Toolkit · Compliance · about 5 minutes
India DPDP Readiness Check
The DPDP Act reaches organisations outside India that offer goods or services to people in India. If you already run GDPR, most of the machinery transfers. These questions target the parts that do not, which is where a mature European programme still fails.
20 questions. Nothing is sent anywhere as you answer, the scoring runs in your browser, and we only receive anything if you ask for the written version at the end.
Scope and applicability
Whether the Act reaches you, which does not depend on having an Indian entity.
Do you know whether you process the digital personal data of people in India?
The Act reaches organisations outside India that offer goods or services to people in India. Self-serve signups count.
Have you identified which processing you do as a Data Fiduciary and which as a Data Processor?
Have you assessed whether volume or sensitivity could see you designated a Significant Data Fiduciary?
Designation brings an India-based Data Protection Officer, an independent data auditor and periodic impact assessments. The lead time cannot be compressed.
Lawful basis
The area where a GDPR programme most often fails outright.
Have you confirmed that no processing of Indian personal data relies on legitimate interests?
There is no legitimate interests basis under DPDP. Marketing and analytics are where this bites hardest.
Is every processing activity mapped either to consent or to one of the defined legitimate uses?
Can consent be withdrawn as easily as it was given, with processing stopping as a result?
Are consent records kept in a form that would evidence validity to the Data Protection Board?
Notice and consent mechanics
Mostly an engineering task rather than a policy one.
Is your notice available in English and the languages listed in the Eighth Schedule of the Indian Constitution?
A consent flow built for one language will not satisfy this.
Is the notice itemised, describing each purpose separately rather than in a single bundled statement?
Is the notice presented at or before the point consent is taken?
Have you considered whether your consent records may need to interoperate with a registered Consent Manager?
Children
Stricter than GDPR, and the threshold catches people out.
Do you treat anyone under 18 as a child for Indian users, rather than 13 or 16?
Do you obtain verifiable parental consent before processing a child's data?
Have you confirmed you do not track, behaviourally monitor or target advertising at children?
These are prohibited outright rather than restricted.
Rights and grievances
Fewer rights than GDPR, but one that has no European equivalent.
Can you fulfil access, correction, completion and erasure requests from Indian Data Principals?
Is there a published grievance redressal mechanism with a named point of contact?
Can you honour a nomination, where someone appoints another person to exercise their rights on death or incapacity?
Breach and transfers
Where reusing GDPR documentation gives the wrong answer.
Can your breach process notify the Data Protection Board and affected Data Principals on India's timeline as well as the ICO on the GDPR one?
Have you assessed transfers against India's restricted-country approach rather than reusing your GDPR adequacy analysis?
DPDP permits transfers except to listed countries. GDPR restricts except to permitted ones. They answer different questions.
Do your processor contracts impose obligations that satisfy DPDP as well as GDPR?