Your privacy policy says one thing. Your systems do another. This finds every place those two disagree.
Each was written by different people at different times, and nobody has ever read them side by side.
Usually written years ago, adapted from a template, and edited by whoever last had time. It is the only one of the three a customer or a regulator can actually read.
Written later, by someone else, purpose by purpose. Where these promise something the policy does not mention, one of the two is wrong.
Your registry: every system, category, recipient and transfer. This is the ground truth, and it is the one nobody compares the policy against.
A tool that only reads your policy can tell you whether it is well written. It cannot tell you the policy is silent about the analytics vendor you added in March, or that it describes a retention period your own schedule contradicts. That comparison is only possible if the same system holds all three — which is the argument for doing this here rather than buying a scanner.
Because almost every Indian policy began as a GDPR template, and the two laws differ in exactly the places a template cannot see.
The DPDP Act grants no portability right. Your policy offers one anyway, because the template it came from was written for a law that does. You have published a promise nobody asked you for and no process to honour.
§14 lets a person nominate someone to exercise their rights if they die or become incapable. No other major regime has it, so no template carries it, so almost no Indian policy mentions it.
A person who is unsatisfied with your grievance handling may complain to the Data Protection Board, and Rule 3 expects them to be told how. Policies inherited from elsewhere point at a supervisory authority that has no jurisdiction here.
“We respond within 30 days” is GDPR language. Rule 14(3) sets ninety days for grievance redressal, and the Act sets no fixed period for the rights themselves. A published promise of thirty days is a promise you can breach.
None of these is fatal on its own. All four are wrong on a document you have published as a statement of how you handle personal data — which is the document a regulator reads first and a claimant quotes back to you.
You give it the URL your policy actually lives at. No export, no upload, no pasting a version that may already be out of date.
Each requirement of §5 and Rule 3 tested separately with the provision named, rather than a score out of a hundred that tells you nothing about what to change.
Where a consent notice describes a purpose your policy never mentions, or the two give different retention periods for the same data, that contradiction is the finding.
A processor in your vendor list and nowhere in your policy. A system hosted abroad with no transfer disclosed. The gap between what you do and what you say you do.
§8(9) requires a published, reachable contact. A grievance address that bounces is a failed obligation, not an IT issue, and it is trivially checkable.
A gap you cannot act on is just a nag. Each finding arrives with the paragraph that would close it, for a person to weigh, edit and accept.
Your policy is prose. Your obligations are structured. Reading one against the other is the whole job, and it is the part a scanner cannot do.
“On request, we will provide your information in a commonly used electronic format so you can transfer it to another provider.”
A data portability commitment. The DPDP Act grants no such right, so this is a promise you made voluntarily and can be held to.
The word “portability” never appears. A keyword scan finds nothing here.“We retain your records for as long as necessary to provide our services.”
Your retention schedule sets seven years for clinical records and ninety days for marketing. The policy describes neither and implies a single open-ended period.
Found by comparing the sentence against your own schedule, not against a rulebook.“We may share your information with trusted partners who help us operate our business.”
Your registry lists eleven processors, two of them hosted outside India. The policy names none of them and does not disclose a transfer abroad at all.
Three documents compared at once: the sentence, the vendor list and the hosting locations.Every gap is priced against the Act’s own Schedule — and most published guidance, ours included until recently, has these wrong.
Failure to take reasonable security safeguards. The heaviest penalty in the Act.
Failure to notify a personal data breach to the Board or to affected people.
Failure in the additional obligations owed in relation to children’s data.
Failure in the extra duties of a Significant Data Fiduciary, if you are named one.
Notice, consent, processor accountability and rights all sit here — the Schedule’s residual entry for any other contravention.
That last row is the one worth reading twice, because it is where most policy gaps land and it is routinely quoted at three to five times its real figure. A vendor telling you a consent defect carries ₹250 Cr is either not reading the Schedule or is counting on you not to. These are also maxima, set by the Board per contravention, not predictions — and §33(2) makes what you did about a gap an express factor in what any of them becomes.
The problem is not that your policy was wrong once. It is that nothing tells you when it becomes wrong again.
Marketing edits the policy without telling compliance. The next read happens because the document moved, not because somebody remembered to look.
A new vendor or a new category in your registry is a change to what your policy should say. That is the trigger nobody currently has.
Fix a finding and it is verified on the next read rather than taken on trust, so you can see the direction of travel over a year instead of one snapshot.
The free Scorecard already covers notice and rights handling across ten weighted dimensions, and our privacy lawyers review published policies against the Act today.
A published policy is a statement your organisation makes. Changing it is not something software should do quietly.
An accepted finding produces revised wording for review. Putting it in front of the public stays a decision a named person makes and the record shows who.
It tests your policy against what your registry says. Where your registry is incomplete so is the finding — which is why the mapping comes first.
It flags where wording does not meet a provision. Whether your position is defensible is a judgement, and our empanelled privacy lawyers make that call today.
Usually, and in both directions at once. It tends to promise data portability, which the DPDP Act does not grant, while omitting nomination under §14 and the right to complain to the Data Protection Board, which it does. It often quotes a thirty-day response window borrowed from a different regime when Rule 14(3) sets ninety days for grievance redressal. None of that is fatal. All of it is wrong on a document you have published as a statement of how you handle personal data.
For most policy defects, up to ₹50 Cr — the Schedule's residual entry, which covers notice under §5, consent under §6, processor accountability under §8(2) and the rights under §11 to §14. The larger figures attach elsewhere: ₹250 Cr for a security failure, ₹200 Cr for breach notification or children's data, ₹150 Cr for a Significant Data Fiduciary's extra duties. Be careful of anyone pricing a consent defect at ₹250 Cr — that number belongs to a different obligation.
Two ways today. The free Scorecard covers notice and rights handling among its ten dimensions and gives you a position in five minutes. For the document itself, our empanelled privacy lawyers review policies against the Act as a service — and for a policy that has been public for two years and inherited from a GDPR template, a person reading it closely is the right answer anyway.
Only the public URL of your policy — the same page any visitor can read. Nothing is uploaded, no credentials are needed, and the version examined is the one actually published rather than whatever was pasted into a form. The sharper comparisons — against your notices and your registry — use records that already sit in your own tenant.
It drafts the paragraph that closes a gap. It does not republish anything: an accepted correction becomes a draft that a named person approves, which is the same rule every other module here follows. For a policy carrying real exposure, have counsel read the revision — that service is available now and does not wait on this module.
No date, deliberately. Join the waitlist and we will tell you when its findings are ones we would act on ourselves. The Scorecard and the lawyer review are available today and do not depend on it.
Real client quotes, attributed by role and sector — we never name a client.
Working across
Ten dimensions scored against the Act, your exposure in rupees, and the three that cost you most — free, and no account.
Thank you — we have it. Someone will reply by email, usually within one working day.
Nothing else is needed from you. If it is urgent, email tushar@ruleexpert.com and it will reach the same people.