DPDP readiness quiz.
15 questions. Weighted.
A self-assessment against the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 — every question cited to the provision it comes from, every answer weighted by what sits behind it in THE SCHEDULE. Reviewed 19 August 2026.
Your answers live in this tab's memory and nowhere else. No API call, no analytics event carrying your answers, no email gate, no stored report — refreshing clears everything. The print button hands the page to your own browser's print dialogue. For a privacy self-assessment that matters more than usual, so check the network tab if you like.
Rule 4 and First Schedule Parts A and B, with s.6(9) and s.27(1)(d). Nothing else new commences — an ordinary Data Fiduciary picks up no new obligation and no monetary penalty exposure on this date.
ss.3–17, s.27 (except cl.(1)(d)), ss.28–34, s.36, s.37 and s.44(2), with Rules 3, 5–16, 22 and 23. Notice, consent, security, breach, erasure, children, rights, SDF duties, cross-border and the penalty machinery all land together.
Have you established that the Act applies to you and produced an inventory of the digital personal data you process, the purpose of each processing activity, and the ground — consent or a specific legitimate use — each rests on?
Three dates, not one
G.S.R. 843(E) of 13 November 2025 appointed different commencement dates for different provisions of the Act, and Rule 1(2)–(4) of the DPDP Rules 2025 did the same for the Rules. Most published summaries collapse them into one deadline; the split below is the gazette position.
DPDP Rules 2025: Rules 1, 2 and 17 to 21 only — plus the Fifth and Sixth Schedules those rules invoke. (Rule 1(2): "Rules 1, 2 and 17 to 21 shall come into force on the date of their publication in the Official Gazette.")
DPDP Act via G.S.R. 843(E) cl.(a): s.1(2), s.2 (definitions), ss.18–26 (Data Protection Board — establishment, composition, appointment, salary and terms, disqualification, resignation/removal, proceedings, officers and employees, members deemed public servants), s.35 (protection of action taken in good faith), ss.38–43 (consequential amendments and residual powers, including the TRAI Act appellate route and s.42 power to amend the Schedule), and s.44(1) and (3). Rules 17–21 supply the search-cum-selection committees, Board salaries (Chairperson Rs 4,50,000/month, other Members Rs 4,00,000/month, without house or car), meeting procedure and one-third quorum, the six-month inquiry completion limit extendable by three months at a time (r.19(9)), the Board as a digital office (r.20), and staff terms (r.21). CORRECTION to the common summary: complaints did NOT open on this date. Section 27 — the Board's power to entertain complaints, intimations and references and to inquire — is not in force in Phase 1 at all. Phase 1 creates the institution, not the jurisdiction. No compliance obligation attaches to any Data Fiduciary.
DPDP Rules 2025: Rule 4 alone, together with the First Schedule Parts A and B that Rule 4 invokes. (Rule 1(3): "Rule 4 shall come into force one year after the date of publication of this Gazette.")
DPDP Act via G.S.R. 843(E) cl.(b): only s.6(9) ("Every Consent Manager shall be registered with the Board in such manner and subject to such technical, operational, financial and other conditions as may be prescribed") and s.27(1)(d) (on receipt of intimation of breach of any condition of registration of a Consent Manager, the Board may inquire and impose penalty). Rule 4 opens applications to the Board; First Schedule Part A sets the registration conditions (company incorporated in India; net worth not less than Rs 2 crore; sound financial condition and management character; technical, operational and financial capacity; MoA/AoA hard-coding the conflict-of-interest obligations and amendable only with prior Board approval; independent certification that the interoperable consent platform meets the Board's data protection standards and assurance framework); Part B sets 13 continuing obligations. Rule 4(4)–(5) give the Board direction, suspension and cancellation powers. CORRECTION to the common summary: general enforcement and the penalty machinery do NOT go live on this date. Sections 28–34 (including s.33 and the Schedule of penalties) commence only at 18 months. For an ordinary Data Fiduciary that is not itself a Consent Manager, no new substantive obligation and no monetary penalty exposure begins on 13 November 2026.
DPDP Rules 2025: Rules 3, 5 to 16, 22 and 23, with the Second, Third, Fourth and Seventh Schedules. (Rule 1(4): "Rules 3, 5 to 16, 22 and 23 shall come into force eighteen months after the date of publication of this Gazette.") The rule split for all three phases is confirmed verbatim against G.S.R. 846(E).
