345 days to full enforcement — May 13, 2027

DPDPA compliance for
Indian SaaS founders.
No demo calls.

Answer 15 questions about your product. See your exact penalty exposure in rupees. Get AI-generated policies, a visual data map, breach tracker, and evidence locker — all self-serve, no lawyers needed.

🔒AI operates on metadata only — personal data never leaves your infrastructure

Calculator: no signup · 2 minutes · see your number in rupees

Who the DPDPA applies to — Section 3

Any organisation that collects, stores, or processes personal data of individuals in India — including organisations headquartered outside India that offer goods or services to people in India.

Source: Section 3, Digital Personal Data Protection Act 2023

Reality check

Most Indian startups are one complaint
away from a ₹50 crore fine

Each of these is an active DPDPA violation. The Data Protection Board is operational.

No standalone privacy notice on your website or app
₹50 Cr
Using Razorpay, AWS, Mixpanel without a signed Data Processing Agreement
₹250 Cr
No documented 72-hour breach notification process
₹200 Cr
No data map showing where personal data lives and flows
₹50 Cr
Handling deletion requests by replying to emails — no SLA tracking
₹50 Cr
No verifiable parental consent for under-18 users
₹200 Cr
Find out your actual exposure →

Free. No signup. 2 minutes.

Free tools

Understand your exposure before anything else

No account required. Both tools run entirely on publicly available information.

Tool 01 — No signup

Website Scanner

Scans your website for undisclosed third-party data processors, missing privacy notices, forms without consent mechanisms, and cross-border data transfers. Results in under 60 seconds.

Run a free scan →

Tool 02 — No signup

Risk Calculator

Five questions about your organisation. Returns your penalty exposure in rupees based on the DPDPA penalty methodology. The number that makes you act.

Calculate your risk →

Key obligations under DPDPA 2023

What compliance requires

The following become mandatory from May 13, 2027. The Data Protection Board is operational and accepting complaints.

Rule 3Up to ₹50 Cr

Standalone Privacy Notice

Every Data Fiduciary must publish a standalone privacy notice — not buried in terms of service — with an itemised description of personal data collected, purposes, and direct links for consent withdrawal and rights exercise.

Rule 6Up to ₹250 Cr

Reasonable Security Safeguards

Encryption at rest and in transit, access controls, log monitoring, data backups, and a documented TOM framework. Security clauses must be present in every Data Processor contract.

Section 8(2)Up to ₹50 Cr

Data Processing Agreements

A signed DPA is required with every third party that processes personal data on your behalf — cloud providers, analytics platforms, CRM tools, communication services.

Rule 7Up to ₹200 Cr

Breach Notification

Affected Data Principals must be notified without delay. A detailed report must be submitted to the Data Protection Board within 72 hours. CERT-In must be notified within 6 hours of detection.

Sections 11–13Up to ₹50 Cr

Data Principal Rights

Access, correction, erasure, and grievance mechanisms must be published and operational. Grievance requests resolved within 90 days. Correction requests within 7 days.

Rule 8Up to ₹50 Cr

Data Retention and Erasure

Retention periods must be defined for every category of personal data. Data must be erased when the purpose is no longer served. Processing logs retained for minimum one year.

How Complyoo works

From assessment to compliance

01

Structured onboarding

15 questions covering your data collection practices, processing tools, storage locations, and existing controls. Completed in under 10 minutes.

02

Risk report and gap analysis

Immediate compliance risk assessment — your penalty exposure in rupees, and the specific gaps that require remediation, ordered by penalty size.

03

Policies, map, and evidence

AI generates your policies from your answers. Your data map is built from your tools. Upload evidence and your controls auto-complete.

🚨

Breach Tracker

₹200 Cr penalty

Breaches happen at 11pm on a Friday. You need to be ready.

Three simultaneous legal obligations the moment a breach is detected:

6 hours

CERT-In Report

From detection. File at incident.cert-in.org.in. Even if you're still investigating.

24 hours

DPBI Initial Notice

Rule 7(2)(a). File with what you know. Don't wait for the full picture.

72 hours

DPBI 72-Hour Report

Rule 7(2)(b). Full incident report with data categories, principals affected, root cause.

Active Incident · Manually logged

Database breach — user records exposed

CERT-In 6hr04:23
DPBI Initial19:45
DPBI 72hr67:45
📄 CERT-In template
📄 DPBI template

Log the breach → clocks start → templates load instantly

Platform features

Everything V1 includes

Every output is generated from your answers — grounded in the specific DPDPA rule it satisfies.

