Enforcement: 13 May 2027·Fines up to ₹250 crore for security failures·Every clinic is a Data Fiduciary under the Act·72-hour breach notification required
DPDP Act 2023 · Clinic Readiness Tool

Is your clinic defensible
under India's DPDP Act?

14 questions tailored to your clinic type. A personalised compliance score and the exact steps to close your gaps, in under 5 minutes.

Free, alwaysUnder 5 minutesNo login requiredDPDP + PCPNDT
Maximum fine · Security failures
250 Cr

Failure to implement reasonable security safeguards: unencrypted records, insufficient access controls, or insecure third-party integrations.

Maximum fine · Breach notification failure
200 Cr

Failure to notify the Data Protection Board and affected patients within 72 hours of a confirmed data breach.

72 hrs
Breach notification window
13 May 2027
Enforcement begins
100%
Of Indian clinics are Data Fiduciaries
How it works

Three steps to your readiness report

01  Answer
Tell us about your practice

14 questions covering consent, data storage, third-party sharing, breach response, and patient rights. Tailored to your clinic type.

02  Score
Get your readiness score

Your responses are scored across six DPDP compliance areas, giving you a clear risk level: Largely Compliant, Partially Ready, or High Risk.

03  Act
Prioritised action list

A precise list of the gaps that need closing, ordered by risk severity. Plain language, no legal jargon. Actionable for any clinic today.

Coverage

Six areas the check covers

Built against the DPDP Act 2023, MCI record-keeping guidelines, and PCPNDT obligations where applicable.

01
Consent & Notices

Do patients receive a written notice before data is collected? Do you have purpose-specific consent: treatment, referrals, and marketing kept separate?

02
Patient Rights

Can patients access, correct, and permanently erase their personal data on request, and can you respond within 48 hours?

03
Data Storage & Retention

Where is patient data stored? Do you have written retention periods and a documented deletion protocol for when data has served its purpose?

04
Third-party Sharing

Do every lab, pharmacy, and SaaS tool that receives patient data from you have signed Data Processing Agreements?

05
Security & Breach Response

Do you have a written incident response plan? Can you detect a breach and notify the Data Protection Board within the mandatory 72-hour window?

06
Children & Sensitive Data

Do you have verified parental consent for patients under 18? Are clinical records protected with role-based access controls?

Free · Instant · Clinic-specific

Take the readiness check

14 questions. Your personalised DPDP risk report at the end.

Your DPDP Readiness Check

14 clinic-specific questions. A personalised compliance score and an actionable gaps list at the end. Free, no login required.

Enforcement: 13 May 2027Is your clinic DPDP-ready? Fines up to ₹250 crore for violations.
Start the free check →