Free tool
DPDP Readiness Score
Ten questions covering the obligations the Data Protection Board will actually test. Answer honestly — the gaps you find here are the ones an auditor finds later.
1.Do you show users a notice explaining each purpose before collecting their data?
2.Do you take separate consent per purpose (not one bundled 'I agree')?
3.Can users withdraw consent as easily as they gave it?
4.Do you keep a record of WHO consented, to WHAT purpose, WHEN, and against WHICH notice text?
5.Can your marketing/CRM tools check consent validity BEFORE contacting a user?
6.Do you have a process for access / correction / erasure requests with tracked deadlines?
7.Are your notices available in the Indian languages your users actually speak?
8.If a notice or purpose changes, do you re-collect consent from affected users?
9.Could you hand an auditor a complete evidence file within one day?
10.Do you know every internal system that stores personal data (for erasure requests)?