Answer 6 questions. Know exactly where you stand under India's DPDP Act 2023.
Personal data includes: name, phone number, email, address, payment info, purchase history, location
E.g., schools, coaching centres, EdTech, gaming apps, children's products
E.g., payment gateways (Razorpay, Paytm), delivery companies (Shiprocket, Dunzo), CRMs, email tools, ad platforms
Based on your answers, the DPDP Act 2023 does not currently apply to your business.
Why?
Not legal advice. If your business activities change, reassess immediately.
Paper-only data that is never digitised is generally not covered under the DPDP Act. However, as soon as any data enters a phone, computer, or software — compliance obligations begin.
⚠️ Be Careful
If anyone in your business photographs a form, enters data into Excel, WhatsApp, or billing software — even once — you become covered under Section 3(a)(ii) of the DPDP Act.
You must be compliant by May 13, 2027
Obtain free, informed, specific consent before collecting data
Consent notice must state exactly what data is collected and why (DPDP Act Section 6)
Publish a Privacy Notice
Must list data collected, purposes, third parties, and how customers can exercise their rights
Handle customer data requests
Customers can request access, correction, or deletion of their data at any time
Report breaches on the legal clock
Tell affected customers and the Data Protection Board without delay, with the detailed Board report within 72 hours
Sign Data Processing Agreements with third parties
As a Data Fiduciary sharing data with processors (Razorpay, Shiprocket etc.), you're responsible for their compliance
Penalty for violation: Up to ₹200 Crore
₹250 Cr
Data breach (failure to protect)
₹200 Cr
Failure to notify breach
₹200 Cr
Children's data violation
₹50 Cr
Other compliance violations
Consent management, DSR ticketing, multilingual notifications — all in one platform built specifically for India's DPDP Act.
Join early access →Each of the six questions maps directly to a provision of the DPDP Act 2023, and your result cites the sections that apply to you:
Covered: the Act applies to you. Your result lists the sections behind that conclusion and your penalty exposure — up to ₹250 crore for failing security safeguards under the Schedule to the Act. Your next step is the interactive DPDP compliance checklist: 14 steps, in order, with citations.
Higher-risk covered: children's data, large volumes, or sensitive sharing put you in the strictest tiers. Start with those steps first — they carry the biggest penalties and take the longest to fix.
Likely not covered: rare in practice — usually purely personal use or no digital data at all. Re-check if you digitise anything: coverage follows the data, not the business type (details in our applicability guide).
Yes — free, no signup, no credit card. It exists so any Indian business can find out where it stands under the DPDP Act in two minutes. EasyDP makes money from its paid compliance platform, not from the checker.