SEC. 4(1) · APPLICABILITY Free · No signup required · Results in 2 minutes

Free DPDP Compliance Checker

Answer 6 questions. Know exactly where you stand under India's DPDP Act 2023.

Question of 6

Where is your business registered or primarily operating?

Do you collect personal data from customers?

Personal data includes: name, phone number, email, address, payment info, purchase history, location

How do you primarily collect customer data?

How many customers' data do you approximately hold?

Do any of your customers include children under 18?

E.g., schools, coaching centres, EdTech, gaming apps, children's products

Do you share customer data with any third-party services?

E.g., payment gateways (Razorpay, Paytm), delivery companies (Shiprocket, Dunzo), CRMs, email tools, ad platforms

Press Enter for the next question

DPDP Likely Does Not Apply to You

Based on your answers, the DPDP Act 2023 does not currently apply to your business.

Why?

Not legal advice. If your business activities change, reassess immediately.

📋

Likely Not Covered — But Verify

Paper-only data that is never digitised is generally not covered under the DPDP Act. However, as soon as any data enters a phone, computer, or software — compliance obligations begin.

⚠️ Be Careful

If anyone in your business photographs a form, enters data into Excel, WhatsApp, or billing software — even once — you become covered under Section 3(a)(ii) of the DPDP Act.

Join early access

Yes — DPDP Compliance is Mandatory for Your Business

You must be compliant by May 13, 2027

DPDP Act Section That Applies to You

Your Compliance Obligations

1

Obtain free, informed, specific consent before collecting data

Consent notice must state exactly what data is collected and why (DPDP Act Section 6)

2

Publish a Privacy Notice

Must list data collected, purposes, third parties, and how customers can exercise their rights

3

Handle customer data requests

Customers can request access, correction, or deletion of their data at any time

4

Report breaches on the legal clock

Tell affected customers and the Data Protection Board without delay, with the detailed Board report within 72 hours

5

Sign Data Processing Agreements with third parties

As a Data Fiduciary sharing data with processors (Razorpay, Shiprocket etc.), you're responsible for their compliance

Your First Document

Obligation 1 needs a consent notice: the short written notice that goes with the consent request, saying what you collect and why. The free consent notice generator fills one in from your business details, in English or your customer's own language. Obligation 2 is a separate, longer privacy notice you publish on your site. Then work through the 14-step compliance checklist.

Children's Data — Extra Obligations Apply

  • • Parental consent required before processing data of anyone under 18
  • • Must check the parent is an adult — using details you already hold, details they give you, or a virtual token from an authorised entity (that third route is not yet operational: it needs a government notification that has not issued)
  • • Cannot serve targeted advertising to children
  • • Cannot track or monitor children's behaviour

Penalty for violation: Up to ₹200 Crore

Work out exactly which of these apply to you — and whether a Fourth Schedule exemption covers your school, clinic or crèche — with the free children's data check.

Your Penalty Exposure

₹250 Cr

Data breach (failure to protect)

₹200 Cr

Failure to notify breach

₹200 Cr

Children's data violation

₹50 Cr

Other compliance violations

Your Risk Level

EasyDP Gets You Compliant in 30 Minutes

Consent management, DSR ticketing, multilingual notifications — all in one platform built specifically for India's DPDP Act.

Join early access →

How the checker works

Each of the six questions maps directly to a provision of the DPDP Act 2023, and your result cites the sections that apply to you:

What your result means

Covered: the Act applies to you. Your result lists the sections behind that conclusion and your penalty exposure — up to ₹250 crore for failing security safeguards under the Schedule to the Act. Your next step is the interactive DPDP compliance checklist: 14 steps, in order, with citations.

Higher-risk covered: children's data, large volumes, or sensitive sharing put you in the strictest tiers. Start with those steps first — they carry the biggest penalties and take the longest to fix.

Likely not covered: rare in practice — usually purely personal use or no digital data at all. Re-check if you digitise anything: coverage follows the data, not the business type (details in our applicability guide).

Common questions

Is the DPDP checker really free?

Yes — free, no signup, no credit card. It exists so any Indian business can find out where it stands under the DPDP Act in two minutes. EasyDP makes money from its paid compliance platform, not from the checker.

Does the checker store my answers?

No. Your answers are processed in your browser to compute the result and are not sent to our servers or stored anywhere. Close the tab and they're gone.

Is the checker's result legal advice?

No. It's an educational assessment based on the DPDP Act 2023 and DPDP Rules 2025 as notified. It tells you which provisions likely apply so you can act early — for a formal legal opinion on unusual situations, consult a professional.

How does the checker decide whether the Act applies to me?

It applies the tests in the law itself: territorial scope and digital collection (Section 3), children's data obligations (Section 9), sharing with third parties (Section 8(2)), and scale factors relevant to Significant Data Fiduciary designation (Section 10). Each answer maps to a provision, and your result cites them.

What should I do after getting my result?

Work through the interactive DPDP compliance checklist — 14 steps from data mapping to documentation, with citations. If you'd rather have the ongoing work automated, see what the EasyDP platform covers.