India's Data Protection Law — Now Enforceable

Are you ready for the
DPDP Act, 2023?

The Digital Personal Data Protection Act is India's first comprehensive data privacy law. Non-compliance carries penalties of up to ₹250 crore. Self-assessment is a powerful way to move forward quickly — know exactly where you stand in under 30 minutes, no consultant required to get started.

Plans start at ₹24,999* for a self-serve assessment — or step up to guided consulting and full remediation support. See plans ↓
*Plus GST as applicable.
Full DPDP Act compliance deadline — 13 May 2027: calculating…
109
Checkpoints
15
Compliance Domains
3
Plan Tiers
₹250Cr
Max Penalty
One assessment engine, three levels of support

Start with a fast, self-serve checklist — no consultant required to see where you stand. When you're ready to close the gaps, step up to a plan that pairs your results with expert consulting, and if you want it, hands-on support until you're actually compliant, not just assessed.

ASWS — Self-Assessment
109 checkpoints, 15 domains, instant gap report. From ₹24,999.
FI — + Expert Consulting
1 × 60-minute session to interpret your gaps and re-test. From ₹49,999.
CI — + Full Remediation
Hands-on support until you're actually compliant. From ₹1,49,999.
Your risk isn't in one place

Personal data doesn't live in a single, tidy database. It's spread across your website, your CRM, WhatsApp conversations with customers, spreadsheets HR keeps "just for now," and every vendor you've ever handed a customer list to.

Most teams have a good handle on the obvious systems — and a genuine blind spot on the messy, informal ones. The assessment maps both, so nothing gets missed when the Board asks where your data actually is.

Website
Forms, cookies, tracking
Usually on the radar
CRM
Profiles, activity logs
Usually on the radar
WhatsApp & chats
Customer conversations
Common blind spot
Vendors
Third-party processors
Common blind spot
Spreadsheets
Ad-hoc exports, lists
Common blind spot
HR & Finance
Payroll, employee data
Usually on the radar
Personal Data
across every system
What is the DPDP Act?

The Digital Personal Data Protection Act, 2023 (DPDP Act) was enacted by the Parliament of India in August 2023 and the DPDP Rules, 2025 were notified in November 2025. It is India's first comprehensive legislation governing how organisations collect, store, process, and share the personal data of individuals.

The law applies to any entity — Indian or foreign — that processes the digital personal data of individuals located in India. This means even a company headquartered outside India must comply if it handles data of Indian residents.

The Act creates a new regulatory body, the Data Protection Board of India (DPB), which is empowered to investigate complaints, conduct audits, and levy financial penalties on non-compliant organisations.

Who must comply?
Every business in India
Any company, LLP, trust, or government body that collects or processes digital personal data of individuals in India.
Foreign companies too
Organisations outside India that profile, target, or process data of Indian residents are covered.
Healthcare, FinTech & EdTech
Sectors handling sensitive data face stricter scrutiny — health, financial, and children's data attract higher safeguards.
Significant Data Fiduciaries
Large-scale processors designated by the government face additional obligations: DPO, DPIA, data audits.
Key Obligations under the DPDP Act

What every Data Fiduciary must do to comply

S.5 Up to ₹50 Cr
Notice to Data Principals
Before or while collecting personal data, you must provide a clear notice in plain language explaining what data is collected, the purpose, and how to exercise rights.
S.6 Up to ₹50 Cr
Consent Management
Consent must be free, specific, informed, unconditional, and unambiguous. Bundled or pre-ticked consent is prohibited. (Consent Manager registration by Nov 2026 applies only to entities operating as a Consent Manager — not a general obligation.)
S.7 Up to ₹50 Cr
Legitimate Uses
Processing without consent is allowed only for narrow legitimate uses — employment, medical emergency, State functions, legal proceedings. Each use is strictly defined.
S.8 Up to ₹250 Cr
Security Safeguards
Implement reasonable security measures proportionate to the data processed. Prevent breaches through technical and organisational controls.
S.8(6) Up to ₹200 Cr
Breach Notification
Notify the Data Protection Board and all affected data principals of every personal data breach — no threshold, no delay.
S.9 Up to ₹200 Cr
Children's Data
Verifiable parental/guardian consent required before processing data of anyone under 18. Behavioural tracking and targeted advertising to minors are banned.
S.11 Up to ₹50 Cr
Data Principal Rights
Individuals have the right to access their data, correct inaccuracies, erase data, nominate a successor, and raise grievances. You must respond within prescribed timelines.
S.10 Up to ₹150 Cr
SDF Obligations
Government-designated Significant Data Fiduciaries must appoint a Data Protection Officer, conduct Data Protection Impact Assessments, and undergo periodic audits.
Enforcement Timeline

Key dates your compliance team must track.

