India’s Privacy Decision Platform
Know exactly what DPDP requires of you, and what to do next
Assess your readiness, compare your options, and choose the right path to compliance. Independent, evidence-based, free to use.
Independent, no implementation soldVendor-neutral comparisons
- Assess6-minute readiness check
- ReadinessScore, gaps, domains
- RecommendationYour 90-day plan
- ImplementationDIY or specialist partner
- Ongoing governanceStay compliant as you grow
First, the honest question
Do you actually need a DPO?
Most Indian companies do not, at least not yet. Here is the real picture before anyone sells you anything.
You are a Significant Data Fiduciary
Very large scale or sensitive data, heavy profiling, children’s data, or a sovereignty sensitive sector, and formally designated an SDF by the government.
You are a regular business
Not designated an SDF. This is most companies between 50 and 1,000 people. Size alone never triggers a DPO under the DPDP Act.
You have EU, UK or Singapore exposure
Selling to or monitoring people in the EU or UK at scale, or doing business in Singapore. These obligations apply whatever your Indian status.
The myth worth killing: “We have 200 employees, so we need a DPO.” The DPDP Act has no employee or revenue trigger. The obligation comes from being designated a Significant Data Fiduciary, not from your headcount. Many companies still appoint one voluntarily for customer security questionnaires, ISO 27701, or investor due diligence. Six minutes tells you where you stand.
Where are you today?
Start from your situation
Pick the statement that fits. Each one leads to a different path.
I don’t know whether DPDP applies to us
Check applicability in a few questions.
Start here →I need to assess our readiness
Get a scored picture of where you stand.
Start here →I need a DPO
Understand the options before you hire or outsource.
Start here →I need implementation help
See what a programme involves and who can deliver it.
Start here →I need templates and tools
Use free instruments built for DPDP.
Start here →I need ongoing support
Keep a programme running after the deadline.
Start here →Significant Data Fiduciaries must appoint an India based DPO answerable to the Board.
EU and UK processing can require a DPO, and expressly permits an external, contracted one.
Notice, consent, security safeguard and breach reporting duties, phased to 13 May 2027.
Start here
A 5-7 minute adaptive readiness check. One score your board can understand.
A few minutes of honest answers about how your company handles personal data, and you’ll know where you stand, what to fix first, and what kind of help fits. Questions adapt to your organisation, processing and applicable obligations.
~6 minutesScore + written reportFree, no signup to begin
Start the free assessmentNo obligation. Your result is generated the same way whether or not you ever engage a partner.
Ahead of most, three gaps stand between you and audit-ready.
Your three priority gaps
How DPOIndia works
A clear path from uncertainty to a running programme
- 1
Understand
Learn what applies to a company like yours.
- 2
Assess
Take the readiness assessment.
- 3
Decide
Compare paths with evidence, not sales calls.
- 4
Implement
Do it yourself or with help.
With a specialist partner - 5
Operate
Keep the programme alive and audit-ready.
With a specialist partner
The DPDP clock
Three dates decide your runway
- 13 Nov 2025
Rules notified
DPDP Rules published; Data Protection Board established and operational.
- 13 Nov 2026
Consent Managers & further rules
Consent Manager registration opens and further rule provisions commence. Penalty enforcement begins 13 May 2027.
← You are here (Aug 2026) - 13 May 2027
Full compliance
Consent, notice, data-principal rights, security safeguards, all enforceable.
DPDP provides for significant penalties for security-safeguard failures, up to a maximum of ₹250 crore, which become enforceable when the penalty provisions commence on 13 May 2027. The window before then is build time, not waiting time. See where you stand →
Decision Hub
The questions every company asks, answered so you can decide
Not articles. Each entry ends with a decision you can make.
Does DPDP apply to my company?
Decide whether you’re in scope, and what tier of obligation you face.
Should I appoint a DPO?
Decide whether you need one now, and whether to hire or outsource.
Do I need consent management?
Decide whether your current consent flows will survive the Rules.
Should I outsource privacy?
Decide what to keep in-house and what to hand to specialists.
Which framework applies to me?
Decide between DPDP-only, ISO 27701, SOC 2, or a sequence.
What should I do first?
Decide your first three moves before the May 2027 deadline.
