DPDP Rules 2025 notified. Core enforcement begins 13 May 2027 — less than 10 months away. Is your organisation ready?

Built for Indian Startups & SMEs

DPDP compliance made simple.

PrivPath helps Indian businesses understand the Digital Personal Data Protection Act, 2023 through an interactive self-assessment. Answer a few questions, evaluate your compliance readiness, and get practical next steps to improve your privacy practices.

250 Cr
Max penalty per breach
50 obligations
Mapped across 8 categories
10 minutes
To complete the assessment
Free
No sign-up required
Who this is for

Built for the businesses that big compliance platforms ignore.

Enterprise DPDP tools cost lakhs, assume a team of lawyers, and are built for large corporates. PrivPath is built for founders, legal interns, compliance managers, and small teams who need to understand their obligations without wading through statutory text.

Early-stage startups
You collect user data from day one — consent, emails, payments. Know your obligations before a complaint is filed.
D2C and e-commerce businesses
Customer data, delivery addresses, payment history — all personal data under the Act. Check where you stand.
HealthTech, EdTech & FinTech
Sensitive personal data triggers stricter rules. Especially relevant for health records, financial data, and children's data.
Legal, compliance & HR teams
Use this as a structured first-pass audit before engaging a consultant or briefing leadership on your compliance posture.
Why DPDP matters

India's data protection law is not optional.

Enforcement begins May 2027
The DPDP Rules 2025 were notified in November 2025. Enforcement kicks in May 2027. That's not a distant deadline — compliance infrastructure takes months to build.
Penalties are real and severe
Fines range from ₹10 crore for procedural violations to ₹250 crore for data breaches caused by absent security measures. For a startup, even the lower end is devastating.
It applies to almost everyone
If you collect personal data of Indian residents — regardless of company size, sector, or whether you're Indian or foreign — the Act applies to you.
At stake
₹250
crore
Maximum per breach event under the Act
₹250 crore — Data breach due to absent security
Section 8(5) failure to implement reasonable security safeguards leading to a personal data breach. The highest penalty tier.
₹200 crore — Children's data violations
Section 9 failure to protect minors' data or obtain verifiable parental consent before processing data of users under 18.
₹50 crore — Breach notification failures
Failure to notify the Data Protection Board and affected users after a confirmed personal data breach within the statutory timeline.
₹10–50 crore — Consent and rights violations
Invalid consent mechanisms, failure to honour withdrawal requests, and non-compliance with user access or erasure requests.
What you get

One tool. Everything a small business needs to start.

01
Plain-English questions
Every question is drawn from the official 50-point DPDPA compliance checklist, translated into language any non-lawyer can understand and honestly answer.
02
Scored across 8 categories
Governance, consent, data rights, security, vendor management, breach response, and more — each category is scored independently so you know exactly where to focus.
03
Instant gap analysis
Your results highlight which areas are compliant, which have partial gaps, and which are critical risks — ordered by severity so you can prioritise.
04
Actionable remediation steps
Every gap comes with a specific, practical next step — not generic advice. You know what to do, not just what's wrong.
05
Maturity level rating
Your overall score maps to a 5-level compliance maturity model — from Initial to Excellent — so you can benchmark your progress over time.
06
100% free. No sign-up.
No email required, no account, no paywall. Built as a public resource for Indian startups and SMEs who need clear guidance without enterprise pricing.
Free self-assessment

Run your DPDP compliance check now.

Based on the official 50-point checklist. Takes about 10 minutes.

PrivPath Assessment
50-point · 8 categories · ~10 minutes

Is your organisation DPDP compliant?

Answer honestly — each question translates a legal obligation from the DPDP Act 2023 into plain language. Your results will show where you stand and exactly what to do next.

Questions are drawn from the DPDPA.com 50-Point Compliance Checklist 2026 by Adv. (Dr.) Prashant Mali. For self-assessment only — not formal legal advice.

1. GovernanceLeadership, DPO, policy
2. Data inventoryMapping, classification
3. Consent & basisCollection, withdrawal
4. Subject rightsAccess, erasure, portability
5. Technical securityEncryption, access control
6. Third partiesVendors, DPAs, audits
7. Breach responseDetection, notification
8. DocumentationRecords, privacy notice
50 pts
Official checklist
8 areas
All scored separately
Free
No sign-up needed

Score guide

80–100 · Excellent 60–79 · Good with gaps 40–59 · Significant work needed 0–39 · Critical issues
Category 1 of 8 ·

Maturity level
Category breakdown (lowest first)
Common questions

Everything a founder needs to know.

Does the DPDP Act apply to my startup if we are small or early-stage?
Yes. The DPDP Act applies to any entity — regardless of size or revenue — that processes personal data of individuals in India. There is no small-business exemption. However, the government may notify different categories of Data Fiduciaries with scaled obligations, so it is worth tracking rules as they are released.
When does enforcement actually begin?
The DPDP Rules 2025 were notified in November 2025. Core enforcement is expected to begin on 13 May 2027. However, specific obligations may have earlier compliance deadlines, and a complaint can be filed against you from the date the relevant provision comes into force.
What is a Data Fiduciary, and am I one?
A Data Fiduciary is any person or entity that determines the purpose and means of processing personal data. If your organisation decides why and how personal data is collected and used — from customers, employees, or users — you are a Data Fiduciary and the DPDP Act's obligations apply to you directly.
Do I need to appoint a Data Protection Officer?
All Data Fiduciaries must designate an accountability owner for data protection. Significant Data Fiduciaries — a category to be formally notified by the government — will have additional requirements including a formal DPO, independent audits, and data protection impact assessments. For most startups, appointing an internal owner with a clear mandate is the starting point.
Is this tool's result legally sufficient for compliance sign-off?
No — and it does not claim to be. PrivPath is a self-assessment tool designed to help you understand your obligations and identify gaps. It is not a substitute for legal advice or a formal compliance audit. Use the results to brief a lawyer or compliance professional, or to structure your internal compliance programme.
What should I do after completing the assessment?
Start with the critical gaps — categories marked red in your results. Each gap comes with a specific action. Prioritise: (1) appointing a compliance owner, (2) drafting a privacy notice, (3) conducting a data inventory, and (4) building a consent mechanism. Then engage a legal professional to review your documentation before enforcement begins.
Run assessment