Home How We Work Security Assurance Resources
DPDP readiness assessment · free

How ready are you for the DPDP Act?

20 questions across ten obligations. About ten minutes. No sign-up, and your answers stay in your browser. At the end you see where your liability sits, what the Schedule says it could cost, and what would reduce it, including where software is not the answer.

The readiness check

DPDP readiness: answer for your organisation as it is today

DPDP readiness · 20 questions0 of 20 answered

01 · Notice and consentS.5, S.6

Every form, app or counter where you collect personal data shows a notice listing the data, the purpose, and how to withdraw and complain.
Each purpose, such as marketing, is a separate choice and never bundled with the service.

02 · WithdrawalS.6(4), S.6(6)

A person can withdraw consent as easily as they gave it.
When someone withdraws, every system and vendor using that data stops, and you can show it.

03 · Knowing your dataS.8

You have a current list of every system that holds personal data, with an owner for each.
You know where identifiers such as Aadhaar or PAN sit, including in spreadsheets and free-text fields.

04 · Security safeguardsS.8(5)

Access to personal data is limited by role and logged.
Personal data is encrypted where it is stored and when it moves.

05 · Breach responseS.8(6)

You have a written procedure to report a breach to CERT-In within six hours and to inform the Board and affected people.
Within a day of a breach you could say whose data was in the affected system, and how many people.

06 · Retention and erasureS.8(7)

Each kind of personal data has a retention period, and it is erased when that period ends.
You can show that a deletion actually happened in the source system.

07 · ProcessorsS.8(1)–(2)

Every vendor that handles personal data for you has a contract with data protection terms.
You know what personal data each vendor can reach.

08 · Rights and grievanceSS.11–14

People can ask for access, correction or erasure, and you track each request to a due date.
A grievance contact is published and answers within a set time.

09 · ChildrenS.9

If you process data of anyone under 18, you obtain verifiable consent from a parent or guardian.
You do not track, profile or target advertising at children.

10 · Evidence and oversightS.33

You can produce a dated record of what each person consented to, and under which notice.
Management reviews privacy compliance at least once a quarter, with minutes.
Answer every question to see your result. “Not sure” counts as a gap.
What you get

A view of exposure, not a sales pitch

Readiness by obligation

Ten obligations scored from your answers, each tied to its section of the Act.

Your largest exposures

Ranked by the gap and by what the Schedule says that failure can cost.

The cheapest fix

For each exposure, what would close it: a contract, a procedure, a register, or software.

FAQ

The readiness check, answered

Is the readiness check free?

Yes. No sign-up is needed to see the result. If you want the detailed report with recommendations, you can ask for it at the end.

Do you store my answers?

No. The check runs in your browser. Nothing is sent unless you choose to request the report.

Is this a legal assessment?

No. It is a structured self-assessment against the obligations of the DPDP Act, with the maximum penalties from its Schedule. A full assessment looks at your actual notices, contracts and systems.

What happens after the check?

If you want, we walk through the result with you, map the exposures that matter, and tell you which ones need software and which do not.

Then decide what to fix, and what to build.

Wekalp is software for data fiduciaries and is not a Consent Manager registered with the Data Protection Board under section 6(9) of the Act. Nothing on this site is legal advice.