Grade your privacy policy against DPDP (free)

Grade your privacy policy against DPDP (free)
Shortlist Stage · Privacy Policy Audit

Grade your privacy policy against DPDP (free)

A self-assessment rubric covering 10 DPDP-specific requirements — score your policy in 20 minutes and know exactly where the gaps are before a regulator or enterprise client finds them.

Quick Answer: A DPDP-compliant privacy policy must cover 10 specific elements: data categories, processing purpose, consent mechanism, retention periods, Grievance Officer contact, all four data principal rights, cross-border transfer disclosure, children's data safeguards (if applicable), update notification mechanism, and plain language. Most Indian company policies currently score 4–6 out of 10.

Your privacy policy is the first document a regulator, an enterprise client's legal team, or a data principal will look at when assessing your compliance posture. It is also, for most Indian companies, the weakest link in their DPDP compliance stack.

This post gives you a 10-point self-assessment rubric you can apply to your current privacy policy right now, without any tools or external help. Each point is drawn directly from the DPDP Act and DPDP Rules 2025 requirements. For each point, you'll see what a passing policy looks like, what a failing policy looks like, and what to do about it.

If you want a full compliance picture beyond just your privacy policy, see our post on what a DPDP gap analysis report covers. For a tool-assisted version of this check, see our post on how DPDP readiness scoring works.

How to use this rubric

Open your current privacy policy in a separate tab. For each of the 10 requirements below, mark yourself 0 (failing) or 1 (passing). A score of 8 or above means your policy is in reasonable shape. A score of 5 or below means you have material compliance gaps that need immediate attention.

The 10-Point DPDP Privacy Policy Rubric

1 Data categories disclosed

Does your policy list the specific categories of personal data you collect? Vague language ("information you provide") does not pass.

✅ PASS: "We collect your name, email address, phone number, PAN number, employment history, and device identifiers."
❌ FAIL: "We collect personal information to provide our services." (No categories specified.)

Fix: List every category of personal data you collect across every touchpoint — website forms, mobile app, customer support, HR systems.

2 Processing purpose stated

For each data category, is the purpose of processing stated explicitly? The purpose must be specific, not generic.

✅ PASS: "We use your email address to send you transactional notifications about your account and, with your separate consent, to send you marketing communications about our products."
❌ FAIL: "We use your information to improve your experience and for business purposes."

Fix: Create a purpose-data matrix and summarise it in plain language in the policy.

3 Consent mechanism described

Does your policy explain how consent is obtained and the legal basis for processing? Under DPDP, consent must be free, specific, informed, and unambiguous.

✅ PASS: "We obtain your consent through a checkbox on our registration form. Each purpose has a separate checkbox. Consent for marketing is optional and does not affect your access to core services."
❌ FAIL: "By using our services, you agree to this privacy policy." (Bundled, non-specific consent.)

Fix: Describe the specific consent mechanism for each purpose, including any legitimate interest basis where applicable.

4 Data retention disclosed

Does your policy state how long you retain each category of personal data? "As long as necessary" is not sufficient.

✅ PASS: "We retain your account data for the duration of your subscription and for 3 years after account closure for legal compliance. Financial records are retained for 7 years as required by law."
❌ FAIL: "We retain your data as long as necessary to provide our services."

Fix: Define retention periods by data category. Map to legal obligations (GST records, employment records) where applicable.

5 Grievance Officer contact

Does your policy name a Grievance Officer with a specific name (or role), email address, and response timeline? This is mandatory under the DPDP Act.

✅ PASS: "Our Grievance Officer is [Name], reachable at grievance@company.com. We will acknowledge complaints within 48 hours and resolve them within 30 days."
❌ FAIL: A general "contact us" email with no named officer and no timeline.

Fix: Designate a Grievance Officer (can be internal or external), add their contact details to the policy, and define your SLA.

6 Data Principal rights explained

Does your policy explain all four rights under DPDP: right to access, right to correction, right to erasure, and right of nomination?

✅ PASS: A dedicated "Your Rights" section that explains each right, how to exercise it, what to expect in terms of response timeline, and any limitations that apply.
❌ FAIL: "You may contact us to update or delete your information." (Does not mention all four rights or how to exercise them.)

