Free DPDPA readiness check · 3–5 minutes

Get your DPDPA readiness score in 3–5 minutes

See your top gaps, first fixes and a sector-specific action plan for your Indian business, in plain English.

I run a…

See all 12 sectors

Free · 3–5 minutes · No email to start · Plain English · Not legal advice

Not sure what personal data you hold? Map it first

Privacy readiness snapshotSample · Clinics & Labs
41/ 100
High-priority action

Significant gaps. Start a focused fix plan now.

Pick your business on the left to see your own read.

Featured inANIBusiness StandardThe TribuneLokmat TimesLatestly

12 sector-specific assessments3–5 minutesNo email to startBuilt for Indian workflows

The everyday data ecosystem

The tools are ordinary. The gaps hide between them.

Most Indian businesses don't lack a privacy policy. They lack visibility into where personal data actually lives.

Personal data enters your business
…and scatters to:
WhatsAppConsent gapLifecycle stage · Collect
What's in there
Customer and candidate names, phone numbers, and photographs of documents (PAN cards, Aadhaar, prescriptions, invoices) sent into ordinary chats and groups.
How it goes wrong
Data is collected with no notice and no recorded consent, on personal handsets the business does not control, and it stays on those handsets after the staff member leaves.
What closes it
Keep WhatsApp for conversation, not for documents. Move anything that collects personal data to a channel that can show a notice and record a consent.

These are ordinary workflows, not integrations. SaralPrivacy does not connect to any of them. DPDPA risk usually hides here, not in legal documents.

What is DPDPA?

DPDPA is India's framework for handling digital personal data, and the DPDP Rules, 2025 have now been notified. For Indian businesses, the real work is operational: fix your notices, consent flows, rights handling, retention logic, and vendor controls. SaralPrivacy helps you understand what matters, assess your risk, and prioritise the next 30 to 90 days.

Your report

This is what you get at the end

Every assessment ends in a scored, sector-specific report. Here is the shape of one. Pick a sector to see how it changes.

Privacy readiness reportSample · illustrative
Recruitment agency
46/ 100
Risk category
High
Five dimensions
Candidate sourcing48
Candidate documents34
Client sharing29
ATS, tool & access55
Retention & rights26
Your top 3 gaps
  1. 1CVs forwarded to clients over email and WhatsApp, with no record of candidate permission.
  2. 2Candidate profiles stay with multiple recipients after the role closes.
  3. 3No deletion period for unsuccessful applicants, so databases grow indefinitely.
Fix these first
  1. 1Record candidate permission at the point you collect the CV, not at placement.
  2. 2Set a deletion period for unsuccessful applicants and put it in writing.
  3. 3List every client and job board you send candidate data to.
Plus a practical checklist
  • Privacy notice published and current
  • Consent collected separately, and withdrawable
  • Vendor list with written terms
  • Retention period defined per data type
  • Named owner for data-rights requests
  • Breach response steps written down

Want it in writing? You can have the full report emailed to you at the end. Optional, and only if you ask.

Get my real score

Explore DPDPA by your sector

Same law. Different data. Different fixes.

Twelve sectors, twelve different exposures. Pick yours and the deck brings it forward.

Recruitment Agencies

Candidate ID & CV risk
  • CV databases & candidate data
  • Client profile sharing
  • Background check documents
  • Cross-border data flows

A client asks for a shortlist, and you forward three CVs straight from your inbox.

Sample score 46/100 · illustrative

CA Firms

PAN / Aadhaar / ITR risk
  • PAN / Aadhaar / bank data
  • Client payroll records
  • Cloud drives & shared folders
  • Sensitive financial documents

A client WhatsApps their PAN card, and it ends up in the firm's shared Drive.

Sample score 52/100 · illustrative

Training Institutes

Student & parent data risk
  • Student & parent data
  • Admissions & lead forms
  • Digital marketing consent
  • Placement data retention

Check whether your admissions, marketing, and student data workflows are DPDPA-ready.

