Grade your privacy policy against DPDP (free)
A self-assessment rubric covering 10 DPDP-specific requirements — score your policy in 20 minutes and know exactly where the gaps are before a regulator or enterprise client finds them.
Your privacy policy is the first document a regulator, an enterprise client's legal team, or a data principal will look at when assessing your compliance posture. It is also, for most Indian companies, the weakest link in their DPDP compliance stack.
This post gives you a 10-point self-assessment rubric you can apply to your current privacy policy right now, without any tools or external help. Each point is drawn directly from the DPDP Act and DPDP Rules 2025 requirements. For each point, you'll see what a passing policy looks like, what a failing policy looks like, and what to do about it.
If you want a full compliance picture beyond just your privacy policy, see our post on what a DPDP gap analysis report covers. For a tool-assisted version of this check, see our post on how DPDP readiness scoring works.
How to use this rubric
Open your current privacy policy in a separate tab. For each of the 10 requirements below, mark yourself 0 (failing) or 1 (passing). A score of 8 or above means your policy is in reasonable shape. A score of 5 or below means you have material compliance gaps that need immediate attention.
The 10-Point DPDP Privacy Policy Rubric
Does your policy list the specific categories of personal data you collect? Vague language ("information you provide") does not pass.
Fix: List every category of personal data you collect across every touchpoint — website forms, mobile app, customer support, HR systems.
For each data category, is the purpose of processing stated explicitly? The purpose must be specific, not generic.
Fix: Create a purpose-data matrix and summarise it in plain language in the policy.
Does your policy explain how consent is obtained and the legal basis for processing? Under DPDP, consent must be free, specific, informed, and unambiguous.
Fix: Describe the specific consent mechanism for each purpose, including any legitimate interest basis where applicable.
Does your policy state how long you retain each category of personal data? "As long as necessary" is not sufficient.
Fix: Define retention periods by data category. Map to legal obligations (GST records, employment records) where applicable.
Does your policy name a Grievance Officer with a specific name (or role), email address, and response timeline? This is mandatory under the DPDP Act.
Fix: Designate a Grievance Officer (can be internal or external), add their contact details to the policy, and define your SLA.
Does your policy explain all four rights under DPDP: right to access, right to correction, right to erasure, and right of nomination?
Fix: Add a structured rights section with one sub-section per right, including the exercise mechanism and SLA.
If any personal data is transferred outside India — including to cloud servers in the US, EU, or Singapore — does your policy disclose this and describe the safeguards?
Fix: Audit every tool you use (CRM, email, analytics, cloud hosting) for data location. Disclose each transfer and the safeguard.
If your service is accessible to or intended for users under 18, does your policy address the heightened requirements under Section 9 of the DPDP Act?
Fix: Either clearly exclude minors and describe your age verification mechanism, or describe your parental consent process.
Does your policy explain how users will be notified when the policy changes? Posting a new version without notice is non-compliant.
Fix: Commit to active notification (email) for material changes, with a defined notice period before changes take effect.
Can a user with no legal background read and understand your policy? DPDP Rules explicitly require policies to be in "clear and plain language." A Flesch Reading Ease score of 50 or above (roughly "standard" difficulty) is a reasonable target.
Fix: Rewrite the policy at a reading level accessible to a general Indian internet user. Use headers, bullet points, and a table for data categories.
Interpreting your score
For a comprehensive compliance view beyond your privacy policy, see our post on DPDP compliance pricing to understand what a full remediation engagement typically covers. If you want to understand how external assessors score your overall readiness, see our post on how DPDP readiness scoring works.
Get an instant automated policy grade
Our free DPDP Policy Grader analyses your live policy URL against all 10 DPDP requirements and gives you a scored report with specific fix recommendations — in under 60 seconds.
Grade Your Policy Free →Frequently Asked Questions
Do we need a separate privacy policy for employees and customers under DPDP?
Not necessarily, but it is good practice. Employees and customers have different data categories, different processing purposes, and different rights contexts. A combined policy is permissible but must clearly distinguish between the two groups in each section. Many organisations find it cleaner to maintain separate documents — a customer-facing privacy notice and an internal employee privacy notice — rather than creating a combined document that is long and confusing for both audiences.
How often should we review and update our privacy policy?
At minimum, annually and whenever you make a material change to your data processing activities — adding a new data category, onboarding a new processor, changing your consent mechanism, or launching a new product feature that involves personal data. The DPDP Rules do not specify a review frequency, but a documented annual review process is the baseline that most enterprise clients and auditors expect to see.
Is our existing privacy policy that predates DPDP still valid?
It is not invalid, but it is almost certainly non-compliant with the DPDP Act and DPDP Rules 2025. Policies drafted under the older IT Act 2000 framework lack the purpose-specific consent mechanism, the four data principal rights, the Grievance Officer requirement with SLA, and the breach notification provisions that DPDP now mandates. An update is required — not optional.