Self-assess your DPDP readiness in 5 minutes

Self-Assess Your DPDP Readiness in 5 Minutes
DPDP · Self-Assessment · Compliance

Self-Assess Your DPDP Readiness in 5 Minutes

Eight yes/no questions. Five minutes of honest reflection. A clear picture of where your organisation stands before the May 2027 DPDP enforcement deadline — and what to fix first.

Quick Answer: You can gauge your DPDP readiness right now with eight core questions covering data inventory, consent, privacy notice, breach response, vendor contracts, Grievance Officer, data rights processes, and retention policy. Score 0–3: high risk. Score 4–6: moderate risk with specific gaps. Score 7–8: good foundation — now formalise it. Use this post as a quick diagnostic, then get a full scored report from the Readiness Score tool.

Most organisations that will be covered by the Digital Personal Data Protection Act 2023 have not yet done a formal readiness assessment. Some have started drafting a privacy policy. A few have identified a Grievance Officer. Almost none have audited their data flows, vendor contracts, and breach response procedures together as a system.

The enforcement deadline — currently expected around May 2027 — sounds distant. It is not. Organisations that start assessing now have time to fix gaps methodically. Those that start in 2026 will be scrambling. Those that wait until 2027 will be exposed.

This post gives you a fast, practical self-assessment: eight questions, one point each, answer honestly. At the end, interpret your score and identify your highest-priority gap. For cross-links on specific topics, see our posts on breach notification timelines, data principal rights, and consent management. For context on where to begin, start with our DPDP compliance roadmap overview.

The 8-Question DPDP Readiness Self-Assessment

For each question, answer Yes (score 1) or No (score 0). Be strict — "in progress" or "we plan to" counts as No.

Question 1: Do you have a data inventory?

A data inventory (sometimes called a data map or Record of Processing Activities) lists every category of personal data your organisation collects, where it is stored, how long it is kept, who has access, and with whom it is shared. Without this, you cannot comply with any other DPDP obligation — you cannot write an accurate privacy notice, you cannot respond to erasure requests, you cannot assess breach scope.

Yes if: You have a documented, current register of your personal data assets, updated at least annually.
No if: You rely on memory, tribal knowledge, or a partial spreadsheet that nobody maintains.

Question 2: Do you have a working consent mechanism?

The DPDP Act requires that consent for processing personal data be free, specific, informed, unconditional, and unambiguous. Pre-ticked boxes, buried consent in terms and conditions, and consent bundled with service agreements do not qualify. You need a mechanism — a form, a checkbox flow, a digital consent receipt — that meets the Act's standard and can be demonstrated to a regulator.

Yes if: You have a consent mechanism that is separate from your T&Cs, that users actively complete, and that generates a record you can retrieve.
No if: Consent is implied, bundled, or obtained via a standard "I agree to our Terms" checkbox.

Question 3: Is your privacy notice DPDP-compliant?

A DPDP-compliant privacy notice must explain: what data you collect, why you collect it, who you share it with, how long you keep it, and how a data principal can exercise their rights (access, correction, erasure, grievance). Many existing privacy policies are either too vague (no specific retention periods, no contact for rights requests) or simply copied from a GDPR template that does not match Indian law.

Yes if: Your privacy notice was reviewed by someone who knows the DPDP Act, is publicly accessible, and covers all the required elements in plain language.
No if: Your privacy notice is generic, outdated, or copied from a template without customisation.

Question 4: Do you have a breach response plan?

The DPDP Act requires Data Fiduciaries to notify the Data Protection Board — and affected data principals — of personal data breaches. You cannot do this effectively without a documented incident response plan that assigns roles, sets notification timelines, and specifies escalation paths. The plan should be tested at least once before enforcement begins.

Yes if: You have a written breach response procedure, named roles, and a tested notification template.
No if: Your response plan is "we'll figure it out when it happens."

Question 5: Do your vendor contracts include data protection clauses?

Every vendor or service provider that handles personal data on your behalf is a Data Processor under the DPDP Act. Your contract with them must include security obligations, breach notification requirements, sub-processor controls, and data deletion on contract end. Standard commercial contracts — even those from large vendors — rarely include all of these elements without negotiation.

Yes if: You have audited your top 10 vendor contracts and confirmed that data processing terms are present and DPDP-aligned.
No if: You have not reviewed vendor contracts through a DPDP lens.

