DPDP Rules 2025 notified. Core enforcement begins 14 May 2027 — less than 10 months away. Is your organisation ready?

Built for Indian Startups & SMEs

DPDP readiness made simple.

PrivPath helps Indian businesses understand the Digital Personal Data Protection Act, 2023 through an interactive self-assessment. Answer a few questions, evaluate your readiness, and get practical next steps to improve your privacy practices.

Up to
250 Cr
Max penalty per breach
9 categories
All scored independently
10 minutes
To complete the assessment
Free
No sign-up required
Who this is for

Built for the businesses that big compliance platforms ignore.

Enterprise DPDP tools cost lakhs, assume a team of lawyers, and are built for large corporates. PrivPath is built for founders, legal interns, compliance managers, and small teams who need to understand their obligations without wading through statutory text.

Early-stage startups
You collect user data from day one — consent, emails, payments. Know your obligations before a complaint is filed.
D2C and e-commerce businesses
Customer data, delivery addresses, payment history — all personal data under the Act. Check where you stand.
HealthTech, EdTech & FinTech
Sensitive personal data triggers stricter rules. Especially relevant for health records, financial data, and children's data.
Legal, compliance & HR teams
Use this as a structured first-pass assessment before engaging a consultant or briefing leadership on your readiness posture.
Why DPDP matters

India's data protection law is not optional.

Enforcement begins May 2027
The DPDP Rules 2025 were notified in November 2025. Enforcement kicks in May 2027. That's not a distant deadline — compliance infrastructure takes months to build.
Penalties are real and severe
Fines can reach up to ₹10 crore for procedural violations and up to ₹250 crore under the Schedule for data breaches caused by absent security measures. For a startup, even the lower end is devastating.
It applies to almost everyone
If you collect personal data of Indian residents — regardless of company size, sector, or whether you're Indian or foreign — the Act applies to you.
At stake
Up to
₹250
crore
Maximum per breach event under the Act.

The Data Protection Board determines actual penalties case-by-case under Section 33(2), considering severity, duration, repetition, and mitigating steps taken — these figures are statutory ceilings, not automatic fines.
Up to ₹250 crore — for breaches involving a failure to implement reasonable security safeguards (Schedule, Data Protection Board discretion)
Section 8(5) failure to implement reasonable security safeguards leading to a personal data breach. The highest penalty tier.
Up to ₹200 crore — for children's data violations (Schedule, Data Protection Board discretion)
Section 9 failure to protect minors' data or obtain verifiable parental consent before processing data of users under 18.
Up to ₹200 crore — for failure to notify the Data Protection Board of a personal data breach
Section 8(6) read with Rule 7(1) requires every Data Fiduciary to notify the Data Protection Board of a personal data breach without delay. Notification to affected Data Principals follows as a separate obligation under Rule 7(2), upon direction from the Board. Failure to comply with either stage exposes the Data Fiduciary to penalties under the Schedule.
Up to ₹50 crore — for consent and rights violations (Schedule, Data Protection Board discretion)
Invalid consent mechanisms, failure to honour withdrawal requests, and non-compliance with user access or erasure requests.
What you get

One tool. Everything a small business needs to start.

01
Plain-English questions
Every question is informed by the DPDP Act 2023, the DPDP Rules 2025, and the DPDPA.com 50-point compliance checklist by Adv. (Dr.) Prashant Mali.
02
Scored across 9 categories
Governance, consent, data rights, security, vendor management, breach response, and more — each category is scored independently so you know exactly where to focus.
03
Instant gap analysis
Your results highlight which areas are compliant, which have partial gaps, and which are critical risks — ordered by severity so you can prioritise.
04
Actionable remediation steps
Every gap comes with a specific, practical next step — not generic advice. You know what to do, not just what's wrong.
05
Maturity level rating
Your overall score maps to a 5-level compliance maturity model — from Initial to Excellent — so you can benchmark your progress over time.
06
100% free. No sign-up.
No email required, no account, no paywall. Built as a public resource for Indian startups and SMEs who need clear guidance without enterprise pricing.
Free self-assessment

Run your DPDP readiness check now.

Based on core statutory frameworks. Takes about 10 minutes.

Phase 2 deadline
Consent Manager ecosystem operational
Rule 4 · Section 6(9)For businesses using or operating a Consent Manager
--Days
--Hours
--Minutes
--Seconds
Phase 3
All obligations enforceable
Sections 3–17 · Rules 3 & 5–16Applies to all Data Fiduciaries processing personal data
--Days
--Hours
--Minutes
--Seconds
Note: Phase dates are administrative notifications under Section 1(2) of the Act and have historically been subject to deferral in Indian data-protection rulemaking. Dates are per recent gazette notifications, subject to change by future government notification.
PrivPath Assessment
Comprehensive diagnostic · 9 categories · ~10 minutes

Is your organisation DPDP ready?

Answer honestly — each question translates a legal obligation from the DPDP Act 2023 into plain language. Your results will show where you stand and exactly what to do next.

Questions are drawn from the DPDPA.com 50-Point Compliance Checklist 2026 by Adv. (Dr.) Prashant Mali. PrivPath is a self-assessment tool for DPDP readiness. It is not legal advice, a compliance certification, or a formal audit — consult a qualified legal professional before relying on these results for compliance decisions.