Aug 2023 — DPDP Act enacted
Parliament passed the Act. Foundation of India's data protection framework.
Nov 2025 — Rules notified — Board operational
DPDP Rules, 2025 gazetted. Data Protection Board of India becomes operational.
Nov 2026 — Consent Manager provisions in force
Rule 4 comes into force — the Consent Manager registration/obligations framework applies to eligible entities.
May 2027 — Core provisions enforceable
Core DPDP Act sections and Rules 3, 5-16, 22 and 23 become enforceable.
Penalty Schedule

Financial penalties under the DPDP Act Schedule

Section Violation Max Penalty
S.8(5) Failure to implement security safeguards ₹250 Crore
S.8(6) / S.9 Breach notification failure / Children's data ₹200 Crore
S.10 Significant Data Fiduciary obligations ₹150 Crore
S.5 / S.6 / S.7 Notice, consent and legitimate use violations ₹50 Crore
S.11 Data principal rights violations ₹50 Crore
Other Non-compliance with Board directions / other ₹50 Crore
How It Works

Every plan starts the same way — the checkpoints are identical, the level of support is what changes

1
Register & Profile
Create a free account and answer a short profile questionnaire — your sector, scale, whether you process children's data, and SDF eligibility. Takes under 2 minutes.
2
Choose Your Plan
Pick ASWS, FI, or CI based on how much support you need — plans start at ₹24,999. Work through 109 checkpoints across 15 compliance domains at your own pace. Save and resume anytime.
3
Download Your Gap Report
Every plan includes a prioritised gap report with penalty-exposure analysis, phased remediation roadmap, and domain scorecards. Download as PDF, share with your team.
4
Get Expert Support
FI and CI plans include live consulting with our compliance team to interpret your gaps — CI adds hands-on remediation support until you're actually compliant.
15 Compliance Domains Assessed

Every domain maps directly to sections of the DPDP Act and Rules

Governance & Accountability
Data Inventory & Classification
Consent Management
Notice & Transparency
Data Minimisation & Purpose Limitation
Security Safeguards
Breach Notification
Data Principal Rights
Children's Data Protection
Significant Data Fiduciary (SDF)
Cross-Border Data Transfers
Grievance Redressal
Vendor & Third-Party Management
Training & Awareness
Record Keeping & Audit
Three Report Tiers — One Assessment

Every report is generated from the same data — tailored for different audiences

CXO / Board Dashboard
For leadership and the board
  • Overall maturity score (Level 1–5)
  • Penalty-exposure heat map
  • Top 10 critical gaps
  • Enforcement deadline tracker
  • Executive summary for board packs
Mid-Management Report
For compliance & legal teams
  • Domain-by-domain scorecard
  • Function-level action plan
  • Phased remediation roadmap
  • Responsibility mapping (HR, IT, Legal…)
  • Quick-win vs. long-term gap split
Full Gap Register
For implementation teams
  • All 109 checkpoints with responses
  • Notes & evidence references
  • Priority score per gap (Critical / High / Medium)
  • DPDP Act section cross-reference
  • Enforceable-from dates per item
All reports available as interactive HTML and downloadable PDF
Free, no assessment required

Not ready for a full assessment? Start with the free handbook.

Penalty exposure by violation category, DPDP applicability flowcharts, a breach-response runbook for the 72-hour notification deadline, and a retention schedule cross-referenced against Indian tax and company law — 11 pages, emailed instantly.

Choose the right level of support for your compliance journey

From a quick self-assessment to fully guided remediation — every plan is built around the DPDP Act, so you know exactly where you stand and what to fix next.

ASWS

As Is Where Is

A fast, do-it-yourself readiness check against DPDP requirements — as-is, where-is.

₹49,999 50% off
₹24,999
Inclusive of all taxes
  • Full DPDP self-assessment
  • 1 assessment attempt
  • As-is, where-is scoring — no rework cycles
  • Instant gap report
Start Assessment
CI

Comprehensive Intervention

Our most complete offering — hands-on support until you're actually DPDP-compliant, not just assessed.

