DPDP Compliance Scanner
Check any website against the DPDP Act 2023 and the DPDP Rules 2025. Cookies, trackers, consent notice, privacy policy and DPO contact, scored in under a minute.
Results in under a minute. Shareable report, downloadable as PDF.
What the scanner checks
Every check maps to a specific provision of the DPDP Rules, so the report cites the rule rather than a generic best practice.
Cookie and tracker check
We load your site in a clean browser with no prior consent and record every cookie and third-party tracker that fires. Anything non-essential that runs before a choice is offered is flagged against Rule 3.
Consent notice check
We look for a consent notice and, more importantly, whether it offers a genuine reject option as prominently as accept. A banner with only "Accept" is not consent under the DPDP Rules.
Privacy notice check
We find your privacy policy and read the text itself against eleven DPDP requirements, from notice and consent withdrawal to grievance redressal and cross-border transfers. Not just whether a policy exists.
DPO contact check
Rule 9 requires a published contact who can answer questions about how personal data is processed. We check whether one is actually reachable on your site.
What a public scan cannot tell you
This scanner sees your site the way a visitor does. It cannot see whether you keep consent records, how you handle data principal requests, whether you can report a breach to the Board within the required window, or what personal data sits in your databases and drives. Those obligations carry the heaviest penalties under the Act, and none of them are visible from outside.
A clean score here means your public-facing surface is in order. It is a starting point, not a certificate.
See what a full DPDP setup coversCommon questions
Is the DPDP compliance scanner free?
Yes. The scan is free, needs no signup, and gives you a shareable report you can download as a PDF.
How long does a scan take?
Usually under a minute. We load your site in a real browser, record what it sets before any consent choice, then read your privacy policy against the DPDP requirements.
What does the compliance score mean?
Sixty per cent comes from what we can measure from outside your site: cookies, trackers, consent notice, HTTPS and a published DPO contact. Forty per cent comes from what your privacy notice actually says. A public scan cannot prove compliance, since it cannot see your retention schedules, processor contracts or internal safeguards, so treat the score as a starting point rather than a verdict.
Does this replace a DPDP compliance audit?
No. It checks what is visible from the outside. Consent records, data principal request handling, breach reporting and your RoPA all sit behind your login and need a proper audit.
Do you store the site I scan?
We keep the report so the link stays shareable, and we reuse a recent report for the same domain rather than re-scanning it. We do not collect personal data from the sites we scan.