Gap assessment, data-flow mapping, and consent audit — evidence your board and Indian regulators actually accept.
Get started- Consent architecture review
- Cross-border transfer logging
- DPO advisory + incident playbooks
Non-compliance is no longer a calculated risk.
The Digital Personal Data Protection Act carries penalties that can end a company. Enforcement begins when rules are notified — and readiness takes 6–12 months.
Failure to implement and maintain reasonable security measures to protect personal data.
Failure to notify the Data Protection Board and affected users in the event of a data breach.
Processing data of minors without verified parental consent. Critical for edtech, gaming, and consumer apps.
Breach of consent, notice, data principal rights, or cross-border transfer requirements.
Explicit, specific, informed consent before collecting any personal data. No pre-ticked boxes.
Plain-language notice of what data, why, how long, and who it's shared with — before collection.
Working mechanisms for users to access, correct, erase data and raise grievances within 30 days.
Reasonable technical and organisational measures. A completed VAPT is your strongest evidence here.
Mandatory notification to the Data Protection Board and affected users within the prescribed timeline.
Verified parental consent for under-18s. No tracking or behavioural targeting of children's data.
Data can only be transferred to government-approved countries. Most companies are currently exposed here.
Significant Data Fiduciaries face additional requirements: DPO appointment, DPIA, regular audits.
Get Your DPDP Compliance Score in 2 Minutes
ComplyScan asks a handful of quick questions across all 8 DPDP obligations, cited to the exact section of the Act — then hands you an instant risk score, a scored PDF report, and your recommended next step. Not legal advice.