DPDPA Workflow

DPDP Act, 2023

In force · Rules notified 2025

When the Board asks, answer with records.

A complaint under the DPDP Act names a person and a date. This workspace runs your registers so every right honoured is evidence — timestamped, cited, exportable. Start by checking whether the Act applies to you — most organisations qualify.

Both free · no account needed · about 5 minutes each

/dashboard
Live demo
Muted

The actual workspace — illustrative walkthrough with sample data.

Your path

Five stops, in order.

Start anywhere — the first three need no account at all.

Prefer the walk written down? One company, one year — the whole journey as a story →

Start without an account

Take the assessment first — sign in only if you want to save it

Cited to the source

Every question and step names the section or rule behind it

Current to DPDP Rules, 2025

G.S.R. 846(E), notified 13 Nov 2025

Built for Indian scope

Data Fiduciaries, SDFs, and in-scope foreign firms

First a right (2017), then a law (2023), now a clock — core obligations are enforceable 13 May 2027. Read the story of the law →

The real cost of non-compliance

It isn’t ₹250 crore. It’s the dividend you never collect.

You’ll see that number everywhere — it’s a scare tactic, and not how we want to earn your time. The real cost of non-compliance is the advantage you never collect: the trust customers extend, the procurement doors that open, the deals that stop stalling — the dividend of genuinely adhering to the DPDPA.

Every step below is a documented finding, not a promise.

1 / 2
01 TRUST EARNED96% say privacy’s benefits outweigh itscostsCISCO, 2025 ↗02 PROCUREMENT UNLOCKED91% of buyers treat privacy certificationsas a buying factorCISCO, 2022 ↗03 DEALS MOVE FASTERSales delays ~80% shorter for the mostprivacy-matureCISCO, 2018 ↗04 GROWTH COMPOUNDSDigital-trust leaders 1.6× more likely togrow ≥10%MCKINSEY, 2022 ↗

The dividend only pays if you genuinely adhere — that’s the part we help you operationalise.

Evaluate your DPDPA readiness — free

Try the whole workspace free — evaluate where you stand, then operationalise your compliance at your own pace.

Whose story is this? Almost every organisation’s.

Scope

Who must comply?

Data Fiduciaries
Significant Data Fiduciaries
Foreign organisations

§ 2 (i) · §§ 4–10

Everyone who decides the why and the how

Any organisation that determines the purpose and means of processing digital personal data — from a two-person D2C brand to a bank. E-commerce, fintech, healthcare, ed-tech, telecom, SaaS, ad-tech, HR-tech, gaming, marketplaces, and government bodies (with carve-outs).

Notice and consent

Security safeguards

Breach reporting

Erasure when the purpose is served

Answering rights requests

And here is what it asks of everyone it reaches.

What the Act requires

Key obligations

01Give notice first

§ 5 · Rule 3

A standalone, itemised, plain-language notice — in English or any of the 22 scheduled languages — before or when consent is sought.

02Take real consent

§ 6

Free, specific, informed, unconditional and unambiguous — and as easy to withdraw as it was to give.

03For children, ask the guardian

§ 9 · Rules 10–12

Verifiable guardian consent for under-18s, and no tracking or targeted advertising directed at children.

04Use it only for the purpose

§ 4

Process personal data only for the specified lawful purpose the person agreed to — nothing else.

05Guard it while you hold it

§ 8 (5) · Rule 6 · § 8 (2)

Reasonable security safeguards — encryption, access control, logs kept a year, backups — and a written contract behind every processor.

06Send it abroad with care

§ 16 · Rule 15

Transfers are permitted except to countries the Central Government restricts; sector-specific localisation rules still apply.

07If it leaks, move fast

§ 8 (6) · Rule 7

Tell affected people without delay, and file the detailed report to the Data Protection Board within 72 hours.

08Erase it when the purpose is served

§ 8 (7) · Rule 8

Delete personal data once its purpose is served or consent is withdrawn — keeping it needs a reason.

09Honour rights, all along

§§ 11–14 · Rule 14

Access, correction, erasure, nomination and grievance redressal — answered within your published window, at most 90 days.

