← Back to Assessments
~5 seconds · no signup

Your website.
A clearer picture of DPDP readiness.

Drop in your website URL. We crawl your home page and policy pages, then check 13 weighted DPDP categories and return a 0–100 score with evidence and a fix for each gap.

Automated, heuristic & indicative — not a legal audit. We only read publicly reachable pages; we can't see content behind a login or rendered by JavaScript. We do not store your website data — the scan result is returned to you and nothing is kept on our side.

  • Mapped to the DPDP Act 2023 and Rules 2025
  • Built in India by a team that runs DPDP assessments
  • Guidance only, not legal advice
01 / A simple starting point

From URL to next steps.

Example scan
  1. 01

    Start with your URL.

    No signup, no card. Just your public website address.

  2. 02

    We connect the evidence.

    Public pages are checked across 13 weighted DPDP categories.

  3. 03

    Know what to fix first.

    A score, findings and practical next steps in one report.

02 / Under the surface

13 checks. One actionable report.

13 weighted categories, drawn directly from the Act and its 2025 Rules — the same ones used to score every scan.

Notices & disclosures

4 checks

Make your data practices visible.

  • Privacy notice published and reachableSection 5(1) - Rule 3
  • Notice itemises purposes and data categoriesSection 5(1)(i)-(ii) - Rule 3(1)
  • Cookie policy with a current cookie inventoryRule 3 - Section 5
  • Processors and cross-border transfers disclosedSection 8(2) and Section 16

Rights & accountability

4 checks

Give every request a clear path.

  • Working mechanism for access, correction and erasureSections 11 to 13 - Rule 13
  • Nomination right disclosedSection 14
  • Grievance Officer published with contact and timelineSection 8(10) - Section 13 - Rule 9
  • Children's data position statedSection 9 - Rule 10

Public security

1 check

Look for safeguards on the public surface.

  • Reasonable security safeguards on the public surfaceSection 8(5) - Rule 6
03 / Make sense of the signals

How to read your score.

0–40High Risk
41–70Developing
71–100Mature
  • 0–40High Risk

    Significant gaps in publicly visible signals. Start with the priority fixes in your report.

  • 41–70Developing

    Some safeguards are visible, with gaps that need attention. Review the evidence for each finding.

  • 71–100Mature

    Stronger publicly visible signals. Internal policies and operational compliance still need a separate assessment.

A high score is not a certificate and not a legal opinion. It means the things a person can check from outside your organisation look right.

A useful first view. Not the whole picture.

What a scanner cannot see.

We would rather say this on the page than in a footnote. A website scan covers the outward facing part of DPDP. It cannot see:

  • What personal data you hold in your databases, spreadsheets and email
  • How long you keep it and whether you delete it on time
  • Which vendors and processors you share it with, and what your contracts say
  • Whether you can actually answer an access or erasure request inside the timeline
  • Whether you have a breach process that can report to the Board within 72 hours
  • Whether you qualify as a Significant Data Fiduciary and carry the extra duties that come with it

Those need a proper assessment against your systems and your records. A clean scan is a good sign. It is not the whole obligation.

Why this matters now

The compliance clock started on 13 November 2025.

MeitY notified the DPDP Rules 2025 on 13 November 2025. The Data Protection Board of India was set up on the same day and can receive complaints from now. Consent manager provisions start from 13 November 2026. Everything else, which is most of what applies to your website, takes effect on 13 May 2027.

That is the build window. Nothing about it is going to get easier by waiting.

  1. 01Rules notified

    The regulatory framework is established.

  2. 02Consent managers

    Consent manager provisions commence.

  3. 03Substantive obligations

    Substantive website obligations take effect.

13 May 2027Full compliance date for substantive obligations
Rs 250 croreMaximum penalty for failing to take reasonable security safeguards
Rs 200 croreMaximum penalty for failing to notify a personal data breach, and for children's data failures
72 hoursTime to give the Data Protection Board a detailed breach report

Source: Digital Personal Data Protection Act 2023 (Schedule) and Digital Personal Data Protection Rules 2025, notified by MeitY on 13 November 2025.

If you want a second pair of eyes

Free review of your scan report.

Send us your report and a SecComply consultant will go through it with you on a call. We explain what each finding means for your business, where the real exposure sits, and what the sequence of work looks like. No cost and no obligation.

Where you want to go further, our DPDP work is advisory. We assess your current position against the Act and the Rules, design the consent flows, notices, records and workflows you need, and recommend the controls. Your teams carry out the changes with our guidance and review.

Book a review call

30 minutes. A consultant, not a sales call.

Some sectors carry more risk than others.

Penalty exposure under DPDP is not spread evenly. Sectors holding financial, health or children's data sit in the highest bands, usually with a sector regulator on top of DPDP.

Frequently asked questions

Is the scanner really free?

Yes. No signup, no card, no trial. You can run it as often as you like.

Do you store my website data?

No. The scan runs against your public pages and the result is returned to you. We do not keep a copy of your site content.

Does a good score make my company DPDP compliant?

No. It means the outward facing obligations look right. Retention, vendor contracts, breach response and rights handling all sit behind the website and need a separate assessment.

Can I scan a website I do not own?

The scan only reads pages that are already public, so yes. It is most useful on your own site, where you can act on the findings.

What is the 13 May 2027 date?

It is when the substantive obligations of the DPDP Act take effect, 18 months after the Rules were notified on 13 November 2025. The Data Protection Board has been operating since November 2025.

What are the penalties?

Up to Rs 250 crore for failing to take reasonable security safeguards, up to Rs 200 crore for failing to notify a breach or for children's data failures, and up to Rs 50 crore for other duty failures. Penalties apply per instance.

How often should I scan?

After any change to your consent banner, your privacy notice, or your analytics and marketing tags. In practice, once a quarter is a reasonable rhythm.

Is this legal advice?

No. It is guidance based on the text of the Act and the Rules. For decisions that carry legal consequence, take advice from a qualified lawyer.

Your next step starts here

Find out where you stand.

Free, about 5 seconds, no signup.