The Digital Personal Data Protection (DPDP) Act sets the rules for how your website, online store or portal asks for, uses and protects people’s personal details. The main duties become enforceable on 13 May 2027. Take the two-minute check to see where you stand.
The DPDP Act passed in 2023 and its Rules were notified on 13 November 2025. The Data Protection Board already exists. The main duties, including notices, consent, security and breach reporting, become enforceable on 13 May 2027.
A contact form, checkout, login, newsletter box, chat widget or analytics tag all collect personal data. The law is not limited to large companies, and it also reaches businesses outside India that serve customers in India.
They can ask what you hold, correct it, have it deleted, withdraw their consent and complain, first to you and then to the Board. Every request needs a tracked answer.
The ceiling is ₹250 crore for failing to protect data, with separate fines for not reporting a breach or mishandling children’s data. These are maximums, not predictions, but one incident can trigger more than one.
Many websites have a form like the one on the left. Nothing looks broken, yet each numbered point is a gap under the DPDP Act. The version on the right shows what “ready” looks like.
Ten quick questions cover the forms, trackers and back-end basics.
Contact forms collect names, numbers and emails, but nothing beside the button says what happens to them or how to withdraw.
Analytics, ad pixels, chat widgets and embedded videos switch on as the page loads, and a cookie banner that hides “Reject” doesn’t fix that.
Job applications hold phone numbers, photos and work history. Old ones often sit in an inbox for years.
Signing up takes one click. Unsubscribing means writing an email, which breaks the “as easy to withdraw as to give” rule.
We review your live pages, forms and scripts and send a plain-language gap report with a fix list in priority order.
Get a review of my websiteThe customer needs to give an address and phone number to buy. That is not permission to send offers, and it needs its own, optional choice.
Abandoned-cart emails and promotional messages need the customer’s clear consent, and a working way to stop them.
Years of customer records pile up “just in case”. The law expects deletion once the purpose is over, and a bigger pile means a bigger leak.
Each one receives customer data, and you stay responsible for what they do with it. Contracts need to say so.
We check your checkout, account pages, scripts and vendor connections, then send a plain-language gap report with a fix list in priority order.
Get a review of my storeIDs, KYC documents, financial or health details are often visible to more people than need them, with no record of who looked.
Users can’t see what you hold or close their account without emailing support, and nobody tracks how long the reply takes.
Analytics, notification and support tools inside the portal or app share user data before anyone has agreed to it.
Who decides it is a breach, who tells the customers, and who sends the Board full details within 72 hours? Most teams have never practised.
We map what your platform stores and who can see it, then send a plain-language gap report with a fix list in priority order.
Get a review of my portalAnswer for the one website, store or portal you run. Where you don’t know, choose “Not sure”. That counts as a gap, because a regulator will ask for proof, not confidence.
Each one comes with the fix in one line.
The most the law allows for each kind of failure.
These are ceilings, not predictions. The Board weighs how serious the failure was, how many people were affected and what you did about it.
This check only knows what you told it. Our team looks at your live pages, forms and scripts, and sends a plain-language gap report with a fix list in priority order.
Only used to put your name on the report. Nothing is sent anywhere, and the file is made in your browser.
This self-check is a general guide based on the DPDP Act, 2023 and the DPDP Rules, 2025. It is not legal advice and cannot see your code or data. How the law applies to your business is a question for your legal counsel.
Milleniance is a software team, so the forms, banners, portals and databases get changed in your real product, not only described in a document. Each part answers specific checks from the self-check above.
Starts every project
We scan your website, app and databases to find every form, tracker, third-party script and stored record that touches personal data, and every vendor it flows to.
Answers checks 1 to 4
Notices at every point of collection, one consent choice per purpose, a banner that waits for the visitor’s decision, and a record of who agreed to what and when.
Answers checks 4 and 5
A self-service place where customers can see, correct and delete their data and withdraw consent, with identity checks, tracked requests and response deadlines.
Answers checks 7 and 8
Encryption, role-based access, logging and monitoring that match what the Rules expect, plus a breach-response plan that has been rehearsed before it is needed.
Answers checks 9 and 10
Retention periods for each kind of record, automated deletion, and a register of every vendor that handles your customers’ data, with the contract terms to match.
Answers check 6
For sites that young people can reach: an age check, a parent-verification flow, and tracking and targeted ads switched off for minors.
We find every form, tracker, script, database and vendor that touches personal data on your website, store or portal.
You get a prioritised list of what’s missing, what each gap could cost and what fixing it involves. Your legal counsel can review it alongside.
We build the notices, consent, rights portal, security and deletion changes into your live platform, and test each one.
We hand over the evidence you would need in an audit, and keep watching as you add new forms, vendors and features.
Share your website address and we’ll send a plain-language gap report. A person on our team reads every request, and we reply within one business day.