Skip to content
IjyaLabs logo
IjyaLabs
Beta — under testing and trial. Do not use for live compliance decisions, statutory submissions, or regulatory reliance. Readiness preparation only, not a certification or audit.
🇮🇳Beta

DPDP Act 2023

India's Digital Personal Data Protection Act & Rules 2025

31
Obligations
6
Categories
₹250cr
Max penalty
Before you start — what to have ready for DPDP Act 2023

Gather these first. Every one of them is something the assessment will ask for, and finding them mid-way is where an assessment stalls.

Decide your scope first

This module works out which controls apply to you from your answers, so complete the scope step first. Starting without it assesses a population you did not choose.

  • Which systems, services and locations are in scope — write this down before you answer anything.
  • Who owns each area, so an answer about it is somebody’s to give.
  • The period the evidence should cover, where the framework opines on a period rather than a moment.

Gather these documents

What DPDP Act 2023 is assessed against. Find them before you start — the assessment reads what you upload, not what you tell it.

  • Privacy notice to Data Principals (Section 5)
  • Record of consent collected, and the consent-withdrawal mechanism
  • Record of Processing Activities
  • Data retention and deletion policy
  • Personal data breach notification procedure
  • Grievance redressal / Data Protection Officer contact process
  • Data Processing Agreements with Data Processors

Have the right people

Who needs to be involved, and what changes if it is only you.

  • Someone who can find the documents — usually whoever owns the control day to day.
  • A second person to review what was uploaded, if you want reviewed coverage. They must not be the person who submitted or attached that evidence: no one reviews their own work.
  • One person can complete the whole assessment. Reviewed coverage will read zero, and that is accurate rather than a fault.
  • A reviewer’s acceptance is what raises a control from partial to proven, and every workspace has that during the open beta. It becomes something a plan includes once there is anything to buy.

Prepare the files

Upload only what the assessment needs. You are responsible for removing or masking personal and sensitive data that a control does not require — do it before you upload. DPDP evidence is about personal data by definition. Never upload actual Data Principal records, consent logs with real identities, or grievance content — upload the procedures and templates, not the data.

  • Upload digital documents only — a Word file, a spreadsheet, or a PDF with real text. A photograph or a scanned paper has no readable text, so it cannot be assessed or prove a control.
  • A scan or a photograph has no text to read, so it cannot prove a control. Export the original instead.
  • The same file cannot be uploaded twice to one library — it is recognised by its contents, not its name.
  • Upload the document itself, not a summary of it. A summary is your description of the evidence, not the evidence.
  • A document that is not about this framework will be accepted and matched against nothing. It still counts against your library, so it is worth checking before you send it.

Know what you will get

So the result is what you expected when you started.

  • You get a readiness position derived from the evidence you upload, and a list of where the gaps are.
  • You do not get an audit, an opinion, or a certification. Only a licensed auditor, an accredited certification body, or the relevant regulator can give you those.
  • Controls you upload nothing for are reported as UNEXAMINED — not as failed. That distinction is deliberate.
  • A document can support a control without proving it. Supporting evidence raises a control to partial; reaching proven takes evidence a second person independently reviewed and accepted.
dpdpa_readiness_2025.1DPDP Act 2023 · Rules 2025 (G.S.R. 846(E))

₹0 to a penalty-mapped obligation gap register — in under 20 minutes

India's Digital Personal Data Protection Act 2023 is enacted law, not a framework. Non-compliance carries penalties up to ₹250 crore per violation. This assessment maps your implementation against up to 31 obligations and prepares you for the phased commencement schedule. The substantive assessment obligations commence from 13 May 2027.

31
Obligations in catalog
across 6 categories (scope-adjusted)
₹250cr
Max penalty per violation
Schedule I, DPDP Act
2
Readiness scores
In-force + future obligations
~20 min
Time to results
No account required

Commencement timeline

13 Nov 2025Institutional provisions

Act sections 1(2), 2, 18–26, 35, 38–43 and specified Rules 1, 2, 17–21. The assessed Data Fiduciary obligations are not yet in force.

13 Nov 2026Consent Manager

Rule 4 — Consent Manager registration and operation

13 May 2027Full commencement

Rules 3, 5–16, 22–23 — Records, breach notification (Rule 7), SDF audit/DPIA (Rule 13), children’s consent (Rules 10–12)

Notification pendingCross-border restrictions

Section 16 — Depends on Central Government notification. Countries notified separately.

Sources: Act commencement notification G.S.R. 843(E) and DPDP Rules 2025, G.S.R. 846(E), Gazette of India, 13 November 2025.

This is an IjyaLabs readiness self-assessment. Scoring reflects implementation state, not legal compliance. Compliance is determined by the Data Protection Board of India. Consult qualified legal counsel for specific compliance decisions. Framework version: dpdpa_readiness_2025.1.