Answer questions about how your organisation actually works and get a score, your penalty exposure in rupees, and a ranked list of what to fix.
That is the normal starting point, and it is worth five minutes to replace it with a number.
You are not sure a clinic your size is even in scope, and nobody has told you otherwise.
A customer asked for your compliance posture and you had nothing to send back.
You handle three different groups of people’s data and have never separated what you owe each one.
Not a lead-capture quiz with the answer behind a form. The assessment is the product, and this much of it is free.
Eleven dimensions of the Act scored separately and weighted, then a single number and a risk band you can put in front of a board.
A penalty range built from the Act’s Schedule — every section you fall short on, weighted by how far short you are.
Ranked by what they cost you, not by what is easiest to fix. Ties broken by the larger penalty, so the expensive thing surfaces first.
The gaps turned into a 0–30, 30–90 and 90+ day roadmap, so your first week has something concrete in it.
A DPDP compliance checklist counts ticks. This DPDP assessment weights each gap by what the Act penalises.
Between 33 and 43 questions depending on your industry and whether children’s data or Significant Data Fiduciary duties apply. A hospital is asked about clinical records; a logistics operator is not. Each answer scores on a five-point scale, not yes/no — because “we have a policy nobody follows” is not the same as “we have none”.
Data mapping, security, notice, consent, rights, breach, retention, vendors, grievance redressal, cross-border transfer and governance — plus children’s data and SDF duties where they apply. Weights shift if you are a Data Processor rather than a Data Fiduciary, because your obligations differ.
If your data mapping or your security scores below 30%, the total is capped at 50 however well everything else scored. Below 30% on both, it is capped at 35. You cannot honour a rights request for data you cannot find, so a high score on top of a blank map would be a lie.
Each gap is multiplied by the maximum penalty the Schedule sets for that obligation — ₹250 Cr for a security failure, ₹200 Cr for breach reporting or children’s data, ₹150 Cr for Significant Data Fiduciary duties, ₹50 Cr for most others — and scaled by how far short you fall.
Indicative only. Penalties are set by the Data Protection Board at its discretion, and are assessed per contravention rather than capped at a single figure.
“Section 6 non-conformance” does not get budget. A rupee figure against a named obligation does.
Everything you need to know where you stand is free. The written report is what you buy, and only if you want it.
One-off. No subscription, and no account needed to take the free assessment first.
No login, no card, no sales call. You get the score, the exposure and the plan whether or not you ever talk to us.
The only thing we ask for before the result is an email, and only so the score is yours to come back to.
Sector, and whether you act as a Data Fiduciary, a Data Processor, or both. This decides which questions you are asked and how the weights are set.
How your organisation actually works, one question at a time, on a five-point scale. Your answers save as you go, so you can stop and come back.
Verify your email and the result is on screen — score, risk band, rupee exposure, your three biggest gaps and the phased plan.
Most DPDP readiness tools are GDPR questionnaires with the country name swapped. Every question here maps to a section of the Act.
Notice under §5 and Rule 3, consent under §6, children under §9, security under §8(5), breach under §8(6) and Rule 7, rights under §11–14. You can check our working.
Exposure comes from the penalties the DPDP Act actually sets, not from GDPR’s 4% of turnover. Different law, different arithmetic.
Fix something, re-score, and watch the number move. The history is kept, so improvement is visible rather than asserted.
Yes. The score, your risk band, your penalty exposure in rupees, your three highest-cost gaps and the phased remediation plan are all free, with no account, no expiring trial and no sales call. The only thing you pay for is the full written report — every dimension broken out, every gap rather than the top three, and a PDF you can hand to a board. You never have to buy it to find out where you stand.
About five minutes. You answer between 33 and 43 questions depending on your industry and whether children’s data or Significant Data Fiduciary duties apply. Answers save as you go, so you can stop and pick it up later without losing anything.
It is as accurate as your answers, and we say so on the result itself — every score carries an “indicative” marker. What it is not is a guess: the weights come from what the Act penalises, the exposure comes from the Schedule, and a dependency rule caps the total if your data mapping or security is weak, so you cannot get a flattering score on top of a blank map. It tells you where to look and what it costs. Confirming it is what an audit is for.
No. The questions are about how your organisation works — who handles personal data, what you tell people, what happens when someone asks for their data back — not about database schemas. A DPO, a founder, a compliance lead or a CTO can all complete it. If you do not know an answer, that is itself a finding worth having.
They are stored against your assessment so you can come back to your result and re-score later, and they sit on infrastructure in India. We ask for an email so the score is yours rather than a stranger’s, and we do not ask for anyone’s personal data — no customer records, no employee lists, nothing about the people you hold data about.
If data mapping or security scores below 30%, the total is capped at 50 — below 30% on both, at 35 — however well the rest scored. It is deliberate. You cannot honour a rights request for data you cannot find, and you cannot secure what you have not mapped, so a high score sitting on top of either would be misleading. The result tells you when the cap has been applied and why.
No, and we would not claim it. It is an exposure model: for each obligation you fall short on, the maximum the Act’s Schedule sets for that obligation, scaled by how far short you fall. Real penalties are set by the Data Protection Board at its discretion, are assessed per contravention, and take into account the nature of the breach and what you did about it. The number is for prioritising work, not for provisioning.
Yes, and it is designed for that. Re-score whenever you like; the history is kept so the movement is visible. Most organisations run it once to find out where they stand, then again after the first thirty days of the plan.
Real client quotes, attributed by role and sector — we never name a client.
Working across
Five minutes, no login, no card. You get the score, your exposure in rupees and the plan — whether or not you ever talk to us.
Thank you — we have it. Someone will reply by email, usually within one working day.
Nothing else is needed from you. If it is urgent, email tushar@ruleexpert.com and it will reach the same people.