Know where your DPDPA readiness stands.
A 5-minute self-check to see where your organisation actually stands on personal data readiness.
The DPDP Act asks whether you can show what personal data you hold, why you hold it, who can access it, and what happens when something goes wrong.
How it works
Three simple steps to your data readiness score.
Step 1
14 focused questions
4 about your organisation, then 10 about how you handle data.
Step 2
About 5 minutes
Plain-language scenarios with nothing to download or prepare.
Step 3
Your score, instantly
See your score out of 100 and the three areas needing attention.
India’s Digital Personal Data Protection Act 2023
India’s Digital Personal Data Protection Act became law in 2023. The rules that make it work were notified on 13 November 2025, and the obligations it puts on your organisation take effect on 13 May 2027. That is under eight months away.
It applies to you if you hold personal data about people in India.
Customers, employees, vendors, job applicants and third party outsourcing all count.
Penalties
The penalties sit in the Act itself, and they fall on the organisation:
- Up toRs 250 crore
for failing to take reasonable security safeguards against a data breach
- Up toRs 200 crore
for failing to tell the Data Protection Board and the affected people when a breach happens
- Up toRs 200 crore
for mishandling children’s data
- Up toRs 50 crore
for breaching any other obligation in the Act
Key takeaway
The Board sets the amount by looking at how serious the lapse was, how long it ran, and what you had already done to prevent it. That last point is why the four minutes below are worth spending.

