Get your DPDPA readiness score in 3–5 minutes
See your top gaps, first fixes and a sector-specific action plan for your Indian business, in plain English.
Free · 3–5 minutes · No email to start · Plain English · Not legal advice
Not sure what personal data you hold? Map it first
Significant gaps. Start a focused fix plan now.
Pick your business on the left to see your own read.
Featured inANIBusiness StandardThe TribuneLokmat TimesLatestly
12 sector-specific assessments3–5 minutesNo email to startBuilt for Indian workflows
The everyday data ecosystem
The tools are ordinary. The gaps hide between them.
Most Indian businesses don't lack a privacy policy. They lack visibility into where personal data actually lives.
- What's in there
- Customer and candidate names, phone numbers, and photographs of documents (PAN cards, Aadhaar, prescriptions, invoices) sent into ordinary chats and groups.
- How it goes wrong
- Data is collected with no notice and no recorded consent, on personal handsets the business does not control, and it stays on those handsets after the staff member leaves.
- What closes it
- Keep WhatsApp for conversation, not for documents. Move anything that collects personal data to a channel that can show a notice and record a consent.
- What's in there
- Shared folders of CVs, ID scans, salary sheets and client files, usually inherited from whoever set them up years ago.
- How it goes wrong
- Links set to “anyone with the link”, and access lists that only ever grow: people are added when a project starts and never removed when it ends.
- What closes it
- Review folder access on a fixed schedule, convert open links to named access, and make removing access part of every exit checklist.
- What's in there
- Master trackers of customers, candidates or patients, copied and re-copied as “final_v3” across desktops, mailboxes and pen drives.
- How it goes wrong
- No one owns the copies, so nothing is ever deleted. A single tracker outlives the purpose it was collected for by years, and no one can say how many versions exist.
- What closes it
- Name one system of record per data set, set a retention period against it, and delete the working copies on a schedule rather than on request.
- What's in there
- The full customer record (contact details, transaction history, internal notes, support conversations), held on your behalf by a third-party processor.
- How it goes wrong
- Signed on click-through terms with no data-processing clause, no breach-notification commitment, and no clear answer to where the data is actually stored.
- What closes it
- Keep a vendor register, add processing terms at the next renewal, and require breach notice to you within a fixed window.
- What's in there
- Years of attachments (offer letters, KYC documents, invoices, lab reports) sitting in individual mailboxes as the de facto filing system.
- How it goes wrong
- Shared credentials, auto-forwarding rules and delegate access mean the real reach of that data is much wider than the org chart, and invisible to any review.
- What closes it
- End shared mailbox credentials, audit forwarding and delegation, and stop using the inbox as a document store.
- What's in there
- Enquiry and contact submissions: name, phone, city, and free text in which people describe a personal situation in far more detail than the form asked for.
- How it goes wrong
- The form collects before it explains: no notice at the point of collection, consent bundled into the submit button, and entries emailed onward in plain text.
- What closes it
- Put an itemised notice at the form itself, separate consent from submission, and route entries to one controlled destination instead of a mailing list.
- What's in there
- Payer name, contact details and transaction records held by the gateway, plus the reconciliation exports finance pulls out of it every month.
- How it goes wrong
- Those exports leave the gateway's controls and land in shared drives, and nobody has checked what the gateway itself retains or which sub-processors it uses.
- What closes it
- Reconcile inside the tool where you can, restrict who can export, and record the gateway and its sub-processors in your vendor register.
- What's in there
- Continuous recording of staff, customers and visitors, plus the visitor register at the entrance, which is personal data on paper.
- How it goes wrong
- No signage saying what is recorded or for how long, retention set to whatever the disk holds, and playback available to anyone who knows the DVR password.
- What closes it
- Post a notice where the camera can see, fix a retention window and enforce it on the device, and restrict playback to named people.
- What's in there
- Boxes of forms and old server folders from closed projects, discontinued products and former employees, kept because nobody was ever asked to decide.
- How it goes wrong
- Data held with no purpose left to justify it. This is the hardest position to defend under DPDPA: there is no live reason to have it, and no plan to remove it.
- What closes it
- Inventory what is there, delete what has no live purpose, and bring the rest under the same retention rules as your live data.