1. GovernanceLeadership, DPO, policy
2. SDF RiskScale, audits, DPIA
3. Data inventoryMapping, classification
4. Consent & basisCollection, withdrawal
5. Subject rightsAccess, erasure
6. SecurityEncryption, controls
7. Third partiesVendors, DPAs
8. BreachDetection, notification
9. AccountabilityRecords, privacy notice
100%
Blended scoring
9 areas
All scored separately
Free
No sign-up needed

Score guide

80–100 · Excellent 60–79 · Good with gaps 40–59 · Significant work needed 0–39 · Critical issues
Disclaimer: PrivPath is a self-assessment tool for DPDP readiness. It is not legal advice, a compliance certification, or a formal audit — consult a qualified legal professional before relying on these results for compliance decisions.
Category 1 of 9 ·

Maturity level
This score and these category labels reflect your self-reported answers, not a legal finding of compliance or non-compliance.
Category breakdown (lowest first)

Your personalised action plan

Common questions

Everything a founder needs to know.

Does the DPDP Act apply to my startup if we are small or early-stage?
Yes. The DPDP Act applies to any entity — regardless of size or revenue — that processes personal data of individuals in India. There is no small-business exemption. However, the government may notify different categories of Data Fiduciaries with scaled obligations, so it is worth tracking rules as they are released.
When does enforcement actually begin?
The DPDP Rules 2025 were notified in November 2025. Core enforcement is expected to begin on 14 May 2027. However, specific obligations may have earlier compliance deadlines, and a complaint can be filed against you from the date the relevant provision comes into force.
What is a Data Fiduciary, and am I one?
A Data Fiduciary is any person or entity that determines the purpose and means of processing personal data. If your organisation decides why and how personal data is collected and used — from customers, employees, or users — you are a Data Fiduciary and the DPDP Act's obligations apply to you directly.
Do I need to appoint a Data Protection Officer?
All Data Fiduciaries must designate an accountability owner for data protection. Significant Data Fiduciaries — a category to be formally notified by the government — will have additional requirements including a formal DPO, independent audits, and data protection impact assessments. For most startups, appointing an internal owner with a clear mandate is the starting point.
Is this tool's result legally sufficient for compliance certification?
No — and it does not claim to be. PrivPath is a self-assessment tool for DPDP readiness. It is not legal advice, a compliance certification, or a formal audit — consult a qualified legal professional before relying on these results for compliance decisions. Use the results to brief a lawyer or compliance professional, or to structure your internal compliance programme.
What should I do after completing the assessment?
Start with the critical gaps — categories marked red in your results. Each gap comes with a specific action. Prioritise: (1) appointing a compliance owner, (2) drafting a privacy notice, (3) conducting a data inventory, and (4) building a consent mechanism. Then engage a legal professional to review your documentation before enforcement begins.
KA
Kimaya Anavkar
LL.B. (Technology Law) · K.C. Law College, Mumbai · Legal Executive, Volody Products
I am a law graduate working at the intersection of legal expertise and product thinking. At Volody Products, I work on CLM model training, prompt engineering, and DPDP Act implementation. I have 15+ published research papers in AI governance and data privacy, NISM securities certifications, and a B.Com with a 9.32 CGPA. I built PrivPath because I noticed that Indian startups had no accessible, free way to understand what the DPDP Act actually required of them — only expensive enterprise tools or bare statutory text. This tool is my attempt to close that gap.
Why I built this
The problem I was solving
The DPDP Act 2023 creates real obligations for every Indian startup — but most small companies have no accessible way to understand what those obligations mean for their specific operations. Existing tools are built for enterprises with legal teams and compliance budgets. PrivPath is built for a founder, an ops manager, or a legal intern who needs to understand their gaps in plain English and know exactly what to fix.
What the tool is grounded in
Every question is informed by the DPDP Act 2023, the DPDP Rules 2025, and the DPDPA.com 50-point compliance checklist by Adv. (Dr.) Prashant Mali. The 50-point checklist is based on the official framework by Adv. (Dr.) Prashant Mali published on DPDPA.com. The phase commencement labels reflect the actual gazette notification (G.S.R. 846(E), MeitY, 13 November 2025). This is not a generic compliance quiz — it is grounded in the statute.
My background in this space
At Volody, I supported DPDP implementation research, drafted foundational compliance documentation, and assisted with data mapping workflows for their CLM platform. I have written and published research on AI governance, neuro-privacy, and digital regulation. PrivPath brings that legal knowledge into a tool anyone can use — no law degree required.
Credentials
Legal Executive Current role
Volody Products — CLM model training, prompt engineering, DPDP implementation
15+ Publications Research
AI governance, neuro-privacy, data protection law — national and international journals
NISM Certified Securities
Securities Markets Foundation & Securities Operations and Risk Management
DPDP Act — Key Terms Explained
Data Principal
The individual whose personal data is being collected or processed. In plain terms: your user, customer, employee, or anyone whose data you hold.
Section 2(j)
Data Fiduciary
Any person or organisation that decides why and how personal data is collected and used. If you run a business that collects user data, you are almost certainly a Data Fiduciary.
Section 2(i)
Data Processor
A third party that processes personal data on behalf of a Data Fiduciary — for example, a cloud storage provider, payroll company, or analytics platform. They follow your instructions; you remain accountable.
Section 2(k)
Significant Data Fiduciary (SDF)
A category of Data Fiduciary that the government may notify based on the volume or sensitivity of data processed, or the risk to data principals. SDFs face additional obligations including a mandatory DPO, annual audits, and data protection impact assessments.
Section 10
Consent Manager
An entity registered with the Data Protection Board that allows individuals to give, manage, review, and withdraw consent through a single platform. Businesses may use a Consent Manager instead of building their own consent infrastructure.
Section 2(g) and Rule 4
Data Protection Board
The regulatory body established under the Act to receive breach notifications, adjudicate complaints, and impose penalties. This is the authority you must notify in the event of a personal data breach.
Section 18
Processing
Any operation performed on personal data — collection, storage, use, sharing, disclosure, deletion, or destruction. The Act's obligations apply to all of these activities, not just collection.
Section 2(x)
Run assessment