Skip to main content
Free 3-minute board diagnostic

Is your board ready for India’s data law?

The Digital Personal Data Protection Act, 2023 carries penalties up to ₹250 crore per violation category — and its obligations sit with the organisation, which makes them board business. Twelve questions, each mapped to the section of the Act it comes from. Scored in your browser: your answers are never sent anywhere.

Educational self-assessment, not legal advice. Section references are to the DPDP Act, 2023.

  1. 2. Is personal data used only for the specific purpose the person consented to — never repurposed for new uses without fresh consent?Purpose Limitation · DPDP Act ss. 4, 6(1)
  2. 3. Can an individual actually obtain a summary of their personal data and get inaccuracies corrected, through a working process (not just a policy page)?Data Principal Rights · DPDP Act ss. 11–12
  3. 4. When consent is withdrawn or the purpose is served, is the data actually erased (including from backups and processors) under a defined retention schedule?Erasure & Retention · DPDP Act ss. 8(7), 12(3)
  4. 5. Do you have a published grievance mechanism with a named officer and response timelines that individuals can actually use?Grievance Redressal · DPDP Act s. 13
  5. 6. Are "reasonable security safeguards" demonstrably in place — encryption, access control, logging — to prevent personal data breach?Security Safeguards · DPDP Act s. 8(5)
  6. 7. If personal data is breached tonight, do you have a tested process to notify the Data Protection Board of India AND each affected individual?Breach Notification · DPDP Act s. 8(6)
  7. 8. If any users could be under 18, do you obtain verifiable parental consent and avoid tracking, behavioural monitoring or targeted advertising directed at children?Children's Data · DPDP Act s. 9
  8. 9. Is every vendor that touches personal data (cloud, CRM, analytics, AI providers) bound by a contract that imposes DPDP-grade obligations on them?Processors & Vendors · DPDP Act s. 8(2)
  9. 10. If you may be notified as a Significant Data Fiduciary (high volume/sensitivity), are you ready for the extra duties — a Data Protection Officer based in India, independent audits and periodic impact assessments?Significant Data Fiduciary Duties · DPDP Act s. 10
  10. 11. Do you know exactly which countries personal data flows to, and can you stop transfers to any territory the government restricts by notification?Cross-Border Transfers · DPDP Act s. 16
  11. 12. Does your board receive regular DPDP-compliance reporting from a named accountable owner — treating the up-to-₹250-crore penalty exposure as a board-level risk?Board Oversight · DPDP Act (Schedule — penalties)

0/12 answered · scored in your browser — your answers are never sent anywhere.

Compliance is one module. Governance is the platform.

Vouli IQ’s compliance engine covers 25 jurisdictions — DPDP, GDPR and the EU AI Act included — inside the AI Boardroom Operating System.