Skip to content
checkDPDP

FAQ

Questions, answered.

The most common things people ask about the scanner, the DPDP Act, and how we handle your data.

About the scan

  • Yes. The compliance scan is free and needs no signup. Paid features cover advanced tools and team workflows.

DPDP basics

  • The Digital Personal Data Protection Act, 2023 is India's first comprehensive data-protection law. It defines roles (Data Principal, Data Fiduciary, Processor, Consent Manager), obligations (notice, consent, security, breach, rights) and penalties.

Cookies & consent

  • If your site uses any non-essential cookies (analytics, ads, marketing) you need prior consent. That means a real banner with granular categories, not a "we use cookies" notification.

Pricing

  • Yes. The compliance scanner and Cookie Consent Manager are free. We charge for advanced tools (consent log at scale, audit exports, team seats).

Data & security

  • No. We only persist the score and a per-category summary needed to display your report. We don't archive the page or its assets.

Securing your website

  • HTTPS everywhere with HSTS, the seven recommended security headers (CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and the three Cross-Origin headers), 2FA on every admin login, encrypted off-server backups, and a documented patching cadence. Section 8(5) sits in the ₹250 crore penalty band, so this is the highest-stakes category to get right.

Data Principal rights

  • Five rights under Sections 11–14: access to a summary of personal data being processed and the processing activities; correction, completion, updation and erasure of personal data; nomination of another individual to exercise rights in case of death or incapacity; grievance redressal through the Fiduciary; and the right to complain to the Data Protection Board if the Fiduciary fails to address the grievance.

Penalties & enforcement

  • ₹250 crore is the headline ceiling for a Section 8(5) security-safeguard failure. Other bands are lower: ₹200 crore for breach-notification failures and children-specific failures, ₹150 crore for Significant Data Fiduciary failures, and ₹50 crore for everything else. There is also a ₹10,000 penalty for Data Principals who file frivolous complaints.