terms, what you collect and why, and how to act on it.
Consent Management
Whether consent is free, specific, informed, revocable, and provable.
Data Principal Rights
Whether individuals can actually exercise access, correction, erasure, grievance, and nomination.
Breach Preparedness
Whether you could detect, escalate, and report a personal data breach in the prescribed manner.
Retention and Erasure
Whether data is erased when its purpose ends, rather than kept by default.
Governance and Accountability
Whether security safeguards, processor contracts, and Significant Data Fiduciary duties are in place.
The deliverable
A defensible number, not a checklist.
Every question and every finding maps to an exact section of the DPDPA 2023 or the DPDP Rules 2025. Your free score names your risk band and your top three gaps. The full report gives you the exact citations and a 30, 60, 90 day remediation plan.