India's data protection law, made practical.
Understand the Digital Personal Data Protection framework, assess your organization's readiness, and turn statutory obligations into working practice — with free tools, templates, and guidance cross-checked against the official text.
Choose your current priority.
Pick what you're trying to do right now and we'll route you straight to the relevant tools and provisions.
Understand DPDP
Read the verified Act text alongside a plain-language breakdown.
GoCheck Applicability
Determine if and how India's DPDP Act applies to your organization.
GoAssess My Organization
Evaluate your compliance maturity across six key pillars.
GoCreate a Notice
Draft compliant consent notices under Section 5.
GoReview Vendors
Evaluate Data Processor contracts and security guarantees.
GoPrepare for a Breach
Plan mandatory intimation timelines to the Board and users.
GoExercise / Handle Rights
Navigate Access, Correction, Erasure and Grievance redressal.
GoYour DPDP compliance journey, mapped from start to action.
A structured eight-step pathway that translates statutory obligations into day-to-day organizational operations.
Understand
Read verified statutory provisions and plain-language breakdowns.
Check Applicability
Determine territorial scope and specific exemptions.
Map Personal Data
Inventory collection points, data categories and storage nodes.
Manage Consent
Build transparent notices and record withdrawal mechanisms.
Secure Data
Implement technical safeguards and valid processor contracts.
Manage Retention
Track purpose fulfilment and automate erasure schedules.
Respond to Breaches
Establish rapid incident escalation and notification workflows.
Review & Improve
Maintain an audit trail, DPO governance and grievance handling.
Practical tools, not just explanations.
Statutory provisions turned into clear, guided operational workflows you can run in minutes.
DPDP Readiness Assessment
Score your organization across six pillars — legal basis, data inventory, consent, security, retention and grievance redressal — and get a prioritized action list.
Replace compliance chaos with clarity.
Move from fragmented spreadsheets to a structured, source-backed compliance foundation.
Fragmented & reactive
- Compliance scattered across spreadsheets
- Unclear departmental ownership
- Disconnected, non-compliant privacy notices
- Unknown third-party vendor risk
- No visibility into retention schedules
Operational & source-backed
- Legal obligations mapped to owners and roles
- Guided, step-by-step diagnostic workflows
- Purpose-built interactive compliance tools
- Reusable templates and policy generators
- Direct cross-references to the official Gazette text
Don't trust summaries. Verify the law.
Official statutory text stays permanently separate from our plain-language operational explanations — so you always know which is which.
“(5) A Data Fiduciary shall protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach.
(6) In the event of a personal data breach, the Data Fiduciary shall give the Board and each affected Data Principal, intimation of such breach in such form and manner as may be prescribed.”
- You must implement reasonable technical and organizational security measures — not just a policy on paper.
- If a breach happens, every affected individual must be told, not only the regulator.
- There is no statutory materiality threshold in the Act itself — timing and form are prescribed by the Rules.
DPDP looks different depending on what you do.
Role-specific toolkits, checklists and provisions curated for your day-to-day workflow.
IT & Security Teams
Mandatory breach response timelines, technical safeguards, data flow mapping and security auditing.
Breach Response PlannerHR & People Teams
Employee data processing, candidate consent notices, employment exceptions and background checks.
Consent Notice BuilderMarketing & Growth
Consent for campaigns, cookie mechanisms, analytics tracking and restrictions on children's data.
Consent Notice BuilderSaaS & Tech Products
Significant Data Fiduciary triggers, API data pipelines, sub-processor agreements and privacy by design.
Vendor AssessmentPrivacy & Legal
DPO governance, legal cross-referencing, Board audit readiness and statutory duties end to end.
Readiness AssessmentBeginner / Student
What DPDP is, who it protects, key statutory terms, and the fundamental rights of Data Principals.
Glossary & OverviewBuilt around the source. Not around assumptions.
Data protection guidance should be grounded in official law. Every tool, checklist and article is cross-referenced against Gazette notifications.
Official text kept distinct
Statutory provisions are never merged or blurred with plain-language explanations.
Cross-referenced provisions
Every tool outcome cites the exact section numbers and gazetted rule schedules it draws on.
Tracked legal updates
Continuously refreshed as the Ministry of Electronics & IT releases further notifications.
Educational decision-support
Independent guidance built to empower privacy and technical teams, without vendor lock-in.
Practical DPDP guidance.
DPDP Compliance for Customer Support Screenshots, Screen Recordings and Remote Sessions
Screenshots and session recordings routinely capture personal data outside your usual retention controls. Here's how to bring that channel into scope.
DPDP Compliance for Database Administrators: Protecting Personal Data in Production Databases
Backups, replicas, query logs and staging copies all extend where personal data lives. A practical checklist for DBAs.
Building a DPDP Compliance Operating Model: Who Owns Privacy Across HR, IT, Legal, Security and Marketing?
Compliance fails quietly when no one owns it. A RACI-style model for spreading DPDP accountability across departments.
DPDP status center.
DPDP Act, 2023
Passed by Parliament and published in the Gazette. Verified statutory base active.
DPDP Rules, 2025
Implementation rules, consent manager parameters and breach intimation guidelines mapped.
Continuous Review
Our editorial desk monitors MeitY notifications and Data Protection Board updates.
Turn DPDP complexity into a clear next step.
Explore verified statutory law, assess your organizational readiness, and use practical tools designed specifically for India's DPDP framework.