DPDP Act, 2023
In force · Rules notified 2025
When the Board asks, answer with records.
A complaint under the DPDP Act names a person and a date. This workspace runs your registers so every right honoured is evidence — timestamped, cited, exportable. Start by checking whether the Act applies to you — most organisations qualify.
Both free · no account needed · about 5 minutes each
The actual workspace — illustrative walkthrough with sample data.
Your path
Five stops, in order.
Start anywhere — the first three need no account at all.
Prefer the walk written down? One company, one year — the whole journey as a story →
Start without an account
Take the assessment first — sign in only if you want to save it
Cited to the source
Every question and step names the section or rule behind it
Current to DPDP Rules, 2025
G.S.R. 846(E), notified 13 Nov 2025
Built for Indian scope
Data Fiduciaries, SDFs, and in-scope foreign firms
First a right (2017), then a law (2023), now a clock — core obligations are enforceable 13 May 2027. Read the story of the law →
The real cost of non-compliance
It isn’t ₹250 crore. It’s the dividend you never collect.
You’ll see that number everywhere — it’s a scare tactic, and not how we want to earn your time. The real cost of non-compliance is the advantage you never collect: the trust customers extend, the procurement doors that open, the deals that stop stalling — the dividend of genuinely adhering to the DPDPA.
Every step below is a documented finding, not a promise.
The dividend only pays if you genuinely adhere — that’s the part we help you operationalise.
Try the whole workspace free — evaluate where you stand, then operationalise your compliance at your own pace.
Whose story is this? Almost every organisation’s.
Scope
Who must comply?
§ 2 (i) · §§ 4–10
Everyone who decides the why and the how
Any organisation that determines the purpose and means of processing digital personal data — from a two-person D2C brand to a bank. E-commerce, fintech, healthcare, ed-tech, telecom, SaaS, ad-tech, HR-tech, gaming, marketplaces, and government bodies (with carve-outs).
Notice and consent
Security safeguards
Breach reporting
Erasure when the purpose is served
Answering rights requests
And here is what it asks of everyone it reaches.
What the Act requires
Key obligations
01Give notice first
§ 5 · Rule 3A standalone, itemised, plain-language notice — in English or any of the 22 scheduled languages — before or when consent is sought.
02Take real consent
§ 6Free, specific, informed, unconditional and unambiguous — and as easy to withdraw as it was to give.
03For children, ask the guardian
§ 9 · Rules 10–12Verifiable guardian consent for under-18s, and no tracking or targeted advertising directed at children.
04Use it only for the purpose
§ 4Process personal data only for the specified lawful purpose the person agreed to — nothing else.
05Guard it while you hold it
§ 8 (5) · Rule 6 · § 8 (2)Reasonable security safeguards — encryption, access control, logs kept a year, backups — and a written contract behind every processor.
06Send it abroad with care
§ 16 · Rule 15Transfers are permitted except to countries the Central Government restricts; sector-specific localisation rules still apply.
07If it leaks, move fast
§ 8 (6) · Rule 7Tell affected people without delay, and file the detailed report to the Data Protection Board within 72 hours.
08Erase it when the purpose is served
§ 8 (7) · Rule 8Delete personal data once its purpose is served or consent is withdrawn — keeping it needs a reason.
09Honour rights, all along
§§ 11–14 · Rule 14Access, correction, erasure, nomination and grievance redressal — answered within your published window, at most 90 days.
10If you are designated significant, prove more
§ 10 · Rule 13An India-based DPO reporting to the board, an independent data auditor, and a DPIA and audit every 12 months.
One datum’s lifetime, ten duties — each one runs as a cited module in the workspace.
Sign in and this is the shape of what you’ll find.
Inside the workspace
Everything you unlock.
The same three phases you’ll see on your dashboard — three of each phase’s modules named here; the full catalog lives one click further.
Rights request register→
90-day clock · Rule 14 (3)Consent ledger→
§ 5–6Breach incident register→
72-hour clock · Rule 7 (2)Compliance dossier
Word · full programmeBoard briefing deck→
PowerPoint · free, no accountGap analysis→
ranked by penalty exposureUnderneath the screens sits one path — the same seven steps, in the same order, for everyone.
Your path to compliance
Seven steps, in the right order.
This is the order practitioners do the work in — each step cited to the Act and Rules — and every step ends with a document you can show an auditor.
The app walks you through all of it.
See if the law applies to you
§ 3 · § 4A free 28-question check: your sector, your data, your users. It tells you whether you are a Data Fiduciary, whether you may be a Significant one, and what to do first.
Map the personal data you hold
§ 8Build the inventory (ROPA): what you collect, why, where it lives, who it is shared with. Every other obligation builds on this map.
Fix your notices & consent
§ 5 · § 6 · Rule 3Standalone, itemised notices in English or any scheduled language. Consent that is free, specific, informed and unbundled — and as easy to withdraw as it was to give.
Secure it & paper your vendors
§ 8 (5) · Rule 6 · § 8 (2)Encryption or masking, access control, logs kept for a year, backups — and a written contract with every processor that handles your data.
Open the front door for rights
§§ 11–14 · Rule 14Publish how people reach you, verify who is asking, and answer access, correction and erasure requests within your published period — at most 90 days.
Be ready for the bad day
§ 8 (6) · Rule 7When a breach happens: tell affected people without delay, file the first intimation to the Board, and the detailed report within 72 hours. Have it drilled before you need it.
Keep it running — and prove it
§ 8 (7) · Rule 8Retention clocks, recurring reviews, an audit trail — and a compliance dossier you can hand to your board, an auditor, or the Data Protection Board.
This is the workspace built for that clock — watch it run.
The product suite
See it in action.
The first five minutes, exactly as you’d live them — and every other module has its own walkthrough, one click further.
Start free — 28 questions, no account
Answer plain-language questions about your organisation. The engine works out whether the Act applies, the role you hold, and your likely Significant Data Fiduciary band — then hands you a prioritised roadmap, each step cited to its section.
Nobody should have to write act one from a blank page.
Don’t start from a blank page
14 ready-to-use templates.
Privacy policies, processing agreements, consent forms, breach notices, a privacy impact assessment — every document the journey asks for, drafted for the DPDP Act.
Browse free
Sign in (free) to read, download & generate
Versions saved to your Document locker
And when you want the map rather than the story:
Find your way
Where to go next.
However this story goes for your organisation, it starts small — twenty minutes tonight is enough.
Two doors in — both free.
The applicability assessment
28 plain-language questions, no account, answers kept in your browser. Leave with a roadmap of exactly what applies to you — every step cited to its section of the Act.
The board briefing deck
Six quick questions — or none. Leave with a board-ready PowerPoint that explains the DPDPA in your board’s language, with a clear ask and speaker notes.
And a promise before you start: compliance must not be overwhelming. Read the design principles this workspace follows →
And one we will not make: we will never tell you that you are compliant. Why we refuse to give you a score →
Read the law for yourself
Official sources
All links verified to resolve at time of publication. Statute text and Rules supersede any summary on this page.