Compare your options
Four ways to run privacy, side by side
Including the ones we earn nothing from.
| Criteria | Internal DPO hire | Virtual or Fractional DPOMost common at 50 to 1,000 staff* | Consultant / Agency | Software only |
|---|---|---|---|---|
| Best for | Large or SDF-track companies | Mid market, steady needs | One-time projects | Teams with in-house ownership |
| Typical cost | ₹25–40L / year | ₹1.5–8L / year | ₹3–15L / project | ₹1–20L / year |
| Time to value | 3–6 months | 2–6 weeks | 4–12 weeks | 1–4 weeks |
| Ongoing effort from you | Low | Low to medium | Medium to high after handover | High |
| DPDP suitability | Strong | Strong | Strong for setup | Tooling, not judgment |
Internal DPO hire
- Best for
- Large / SDF-track
- Cost
- ₹25–40L / yr
- Time to value
- 3–6 months
- Your effort
- Low
Virtual or Fractional DPO Most common*
- Best for
- Mid market
- Cost
- ₹1.5–8L / yr
- Time to value
- 2–6 weeks
- Your effort
- Low–medium
Consultant / Agency
- Best for
- One-time projects
- Cost
- ₹3–15L / project
- Time to value
- 4–12 weeks
- Your effort
- Medium–high
Software only
- Best for
- In-house ownership
- Cost
- ₹1–20L / yr
- Time to value
- 1–4 weeks
- Your effort
- High
*Based on observed engagement patterns in the 50–1,000 employee segment. All figures are observed market ranges, not quotes. See the full comparison →
Privacy tools
Free instruments you can use right now
DPDP Readiness Assessment
A short adaptive check. A score, your three priority gaps, and a prioritised 90-day plan.
Start assessmentCompliance Cost Benchmarks
What DPDP programmes, DPO support, and certifications actually cost in India, observed ranges by company size.
See the benchmarks →Penalty calculator
Model your exposure under the DPDP penalty schedule.
Coming soonVendor checklist
Assess processors and sub-processors against DPDP duties.
Coming soonConsent generator
Draft DPDP-aligned notice and consent language.
Coming soonCompliance roadmap
Turn your assessment into a sequenced plan to May 2027.
Coming soonFramework coverage
One place for every regime you’ll be asked about
DPDP Act
India’s data protection law
Guides · Assessment · PartnersGDPR
EU / UK obligations
Guides · PartnersISO 27001
Information security
Guides · PartnersISO 27701
Privacy management
Guides · PartnersSOC 2
Customer trust reports
Guides · PartnersDPIA
Impact assessments
Guides · TemplatesRoPA
Records of processing
Guides · TemplatesConsent & rights
Consent, DSR & grievance flows
Guides · TemplatesIndustries
Guidance grounded in your sector
Why DPOIndia
Built to be on your side of the table
Independent
We don’t deliver implementation. We help you decide, then introduce you to people who do.
Vendor-neutral
Our comparisons include options we earn nothing from, hiring internally, or buying software.
Evidence-based
Every figure is sourced. Benchmarks state their sample size or don’t appear at all.
India-focused
DPDP-first, with sector regulators, RBI, SEBI, IRDAI, CERT-In, treated as part of the picture.
Practical
Plans, templates, and cost ranges you can act on, not theory.
Knowledge Centre
Understand before you spend
A decision-first starting point for organisations beginning with DPDP
One structured walkthrough, applicability, obligations, first three moves, instead of twenty scattered articles.
Open the guide →- Guide
The DPDP compliance timeline, explained
What switched on in November 2025, what begins in November 2026, and what full compliance in May 2027 requires.
- Decision tree
DPO: hire, outsource, or wait?
A structured walk through the appointment decision for companies between 50 and 1,000 people.
- Explainer
What enterprise security questionnaires actually check
The three items most Indian mid-market companies fail, and how to fix them before the next deal stalls.
Prefer to talk it through?
What the call covers
- Your assessment result, interpreted
- Which path fits your size and sector
- Realistic costs and timelines
What it doesn’t
- No pitch
- No obligation
- No pressure to use a partner
FAQ
Fair questions, straight answers
Is the assessment really free?
Yes. The assessment, your score, and the written report are free, with no card and no obligation.
Do I have to use one of your partners?
No. Many companies use the assessment and plan on their own. Partner introductions happen only if you ask for one.
What happens to my assessment data?
It’s used to generate your report and, in aggregate and anonymised, to build the benchmarks. It’s never sold, and never shared with a partner unless you request an introduction.
What if DPDP doesn’t apply to my company?
Then we’ll tell you that. The applicability check exists to give you a clear answer either way.