₹300,000 50% off
₹149,999
Inclusive of all taxes
  • Full DPDP self-assessment
  • 5 assessment attempts
  • 2 x 60-minute expert consultations
  • Full remediation support end-to-end
  • Email support
  • 3 weeks of callback support, up to 10 hours
Get Full Support

Not sure which plan fits your organisation? Talk to our compliance team →

Frequently Asked Questions

About the DPDP Act, and about this assessment

Any company, LLP, trust, or government body that collects or processes the digital personal data of individuals in India — regardless of sector or size. Organisations handling sensitive categories such as health, financial, or children’s data face additional obligations and scrutiny.

Yes. The Act applies to any entity — Indian or foreign — that processes the digital personal data of individuals located in India, including profiling them or offering them goods and services. Where you’re incorporated doesn’t matter; where your data principals are located does.

The DPDP Act, 2023 is the primary legislation passed by Parliament — it sets out rights, obligations, and the penalty structure. The DPDP Rules, 2025, notified in November 2025, fill in operational detail: breach-notice formats, Consent Manager registration, DPIA requirements for SDFs, and more. You need to comply with both.

Penalties are set out in the Schedule to the Act and scale by violation type — up to ₹250 crore for failing to implement reasonable security safeguards (S.8(5)), up to ₹200 crore for breach-notification failures or children’s-data violations, up to ₹150 crore for Significant Data Fiduciary non-compliance, and up to ₹50 crore for notice, consent, and data-principal-rights violations. See the Penalty Schedule above for the full breakdown.

An SDF is a Data Fiduciary the Central Government designates, by notification, based on factors like the volume and sensitivity of data processed and the risk to data principals. SDFs carry extra obligations — appointing a DPO, conducting Data Protection Impact Assessments, and undergoing periodic data audits (S.10, Rule 13). The assessment’s profile step asks about your sector, scale, and the data you process to flag likely SDF exposure — final designation is made by government notification, not by this tool.

A DPO is a mandatory appointment for Significant Data Fiduciaries. Organisations that aren’t (yet) designated SDFs aren’t required to appoint one under the Act, though many designate a privacy point of contact as good practice ahead of time.

The Act was enacted in August 2023, and the Rules were notified in November 2025, bringing the Data Protection Board of India online. Consent Manager provisions (Rule 4) come into force on 13 November 2026, and core DPDP Act sections and Rules 3, 5-16, 22 and 23 become enforceable on 13 May 2027. See the Enforcement Timeline above for the complete schedule.

Most organisations complete the profile step and all 109 checkpoints in under 30 minutes of focused work. Your progress saves automatically, so you can pause and pick up exactly where you left off — there’s no need to finish in one sitting.

All three plans run the same 109-checkpoint, 15-domain assessment, so your underlying results are identical — the difference is the support layered on top. ASWS (As Is Where Is) is self-serve: complete the assessment and download your gap report. FI (First Intervention) adds a live session with our compliance team to walk through your gaps. CI (Comprehensive Intervention) adds hands-on remediation support until you’re actually compliant, not just assessed. Plans start at ₹24,999.

Yes. Your responses, notes, and evidence references are used solely to generate your reports and aren’t shared with third parties. Aptus Software Labs acts as a data processor for this information, not a data controller — see our Privacy Notice for full detail on what’s collected and how it’s handled.

Yes — every plan includes a downloadable PDF report, and you can generate the CXO/Board tier, the Mid-Management tier, or the Full Gap Register depending on the audience. See Report Tiers above.

No. This is an informational self-assessment readiness tool only — it doesn’t constitute legal advice. The scoring model, priority ranking, and maturity bands are Aptus Software Labs’ own design, not endorsed by or sourced from the Data Protection Board of India or any regulator. Your organisation remains solely responsible for its own compliance; we’d recommend involving legal counsel before relying on any output for a regulatory submission.

Know your DPDP posture today

Plans start at ₹24,999* — from a fast self-serve assessment to fully guided remediation. Takes 30 minutes to start. Get a boardroom-ready gap report with penalty-exposure analysis and a phased remediation roadmap.

*Plus GST as applicable. See plan details.

Informational readiness tool only — not legal advice. Aptus Software Labs, Bengaluru.