FAQ
Questions, answered.
The most common things people ask about the scanner, the DPDP Act, and how we handle your data.
About the scan
- Yes. The compliance scan is free and needs no signup. Paid features cover advanced tools and team workflows.
DPDP basics
- The Digital Personal Data Protection Act, 2023 is India's first comprehensive data-protection law. It defines roles (Data Principal, Data Fiduciary, Processor, Consent Manager), obligations (notice, consent, security, breach, rights) and penalties.
Pricing
- Yes. The compliance scanner and Cookie Consent Manager are free. We charge for advanced tools (consent log at scale, audit exports, team seats).
Data & security
- No. We only persist the score and a per-category summary needed to display your report. We don't archive the page or its assets.
Securing your website
- HTTPS everywhere with HSTS, the seven recommended security headers (CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and the three Cross-Origin headers), 2FA on every admin login, encrypted off-server backups, and a documented patching cadence. Section 8(5) sits in the ₹250 crore penalty band, so this is the highest-stakes category to get right.
Data Principal rights
- Five rights under Sections 11–14: access to a summary of personal data being processed and the processing activities; correction, completion, updation and erasure of personal data; nomination of another individual to exercise rights in case of death or incapacity; grievance redressal through the Fiduciary; and the right to complain to the Data Protection Board if the Fiduciary fails to address the grievance.
Penalties & enforcement
- ₹250 crore is the headline ceiling for a Section 8(5) security-safeguard failure. Other bands are lower: ₹200 crore for breach-notification failures and children-specific failures, ₹150 crore for Significant Data Fiduciary failures, and ₹50 crore for everything else. There is also a ₹10,000 penalty for Data Principals who file frivolous complaints.