—days until DPDP duties apply
Free DPDP compliance check for your website
Find out what your site does before a visitor says yes. We open it in a real browser as a first-time visitor from India, record every tracker and cookie, test your “Reject” button, and read your privacy notice against the DPDP Act, 2023 and DPDP Rules, 2025.
- Automated checks
- 25
- Internal questions
- 8
- Every gap cites
- Section & Rule
A fix list your developer can act on today
Every check shows what we found, why it matters under the DPDP Act, and exactly what to change. Share the report link with your developer, agency or lawyer.
Images show an example report for a fictional play school. Your report is generated from your own website.
We visit your site the way a new customer does
Most DPDP gaps are invisible to the site owner because you have already clicked “Accept”. The checker starts fresh every time.
Open your site as a first-time visitor
A real Chrome browser loads your homepage from an Indian locale, with no cookies and no earlier choices.
Record everything before a choice is made
Every request to analytics, advertising and session-recording services, and every tracking cookie written, is logged with its time.
Click “Reject” and reload
If your consent prompt offers a reject option, we use it and check whether tracking actually stops on the next page load.
Read your notice, forms and contacts
We find your privacy notice, rights page and contact page, and check them against Section 5, Section 6, Rule 3, Rule 9 and Rule 14.
Score it and list the fixes
Each check is weighted by risk. You get a score out of 100, the top gaps to fix first, and a link to share.
- 0.00 sHomepage requestedstart
- 0.41 sGoogle tag loadstracker
- 0.58 s_ga cookie writtencookie
- 0.73 sMeta Pixel firestracker
- 1.20 sCookie banner appearstoo late
- visitor clicks “Reject”
- 4.02 sSession recording continuesignored
25 checks mapped to the DPDP Act and Rules
Checks are grouped the way the law is: what you tell people, how you ask, how people exercise their rights, and how you protect the data.
Consent & tracking 7 checks
- Consent prompt appears before optional tracking
- No analytics, ad or recording tags fire before a choice
- No tracking cookies written on first load
- “Reject” is as easy to find as “Accept”
- Rejecting actually stops tracking
- A “Manage consent” link to change your mind
- No pre-ticked boxes on forms
Privacy notice 9 checks
- Notice is published and linked site-wide
- Written for DPDP, not a GDPR or IT Rules template
- Lists each item of data and its purpose
- Explains how to withdraw consent
- Covers access, correction, erasure, nomination, grievance
- Names the Data Protection Board complaint route
- States retention, updated after the Rules, Indian languages
Rights & grievances 3 checks
- A published way to request access, correction or erasure
- Contact details of a DPO or person who answers privacy questions
- A stated grievance response time within 90 days
Security basics 4 checks
- Every page on HTTPS, with http:// redirected
- HSTS header set
- Content-Security-Policy and other security headers
- No form sends personal data over plain http
Children's data 2 checks
- Parental consent explained, if the site serves children or students
- No ad tracking or behavioural monitoring aimed at children
Inside your business 8 questions
- Data inventory and consent records
- Vendor contracts and one-year security logs
- 72-hour breach plan and retention schedule
- Rights requests and parental consent process
Why most Indian websites are not DPDP ready yet
These are the problems the checker finds most often on business, school, clinic and e-commerce sites. Most take a day or less to fix.
Analytics and pixels load before consentSection 6(1)
Google Analytics, Meta Pixel and Microsoft Clarity are usually pasted into the site header, so they run the moment the page opens. A banner that appears afterwards cannot make that processing consented.
Hold optional tags until the visitor opts in, through consent-gated tags or a script blocker.
A banner with only an “Accept” buttonSection 6(1), Section 6(4)
“We use cookies. OK” is not a choice. Consent has to be free and unambiguous, and withdrawing it has to be as easy as giving it.
Put “Reject” next to “Accept” with the same prominence, and add a “Manage consent” link in the footer.
A privacy policy copied from a GDPR templateSection 5, Rule 3
GDPR policies miss DPDP-specific items: the right to nominate, the Data Protection Board complaint route, an itemised list of data with purposes, and the option to read the notice in an Indian language.
Rewrite the notice against the DPDP Rules, 2025 and date it.
Pre-ticked WhatsApp and marketing boxesSection 6(1)
Enquiry forms often tick “Send me offers on WhatsApp” by default. Consent under the DPDP Act needs a clear affirmative action, so a box the visitor did not tick does not count.
Leave optional boxes unticked and log each consent with the notice version shown.
