Skip to main content
Free tool

DPDP readiness check

The Digital Personal Data Protection Act applies to organisations handling the personal data of people in India. Most coverage of it has been legal. This is the operational version: what has to change in your systems, checked against where you currently stand.

It is not legal advice and does not attempt to be. It covers the engineering half of the problem, which is the half that usually turns out to be missing.

Free, no sign-up, and nothing you enter leaves your browser. There is no server behind this page.

Knowing what you hold

  • Can you list every system that holds personal data, and what it holds?

    Including spreadsheets, shared mailboxes and old file shares, not just the CRM.

  • Is each collection of personal data tied to a stated purpose?

    Purpose limitation is the principle most operational practice quietly ignores.

  • Do you know which third parties process personal data on your behalf?

    Processors are your responsibility, including the ones a department bought directly.

Protecting it

  • Does every person accessing personal data use a named account?

    Shared reception, counter or clinic logins defeat the audit trail entirely.

  • Is encryption verified on endpoints and backups, rather than assumed?

    A lost unencrypted laptop is a reportable event; an encrypted one usually is not.

  • Is access to personal data limited to those who genuinely need it?

    Access granted for a previous role and never removed is the usual cause of sprawl.

Responding

  • Could you find everything you hold about one person, across every system?

    The data map is what makes this achievable within a reasonable time.

  • Can you delete a person’s data when required, including from backups?

    Deletion that leaves copies behind is not deletion.

  • Is there a retention policy that actually deletes rather than just describing deletion?

    Keeping everything forever enlarges every breach you might ever have.

Breach readiness

  • Would you detect a breach involving personal data?

    You cannot notify what you never noticed.

  • Is there a documented breach process with named decision-makers?

    Deciding who notifies during an incident wastes the hours that matter.

  • Are logs retained long enough to reconstruct what happened?

    A breach you cannot describe is a breach you cannot notify accurately.

What the Act asks for, operationally

Know what personal data you hold and why. Limit its use to the purpose it was collected for. Apply reasonable security safeguards. Be able to respond when someone asks what you hold or asks you to delete it. Be able to notify a breach.

Every one of those is straightforward to state and impossible to do without a data map, which is why the first section here is about knowing what you hold rather than about any technical control.

Where businesses usually fail

Shared logins are the most common single gap, particularly at reception desks, clinic counters and retail tills. A shared account means you cannot attribute a record access to a person, which undermines your audit trail and your ability to investigate anything.

The second is retention. Most businesses keep everything forever, which is the opposite of purpose limitation and enlarges every breach they might ever have. A retention policy that describes deletion without anything implementing it provides no protection at all.

This overlaps with other obligations

CERT-In directions cover incident reporting and log retention. Sector regulators add their own expectations, particularly in financial services and healthcare. Customer security questionnaires ask many of the same questions in different words.

The underlying controls overlap heavily, so work done for one satisfies much of another. Build once, evidence many times, and treat this assessment as a starting point rather than a separate exercise.

More tools

Others you might use

Want a second opinion?

Send us your numbers and we will tell you what they mean

No obligation and no sales sequence. If the honest answer is that you do not need us, that is what you will get. Initial reply within 4 business hours.