- What's in there
- Personal data handed to payroll providers, staffing agencies, marketing agencies, diagnostic labs, couriers and IT contractors.
- How it goes wrong
- Handoffs happen over email and chat with no contract clause, no record of what was shared, and no obligation on the other side to delete it afterwards.
- What closes it
- List every party you share with, add processing and deletion terms to each, and keep a record of what was shared and when.
These are ordinary workflows, not integrations. SaralPrivacy does not connect to any of them. DPDPA risk usually hides here, not in legal documents.
What is DPDPA?
DPDPA is India's framework for handling digital personal data, and the DPDP Rules, 2025 have now been notified. For Indian businesses, the real work is operational: fix your notices, consent flows, rights handling, retention logic, and vendor controls. SaralPrivacy helps you understand what matters, assess your risk, and prioritise the next 30 to 90 days.
Your report
This is what you get at the end
Every assessment ends in a scored, sector-specific report. Here is the shape of one. Pick a sector to see how it changes.
- 1CVs forwarded to clients over email and WhatsApp, with no record of candidate permission.
- 2Candidate profiles stay with multiple recipients after the role closes.
- 3No deletion period for unsuccessful applicants, so databases grow indefinitely.
- 1Record candidate permission at the point you collect the CV, not at placement.
- 2Set a deletion period for unsuccessful applicants and put it in writing.
- 3List every client and job board you send candidate data to.
- Privacy notice published and current
- Consent collected separately, and withdrawable
- Vendor list with written terms
- Retention period defined per data type
- Named owner for data-rights requests
- Breach response steps written down
Want it in writing? You can have the full report emailed to you at the end. Optional, and only if you ask.
Get my real scoreHow it works
Start anywhere. It's all free to try.
Four steps to DPDPA-ready. Follow them in order, or jump straight to what you need.
Explore DPDPA by your sector
Same law. Different data. Different fixes.
Twelve sectors, twelve different exposures. Pick yours and the deck brings it forward.
Recruitment Agencies
- CV databases & candidate data
- Client profile sharing
- Background check documents
- Cross-border data flows
A client asks for a shortlist, and you forward three CVs straight from your inbox.
Sample score 46/100 · illustrative
CA Firms
- PAN / Aadhaar / bank data
- Client payroll records
- Cloud drives & shared folders
- Sensitive financial documents
A client WhatsApps their PAN card, and it ends up in the firm's shared Drive.
Sample score 52/100 · illustrative
Training Institutes
- Student & parent data
- Admissions & lead forms
- Digital marketing consent
- Placement data retention
Check whether your admissions, marketing, and student data workflows are DPDPA-ready.
Sample score 44/100 · illustrative
D2C Brands
- Email / SMS / WhatsApp marketing
- Third-party analytics & pixels
- Customer loyalty data
- Retention of inactive customers
A customer completes checkout, and your marketing list quietly gains a subscriber.
Sample score 49/100 · illustrative
Clinics & Diagnostic Labs
- Prescriptions & lab reports
- WhatsApp report sharing
- Reception & lab staff access
- Old patient-record retention
Check whether your patient-data and report-sharing workflows are DPDPA-ready.
Sample score 42/100 · illustrative
Schools & Colleges
- Children's data & parent consent
- School apps, ERP & LMS
- CCTV, biometric & transport GPS
- Student photos & old records
Check whether your student-data, parent-consent and monitoring workflows are DPDPA-ready.
Sample score 43/100 · illustrative
Law Firms & Legal Consultants
- Client KYC & evidence files
- Junior / intern / ex-staff access
- WhatsApp & email document sharing
- Closed matter-file retention
Check whether your matter intake, sensitive-file access and sharing workflows are DPDPA-ready.
Sample score 50/100 · illustrative
Real Estate & Property Firms
- Buyer/tenant KYC & PAN/Aadhaar
- WhatsApp lead & document sharing
- Broker networks & loan partners
- Old lead-database retention
Check whether your KYC handling, broker sharing and lead retention workflows are DPDPA-ready.
