Do you handle personal data of people in India — customers, users, patients, students, employees — or offer goods or services to people in India from abroad?
This is the whole test for whether the law applies to you. Digital data counts, and so does data collected on paper and then typed into a system.
Has a customer, investor, auditor or partner asked you about DPDP compliance?
Not a legal question. It tells us whether you need an answer for someone this quarter or are planning ahead.
Do people under 18 use your product or service, or is their personal data in your systems — students, patients, dependants, children of employees?
Anyone under 18 counts as a child under this law, and children's data has its own rules with the highest penalties. Even services not aimed at children are expected to take reasonable steps to check a user's age.
Do you have employees or contractors in India whose personal data you hold?
Payroll, HR files, attendance, background checks. Almost every organisation says yes.
Which best describes your organisation?
Some rules depend on what you do: very large online platforms must delete inactive users' data; some sectors are expected to be named as 'significant' and given extra duties; schools and hospitals have specific exemptions for children's data.
Roughly how many registered users do you have in India?
Registered, not active. Above a threshold — 2 crore for e-commerce and social media, 50 lakh for gaming — you must erase the data of anyone who has not used the service for three years.
Roughly how many people's personal data do you hold in total?
The government can name organisations as 'Significant Data Fiduciaries' — a label that brings extra duties like an annual audit and a data protection officer. Nobody has been named yet. We use your size and sector to estimate whether you might be, and we say clearly that it is an estimate.
Do you hold personal data on paper or on devices at physical premises — files, ID copies, CCTV, visitor registers, laptops?
The law covers data that is later digitised, and the duty to keep data secure extends to wherever it physically sits.
Do either of these apply to you?
Both switch on a separate set of standards that replaces most of the law for that particular processing. Most organisations answer 'neither'.
Are you a registered Consent Manager, or planning to apply to be one?
A Consent Manager is a company that runs a platform where people give, manage and withdraw consent across many businesses — a bit like a consent wallet. It needs registration with the Data Protection Board from November 2026. Most organisations answer no.
Do you record phone or video calls with customers, patients or users?
Support lines, telemedicine, sales calls, interviews. A recording is personal data and needs a notice, and sometimes consent, before it starts.
Do you use biometric attendance — fingerprint or face — for staff?
Do you share personal data with other companies who use it for their own purposes — partners, insurers, lenders, group companies — as opposed to vendors who only process it for you?
A vendor acting on your instructions (a payment gateway, a cloud host) is different from a company that uses the data for itself. Sharing with the second kind has its own rules and needs its own basis.
Do you obtain personal data from anyone other than the person themselves — data brokers, lead lists, partners, scraped or public sources?
Do you rely on any legal exemptions — for example enforcing a claim, acting for a court or regulator, investigating a crime, a court-approved merger, or tracing loan defaulters?
The law exempts some specific activities from most of its rules. Relying on one means being able to show it applies to you.
Are you a startup recognised by the government's DPIIT scheme?
DPIIT is the department that certifies startups. The government may exempt recognised startups from some duties around notices, retention and rights. None have been exempted yet; if you qualify, this needs watching.
Do you rely on either of these carve-outs?
Both are narrow. 'Made public by the person' means they published it themselves — not that it was findable online.
Which of these describes you, if any?
Each of these is exempt from parental consent and the tracking ban for one specific activity — and nothing else.
Do you process children's data for any of these purposes?
Where does personal data live?
Determines which environment checklists apply. 'Only in software we subscribe to' is common for smaller organisations.
For each environment, roughly how many systems or applications hold personal data?
Drives effort and price. It is a starting point — the estate review replaces it with what we actually find.
Which vendors or platforms handle personal data for you — payments, SMS, analytics, CRM, support desk, cloud, outsourced teams?
Your vendor list. In the estate review, the apps connected to your Google Workspace or Microsoft 365 are compared against it.
Is any personal data stored, replicated or backed up outside India?
'Not sure' is the most common answer and is itself a finding. The scan answers it.
Which certifications or audits do you already hold?
Used for credit — controls you have already evidenced for ISO 27001 or SOC 2 are not re-tested from scratch.
Who in your organisation is accountable for DPDP compliance today?
The scope declaration names this person. If the answer is 'nobody yet', that is the first finding before the scan even starts.
Check your answers.
This is the screen where a hurried “not sure” gets fixed. Every “not sure” counts as yes, so each one pushes your number up.
On that answer the DPDP Act does not apply to you. If anything changes - an India launch, Indian users, an Indian subsidiary - come back.
Nothing to do here today. The Act and the Rules are worth a read anyway — the definitions in section 2 decide who is caught, and they are broader than most people expect.
Read the law