Sample score 44/100 · illustrative

D2C Brands

Marketing & pixel-data risk
  • Email / SMS / WhatsApp marketing
  • Third-party analytics & pixels
  • Customer loyalty data
  • Retention of inactive customers

A customer completes checkout, and your marketing list quietly gains a subscriber.

Sample score 49/100 · illustrative

Clinics & Diagnostic Labs

Health-data risk
  • Prescriptions & lab reports
  • WhatsApp report sharing
  • Reception & lab staff access
  • Old patient-record retention

Check whether your patient-data and report-sharing workflows are DPDPA-ready.

Sample score 42/100 · illustrative

Schools & Colleges

Children's-data risk
  • Children's data & parent consent
  • School apps, ERP & LMS
  • CCTV, biometric & transport GPS
  • Student photos & old records

Check whether your student-data, parent-consent and monitoring workflows are DPDPA-ready.

Sample score 43/100 · illustrative

Law Firms & Legal Consultants

Sensitive case-file risk
  • Client KYC & evidence files
  • Junior / intern / ex-staff access
  • WhatsApp & email document sharing
  • Closed matter-file retention

Check whether your matter intake, sensitive-file access and sharing workflows are DPDPA-ready.

Sample score 50/100 · illustrative

Real Estate & Property Firms

KYC & broker-sharing risk
  • Buyer/tenant KYC & PAN/Aadhaar
  • WhatsApp lead & document sharing
  • Broker networks & loan partners
  • Old lead-database retention

Check whether your KYC handling, broker sharing and lead retention workflows are DPDPA-ready.

Sample score 45/100 · illustrative

Hotels, Hospitality & Travel

Guest-ID retention risk
  • Guest IDs & passport copies
  • OTA & travel-vendor sharing
  • WhatsApp confirmations & CCTV
  • Old guest-record retention

See whether your guest IDs, OTA sharing, travel documents and record retention are DPDPA-ready.

Sample score 47/100 · illustrative

Pharmacies & Online Pharmacies

Prescription-data risk
  • Prescriptions & medicine history
  • WhatsApp orders & health indicators
  • Delivery-partner data sharing
  • Old prescription retention

Check whether your prescriptions, medicine-history handling and vendor sharing are DPDPA-ready.

Sample score 44/100 · illustrative

Fintech, NBFC & Digital Payments

KYC & profiling risk
  • KYC, PAN/Aadhaar & bank data
  • Bureau checks & credit profiling
  • DSAs & collection-agent access
  • Old application & KYC retention

See whether your KYC, profiling, partner sharing and agent access are DPDPA-ready.

Sample score 55/100 · illustrative

Gyms, Salons & Spas

Photo & health-data risk
  • Health & body measurements
  • Customer & before-after photos
  • WhatsApp campaigns & staff phones
  • Old member-record retention

Check whether your photo consent, health-data handling and staff access are DPDPA-ready.

Sample score 41/100 · illustrative

1 / 12

Explore all 12 industries

Daily briefings

Stay ahead of DPDPA developments

Clear, actionable briefings on DPDPA updates, enforcement signals, and compliance guidance, written for business owners, not lawyers.

Latest2 Sept 2026All briefings

Swipe to browse. One briefing every morning, 9 AM IST.

Learn more

If you'd rather read first

The assessment is faster. But if you want the background, start here.

The complete DPDPA guide

What the Act requires, who it applies to, and a 90-day plan, written against the DPDP Rules, 2025 as notified.

Read the guide

Choose your language

Compliance checklist

The statutory and operational controls, laid out as a list you can work through and tick off.

Open the checklist

Template library

17 free notices, consent lines, vendor checklists and sector checklists you can adapt today.

Get the templates

Before you start

The questions people ask first

What it takes, what you get, and what happens to your answers.

If your business collects, stores, or processes personal data of Indian citizens (even just names, email addresses, or mobile numbers), it is likely covered by the DPDPA. There is no explicit exemption for small or micro businesses in the current text of the Act. However, the government may notify specific exemptions for certain categories of businesses through rules. Until then, all businesses collecting personal data should plan for compliance. The first step is understanding what data you collect and why.

Know your gaps. Fix what matters. Signal trust.

Take free assessment

Free · 3–5 minutes · No email to start