DPDP Act Readiness
ACH / DPDP
Authorised methodology · CERT-In aligned

Gap assessment, data-flow mapping, and consent audit — evidence your board and Indian regulators actually accept.

Get started
  • Consent architecture review
  • Cross-border transfer logging
  • DPO advisory + incident playbooks
DPDP Act 2023 — India

Non-compliance is no longer a calculated risk.

The Digital Personal Data Protection Act carries penalties that can end a company. Enforcement begins when rules are notified — and readiness takes 6–12 months.

₹250 Cr
maximum penalty for failure to implement adequate security safeguards
₹250 Cr
Security Safeguards

Failure to implement and maintain reasonable security measures to protect personal data.

₹200 Cr
Breach Notification

Failure to notify the Data Protection Board and affected users in the event of a data breach.

₹200 Cr
Children's Data

Processing data of minors without verified parental consent. Critical for edtech, gaming, and consumer apps.

₹50 Cr
Other Obligations

Breach of consent, notice, data principal rights, or cross-border transfer requirements.

The 8 obligations every company must meet
01
Lawful consent

Explicit, specific, informed consent before collecting any personal data. No pre-ticked boxes.

02
Notice

Plain-language notice of what data, why, how long, and who it's shared with — before collection.

03
Data Principal Rights

Working mechanisms for users to access, correct, erase data and raise grievances within 30 days.

04
Security safeguards

Reasonable technical and organisational measures. A completed VAPT is your strongest evidence here.

05
Breach notification

Mandatory notification to the Data Protection Board and affected users within the prescribed timeline.

06
Children's data

Verified parental consent for under-18s. No tracking or behavioural targeting of children's data.

07
Cross-border transfers

Data can only be transferred to government-approved countries. Most companies are currently exposed here.

08
Data Fiduciary duties

Significant Data Fiduciaries face additional requirements: DPO appointment, DPIA, regular audits.

Get your DPDP gap assessment Most companies take 6–12 months to reach readiness. Start now.
ComplyScan · Free assessment

Get Your DPDP Compliance Score in 2 Minutes

ComplyScan asks a handful of quick questions across all 8 DPDP obligations, cited to the exact section of the Act — then hands you an instant risk score, a scored PDF report, and your recommended next step. Not legal advice.

Learn more about ComplyScan →