No named person for privacy questionsSection 8(9), Rule 9
Most sites list a generic info@ address. The Rules ask you to publish the contact details of your Data Protection Officer, or a person who can answer questions about your processing, prominently on your website.
Publish a named privacy or grievance contact, with a request form and a response time.
What the DPDP Act asks of your website
The Digital Personal Data Protection Act, 2023 applies to any business that processes digital personal data of people in India, whatever its size. For a website, these are the duties that show.
Give a clear notice
Before or when you ask for consent, tell people what data you collect, for which purpose, how to withdraw consent, how to exercise their rights and how to complain to the Board. It must stand on its own, in plain language, and be available in English or an Eighth Schedule language.
Get valid consent
Consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the data needed for that purpose. You must be able to prove it was given.
Make withdrawal as easy as giving
People can withdraw consent at any time, and it must be as easy as it was to give. After withdrawal you stop processing, and so do your processors.
Handle rights and grievances
Publish how people can ask for a summary of their data, correction, completion, updating or erasure, and nominate someone. Answer grievances within a period of no more than 90 days.
Protect the data, and report breaches
Use reasonable safeguards such as encryption, access control and logs kept for at least a year. Tell affected people and the Data Protection Board about a breach without delay, with a detailed report within 72 hours.
Take extra care with children
Anyone under 18 is a child under the Act. You need verifiable consent from a parent or lawful guardian, and must not track, behaviourally monitor or target ads at children.
| Up to | For | Provision |
|---|---|---|
| ₹250 crore | Failing to take reasonable security safeguards to prevent a personal data breach | Sec 8(5) |
| ₹200 crore | Failing to notify the Board and affected people of a breach | Sec 8(6) |
| ₹200 crore | Breaching the additional duties for children's data | Sec 9 |
| ₹150 crore | Breaching the additional duties of a Significant Data Fiduciary | Sec 10 |
| ₹50 crore | Breaching any other provision of the Act or Rules | Schedule, item 7 |
DPDP readiness for your sector
Schools, hospitals, lenders and online stores each collect different data and face different duties. See what applies to yours.
DPDP readiness check: questions
Can't find your answer? Write to us and a person on our team will reply.
How do I check if my website is DPDP compliant?
Enter your website address above. The checker opens your site as a first-time visitor, records trackers and cookies set before consent, tests whether the reject option works, reviews your privacy notice against Section 5 and Rule 3, and checks for a data-rights route, a privacy contact and basic security. You get a score out of 100 and a prioritised fix list.
Is a high readiness score the same as being DPDP compliant?
No. The check reads what is publicly visible on your website and your answers to eight questions. Compliance also depends on how you collect, use, store and delete data inside your business. Use the score to find gaps, and have a lawyer review your notice and processes.
When does the DPDP Act apply to my website?
The DPDP Rules, 2025 were notified on 13 November 2025. Most duties for businesses, including notices, consent, security safeguards, breach reporting and data-rights handling, apply 18 months later, from 13 May 2027. It is worth fixing website gaps now, because they are the easiest for customers and the Board to see.
Does the DPDP Act require a cookie banner?
The Act does not mention cookies by name. It covers all digital personal data. Analytics and advertising tags usually collect identifiers linked to a person, so they need consent given by a clear affirmative action before they run, unless another lawful ground applies. A consent prompt is the usual way to get it.
Is a GDPR privacy policy enough for DPDP?
Usually not. A DPDP notice has to itemise the personal data and each purpose, explain how to withdraw consent, describe the rights to access, correction and erasure, grievance redressal and nomination, name how to complain to the Data Protection Board of India, and be available in English or an Eighth Schedule language.
What is the penalty for not complying with the DPDP Act?
Up to ₹250 crore for failing to take reasonable security safeguards that leads to a personal data breach, up to ₹200 crore for failing to report a breach or for breaching duties about children's data, and up to ₹50 crore for other breaches of the Act.
Is the DPDP readiness check free?
Yes. The check is free and needs no sign-up. You can run up to 10 checks an hour, and each report is kept for 30 days so you can share its link with your developer or lawyer.
What does the checker do on my website?
It loads your public pages the way a visitor would, clicks only the reject option in your consent prompt, and reads your privacy notice and contact pages. It does not log in, submit forms or store page content beyond the findings in your report.
Close the gaps with one script tag
ConsentKit adds a consent notice in English and Indian languages, blocks trackers until people agree, keeps a consent log you can show, and handles data-rights requests.