How exposed is your organisation to DPDP penalties?
The Digital Personal Data Protection Act imposes penalties up to ₹250 crore. Measure your exposure across five critical dimensions with a transparent, research-backed methodology.
Five dimensions we score
Each dimension is scored 0 to 100 and weighted; together they produce your composite exposure index.
Data Volume & Sensitivity
The number of data principals, the sensitivity of the categories you hold, and the length of your processor chain.
Regulatory Classification Risk
Your sector, revenue, and the likelihood of being named a Significant Data Fiduciary.
Consent Architecture Maturity
How you collect consent, whether withdrawal and erasure work, and Consent Manager readiness.
Children's Data Exposure
Whether you process minors' data, parental-consent mechanisms, and behavioural monitoring.
Breach Preparedness
Your breach response plan, 72-hour notification capability, and DPIA status.
How it works
1. Answer 15 questions
Five dimensions, three questions each. Two minutes, no sign-up.
2. Get your exposure index
A 0-100 composite, a risk band, your penalty exposure, and a radar across all five dimensions.
3. See what to fix
Specific recommendations for the dimensions that scored worst, and how Amberoon can help.
Ready to see where you stand?
The assessment is free, takes two minutes, and stores nothing.
Start the assessmentFrequently asked questions
What is the maximum penalty under the DPDP Act?
Up to ₹250 crore for failing to take reasonable security safeguards, set out in the Schedule to the Act and imposed by the Data Protection Board under Section 33.
When does DPDP compliance become mandatory?
The DPDP Rules were notified in November 2025, with most obligations enforceable from 13 May 2027.
What is a Significant Data Fiduciary?
An organisation the Central Government designates based on the volume and sensitivity of data it processes; SDFs face extra duties: a DPIA, an independent audit, and a Data Protection Officer.
How is the exposure score calculated?
Answers are scored across five weighted dimensions, Data Volume & Sensitivity (30%), Regulatory Classification Risk (20%), Consent Architecture Maturity (20%), Children's Data Exposure (15%), and Breach Preparedness (15%), into a 0 to 100 composite and a risk band.