DPDP Act via G.S.R. 843(E) cl.(c): ss.3–5, s.6(1)–(8) and (10), ss.7–10, ss.11–17, s.27 except cl.(1)(d), ss.28–34, s.36, s.37, and s.44(2). This is the entire operative regime: application and extraterritorial reach (s.3), grounds for processing (s.4), notice (s.5), consent (s.6), legitimate uses (s.7), general obligations of the Data Fiduciary including reasonable security safeguards, breach intimation and erasure (s.8), children (s.9), Significant Data Fiduciary obligations (s.10), Data Principal rights and duties (ss.11–15), the cross-border restriction power (s.16), exemptions (s.17), the Board's powers, functions and procedure (ss.27–28), appeals and alternate dispute resolution (ss.29–32), penalties (s.33) and the Schedule, and crediting of penalties to the Consolidated Fund (s.34). Rules 3 and 5–16 supply the operational detail (notice content, security floor, breach clocks, erasure timers, children's verifiable consent, SDF obligations, rights mechanics, cross-border); Rule 22 the Appellate Tribunal appeal; Rule 23 the Government's power to call for information under the Seventh Schedule.
What a breach can cost
Monetary penalties sit in THE SCHEDULE to the Act, read with s.33. None of it is in force yet: G.S.R. 843(E) cl.(c) brings ss.28–34 into force only eighteen months after 13 November 2025, i.e. 13 May 2027.
| # | Breach | Ceiling |
|---|---|---|
| 1 | Breach in observing the obligation of a Data Fiduciary to take reasonable security safeguards to prevent personal data breach under s.8(5) This single entry is the source of the headline figure; it is not a general cap on all breaches. | may extend to Rs 250 crore |
| 2 | Breach in observing the obligation to give the Board or affected Data Principal notice of a personal data breach under s.8(6) Can be levied on top of entry 1 for the same incident — Rs 450 crore of combined headroom. | may extend to Rs 200 crore |
| 3 | Breach in observance of additional obligations in relation to children under s.9 | may extend to Rs 200 crore |
| 4 | Breach in observance of additional obligations of a Significant Data Fiduciary under s.10 | may extend to Rs 150 crore |
| 5 | Breach in observance of the duties under s.15 (impersonation, suppression of material information, false or frivolous complaints, inauthentic correction/erasure requests) This lands on individual Data Principals, not on businesses. | may extend to Rs 10,000 |
| 6 | Breach of any term of a voluntary undertaking accepted by the Board under s.32 | Up to the extent applicable for the breach in respect of which the s.28 proceedings were instituted |
| 7 | Breach of any other provision of the Act or the rules made thereunder The residual entry — the actual exposure for notice (s.5/r.3), consent (s.6), retention and erasure (s.8(7)–(8)/r.8), rights and grievance (ss.11–14/r.14), DPO contact publication (s.8(9)/r.9) and cross-border (s.16/r.15) failures. | may extend to Rs 50 crore |
- s.33(1): a penalty may be imposed only after the Board concludes an inquiry, determines the breach is "significant", and gives the person an opportunity of being heard.
- s.33(2): the amount is fixed by reference to seven factors — (a) nature, gravity and duration of the breach; (b) type and nature of the personal data affected; (c) repetitive nature of the breach; (d) whether the person realised a gain or avoided a loss; (e) whether the person took mitigating action, and its timeliness and effectiveness; (f) proportionality and deterrent effect; (g) likely impact of the penalty on the person.
- The amounts are ceilings per breach, not fixed fines. There is no turnover-percentage cap of the GDPR 2% / 4% kind.
- s.34: all sums realised are credited to the Consolidated Fund of India.
- Appeal lies to the Appellate Tribunal (TDSAT) under s.29 within sixty days of receipt of the order, filed digitally under r.22 with a fee equal to that for a TRAI Act appeal, payable by UPI or another RBI-authorised system, waivable at the Chairperson's discretion.
- Rule 19(9) requires the Board to complete an inquiry within six months of receiving the intimation, complaint, reference or direction, extendable in writing by up to three months at a time.
Unsupported: Claims in secondary commentary that s.33 permits the Board to enhance or double a penalty (a purported s.33(3)). The Act as published by MeitY contains only s.33(1) and s.33(2), and no doubling or multiplier provision was found. Treat the "up to Rs 500 crore" figure that appears in some vendor material as unsupported.
Significant Data Fiduciary status is conferred, not self-assessed.
