DPDP readiness checker

How ready are you for the DPDP Act?

12 questions. About 3 minutes. You get a score for each area and a 90-day plan by email.

0 of 12 answered

Data inventory

Do you keep an up-to-date list of the personal data you collect, where it is stored and why?

1.Do you keep an up-to-date list of the personal data you collect, where it is stored and why?

Do you know which systems, apps and spreadsheets hold personal data, including backups?

2.Do you know which systems, apps and spreadsheets hold personal data, including backups?

Notice and consent

Do you show a clear notice describing what personal data you collect and the purpose, before or at collection?

3.Do you show a clear notice describing what personal data you collect and the purpose, before or at collection?

Can users give, review and withdraw consent as easily as they gave it, and do you record those choices?

4.Can users give, review and withdraw consent as easily as they gave it, and do you record those choices?

Rights, retention and erasure

Do you have a process to respond to requests to access, correct or erase personal data?

5.Do you have a process to respond to requests to access, correct or erase personal data?

Do you delete or anonymise personal data once the purpose is served, under a written retention schedule?

6.Do you delete or anonymise personal data once the purpose is served, under a written retention schedule?

Have you published a grievance contact that people can use to raise data concerns?

7.Have you published a grievance contact that people can use to raise data concerns?

Breach response

Do you have a written personal data breach response plan with named owners?

8.Do you have a written personal data breach response plan with named owners?

Could you detect a breach, and notify the Data Protection Board and affected people, without delay?

9.Could you detect a breach, and notify the Data Protection Board and affected people, without delay?

Vendors and processors

Do your contracts with vendors who process personal data for you include data protection and security obligations?

10.Do your contracts with vendors who process personal data for you include data protection and security obligations?

Security safeguards

Is personal data encrypted in transit and at rest, with access limited by role and reviewed regularly?

11.Is personal data encrypted in transit and at rest, with access limited by role and reviewed regularly?

Do you log and monitor access to personal data, keep backups, and test your systems through regular security testing such as VAPT?

12.Do you log and monitor access to personal data, keep backups, and test your systems through regular security testing such as VAPT?

Why DPDP readiness matters now

The Digital Personal Data Protection Act, 2023 sets out how organisations that process digital personal data in India must handle it. The DPDP Rules were notified in November 2025 with a phased rollout, so many obligations take effect over the following months. Businesses that act early have time to fix gaps before enforcement rather than after a complaint or breach.

The Act expects data fiduciaries to give clear notices, obtain and manage consent, respect the rights of data principals, notify personal data breaches and take reasonable security safeguards to prevent breaches. That last point is where most technical work lies: access control, encryption, masking, logging, monitoring and backups.

What the checker covers

Questions are grouped into six areas: data inventory, notice and consent, rights and retention, breach response, vendors and processors, and security safeguards. Each answer scores Yes 2, Partly 1, No 0. Areas scoring 75% or more are green, 40% to 74% amber, and below 40% red.

Where Scantra fits

Lawyers advise on legal obligations. We focus on the security side: testing whether your safeguards actually protect personal data. See our VAPT services, the VAPT FAQ, or the VAPT cost estimator.

Questions

What is the DPDP readiness checker?

A free 12-question self-assessment covering data inventory, notice and consent, data principal rights, breach response, vendors and security safeguards. You get an instant overall score and a red, amber or green rating for each area.

Is this legal advice?

No. The checker is a self-assessment based on your answers. It helps you find gaps, especially in security safeguards. Confirm your legal obligations with a qualified legal adviser.

What is in the full report?

A prioritised list of gaps with practical recommendations for each weak area, plus a 90-day action plan. It is emailed to the address you provide.

Where does Scantra help?

We focus on the security side: verifying reasonable security safeguards such as access controls, encryption, logging and monitoring through VAPT and security reviews.

Do you store my answers?

We store your name, work email, company and score summary to send the report and follow up about it. See our privacy policy for details.

This tool is not legal advice. Results depend on your own answers.

Get started

Ready to find what attackers will?

Talk to a senior pentester. Get a tailored scope, sample report and timeline within 24 hours.