Does India's DPDP Act apply to you?
A free self-assessment for Indian organisations. Ten questions, about two minutes. You get the answer immediately — no sign-up and no email required — and it tells you which obligations don't apply to you as well as which do.
What this checks
Two things, in order. First, whether the Digital Personal Data Protection Act 2023 reaches your organisation at all — which turns on section 3: processing personal data in digital form in India, or processing it outside India while offering goods or services to people in India. Purely personal or domestic activity by an individual is outside the Act; an organisation is not.
Second, if it does apply, which specific obligations land on you. That depends on what you hold and who you hold it about. A hotel that transfers nothing abroad does not carry the cross-border rules. A school that holds student records carries obligations most other organisations do not. We show you both lists, with the section behind every entry.
Written for organisations without a compliance team
Schools, colleges and coaching centres. Every student under 18 is a child under the Act, so section 9 covers most of what you do: verifiable consent from a parent or lawful guardian, plus a flat prohibition on tracking children, monitoring their behaviour, or directing advertising at them. That prohibition is not something parental consent unlocks — which makes your edtech and ERP stack the real exposure, not your servers.
Hotels, resorts and guesthouses. You almost certainly hold photocopies of government ID. Section 8(7) requires erasure once the purpose is served unless another law requires retention — so the question is which law made you take the copy, whether it requires you to keep it, and for how long.
Hospitals, clinics and diagnostic labs. Health data is among the sensitivity factors behind Significant Data Fiduciary status under section 10. And the Act will not tell you how long to keep a case sheet: medical-record retention comes from the Clinical Establishments Act, your state's rules and NMC regulations, which can pull in the opposite direction to section 8(7).
What we do with your answers
Nothing, unless you ask us to. The assessment is stateless — running it writes no record at all. If you want the summary by email you can enter an address at the end, and only then do we store that address and your answers, for up to 24 months. There is no name field, no phone field and no company field, because we do not need them.
What this is not
It is not legal advice, and it is not a certification. The DPDP Act creates no certification scheme — there is no accredited DPDPA certifier, and anyone offering to sell you a DPDPA certificate is selling something that does not exist in law. What this gives you is a reasoned starting list, computed from your answers, with the statute behind each item so you can check it yourself or take it to a lawyer.