Question 6: Have you appointed a Grievance Officer?

The DPDP Act requires Data Fiduciaries to provide a mechanism for data principals to raise grievances — and to appoint a Grievance Officer (or accessible contact) to handle them. For Significant Data Fiduciaries, this is a formal appointment with a published name and contact. For other fiduciaries, the requirement is functional: there must be someone who receives and responds to grievances within the prescribed timeframe.

Yes if: A named person or team is responsible for DPDP grievances, their contact is published, and there is a process to respond within the required window.
No if: Grievances go to a generic inbox that nobody monitors.

Question 7: Do you have a process for data principal rights requests?

Under the DPDP Act, data principals have the right to access their data, correct inaccuracies, erase their data (in most cases), and nominate a representative. These requests must be handled within prescribed timelines. A process means: a channel for receiving requests, someone responsible for responding, a way to verify identity, and a procedure for executing the action in your systems.

Yes if: You have a documented, tested process for handling access, correction, and erasure requests — with defined timelines and accountable owners.
No if: Rights requests would go to your generic contact form and nobody is sure what to do with them.

Question 8: Do you have a documented data retention policy?

The DPDP Act requires that personal data be retained only as long as necessary for the purpose for which it was collected. This means you need a retention schedule — a document that specifies, for each category of data, how long it is kept and what happens to it at the end of that period (deletion, anonymisation, archiving). Without a retention policy, you will find it impossible to respond accurately to erasure requests or to demonstrate compliance in an audit.

Yes if: You have a written retention schedule, it is followed in practice, and data is deleted or anonymised when the period expires.
No if: Data is retained indefinitely, or retention periods exist only in someone's head.

Interpreting Your Score

0–3: High Risk. You have significant foundational gaps. A regulator audit or a data breach right now would expose you to substantial penalties and reputational damage. Prioritise the data inventory and consent mechanism — without these, other compliance work has nowhere to anchor. You need a structured compliance programme, not a checklist exercise.

4–6: Moderate Risk. You have made a start, but there are specific gaps that create material exposure. Identify which questions you answered No and address them in order of enforcement risk. Breach response and vendor contracts are frequently the weakest links at this stage.

7–8: Good Foundation. You have the core building blocks in place. Now the work is formalisation, documentation, and testing. Regulators are not satisfied by the existence of policies — they want evidence that policies are followed, updated, and understood by staff. Move from "we have this" to "we can demonstrate this."

Get your full DPDP Readiness Score with a detailed gap report

The self-assessment above tells you where you stand. Our full DPDP Readiness Score tool goes deeper — 40+ parameters, weighted by enforcement priority, with a detailed PDF report and a prioritised remediation plan you can act on immediately.

Get Your DPDP Readiness Score — ₹999

Frequently Asked Questions

How long does a proper DPDP readiness assessment take?

A comprehensive DPDP readiness assessment — covering data inventory, consent flows, privacy notices, vendor contracts, breach response, and rights management — typically takes 2–4 weeks for a mid-market organisation. That includes document review, stakeholder interviews, and gap analysis. The 5-minute self-assessment in this post is a diagnostic to identify where to focus, not a substitute for a full assessment. If your score is 0–3, we recommend starting with a structured compliance engagement rather than trying to self-remediate across all eight areas simultaneously.

If I score 7 or 8 on this assessment, am I DPDP-compliant?

Not necessarily — but you are well-positioned. A score of 7–8 means you have the right building blocks in place. DPDP compliance is not a binary state; it is a continuous programme. The DPDP Rules 2025 (currently in draft) will add more specific requirements — for consent notice format, breach notification timelines, and Significant Data Fiduciary obligations. A high self-assessment score is a strong foundation, but it should be validated by a formal audit and updated as the Rules are finalised.

Which of the 8 areas is most commonly missed by Indian organisations?

In our experience working with mid-market Indian companies, the three most commonly missed areas are: (1) vendor contracts — most organisations have not reviewed their MSAs for data processing clauses; (2) data retention — data is typically retained indefinitely with no formal schedule; and (3) breach response — most organisations have no documented incident response plan that covers personal data. These three gaps are also among the highest-risk from a regulatory standpoint, because they are the easiest for the Data Protection Board to verify and penalise.

Previous Post Next Post

Get Free DPDP Checklist