India's DPDP Act 2023 & Rules 2025
DPDPA readiness assessments, drafted for you, verified by you.
Time left to comply with the DPDP Act
Until the main duties apply on 13 May 2027, 00:00 IST. After that the Data Protection Board can impose penalties of up to ₹250 crore.
- Guided intake mapped to every obligation in the Act and Rules.
- Risk register and data-flow map built from the client's own answers and evidence.
- A GRC Analyst that reads your workspace and cites the provision it relies on.

How an engagement runs
Four steps from first question to a delivered assessment
- 1
Intake
Business-language questions for the client. Follow-ups appear only when they're relevant, like parental consent for an EdTech client.
- 2
Findings
A rule-based assessment gives one finding per obligation. Each finding's citation is checked against the text of the Act and Rules.
- 3
Documents
Gap report, RoPA, privacy notice, breach playbook and a draft DPA for the client's lawyer. A person reviews each one before it can be downloaded as .docx.
- 4
Delivery
Blocked until every check passes. There is no override, so nothing half-finished reaches a client.
Around each engagement
The registers the Act expects you to keep
Every record has an owner, a due date, a status that won't move without the facts it needs, a full history and evidence attached.
Privacy operations
- Personal data
- Discovery scans and a data inventory with purpose, legal basis, retention and owner.
- Consent
- Consent records for each purpose, with withdrawals.
- Requests
- Access, correction, erasure, grievance and nomination, on a response clock of up to 90 days (Rule 14(3)).
- Breaches
- Each breach tracked against the Board's detailed report, due 72 hours after awareness (Rule 7(2)(b)).
Compliance
- Controls
- The client's status for every obligation. "Not applicable" needs a reason and an admin; "implemented" needs evidence.
- Tasks
- Turn any gap, risk or control into assigned work with an owner and due date.
- Evidence
- A library of files checked against their type, stored under random names, downloadable only when signed in.
- Policies
- Version, approver and next review date for each policy.
Risk
- Risk register
- Every gap and failed check becomes a risk, scored likelihood × impact on a 5×5 matrix, with treatment and owner.
- Vendors and processors
- Contract, data location and review date for each one.
- DPIA
- Data protection impact assessments for Significant Data Fiduciaries.
- Data-flow map
- Where personal data is collected, stored and shared, and which flows leave India.
GRC Analyst
Ask about any client. Get an answer with the provision behind it.
The Analyst reads the workspace's engagements, findings, risks, evidence and data flows, and follows an auditor's workflow: planning, fieldwork, evidence, risk and reporting. It can't change anything.
Open GRC FlowExample answer
Summarise Arogya Health Clinics for management
Arogya is 58/100 ready. Of 8 obligations assessed, 2 are compliant, 4 are gaps and 2 are open items.
The biggest exposure is security: the appointment database isn't encrypted at rest and logs are kept for 30 days instead of one year. A security failure carries the highest penalty in the Act, up to ₹250 crore.
Patient data is backed up to the EU. That's allowed unless the government restricts the destination, but it should be recorded and reviewed.
Section 8(5)Rule 6Section 16
Personal data discovery
Find the personal data in a client export
Upload a CSV or JSON of customers, employees or patients. The scan flags fields that look like personal data, and a person confirms or rejects each one before it enters the data inventory.
- Aadhaar (Verhoeff checksum)
- PAN
- GSTIN (checksum)
- Passport
- Voter ID
- Driving licence
- Indian mobile
- UPI ID
- Card number (Luhn)
- IP address
- Date of birth
- Health
- Biometric
- Salary
- Address
Private by design
- The file is parsed in memory and never written to disk.
- At most 200 records are sampled per field.
- Only a masked shape of each value is stored, like +99 99999 99999.
- Nothing from the scan is sent to the AI.
- Ages under 18 are flagged as children's data under Section 9.
Documents
Drafted for you, signed off by a person
Each document is built from the intake and findings. Nothing can be downloaded as .docx until someone has reviewed it.
- Gap reportEvery obligation, its status and what to fix
- Record of processing (RoPA)From the data inventory
- Privacy noticeBuilt from the intake answers
- Breach playbookWith the Board's reporting deadlines
- Data processing agreementMarked draft for the client's lawyer
Why now
The main duties apply from 13 May 2027
11 August 2023
The DPDP Act receives Presidential assent.
November 2025
The DPDP Rules are notified and the Data Protection Board is set up.
November 2026
Rules on registering Consent Managers take effect.
13 May 2027
Notice, consent, security, breach reporting, erasure, children's data and Data Principal rights all apply.
Maximum penalty per instance
- ₹250 crore
- Failing to take reasonable security safeguards (Section 8(5))
- ₹200 crore
- Failing to report a breach to the Board and affected people (Section 8(6))
- ₹200 crore
- Breaking the additional rules for children's data (Section 9)
- ₹150 crore
- A Significant Data Fiduciary missing its extra duties (Section 10)
- ₹50 crore
- Breaching any other provision of the Act or Rules
Privacy and GRC consultants
Run DPDPA readiness assessments for many clients at once. The dashboard shows every client's stage, readiness score and top risks.
In-house compliance teams
Treat each business unit or entity as an engagement and keep one register of risks, evidence and requests across the group.
See it with sample clients
Six clients at every stage, from intake to delivered. No sign-up needed.