Fix: Add a structured rights section with one sub-section per right, including the exercise mechanism and SLA.

7 Cross-border transfers disclosed

If any personal data is transferred outside India — including to cloud servers in the US, EU, or Singapore — does your policy disclose this and describe the safeguards?

✅ PASS: "We use AWS (US-East region) for hosting. Your data may be stored outside India. AWS's data protection standards are described at [link]. We have executed a Data Processing Agreement with AWS that requires equivalent protections."
❌ FAIL: No mention of international data transfers despite using any foreign SaaS tool.

Fix: Audit every tool you use (CRM, email, analytics, cloud hosting) for data location. Disclose each transfer and the safeguard.

8 Children's data safeguards (if applicable)

If your service is accessible to or intended for users under 18, does your policy address the heightened requirements under Section 9 of the DPDP Act?

✅ PASS: "Our service is not intended for users under 18. We do not knowingly collect data from minors. If we discover we have collected data from a minor, we will delete it within 48 hours." (Or, if applicable: a description of parental consent mechanisms.)
❌ FAIL: No mention of age restrictions or children's data, despite the service being potentially accessible to minors.

Fix: Either clearly exclude minors and describe your age verification mechanism, or describe your parental consent process.

9 Update notification mechanism

Does your policy explain how users will be notified when the policy changes? Posting a new version without notice is non-compliant.

✅ PASS: "We will notify you of material changes to this policy by email at least 14 days before the change takes effect. Continued use of our service after notification constitutes acceptance."
❌ FAIL: "We may update this policy from time to time. Check this page periodically." (Places the notification burden on the user.)

Fix: Commit to active notification (email) for material changes, with a defined notice period before changes take effect.

10 Plain language throughout

Can a user with no legal background read and understand your policy? DPDP Rules explicitly require policies to be in "clear and plain language." A Flesch Reading Ease score of 50 or above (roughly "standard" difficulty) is a reasonable target.

✅ PASS: Short sentences, defined terms, active voice, no Latin phrases or undefined acronyms.
❌ FAIL: Dense paragraphs of legal language, undefined terms, passive voice throughout.

Fix: Rewrite the policy at a reading level accessible to a general Indian internet user. Use headers, bullet points, and a table for data categories.

Interpreting your score

0–4
Critical gaps — material compliance risk. Rewrite required before any enterprise client review.
5–7
Moderate gaps — addressable with targeted updates. Prioritise points 5, 6, and 3.
8–10
Strong foundation — minor updates may be needed for Rules 2025 specifics.

For a comprehensive compliance view beyond your privacy policy, see our post on DPDP compliance pricing to understand what a full remediation engagement typically covers. If you want to understand how external assessors score your overall readiness, see our post on how DPDP readiness scoring works.

Get an instant automated policy grade

Our free DPDP Policy Grader analyses your live policy URL against all 10 DPDP requirements and gives you a scored report with specific fix recommendations — in under 60 seconds.

Grade Your Policy Free →

Frequently Asked Questions

Do we need a separate privacy policy for employees and customers under DPDP?

Not necessarily, but it is good practice. Employees and customers have different data categories, different processing purposes, and different rights contexts. A combined policy is permissible but must clearly distinguish between the two groups in each section. Many organisations find it cleaner to maintain separate documents — a customer-facing privacy notice and an internal employee privacy notice — rather than creating a combined document that is long and confusing for both audiences.

How often should we review and update our privacy policy?

At minimum, annually and whenever you make a material change to your data processing activities — adding a new data category, onboarding a new processor, changing your consent mechanism, or launching a new product feature that involves personal data. The DPDP Rules do not specify a review frequency, but a documented annual review process is the baseline that most enterprise clients and auditors expect to see.

Is our existing privacy policy that predates DPDP still valid?

It is not invalid, but it is almost certainly non-compliant with the DPDP Act and DPDP Rules 2025. Policies drafted under the older IT Act 2000 framework lack the purpose-specific consent mechanism, the four data principal rights, the Grievance Officer requirement with SLA, and the breach notification provisions that DPDP now mandates. An update is required — not optional.

Previous Post Next Post

Get Free DPDP Checklist