How exposed is your business under India’s DPDP Act?
Eighteen questions across six areas, in under five minutes. You get a score, a breakdown by area and your three biggest gaps named specifically rather than described in general terms.
“Almost every conversation about DPDP starts with the wrong date. People have read that the deadline is November 2026, so they either panic about nine weeks they do not have or dismiss it because they think they missed nothing. The obligations commence in May 2027. That is eight months, which is enough time and only if the work starts with finding the data rather than rewriting the privacy policy.”
Tejas Dhabalia, Co-founder, DS Consulting
Before you start
There is no passing score here. The Data Protection Board of India, the regulator the Act creates, does not rate organisations and neither does anyone else. What this measures is how much of a defence you would have if it asked to see your process, and most businesses we talk to are further behind than they expect. That is not a failure of intent. The law rewards specific documented practices rather than general good intentions, and documentation is the part that gets deferred.
Answer for what is true today, not what is planned. A generous answer produces a comfortable score and no useful next step.
Standalone notice, itemised purposes, affirmative consent, working withdrawal
Access, correction and erasure, and a named owner for requests
Written response plan, detection speed, and whether it has ever been tested
Defined retention periods, and a process that actually deletes
Verifiable parental consent, and no targeted advertising to minors
DPDP terms in processor contracts, and someone designated as responsible
Weighting follows the penalty schedule rather than question count. Breach readiness and vendor accountability carry more because failing to take reasonable security safeguards carries a ceiling of ₹250 crore and failing to notify a breach carries ₹200 crore.
Notice and consent
Where the evidence of compliance is created. Get this wrong and everything downstream inherits the problem.
Do you have a standalone privacy notice, separate from your terms of service, written in plain language?
Does your notice itemise what data you collect and why, for each purpose separately?
Is consent captured through a clear affirmative action, with no pre-ticked boxes and no bundling with unrelated terms?
Can a customer withdraw consent as easily as they gave it?
Why the date matters more than the score
India has had a data protection law on paper since August 2023. It sat unenforced for two years, until the DPDP Rules 2025 were notified on 13 November 2025 with an eighteen month phased timetable behind them.
A great deal of published guidance reports that the substantive obligations land at the twelve month mark, in November 2026. They do not. November 2026 commences the consent manager framework, which creates a registered class of intermediary that individuals can use to manage consent across many companies at once. Everything this assessment asks about commences at the eighteen month mark, on 13 May 2027.
The practical consequence is that you have roughly eight months rather than two, and also that any adviser quoting you the November date has not read the commencement notification. The full breakdown of what commences when, with the primary sources, is on the DPDP commencement timeline page.
One caveat worth carrying. The government has been reported as considering a shorter compliance timeline than the eighteen months notified. Nothing has been formally amended, so plan against May 2027 and treat an earlier date as a risk.
Frequently asked questions
When do the DPDP obligations actually start?
13 May 2027 for the obligations this assessment covers. The DPDP Rules 2025 were notified on 13 November 2025 with an eighteen month phased timetable. The twelve month mark, November 2026, commences the consent manager framework, which is a supplier category rather than a duty on your business. Notice, consent, security safeguards, breach notification, rights, retention and children's data all commence at the eighteen month mark.
Is there a passing score?
No. The Data Protection Board of India, the regulator created by the Act, does not score organisations and neither does anyone else. The bands here are a way of describing how much of a defence you would have if that regulator asked to see your process, and the useful output is the named gaps rather than the number. Most mid-market companies that have not started land in the high exposure band, which is an accurate reading rather than a scare.
Does this apply to us if we are not an Indian company?
If you process personal data of people in India in connection with offering them goods or services, yes. The Act reaches processing outside India on that basis, so place of incorporation does not settle the question. A company registered anywhere that runs a signup flow, a support desk or a payment page serving people in India is within scope.
How is the score weighted?
By consequence rather than by question count. Breach readiness and vendor accountability carry more weight because the penalty ceilings behind them are higher: up to INR 250 crore for failing to take reasonable security safeguards and up to INR 200 crore for failing to notify a breach. Two questions on record volume and platform type carry no points at all. Holding a lot of records is not a readiness failure, so those set a flag on significant data fiduciary designation instead of moving the score.
Sources
Both primary. Secondary summaries of this timetable disagree with each other, which is why this assessment carries its own date rather than borrowing one.
- Government notifies DPDP Rules to empower citizens and protect privacy
Press Information Bureau, Ministry of Electronics and Information Technology, 14 November 2025. Source for the eighteen month phased timetable, the standalone itemised notice requirement and the ninety day response window for rights requests.
- Ministry of Electronics and Information Technology
Publisher of the DPDP Act 2023, the DPDP Rules 2025 and the commencement notifications. The penalty ceilings quoted in this assessment come from the Schedule to the Act.
Dates and figures verified 11 September 2026. This is a management tool and not legal advice.
The commencement timeline
Three phases, and the one most commentary gets wrong. What is in force now, what November 2026 actually brings, and what commences on 13 May 2027.
Read the timeline