Methodology
How DPDP Self-Check translates your answers into a compliance score, maturity rating, and gap analysis.
Each question has a weight (1–3) and a response multiplier:
100%
Yes
50%
Partial
0%
No
Excluded
N/A
Section score = Σ(response_multiplier × question_weight) / Σ(question_weight for non-N/A questions) × 100. N/A answers are excluded from both numerator and denominator. Unanswered questions are not counted, and a section with no scorable answers is left out of the composite.
Significant gaps. The organisation lacks fundamental controls for most obligations. Immediate action required. High regulatory risk.
Some controls are in place but coverage is inconsistent. Key obligations are partially met. A structured remediation plan is needed.
Most obligations are met with documented controls. Gaps are specific and addressable. Organisation can demonstrate compliance readiness to auditors.
Comprehensive compliance posture with proactive controls. Suitable for presenting to a DPO, external auditor, or the Data Protection Board.
The composite score is a penalty-exposure weighted average of section scores. Section weights are an editorial judgement informed by the penalty tiers in the DPDP Schedule: security, breach and children's data carry the highest weight. Fixing the most consequential gaps therefore has the most impact on your score.
| Section | DPDP Citation | Max Penalty | Weight |
|---|---|---|---|
| Security Safeguards | Section 8(5) | Up to INR 250 crore | 10 |
| Breach Notification | Section 8(6) | Up to INR 200 crore | 9 |
| Children's Data | Section 9 | Up to INR 200 crore | 9 |
| Significant Data Fiduciary | Section 10 | Up to INR 150 crore | 8 |
| Notice & Consent | Sections 5-7 | Up to INR 50 crore | 7 |
| Data Fiduciary Obligations | Section 8 | Up to INR 50 crore | 7 |
| Cross-Border Transfer | Section 16 | Up to INR 50 crore | 6 |
| Data Protection Officer | Section 10(2)(a) | Up to INR 150 crore (SDF) | 5 |
| Data Principal Rights | Sections 11-14 | Up to INR 50 crore | 4 |
| Grievance Redressal | Section 13 | Up to INR 50 crore | 4 |
| Applicability & Scope | Sections 2-3 | Foundational — enables all other obligations | 3 |
Trade-off: Weighting by penalty exposure incentivises focus on high-risk areas but may understate breadth of compliance. An organisation could score well on Security Safeguards but poorly on Grievance Redressal and still get a high composite score. Review section-level scores independently.
The DPDP Act imposes obligations on all Data Fiduciaries processing personal data. It would be paradoxical for a DPDP compliance tool to itself violate those principles. DPDP Self-Check is designed to model DPDP compliance at the architectural level:
This design directly implements the data minimisation and purpose limitation principles of the DPDP Act — collecting no data beyond what is strictly necessary for the tool to function.
Disclaimer & Limitations
This tool is a self-assessment aid and does not constitute legal advice. It is not a substitute for a professional privacy audit or the advice of qualified privacy counsel.
The DPDP Rules, 2025 were notified in November 2025 and commence in phases: the Data Protection Board provisions immediately, consent-manager provisions from 14 November 2026, and most substantive obligations (notice, consent, security, breach, children) from 14 May 2027. This tool reflects the Act and Rules as reviewed in October 2026; check for later amendments.
This tool does not imply endorsement by MeitY, the Data Protection Board of India, or any government body. “DPDP Self-Check” is an independent tool published by Global Cyber Associates.
Always consult a qualified privacy lawyer before making binding compliance decisions.