Before you spend a single rupee, see what DPDP compliance looks like for YOUR industry. Select your business type below — the entire page updates with relevant examples, dashboards, and penalty calculations.
Most Indian websites use a single "Accept All" popup. Under DPDP, this is a violation worth Rs 50 Crore. Here is what needs to change:
After we implement DPDP compliance, you get a live dashboard. No more scrambling during audits — everything is tracked, documented, and board-ready.
SAMPLE DATA — Your actual dashboard will show your real numbers
Adjust the inputs below to match your business. The DPDP penalty applies regardless of company size — a 5-person startup faces the same maximum as Infosys.
A free 30-minute call with our technical team. No sales pitch. We review your current state, identify the top 3 gaps, and give you a clear roadmap with timelines and costs. If you decide to proceed, implementation starts the same week.
Free gap assessment (30 min call)
Receive detailed scope + fixed quote
Implementation starts (8-12 weeks)
The Digital Personal Data Protection Act 2023 (DPDP Act) applies to every Data Fiduciary in India — any entity that collects, stores, or processes personal data digitally. This includes NBFCs, fintech companies, e-commerce platforms, healthcare providers, EdTech startups, and manufacturing firms. There is no exemption based on revenue, employee count, or company size. Whether you are a 5-person startup in Bangalore or a 500-employee NBFC in Mumbai, the same Rs 250 Crore penalty applies.
Companies in Kolkata, Mumbai, Delhi, Chennai, Ahmedabad, and Indore face identical obligations under the Act.
Under Schedule I of the DPDP Act, penalties range from Rs 10,000 (per-day for delayed DSR response) to Rs 250 Crore (for processing children’s data without verifiable parental consent). Key penalty triggers include: non-compliant consent mechanisms (pre-ticked boxes, bundled consent), failure to notify the Data Protection Board within 72 hours of a breach, inadequate security measures (Aadhaar in shared Excel files, unencrypted PAN data), and not publishing a grievance officer contact. Our penalty calculator above uses the statutory maximums from the Act.
Section 6 of the DPDP Act requires that consent be free, specific, informed, unconditional, and unambiguous with a clear affirmative action. This means: no pre-ticked checkboxes, no bundled consent (combining Terms of Service with data consent), no implied consent (browsing does not equal consent), and granular purpose-specific options. Every website, app, and digital form that collects personal data must implement a compliant consent management platform before the November 2026 Consent Manager deadline.
NBFC & Fintech: RBI Master Direction on IT Governance + DPDP dual compliance. KYC data (Aadhaar, PAN) requires enhanced safeguards. E-commerce: Cookie tracking, personalized ads, and marketing emails all require separate consent. Healthcare: Health data is sensitive personal data under DPDP, requiring explicit granular consent plus ABDM compliance. EdTech: Children’s data (under 18) attracts the highest penalty of Rs 200 Crore — verifiable parental consent is mandatory. Manufacturing: Employee data (Aadhaar, PAN, bank details) requires formal consent even in employer-employee relationships.
KhojKaro is India’s specialist DPDP compliance implementation partner. We serve businesses across Mumbai, Delhi, Kolkata, Chennai, Bangalore, Ahmedabad, Indore, Pune, and Hyderabad. Take our free DPDP readiness assessment to find out where you stand.