Know your compliance risk before the Data Protection Board asks
Purpose of this tool
This is a 25-question, 5-minute self-assessment across five DPDPA (Digital Personal Data Protection Act, 2023) control areas: Consent Management & Notice, Data Fiduciary Obligations, Data Principal Rights, Breach Notification, and Cross-Border/DPBI Readiness. It is meant to give an organisation an honest, structured first read of where its data-protection practice actually stands — before a regulator, a customer audit, or a breach forces the question.
Score each statement 1 (no control exists) to 5 (implemented and evidenced). At the end you'll get a risk level, a dimension-by-dimension breakdown, and a recommended engagement tier. Each statement below carries a short note on the relevant DPDPA provision, so the assessment also works as a quick primer on what the Act actually expects.
Caution: This is a self-scored, self-diagnostic tool, not a legal opinion. It does not verify evidence, and the resulting risk band is indicative only — actual regulatory exposure depends on facts specific to your organisation, your data flows, and how the DPDP Rules are eventually notified and interpreted. Use it to guide a conversation with qualified counsel and technical advisors, not as a substitute for one.
| Dimension | Score | Status |
|---|
We'll walk through your dimension breakdown together and agree the right next step — a targeted fix, the full readiness sprint, or just a second opinion.
Rohit Sahai · Senior Technology Executive & Independent Director