Section 10(1) lets the Central Government notify "any Data Fiduciary or class of Data Fiduciaries" as an SDF on an assessment of relevant factors "including" (a) the volume and sensitivity of personal data processed; (b) risk to the rights of Data Principal; (c) potential impact on the sovereignty and integrity of India; (d) risk to electoral democracy; (e) security of the State; and (f) public order. The list is non-exhaustive and there is no numeric threshold anywhere in the Act or the Rules — nothing analogous to a user count or turnover trigger. Seventh Schedule entry 3 names the authorised person for carrying out the SDF assessment as an officer of MeitY designated by the Secretary, and Rule 23 gives the Government power to call for information from any Data Fiduciary or intermediary for that purpose.
As at 19 August 2026 no entity or class has been notified as a Significant Data Fiduciary.
Appoint a DPO who (i) represents the SDF under the Act, (ii) is based in India, (iii) is an individual responsible to the Board of Directors or similar governing body, and (iv) is the point of contact for the grievance redressal mechanism. Materially stricter than GDPR Article 37 — a group DPO sitting in the EU, or a compliance function reporting into legal rather than the board, does not satisfy it.
Appoint an independent data auditor to carry out a data audit evaluating the SDF's compliance with the Act.
Rule 13(1) requires a Data Protection Impact Assessment and an audit once in every period of twelve months from the date on which the entity is notified as an SDF; r.13(2) requires the person carrying them out to furnish to the Board a report containing significant observations. The clock starts on designation, not on the Rules' commencement, and the output goes to the regulator rather than staying internal.
Rule 13(3) requires due diligence to verify that technical measures, including algorithmic software, adopted for hosting, display, uploading, modification, publishing, transmission, storage, updating or sharing of personal data are not likely to pose a risk to Data Principals' rights. Rule 13(4) requires the SDF to ensure that personal data specified by the Central Government — on the recommendation of a committee constituted under r.13(5) including MeitY officials — and the traffic data pertaining to its flow are not transferred outside India. This is the only localisation mandate in the whole framework: it binds SDFs alone, and only over categories the Government later specifies.
Schedule entry 4 caps SDF-obligation breaches at Rs 150 crore.
Planning point: MeitY's January 2026 consultation proposed bringing s.10(1), r.13(4) and r.15 into force immediately rather than at eighteen months and compressing the SDF compliance window to twelve months (13 November 2026). That proposal was not notified as at 19 August 2026, but any organisation plausibly in scope should build to the earlier date.
What we could not verify
Everything else on this page traces to the gazette text of the Act, G.S.R. 843(E) or the DPDP Rules 2025. The items below could not be confirmed from a primary source as at 19 August 2026, so they are listed as open rather than filled in with something plausible.
ConsequentialAcceleration proposal — has the compliance window been compressed?
Whether MeitY's January 2026 proposal to compress the DPDP compliance window from eighteen months to twelve (moving SDF compliance to 13 November 2026) and to bring s.10(1), r.13(4), r.15 and s.17(2) into force immediately has been notified in the Gazette. Sources dated to 22 July 2026 still describe it as an unnotified consultation proposal following stakeholder discussions on 23 January 2026 with comments due 4 February 2026. No amending notification was located.
ConsequentialConsent Manager penalties from 13 November 2026 — unresolved
Whether monetary penalties can in fact be imposed on a Consent Manager from 13 November 2026. G.S.R. 843(E) cl.(b) brings s.27(1)(d) into force at twelve months, and that clause speaks of inquiring "and impose penalty as provided in this Act" — but s.33 and the Schedule commence only at eighteen months under cl.(c). Several commentaries assert that the penalty framework for consent managers is enforced in Phase 2; the gazette text does not support a monetary penalty before 13 May 2027. Rule 4(4) directions and Rule 4(5) suspension or cancellation of registration are available from 13 November 2026 regardless.
ConsequentialConsent Manager application materials not published
Whether the Board has published the "data protection standards and assurance framework" referred to in First Schedule Part A item 9(a), or the application particulars, information and documents contemplated by Rule 4(1). Neither located. Until they exist a prospective Consent Manager cannot fully assemble an application.
OpenData Protection Board appointments
Whether the Chairperson and Members of the Data Protection Board of India have been appointed and assumed office as at 19 August 2026. MeitY invited applications on 6 May 2026 with a further notification on 6 June 2026; commentary dated April 2026 states the search-cum-selection committees were delayed and no Chairperson or Members had been appointed. No appointment notification was located.
OpenSDF designations
Whether any Data Fiduciary or class has been notified as a Significant Data Fiduciary under s.10(1). None located.
