DPDP NavigatorAct 2023 · Rules 2025
All tools
Comprehensive auditv1.3Live

DPDP Readiness Assessment

Score your organization across six pillars — legal basis, data inventory, consent, security, retention and grievance redressal — and get a prioritized action list.

Legal Basis

Needs Attention · 0%
We know, for every processing activity, whether it relies on consent or a specific Section 7 legitimate use.
We've confirmed whether the DPDP Act applies to each of our data flows, including any cross-border ones.
We've identified whether we're a Data Fiduciary, Processor, or Significant Data Fiduciary for each activity.
Obligation Finder

Data Inventory

Needs Attention · 0%
We maintain an up-to-date register of personal data categories, purposes, and storage locations.
We know which third parties and Data Processors receive each category of personal data.
We've mapped any cross-border transfers of personal data.
Personal Data Inventory

Consent Management

Needs Attention · 0%
Our consent notices are itemised by purpose, in plain language, before or at the point of collection.
Withdrawing consent is as easy as giving it, and withdrawal is propagated to our processors.
We obtain verifiable parental consent wherever we knowingly process a child's data.
Consent Notice Builder

Security Safeguards

Needs Attention · 0%
We apply encryption or masking to personal data, with access controls and logging in place.
We retain security and access logs for at least one year for breach detection and investigation.
All Data Processor contracts contain security obligations that mirror our own.
Vendor Assessment

Retention & Erasure

Needs Attention · 0%
We have documented retention periods linked to the purpose of each data category.
We erase or anonymise data once its purpose is served or consent is withdrawn, whichever is earlier.
We notify users before erasing dormant accounts, where applicable.
Retention Planner

Breach & Grievance Readiness

Needs Attention · 0%
We have a tested incident response plan covering Board and Data Principal breach intimation.
We have a published, working grievance redressal mechanism with a named contact.
We track rights requests (access, correction, erasure) against a response SLA.
Breach Response Planner
Overall readiness
0%
0 of 18 questions answered

Saved automatically in your browser. Nothing is sent to a server.