India’s Privacy Decision Platform

Know exactly what DPDP requires of you, and what to do next

Assess your readiness, compare your options, and choose the right path to compliance. Independent, evidence-based, free to use.

Independent, no implementation soldVendor-neutral comparisons

First, the honest question

Do you actually need a DPO?

Most Indian companies do not, at least not yet. Here is the real picture before anyone sells you anything.

Path A · India

You are a Significant Data Fiduciary

Very large scale or sensitive data, heavy profiling, children’s data, or a sovereignty sensitive sector, and formally designated an SDF by the government.

Mandatory: a named, India based DPO reporting to your Board.
Check your SDF likelihood
Path B · India

You are a regular business

Not designated an SDF. This is most companies between 50 and 1,000 people. Size alone never triggers a DPO under the DPDP Act.

Required: a published contact point and a grievance process, not a full DPO.
See what you actually need
Path C · Global

You have EU, UK or Singapore exposure

Selling to or monitoring people in the EU or UK at scale, or doing business in Singapore. These obligations apply whatever your Indian status.

Often mandatory: a DPO under GDPR, where external is allowed, or Singapore’s PDPA.
See global coverage

The myth worth killing: “We have 200 employees, so we need a DPO.” The DPDP Act has no employee or revenue trigger. The obligation comes from being designated a Significant Data Fiduciary, not from your headcount. Many companies still appoint one voluntarily for customer security questionnaires, ISO 27701, or investor due diligence. Six minutes tells you where you stand.

Where are you today?

Start from your situation

Pick the statement that fits. Each one leads to a different path.

Find your starting point →

S.10(2)(a), DPDP Act 2023

Significant Data Fiduciaries must appoint an India based DPO answerable to the Board.

Art. 37 to 39, GDPR

EU and UK processing can require a DPO, and expressly permits an external, contracted one.

DPDP Rules, 2025

Notice, consent, security safeguard and breach reporting duties, phased to 13 May 2027.

Start here

A 5-7 minute adaptive readiness check. One score your board can understand.

A few minutes of honest answers about how your company handles personal data, and you’ll know where you stand, what to fix first, and what kind of help fits. Questions adapt to your organisation, processing and applicable obligations.

~6 minutesScore + written reportFree, no signup to begin

Start the free assessment 

No obligation. Your result is generated the same way whether or not you ever engage a partner.

How DPOIndia works

A clear path from uncertainty to a running programme

  1. 1

    Understand

    Learn what applies to a company like yours.

  2. 2

    Assess

    Take the readiness assessment.

  3. 3

    Decide

    Compare paths with evidence, not sales calls.

  4. 4

    Implement

    Do it yourself or with help.

    With a specialist partner
  5. 5

    Operate

    Keep the programme alive and audit-ready.

    With a specialist partner

The DPDP clock

Three dates decide your runway

  1. 13 Nov 2025

    Rules notified

    DPDP Rules published; Data Protection Board established and operational.

  2. 13 Nov 2026

    Consent Managers & further rules

    Consent Manager registration opens and further rule provisions commence. Penalty enforcement begins 13 May 2027.

    ← You are here (Aug 2026)
  3. 13 May 2027

    Full compliance

    Consent, notice, data-principal rights, security safeguards, all enforceable.

DPDP provides for significant penalties for security-safeguard failures, up to a maximum of ₹250 crore, which become enforceable when the penalty provisions commence on 13 May 2027. The window before then is build time, not waiting time. See where you stand →

Compare your options

Four ways to run privacy, side by side

Including the ones we earn nothing from.

Compare all options →

CriteriaInternal DPO hireVirtual or Fractional DPOMost common at 50 to 1,000 staff*Consultant / AgencySoftware only
Best forLarge or SDF-track companiesMid market, steady needsOne-time projectsTeams with in-house ownership
Typical cost₹25–40L / year₹1.5–8L / year₹3–15L / project₹1–20L / year
Time to value3–6 months2–6 weeks4–12 weeks1–4 weeks
Ongoing effort from youLowLow to mediumMedium to high after handoverHigh
DPDP suitabilityStrongStrongStrong for setupTooling, not judgment

Internal DPO hire

Best for
Large / SDF-track
Cost
₹25–40L / yr
Time to value
3–6 months
Your effort
Low

Virtual or Fractional DPO Most common*

Best for
Mid market
Cost
₹1.5–8L / yr
Time to value
2–6 weeks
Your effort
Low–medium

Consultant / Agency

Best for
One-time projects
Cost
₹3–15L / project
Time to value
4–12 weeks
Your effort
Medium–high

Software only

Best for
In-house ownership
Cost
₹1–20L / yr
Time to value
1–4 weeks
Your effort
High

*Based on observed engagement patterns in the 50–1,000 employee segment. All figures are observed market ranges, not quotes. See the full comparison →

Privacy tools

Free instruments you can use right now

DPDP Readiness Assessment

A short adaptive check. A score, your three priority gaps, and a prioritised 90-day plan.

Free~6 min

Start assessment

Compliance Cost Benchmarks

What DPDP programmes, DPO support, and certifications actually cost in India, observed ranges by company size.

See the benchmarks →

Penalty calculator

Model your exposure under the DPDP penalty schedule.

Coming soon

Vendor checklist

Assess processors and sub-processors against DPDP duties.

Coming soon

Consent generator

Draft DPDP-aligned notice and consent language.

Coming soon

Compliance roadmap

Turn your assessment into a sequenced plan to May 2027.

Coming soon

Why DPOIndia

Built to be on your side of the table

Independent

We don’t deliver implementation. We help you decide, then introduce you to people who do.

Vendor-neutral

Our comparisons include options we earn nothing from, hiring internally, or buying software.

Evidence-based

Every figure is sourced. Benchmarks state their sample size or don’t appear at all.

India-focused

DPDP-first, with sector regulators, RBI, SEBI, IRDAI, CERT-In, treated as part of the picture.

Practical

Plans, templates, and cost ranges you can act on, not theory.

Prefer to talk it through?

What the call covers

  • Your assessment result, interpreted
  • Which path fits your size and sector
  • Realistic costs and timelines

What it doesn’t

  • No pitch
  • No obligation
  • No pressure to use a partner
Book a 20-minute call
WhatsApp ushello@dpoindia.inWe reply within one business day

FAQ

Fair questions, straight answers

Is the assessment really free?

Yes. The assessment, your score, and the written report are free, with no card and no obligation.

Do I have to use one of your partners?

No. Many companies use the assessment and plan on their own. Partner introductions happen only if you ask for one.

What happens to my assessment data?

It’s used to generate your report and, in aggregate and anonymised, to build the benchmarks. It’s never sold, and never shared with a partner unless you request an introduction.

What if DPDP doesn’t apply to my company?

Then we’ll tell you that. The applicability check exists to give you a clear answer either way.

More questions? Contact us →

Chat on WhatsApp
Follow DPOIndia in Google SearchAdd as a preferred source on Google