Ten quick questions mapped to India's DPDP Act. Get a 0 to 100 readiness score and a section-by-section list of what to fix first.
1.Do you give an itemized, plain-language notice (what data, which purposes, how to withdraw, how to complain) before collecting personal data?
2.Is your consent free, specific, informed, unambiguous and captured by a clear affirmative action (not pre-ticked or bundled)?
3.Do you block non-essential trackers and processing until the data principal consents?
4.Can a person withdraw consent as easily as they gave it, with processing stopping promptly after?
5.If minors may use your service, do you verify age and obtain verifiable parental consent, with no tracking or targeted ads at children?
6.Do you keep verifiable consent records you could produce for the Data Protection Board (who consented, to what, when, under which notice)?
7.Can data principals exercise access, correction, erasure and grievance rights through a working request process with deadlines?
8.Does your notice tell people how to raise a grievance and complain to the Data Protection Board?
9.Do you have a breach response that can notify the Board and affected people within the Rules' timelines?
10.Do you delete personal data once its purpose is served (and apply retention limits), rather than keeping it indefinitely?