SEC. 4(1) · APPLICABILITY Free · No signup required · Results in 2 minutes

Free DPDP Compliance Checker

Answer 6 questions. Know exactly where you stand under India's DPDP Act 2023.

Question of 6

Where is your business registered or primarily operating?

Do you collect personal data from customers?

Personal data includes: name, phone number, email, address, payment info, purchase history, location

How do you primarily collect customer data?

How many customers' data do you approximately hold?

Do any of your customers include children under 18?

E.g., schools, coaching centres, EdTech, gaming apps, children's products

Do you share customer data with any third-party services?

E.g., payment gateways (Razorpay, Paytm), delivery companies (Shiprocket, Dunzo), CRMs, email tools, ad platforms

DPDP Likely Does Not Apply to You

Based on your answers, the DPDP Act 2023 does not currently apply to your business.

Why?

Not legal advice. If your business activities change, reassess immediately.

📋

Likely Not Covered — But Verify

Paper-only data that is never digitised is generally not covered under the DPDP Act. However, as soon as any data enters a phone, computer, or software — compliance obligations begin.

⚠️ Be Careful

If anyone in your business photographs a form, enters data into Excel, WhatsApp, or billing software — even once — you become covered under Section 3(a)(ii) of the DPDP Act.

Join early access

Yes — DPDP Compliance is Mandatory for Your Business

You must be compliant by May 13, 2027

DPDP Act Section That Applies to You

Your Compliance Obligations

1

Obtain free, informed, specific consent before collecting data

Consent notice must state exactly what data is collected and why (DPDP Act Section 6)

2

Publish a Privacy Notice

Must list data collected, purposes, third parties, and how customers can exercise their rights

3

Handle customer data requests

Customers can request access, correction, or deletion of their data at any time

4

Report breaches on the legal clock

Tell affected customers and the Data Protection Board without delay, with the detailed Board report within 72 hours

5

Sign Data Processing Agreements with third parties

As a Data Fiduciary sharing data with processors (Razorpay, Shiprocket etc.), you're responsible for their compliance

Children's Data — Extra Obligations Apply

  • • Parental consent required before processing data of anyone under 18
  • • Must verify parent's identity (DigiLocker age token recommended)
  • • Cannot serve targeted advertising to children
  • • Cannot track or monitor children's behaviour

Penalty for violation: Up to ₹200 Crore

Your Penalty Exposure

₹250 Cr

Data breach (failure to protect)

₹200 Cr

Failure to notify breach

₹200 Cr

Children's data violation

₹50 Cr

Other compliance violations

Your Risk Level

EasyDP Gets You Compliant in 30 Minutes

Consent management, DSR ticketing, multilingual notifications — all in one platform built specifically for India's DPDP Act.

Join early access →

How the checker works

Each of the six questions maps directly to a provision of the DPDP Act 2023, and your result cites the sections that apply to you:

  • Q1–Q2Where you operate and what you collect test the Act's basic scope — it covers digital personal data processed in India, and processing abroad connected to offering goods or services to people in India (Section 3).
  • Q3How you collect matters because paper records that get typed into any software are covered too — "offline" businesses usually aren't outside the Act (Section 3).
  • Q4Customer volume feeds the risk picture — scale is among the factors the government weighs when designating Significant Data Fiduciaries with extra duties (Section 10).
  • Q5Children under 18 trigger verifiable parental consent and the ban on tracking and targeted ads at children — the ₹200 crore penalty tier (Section 9, Rule 10 of the DPDP Rules 2025).
  • Q6Third-party sharing tests your processor exposure — you stay responsible for what vendors do with your customers' data, so those contracts need data-protection terms (Section 8(2)).

What your result means

Covered: the Act applies to you. Your result lists the sections behind that conclusion and your penalty exposure — up to ₹250 crore for failing security safeguards under the Schedule to the Act. Your next step is the interactive DPDP compliance checklist: 14 steps, in order, with citations.

Higher-risk covered: children's data, large volumes, or sensitive sharing put you in the strictest tiers. Start with those steps first — they carry the biggest penalties and take the longest to fix.

Likely not covered: rare in practice — usually purely personal use or no digital data at all. Re-check if you digitise anything: coverage follows the data, not the business type (details in our applicability guide).

Common questions

Yes — free, no signup, no credit card. It exists so any Indian business can find out where it stands under the DPDP Act in two minutes. EasyDP makes money from its paid compliance platform, not from the checker.