Data Protection & Technology Wing

DPDP Act compliance,
engineered - not improvised.

India's Digital Personal Data Protection Act carries combined penalty exposure north of ₹850 crore. We help founders and enterprises map their exposure, close the gaps, and build a defensible compliance posture - before the deadline, not after.

Take the Pulse Check → Full Deep-Dive Assessment →
or speak with our team directly →
Substantive obligations enforceable in
The exposure, quantified

What non-compliance actually costs.

Penalties under the DPDP Act 2023 are levied per instance of default, by provision - figures below are the statutory maximums per Schedule to the Act.

Section 8(5)
₹250 Cr
Failure to implement reasonable security safeguards against a data breach.
Section 8(6)
₹200 Cr
Failure to notify the Data Protection Board and affected individuals of a breach.
Section 9
₹200 Cr
Non-compliance with obligations relating to children's personal data.
Section 10
₹150 Cr
Breach of additional obligations placed on Significant Data Fiduciaries.
Any Other Provision
₹50 Cr
Residual penalty for any other contravention of the Act or its rules.
Maximum combined exposure across provisions
₹850+ Crore
Phased rollout

The compliance clock is already running.

Phase 1 · Live
14 Nov 2025
The Data Protection Board of India is constituted and becomes operational.
Phase 2
14 Nov 2026
Consent Manager registration framework opens for intermediaries.
Phase 3
~May 2027
Substantive obligations and penalty provisions become fully enforceable.
Where we look

Four domains. One posture.

Entity & Scope
Mapping where you touch personal data, and whether you are a Fiduciary, Processor, or both.
Consent & Notice
Itemised notices, granular consent, and clean withdrawal mechanics.
Security & Breach Readiness
Safeguards, detection, and a documented plan for the day something goes wrong.
Rights & Governance
Grievance handling, DPO appointment, and board-level accountability.
Free · No sign-up · Nothing leaves your browser

The Pulse Check & Deep-Dive Assessment

Answer honestly across four domains. The Pulse Check takes about two minutes; the Deep-Dive Assessment gives a full category-by-category breakdown.

0 / 8 ANSWERED
Beyond the free tools

The ISL DPDP Readiness Certification

A mock regulatory inquiry - modelled as closely as possible on how the Data Protection Board is expected to examine a Data Fiduciary - so you know exactly where your organisation stands before a real one ever arrives.

ISL DPDP Readiness Certificate
Issued to organisations that meet the readiness threshold on independent, evidence-based review.
01
Document & data-flow review
We request and review the same categories of records a regulator would - consent logs, notices, vendor DPAs, breach-response documentation, and retention policies.
02
Simulated inquiry
A structured mock-inquiry session with your compliance owners, modelled on how the Data Protection Board is expected to question a Data Fiduciary under the Act.
03
Evidence-based scoring
All four domains - Entity & Scope, Consent & Notice, Security & Breach Readiness, Rights & Governance - are scored against documentary evidence, not self-reported answers.
04
Certificate & remediation report
Organisations that meet the threshold receive the ISL DPDP Readiness Certificate, alongside a detailed report of any residual gaps and a remediation roadmap.
Request a Readiness Audit
The ISL DPDP Readiness Certificate is a private advisory assessment issued by Ivory Slate Legal. It reflects our professional evaluation of an organisation's DPDP readiness at a point in time and is not a statutory certification, registration, or approval issued by the Data Protection Board or any government authority.
Questions

Frequently asked.

What is the DPDP Act, in a sentence?+
India's Digital Personal Data Protection Act, 2023 is the country's first comprehensive data-protection law, governing how organisations may collect, process, and store the personal data of individuals in India.
Who does it apply to?+
Any entity - Indian or foreign - that processes the personal data of individuals in India, whether collected digitally or digitised afterward, including businesses, platforms, and service providers.
What happens if we're not compliant by the deadline?+
Once substantive obligations become enforceable, the Data Protection Board can levy penalties per instance of default, running into hundreds of crores for the more serious contraventions - in addition to reputational and contractual exposure.
Is this self-assessment a substitute for legal advice?+
No. It is an indicative, educational tool to help you spot gaps quickly. A proper compliance posture requires a documented legal review tailored to your data flows, sector, and scale.
How does Ivory Slate Legal help beyond this tool?+
We conduct structured DPDP readiness audits, draft the consent and notice architecture, build breach-response playbooks, and represent clients before the Data Protection Board where needed.
What is the ISL DPDP Readiness Certificate?+
It is our own evidence-based audit and certification service - a mock regulatory inquiry into your document trail and processes, scored against the same domains a real inquiry would examine. It is a private professional assessment by Ivory Slate Legal, not a government-issued certification.
Next step

Know your gaps before the Board finds them.

Schedule a DPDP Consultation