How ready are you for the DPDP Act?
A free, 3-minute self-assessment for Indian Data Fiduciaries. Get an instant Significant Data Fiduciary likelihood and a readiness score across 7 DPDP obligation areas, with your top actions prioritised — no signup, and your answers never leave your browser.
- Legal baseline
- DPDP Act, 2023 · DPDP Rules, 2025 (notified 13 Nov 2025)
- Next milestone
- 13 Nov 2026 — Consent Manager registration (Rule 4)
- Substantive obligations
- 13 May 2027 — security, breach, retention, rights (Rules 3, 5–16)
What this checker assesses
6 profile questions, then up to 22 readiness questions across 7 obligation areas — each mapped to the governing Section of the Act and Rule.
Scope note: this catalog covers the operational and security-side obligations above, mirroring the Offload DPDP module. Notice (Section 5), consent management (Section 6) and children's data (Section 9) are not yet scored here — confirm those with counsel.
About this tool
Is this DPDP readiness score a legal assessment?
No. It is an indicative self-assessment that gives you a directional readiness signal and a Significant Data Fiduciary (SDF) likelihood based on your answers. It is not legal advice, not an audit, and not a certification or formal designation — confirm your obligations with qualified legal counsel. The scoring mirrors the methodology in the Offload Security DPDP module.
What is a Significant Data Fiduciary (SDF)?
Under Section 10 of the DPDP Act, the Central Government can designate certain Data Fiduciaries as Significant based on the volume and sensitivity of data they process and the risk to data principals. SDFs carry additional obligations — appointing a Data Protection Officer, periodic independent audits, and Data Protection Impact Assessments. Official thresholds are not yet notified, so this tool gives a likelihood signal to help you plan. Only the Central Government can actually designate SDF status.
Are the DPDP Rules already in force?
The DPDP Act, 2023 is enacted and the DPDP Rules, 2025 were notified on 13 Nov 2025, but the obligations commence in phases. Rules 1, 2 and 17–21 took effect on publication; Rule 4 (Consent Manager registration) comes into force on 13 Nov 2026; the substantive obligations in Rules 3, 5–16, 22 and 23 — security safeguards, breach notification, retention, rights — come into force on 13 May 2027. Treat this checker as readiness planning against that timeline, and confirm the commencement date for each obligation with counsel.
Does anything I enter leave my browser?
Your questionnaire answers are scored entirely in your browser. Nothing is sent anywhere unless you choose to enter your email to unlock the detailed breakdown. This page runs no third-party trackers on your answers.
How is the readiness percentage calculated?
Six questions estimate your Significant Data Fiduciary likelihood, then each of up to 22 DPDP obligations across 7 areas becomes one plain-language question (fewer if some areas don't apply to you). 'Yes' counts fully, 'Partially' counts half, 'No' / 'Not sure' count as a gap, and 'N/A' is excluded from your score. The percentage is your credited controls over the controls that apply to you. Significant Data Fiduciary controls only count if the tool flags you as a likely SDF.
This checker is an indicative self-assessment, not legal advice, an audit, or a formal DPDP designation. For a live, evidence-backed readiness review mapped to security controls, see the Offload DPDP module. Spot an inaccuracy in the legal content? Tell us — we review regularly.
Turn this score into an evidence-backed program.
Offload's DPDP module tracks breach deadlines, DPIAs, SDF obligations, and audit packs — deployable fully on-premises.