See it in the workspace →runs through the whole lifecycle

10If you are designated significant, prove more

§ 10 · Rule 13

An India-based DPO reporting to the board, an independent data auditor, and a DPIA and audit every 12 months.

See it in the workspace →runs through the whole lifecycle

One datum’s lifetime, ten duties — each one runs as a cited module in the workspace.

Sign in and this is the shape of what you’ll find.

Inside the workspace

Everything you unlock.

The same three phases you’ll see on your dashboard — three of each phase’s modules named here; the full catalog lives one click further.

Underneath the screens sits one path — the same seven steps, in the same order, for everyone.

Your path to compliance

Seven steps, in the right order.

This is the order practitioners do the work in — each step cited to the Act and Rules — and every step ends with a document you can show an auditor.

The app walks you through all of it.

1

See if the law applies to you

§ 3 · § 4

A free 28-question check: your sector, your data, your users. It tells you whether you are a Data Fiduciary, whether you may be a Significant one, and what to do first.

You produce: Your personal roadmapSee this step →
2

Map the personal data you hold

§ 8

Build the inventory (ROPA): what you collect, why, where it lives, who it is shared with. Every other obligation builds on this map.

You produce: Record of processing activitiesSee this step →
3

Fix your notices & consent

§ 5 · § 6 · Rule 3

Standalone, itemised notices in English or any scheduled language. Consent that is free, specific, informed and unbundled — and as easy to withdraw as it was to give.

You produce: Notices, consent screens, consent ledgerSee this step →
4

Secure it & paper your vendors

§ 8 (5) · Rule 6 · § 8 (2)

Encryption or masking, access control, logs kept for a year, backups — and a written contract with every processor that handles your data.

You produce: Security baseline, processor register, DPAsSee this step →
5

Open the front door for rights

§§ 11–14 · Rule 14

Publish how people reach you, verify who is asking, and answer access, correction and erasure requests within your published period — at most 90 days.

You produce: Rights portal, grievance process, request registerSee this step →
6

Be ready for the bad day

§ 8 (6) · Rule 7

When a breach happens: tell affected people without delay, file the first intimation to the Board, and the detailed report within 72 hours. Have it drilled before you need it.

You produce: Incident playbook, Board reportSee this step →
7

Keep it running — and prove it

§ 8 (7) · Rule 8

Retention clocks, recurring reviews, an audit trail — and a compliance dossier you can hand to your board, an auditor, or the Data Protection Board.

You produce: Registers, calendar, dossierSee this step →

This is the workspace built for that clock — watch it run.

The product suite

See it in action.

The first five minutes, exactly as you’d live them — and every other module has its own walkthrough, one click further.

/assessment
Live demo
Muted

Start free — 28 questions, no account

Answer plain-language questions about your organisation. The engine works out whether the Act applies, the role you hold, and your likely Significant Data Fiduciary band — then hands you a prioritised roadmap, each step cited to its section.

Nobody should have to write act one from a blank page.

Don’t start from a blank page

14 ready-to-use templates.

Privacy policies, processing agreements, consent forms, breach notices, a privacy impact assessment — every document the journey asks for, drafted for the DPDP Act.

Browse free

Sign in (free) to read, download & generate

Versions saved to your Document locker

Browse the template library →Original templates, drafted against the Act and Rules · not legal advice.

However this story goes for your organisation, it starts small — twenty minutes tonight is enough.

Two doors in — both free.

For you

The applicability assessment

28 plain-language questions, no account, answers kept in your browser. Leave with a roadmap of exactly what applies to you — every step cited to its section of the Act.

For your board

The board briefing deck

Six quick questions — or none. Leave with a board-ready PowerPoint that explains the DPDPA in your board’s language, with a clear ask and speaker notes.

Ready for the full workspace? Any Google account works — personal or company, no separate registration. Sign in to save your roadmap, run the registers, and keep every generated document.

And a promise before you start: compliance must not be overwhelming. Read the design principles this workspace follows →

And one we will not make: we will never tell you that you are compliant. Why we refuse to give you a score →

Read the law for yourself

Official sources

All links verified to resolve at time of publication. Statute text and Rules supersede any summary on this page.