OpenCross-border restrictions under s.16(1) / r.15
Whether the Central Government has issued any notification under s.16(1) restricting transfer to a named country or territory, or any general or special order under Rule 15 specifying requirements for making personal data available to a foreign State or an entity under its control. None located.
OpenRule 13(4) localisation categories
Whether the Central Government has specified, under Rule 13(4), the categories of personal data an SDF must keep within India, or constituted the Rule 13(5) committee. Neither located.
Opens.9(5) higher-age notification
Whether s.9(5) — the power to notify a higher age above which a Data Fiduciary with verifiably safe children's processing is exempt from s.9(1) and s.9(3) — has been operationalised for anyone. No notification located.
OpenFourth Schedule lettering error
The Fourth Schedule Note in the gazette text of the DPDP Rules 2025 has duplicated clause lettering: both "advertisement" and "allied healthcare professional" are lettered (a). This appears to be a drafting error; no corrigendum was located.
Opens.6(7)–(8) wording not verified at character level
Precise wording of s.6(7) and s.6(8) could not be confirmed against the primary PDF at character level (the fetched Act text rendered those sub-sections through a summarising layer). s.6(9) was confirmed. Verify s.6(7)–(8) against the MeitY PDF before quoting them in a client-facing product.
OpenPenalty-doubling claims are unsupported
Claims circulating in secondary commentary that s.33 permits the Board to enhance or double a penalty (a purported s.33(3)) — the Act as published by MeitY contains only s.33(1) and s.33(2), and no doubling or multiplier provision was found. Treat the "up to Rs 500 crore" figure that appears in some vendor material as unsupported.
Frequently asked
Does any part of the DPDP Act apply to my company right now?
It depends on the date, because G.S.R. 843(E) split commencement into three. On 13 November 2025 only the Data Protection Board framework came into force — s.1(2), s.2, ss.18–26, s.35, ss.38–43 and s.44(1) and (3), with Rules 1, 2 and 17–21. No compliance obligation attached to any Data Fiduciary, and contrary to much of the commentary, complaints did not open: s.27 was not in force in that phase at all. On 13 November 2026 exactly one thing commences — s.6(9), s.27(1)(d) and Rule 4 with First Schedule Parts A and B, which open Consent Manager registration. On 13 May 2027 the operative regime lands: ss.3–5, s.6(1)–(8) and (10), ss.7–17, s.27 except cl.(1)(d), ss.28–34, s.36, s.37 and s.44(2), with Rules 3, 5–16, 22 and 23.
So there is no penalty exposure before 13 May 2027?
For an ordinary Data Fiduciary, that is what the gazette text says. Sections 28–34 — the Board's inquiry powers, appeals, penalties under s.33 and THE SCHEDULE — commence only eighteen months after 13 November 2025. The one open question concerns Consent Managers: s.27(1)(d) commences at twelve months and speaks of inquiring and imposing penalty as provided in the Act, but s.33 and the Schedule do not commence until eighteen months. Several commentaries assert the consent-manager penalty framework is live in Phase 2; the gazette text does not support a monetary penalty before 13 May 2027, and we have left that flagged as unresolved rather than resolving it either way. Rule 4(4) directions and Rule 4(5) suspension or cancellation of registration are available from 13 November 2026 regardless.
How large can a DPDP penalty actually be?
THE SCHEDULE, read with s.33, sets ceilings per breach rather than fixed fines. Rs 250 crore for failing to take reasonable security safeguards under s.8(5); Rs 200 crore for failing to notify a personal data breach under s.8(6); Rs 200 crore for the children's obligations under s.9; Rs 150 crore for Significant Data Fiduciary obligations under s.10; Rs 10,000 for a Data Principal's own duties under s.15; the applicable amount for breaching a voluntary undertaking under s.32; and Rs 50 crore as the residual entry covering everything else, including notice, consent, retention, rights and cross-border failures. One incident can attract the s.8(5) and s.8(6) entries concurrently, so Rs 450 crore of headroom. There is no turnover-percentage cap of the GDPR 2%/4% kind, and the Act as published contains no provision allowing the Board to double or enhance a ceiling — the "up to Rs 500 crore" figure in some vendor material is unsupported.
Are we a Significant Data Fiduciary?
