Cookie consent banner
Granular, prior consent with reject as easy as accept — no pre-ticked boxes, no dark patterns.
Free DPDP scanner · DPDP Act 2023
The free DPDP scanner built for India's Digital Personal Data Protection Act 2023. Paste your URL — get a 0–100 compliance score, a 10-category gap report and the exact fixes in 60 seconds. No signup.
No signup. No data stored about your site. By scanning you agree to our Terms and Privacy Policy.
What we check
Each check links to a specific obligation. We tell you what we found, why it matters, and how to fix it.
Granular, prior consent with reject as easy as accept — no pre-ticked boxes, no dark patterns.
A clear notice in plain language listing purposes, categories of personal data and how to exercise rights.
An obvious mechanism to withdraw consent — and it must be as easy as giving it in the first place.
All forms, trackers and integrations that collect personal data are disclosed before collection.
No analytics, ads or pixels load before the user opts in. Reject = nothing fires.
A Grievance Officer or contact point is published, with an SLA for response.
Access, correction, erasure, nomination and grievance — all reachable in one place.
If data leaves India, the notice says where and why — and the destination is not on the blacklist.
Verifiable parental consent for users under 18. No behavioural tracking, no targeted ads.
HTTPS, modern headers (HSTS, CSP, X-Content-Type), and no obvious leakage of personal data.
Already know your consent banner is the gap? Skip the scan and build a DPDP-compliant cookie banner in 5 minutes →
India-focused
If you'd rather use a packaged platform than our free tools, these are the India-aware consent managers and privacy suites built around the DPDP Act 2023 and the 2025 Rules.
AI-driven data + privacy automation with a strong India practice.
Best for
Mid-to-large organisations with complex data estates and India operations.
India-built consent management bundled with qualified DPO advisory.
Best for
Indian organisations that want a CMP and a DPDP-trained DPO from one team.
DPDP-native consent platform with decentralised identity and Account Aggregator hooks.
Best for
Indian BFSI, fintech and healthtech that need verifiable, portable consent.
Privacy engineering platform founded by Indian engineers — privacy as code.
Best for
Engineering-heavy teams who want privacy reviews inside the SDLC, not bolted on.
Plug-and-play cookie consent banner used on 1.5M+ sites globally — built in India.
Best for
SMBs, agencies and WordPress / Shopify sites that want a polished banner fast.
India-built privacy + consent management — CMP, DSR, vendor risk in one.
Best for
Indian SMBs and mid-market teams wanting an all-in-one privacy stack.
Editorial listings · no vendor pays for placement · brand tiles are stylised wordmarks, not the vendors' trademarks.
How it works
No signup, no account, no credit card. The scan runs server-side and returns a 0–100 DPDP Act 2023 compliance score inside 60 seconds.
01
Any public Indian website. The scanner only reads what a browser sees on a normal page load — no auth bypass, no payload sent.
02
The crawler fetches home + privacy + cookie + grievance + rights pages, runs ~40 deterministic checks plus heuristic analysis, then refines the narrative with an LLM. Every finding cites a DPDP section.
03
0–100 score, a 10-category Pass/Warn/Fail breakdown, the exact one-sentence fix for each gap, and a downloadable PDF report you can share with your compliance team.
Why this scanner
Every check is mapped to a named section of the Digital Personal Data Protection Act 2023 or the Rules notified by MeitY in November 2025. Sections 5, 6, 8, 9, 11, 16 — cited by number on every finding.
No signup, no credit card, no per-scan limit, no premium tier behind the scanner. A one-person founder and an enterprise compliance team get the same 10-category report.
Pass / Warn / Fail and the 0–100 number are decided by hand-coded heuristics over the crawl data. The optional LLM only refines the written narrative; it never moves the score.
When the scanner suggests a consent platform, it points to India-built or India-aligned CMPs (Tsaaro, CookieYes, Privado.ai). No foreign-vendor pitch.
Honest by design
If a check couldn't actually be performed (e.g. the page blocked us), we mark it 'couldn't verify' — never a silent pass.
We don't display fabricated 'X sites scanned today' numbers. When we publish stats, they'll be real.
The 'Secured by checkDPDP' badge is reserved for sites that have actually passed a scan — not anyone who pastes the snippet.
Common questions
Quick answers to the questions we get most about how the free DPDP scan works.
Paste your website URL into the form above and press Scan. The free DPDP scanner fetches the public-facing pages, runs ~40 deterministic checks plus heuristic page-content analysis, and returns a 0–100 DPDP Act 2023 compliance score with a 10-category gap report — usually inside 60 seconds. No signup, no account, no credit card.
Most scans return results in 10–18 seconds. The crawler fetches up to five pages (home + privacy + cookie + grievance + rights) with an 8-second timeout each, then runs heuristic analysis plus an LLM-refined narrative. Worst case is 60 seconds — beyond that the scan is cancelled and you can re-run.
Yes. The scanner only reads publicly-fetched HTML, HTTP headers and policy pages — exactly what any browser sees on a normal page load. It does not bypass authentication, attempt login, or send any payload to the target site. You can scan competitors, partners, vendors or your own properties for free.
Yes. The scanner is industry-agnostic for the core 10 DPDP categories. For sector overlays (BFSI under RBI, healthtech under HIPAA-equivalent rules, e-commerce under consumer-protection rules), pair the scan with the industry guide at /industries — each sector has a dedicated DPDP exposure profile.
Yes. The full 10-category scan returns a 0–100 score and per-category findings with no signup, no credit card and no usage cap. We do not store the URL you scanned or its content. There is no premium tier hidden behind the scanner — the same scan that runs for a one-person founder runs for an enterprise compliance team.
checkDPDP is the only free DPDP scanner built specifically for the Indian Digital Personal Data Protection Act 2023 and the Rules 2025 — not a generic GDPR scanner re-skinned for India. Every check is mapped to a named DPDP section (5, 6, 8, 9, 11, 16) and the recommendations point to India-built consent management platforms (Tsaaro, CookieYes, Privado.ai) rather than US/EU tools that may not fit the Indian regulatory mandate.
Yes. The scanner is anchored to the Act and the November 2025 Rules. It checks for: Section 5 privacy notice itemisation, Section 6 consent UX, Section 6(4) withdrawal equality, Section 8(5) reasonable security safeguards, Section 8(10) Grievance Officer publication, Section 9 children-data treatment, Sections 11–14 data principal rights, and Section 16 cross-border transfer disclosure. Every finding cites the section by number.
The scanner runs ~40 deterministic technical checks (HTTPS, HSTS, CSP, consent banner presence, pre-consent tracker fires, grievance officer disclosure, etc.) plus heuristic page-content analysis. It surfaces what is verifiable from the public-facing site — it cannot inspect backend records, vendor contracts, or DPIAs. For a full audit of those, use Free Audit. Realistic catch rate on Indian sites is ~85% for static and server-rendered pages; full SPAs are lower due to client-side hydration.
Every gap links to a plain-English fix and, where useful, a free tool — banner builder, privacy notice generator, DPA template, breach notification template. You can also book a follow-up audit, ask the DPDP AI assistant, or apply for a publicly verifiable DPDP-Verified certificate.
No. The scan runs server-side, results are returned to your browser, and we do not log the URL, the content or any personal data. We do not sell or share scan data with vendors or any third party.
More questions? Read the full DPDP FAQ → or start with the DPDP Act guide →