The Digital Personal Data Protection Act, 2023 sets May 2027 as the deadline for full enforcement. With penalties up to ₹250 crore per violation, knowing where your compliance gaps are is the first step toward closing them.
This free assessment evaluates your organisation across 8 key compliance areas in 20 questions. It takes approximately 5 minutes. You will receive an overall readiness score (0-100), category-by-category breakdown, risk classification, and tailored recommendations.
Four simple steps from question prompt to tailored compliance action plan.
Covers consent, DSR, security, breach response, vendor risk, children's data, and governance.
Your overall readiness score (0-100) calculated in real time.
See which categories are strong and where your highest-risk gaps are.
Prioritised recommendations for what to fix first, with links to relevant PrivacyOS tools and guides.
Answer the 20 questions below based on your organisation's current data practices.
1.Do you present a standalone privacy notice before collecting personal data?
2.Is your consent mechanism opt-in only with no pre-checked boxes?
3.Can users withdraw consent as easily as they gave it?
4.Do you have a documented process for responding to data access requests?
5.Can you erase a user's data across all systems upon request?
6.Do you have a published grievance redressal mechanism with contact details?
7.Do you maintain an up-to-date inventory of all personal data you process?
8.Do you know which third parties and cloud services have access to your personal data?
9.Is personal data encrypted at rest and in transit?
10.Do you enforce role-based access control and multi-factor authentication?
11.Do you conduct regular security assessments or penetration testing?
12.Do you have a written incident response plan for personal data breaches?
13.Can you notify the Data Protection Board within 72 hours of discovering a breach?
14.Do you have data processing agreements with all third-party vendors handling personal data?
15.Do you assess the data security practices of vendors before onboarding them?
16.Do you verify age before processing data of individuals under 18?
17.Do you prohibit behavioural monitoring, tracking, or targeted advertising directed at children?
18.Have you appointed a Data Protection Officer or designated privacy lead?
19.Do your employees receive regular training on data privacy and security?
20.Do you have documented data retention and secure disposal policies?
Enter your details to view your overall score, category breakdown, risk band, and priority remediation roadmap.
Actionable intelligence delivered straight to your engineering and legal leads.
A single quantitative metric representing your overall compliance posture against the DPDP Act 2023 and DPDP Rules 2025.
Clear visual breakdown showing exact areas of strength and exposure across consent, DSR, security, vendor risk, breach notification, and children's data.
Clear categorization into High Readiness, Moderate Risk, or Critical Exposure based on regulatory penalty exposure.
Actionable, ordered recommendations telling your team exactly what to build, document, and deploy first.
Understanding regulatory exposure levels before the May 2027 enforcement milestone.
Strong foundation. Focus on documentation, fine-tuning edge cases, and continuous monitoring. You are well-positioned for the May 2027 deadline.
Some controls in place, but significant gaps in technical automation, breach workflows, or vendor governance. You have 12-18 months to close these gaps.
High vulnerability to regulatory penalties (up to ₹250 crore). Immediate remediation is required across consent, security, and governance.
Schedule a 30-minute session with our data protection engineers to map your assessment gaps directly to PrivacyOS automated modules.