Free self-assessment · Under 60 minutes
The DPDP Shield: 47 Points to Readiness
The DPDP Rules 2025 were notified on 13 November 2025, and full compliance is required by 13 May 2027. Practical, actionable, and free from legal jargon.
Until the 13 May 2027 deadline
–
Days
–
Hours
–
Minutes
–
Seconds
40–47
Strong readiness
30–39
Priority improvements
20–29
Material gaps
Below 20
Significant gaps
A Governance & Accountability
8 points
- A1
Have you identified all personal data processing activities?
- A2
Have you appointed a Data Protection Officer (DPO) or designated grievance officer?
- A3
Is your DPO contact information publicly available?
- A4
Have you documented your data retention schedule?
- A5
Have you established a grievance redressal mechanism?
- A6
Is your grievance response timeline defined (target: within 90 days)?
- A7
Have you conducted a Data Protection Impact Assessment (DPIA) for high-risk processing?
- A8
Have you registered as a Significant Data Fiduciary (if applicable)?
B Consent Management
10 points
- B1
Is consent obtained through clear affirmative action (no pre-ticked boxes)?
- B2
Is consent granular (separate consent for each processing purpose)?
- B3
Is your privacy notice available before consent is requested?
- B4
Does your privacy notice specify: what data, why, how long, and with whom?
- B5
Is the privacy notice available in English and relevant regional languages?
- B6
Can users withdraw consent as easily as they gave it?
- B7
Do you maintain a tamper-evident consent audit trail?
- B8
Have you implemented parental consent mechanisms for children’s data?
- B9
Do you re-notify users when processing purposes change?
- B10
Have you reviewed retrospective notices for pre-Act data?
C Data Principal Rights
8 points
- C1
Can users access their personal data within a defined timeframe?
- C2
Can users request correction of inaccurate data?
- C3
Can users request erasure (right to be forgotten)?
- C4
Can users nominate another person to exercise rights on their behalf?
- C5
Is there a simple, public mechanism for rights requests?
- C6
Are rights requests tracked and responded to within statutory timelines?
- C7
Is there a process for handling frivolous or vexatious requests?
- C8
Are data principal rights communicated clearly in your privacy notice?
D Security Safeguards
7 points
- D1
Have you implemented “reasonable security safeguards” for personal data?
- D2
Is personal data encrypted at rest and in transit?
- D3
Do you have access controls based on the principle of least privilege?
- D4
Is there a personal data breach notification protocol?
- D5
Can you notify the Data Protection Board within prescribed timelines?
- D6
Do you have business continuity and disaster recovery plans for personal data?
- D7
Have you conducted penetration testing on systems processing personal data?
E Third-Party & Cross-Border Data
6 points
- E1
Have you identified all third-party processors (cloud, analytics, payments)?
- E2
Do you have Data Processing Agreements (DPAs) with all processors?
- E3
Are cross-border data transfers limited to approved jurisdictions?
- E4
Have you notified users of international transfers?
- E5
Do you conduct due diligence on processor security practices?
- E6
Is there a processor termination and data return/deletion protocol?
F Employee & Workforce Data
4 points
- F1
Are employees informed about workplace data processing?
- F2
Is employee consent obtained for non-essential processing (e.g., monitoring)?
- F3
Are ex-employee data retention and deletion policies defined?
- F4
Is HR data subject to the same security controls as customer data?
G Documentation & Audit Readiness
4 points
- G1
Is your privacy notice dated and version-controlled?
- G2
Do you maintain records of processing activities (ROPA)?
- G3
Can you demonstrate compliance to the Data Protection Board?
- G4
Have you scheduled annual privacy compliance reviews?
This self-assessment is general guidance, not legal advice. Obligations depend on the provisions applicable to your organisation. Need a hand with the gaps? See our GRC & compliance services.