DPDP Act 2023 Compliance Assessment

How exposed is your organisation to DPDP penalties?

The Digital Personal Data Protection Act imposes penalties up to ₹250 crore. Measure your exposure across five critical dimensions with a transparent, research-backed methodology.

Your data never leaves your control. Answers are used only to compute your score and are never stored, logged, or shared.
₹250 CrMaximum penalty (security-safeguards failure)
800M+Estimated data principals under scope
May 2027Full compliance deadline

Five dimensions we score

Each dimension is scored 0 to 100 and weighted; together they produce your composite exposure index.

Data Volume & Sensitivity

The number of data principals, the sensitivity of the categories you hold, and the length of your processor chain.

Regulatory Classification Risk

Your sector, revenue, and the likelihood of being named a Significant Data Fiduciary.

Consent Architecture Maturity

How you collect consent, whether withdrawal and erasure work, and Consent Manager readiness.

Children's Data Exposure

Whether you process minors' data, parental-consent mechanisms, and behavioural monitoring.

Breach Preparedness

Your breach response plan, 72-hour notification capability, and DPIA status.

How it works

1. Answer 15 questions

Five dimensions, three questions each. Two minutes, no sign-up.

2. Get your exposure index

A 0-100 composite, a risk band, your penalty exposure, and a radar across all five dimensions.

3. See what to fix

Specific recommendations for the dimensions that scored worst, and how Amberoon can help.

Ready to see where you stand?

The assessment is free, takes two minutes, and stores nothing.

Start the assessment

Frequently asked questions

What is the maximum penalty under the DPDP Act?

Up to ₹250 crore for failing to take reasonable security safeguards, set out in the Schedule to the Act and imposed by the Data Protection Board under Section 33.

When does DPDP compliance become mandatory?

The DPDP Rules were notified in November 2025, with most obligations enforceable from 13 May 2027.

What is a Significant Data Fiduciary?

An organisation the Central Government designates based on the volume and sensitivity of data it processes; SDFs face extra duties: a DPIA, an independent audit, and a Data Protection Officer.

How is the exposure score calculated?

Answers are scored across five weighted dimensions, Data Volume & Sensitivity (30%), Regulatory Classification Risk (20%), Consent Architecture Maturity (20%), Children's Data Exposure (15%), and Breach Preparedness (15%), into a 0 to 100 composite and a risk band.