You do not decide. SDF status is conferred by Central Government notification under s.10(1), on an assessment of factors including the volume and sensitivity of personal data processed, risk to the rights of Data Principals, potential impact on the sovereignty and integrity of India, risk to electoral democracy, security of the State, and public order. The list is non-exhaustive and there is no numeric threshold anywhere in the Act or the Rules. Seventh Schedule entry 3 names a MeitY officer designated by the Secretary as the person who carries out that assessment, and Rule 23 lets the Government call for information for the purpose. As at 19 August 2026 no entity or class had been notified. Once designated, Rule 13(1) runs a twelve-month clock from the designation date for the first DPIA and audit — so the practical answer for anyone plausibly in scope is to build the package before the notification, not after.
We have a GDPR Article 28 DPA with every vendor. Does that carry over to DPDP?
No, and the reason is structural rather than cosmetic. Section 8(1) makes the Data Fiduciary responsible for compliance irrespective of any agreement to the contrary and irrespective of the processor's failure, while DPDP imposes essentially no direct statutory duty on the Data Processor — so unlike GDPR, the contract is the only instrument that moves risk, and there is no Article 28(3) checklist to fall back on. Section 8(2) also narrows engagement: a processor may be engaged only under a valid contract and only for activity related to offering goods or services to Data Principals. Practically, a DPDP processor contract needs the r.6(1)(f) security-safeguards flow-down, a breach-escalation clock fast enough to feed your Rule 7 Board report, erasure on instruction mirroring s.8(7)(b), and support for the r.8(3) one-year log floor. Fix the vocabulary too: controller, processor and data subject become Data Fiduciary, Data Processor and Data Principal; "legitimate interests" has no analogue under s.7's closed list; and SCC and adequacy language is inert under s.16's restriction model.
Do we have to appoint a Data Protection Officer?
Only if you are designated a Significant Data Fiduciary. Section 8(9) requires an ordinary Data Fiduciary to publish the business contact information of a person able to answer a Data Principal's questions about processing — that person does not have to carry the DPO title, so do not manufacture an obligation you do not have. If you are designated an SDF, s.10(2)(a) is stricter than GDPR Article 37: the DPO must be an individual, based in India, responsible to the Board of Directors or similar governing body, and the point of contact for grievance redressal. An EU-based group DPO does not satisfy it. Note also Rule 9's second limb, which is routinely missed — the contact information must appear not only on your site or app but in every response to a communication exercising Data Principal rights.
Does DPDP require data localisation?
Not as a general rule. Section 16 is a blacklist power, not an adequacy whitelist: transfer outside India is permitted by default, and the Central Government may notify countries or territories to which transfer is restricted — the inverse of the GDPR Chapter V model. The only localisation mandate in the framework is Rule 13(4), which binds Significant Data Fiduciaries alone and only over categories of personal data the Central Government later specifies on the recommendation of a Rule 13(5) committee. As at 19 August 2026 no s.16(1) restriction and no r.13(4) category had been notified. Section 16(2) expressly preserves stricter sectoral law, so RBI payment-data localisation, IRDAI and telecom directions continue to bind you regardless of what DPDP permits.
Could the 13 May 2027 date move?
Possibly, and it is the biggest open question in this area. MeitY's January 2026 consultation proposed compressing the compliance window from eighteen months to twelve — moving SDF compliance to 13 November 2026 — and bringing s.10(1), r.13(4), r.15 and s.17(2) into force immediately. Sources dated 22 July 2026 still described it as an unnotified consultation proposal, and no amending notification was located as at 19 August 2026. We have left that flagged as unconfirmed rather than assuming either outcome. If you are plausibly in SDF scope, build to the earlier date.
Do my answers leave the browser?
No. The quiz runs entirely in your browser's memory. There is no API call, no analytics event carrying your answers, no email gate and no stored report — refreshing the page clears everything. The print button hands the page to your own browser's print dialogue so you can save a PDF locally; nothing is uploaded to produce it. For a privacy self-assessment that matters more than usual, so it is worth verifying in your browser's network tab.
Disclaimer: This quiz is a self-assessment aid, not a compliance audit and not legal advice. It does not create an advocate-client relationship, nothing you enter is verified, and the score it produces has no standing before the Data Protection Board — a high score is not a defence to an inquiry under s.28 or to a penalty under s.33. Provisions cited here are current to 19 August 2026 and the commencement position may have changed since; confirm every provision against the gazette text of the DPDP Act 2023, G.S.R. 843(E) and the DPDP Rules 2025, and take advice on your own facts before acting.
The quiz finds the gaps.
The scanner reads the contracts.
Paste a processor agreement or a DPA into the free scanner and LexVio flags the DPDP-shaped holes — missing security-safeguards flow-down, breach clocks that cannot feed a 72-hour Board report, GDPR erasure language that does not mirror s.8(7)(b).