Sample score 45/100 · illustrative
Hotels, Hospitality & Travel
- Guest IDs & passport copies
- OTA & travel-vendor sharing
- WhatsApp confirmations & CCTV
- Old guest-record retention
See whether your guest IDs, OTA sharing, travel documents and record retention are DPDPA-ready.
Sample score 47/100 · illustrative
Pharmacies & Online Pharmacies
- Prescriptions & medicine history
- WhatsApp orders & health indicators
- Delivery-partner data sharing
- Old prescription retention
Check whether your prescriptions, medicine-history handling and vendor sharing are DPDPA-ready.
Sample score 44/100 · illustrative
Fintech, NBFC & Digital Payments
- KYC, PAN/Aadhaar & bank data
- Bureau checks & credit profiling
- DSAs & collection-agent access
- Old application & KYC retention
See whether your KYC, profiling, partner sharing and agent access are DPDPA-ready.
Sample score 55/100 · illustrative
Gyms, Salons & Spas
- Health & body measurements
- Customer & before-after photos
- WhatsApp campaigns & staff phones
- Old member-record retention
Check whether your photo consent, health-data handling and staff access are DPDPA-ready.
Sample score 41/100 · illustrative
Daily briefings
Stay ahead of DPDPA developments
Clear, actionable briefings on DPDPA updates, enforcement signals, and compliance guidance, written for business owners, not lawyers.
Hover a card to bring it forward.Swipe to browse. One briefing every morning, 9 AM IST.
Learn more
If you'd rather read first
The assessment is faster. But if you want the background, start here.
The complete DPDPA guide
What the Act requires, who it applies to, and a 90-day plan, written against the DPDP Rules, 2025 as notified.
Read the guideChoose your language
Compliance checklist
The statutory and operational controls, laid out as a list you can work through and tick off.
Open the checklistTemplate library
17 free notices, consent lines, vendor checklists and sector checklists you can adapt today.
Get the templatesBefore you start
The questions people ask first
What it takes, what you get, and what happens to your answers.
If your business collects, stores, or processes personal data of Indian citizens (even just names, email addresses, or mobile numbers), it is likely covered by the DPDPA. There is no explicit exemption for small or micro businesses in the current text of the Act. However, the government may notify specific exemptions for certain categories of businesses through rules. Until then, all businesses collecting personal data should plan for compliance. The first step is understanding what data you collect and why.
Nothing about yourself, and no documents. The assessment asks practical questions about how your business already works: where customer or staff data is stored, whether you have a privacy notice, how you collect consent, who can reach shared folders, and what happens when someone asks for their data. If you run the business or its operations, you can answer every question from memory in a few minutes.
No. You can take the whole assessment and see your score, your risk category, your top gaps and your first recommended actions without entering an email address. An email is only needed if you want the full report sent to you. That is a choice at the end, not a gate at the start.
A readiness score out of 100, your risk category, scores across five dimensions (notice and collection, consent, sharing and vendors, access and security, retention and response), your top three privacy gaps, your first recommended actions, and a practical DPDPA checklist. It is written in plain English and organised by what to do first, not by section of the Act.
Only if you ask for the report. Your score is calculated in your browser as you answer, and nothing is sent to us unless you enter your contact details and request the full report at the end. If you close the tab before that point, we have no record of your answers, because none was ever transmitted.
It is a readiness indicator, not an audit. The score reflects the answers you give about your own workflows, so it is as accurate as those answers are. It is designed to tell you reliably where your biggest gaps sit and what to fix first. It is not a certification, and it does not inspect your systems. Treat it as a prioritised starting point for the next 30 to 90 days.
You get your gaps and your first actions immediately on screen, and you can work through them yourself. Most of the first fixes are decisions and documentation, not software. If you want to go further, you can map where your personal data actually sits, generate a privacy notice, or download the checklist and templates. Nothing is charged, and no account is created.
No. SaralPrivacy is an education and readiness platform, not a law firm. We tell you what to prepare and what to prioritise in plain English. For a formal opinion on your specific position, particularly if you have had a breach, a regulatory query, or a contractual dispute, engage a qualified data protection lawyer. The assessment is useful preparation for that conversation, not a substitute for it.
Know your gaps. Fix what matters. Signal trust.
Take free assessmentFree · 3–5 minutes · No email to start