First screen after onboarding

Penalty Dashboard

Your exact rupee exposure — ₹45-75 lakh shown as the hero metric, not a generic checklist. Know your number the moment you complete onboarding.

DPDPA 2023 penalty methodology

Streaming — appears word by word

AI Policy Generation

11 DPDPA policies generated section-by-section from your answers. Your Privacy Notice mentions Razorpay and AWS by name — not 'payment processor' and 'cloud provider'.

Rule 3, 6, 7, 8, 14, 15 DPDPA

Visual Data Map

Interactive diagram: Source → Storage → Processor → Destination. See which vendors are missing DPAs, which flows are cross-border. Export as 7-page audit PDF.

Rule 15, Section 16 DPDPA

New

Breach Tracker

Log a breach manually. Three clocks start: CERT-In 6-hour, DPBI Initial Notice, DPBI 72-Hour Report. Templates you already generated load instantly. No searching at 11pm.

Rule 7, CERT-In Directions 2022

Evidence Locker

Upload proof that controls are implemented. AI reviews each file against the specific control requirement and auto-completes the control when verified.

DPDPA accountability obligations

Controls Checklist

57 DPDPA controls, ordered by penalty exposure. Each shows the applicable Rule, penalty amount, and effort estimate. Focus Mode guides you through step by step.

Parts 6 + 15, DPDPA reference

Vendor DPA Tracker

Your actual tools — Razorpay, AWS, Mixpanel, Stripe — with direct DPA links. Track signed/pending/missing status. See which vendors still need agreements.

Section 8(2) DPDPA 2023

Audit Export

One-click export of your data map as a 7-page PDF audit document with signature fields. The document you hand a DPBI inspector or investor due diligence team.

DPDPA audit requirements

No signup required

Free Risk Calculator

Five questions. See your DPDPA exposure before signing up. No email, no account. Your number in rupees in 2 minutes.

complyoo.com/calculator

Why Complyoo

Built different

🚀

No demo call required

Every competitor requires a call before you can start. Complyoo is the only platform where you go from zero to compliant tonight, without talking to anyone.

Policies from YOUR answers, not generic templates

Your Privacy Notice mentions Razorpay, Mixpanel, and AWS because you told us you use them. Not 'Third-Party Analytics Provider A'. Real documents for your real stack.

Penalty in rupees as the hero metric

You don't open Complyoo and see a 47-item checklist. You see ₹45-75 lakh in red. That's the number that makes you act. Everything else follows from that.

💳

₹2,999/month. Public pricing. No negotiation.

Consultants charge ₹5 lakh for a one-time engagement. Every competitor requires a sales call for pricing. Our pricing is on this page. You can start tonight.

Product roadmap

Built to grow with you

Start with the essentials. Operational and infrastructure capabilities follow as your organisation scales.

V1Available now
2,999/mo

Assess your obligations. Generate your documents.

Risk report + penalty exposure in rupees
AI-generated policies — all 11 DPDPA types
Visual data map with DPA status overlays
Breach Tracker with three countdown timers
Evidence locker with AI review
Controls checklist ordered by penalty exposure
Vendor DPA tracking with direct links
Audit-ready PDF export
V2Coming soon

Operate your compliance programme.

DSR portal — live data rights workflow
Consent SDK — 2 lines of JavaScript
Vendor monitoring and renewal alerts
Trust Center — share compliance status
AI data exposure monitor
Live AWS/GitHub integrations
Team collaboration and assignments
V3Coming soon

Full DPDPA compliance infrastructure.

AI Audit Simulator — DPBI readiness test
DPIA methodology tool for SDFs
Sector modules — Fintech, Healthtech, Edtech
Regulatory change engine
Developer API for CI/CD pipelines
Enterprise sales motion and SLAs

Pricing

Simple. Public. No calls required.

Consultants charge ₹5 lakh for a one-time engagement. We charge ₹2,999/month for a living system.

V1 — Everything you need to start

₹2,999/month

or ₹24,999/year — save ₹11,000

Structured onboarding — 15 questions, 10 minutes
Penalty dashboard — your rupee exposure in real time
AI-generated policies — all 11 DPDPA types
Visual data map with DPA status overlays
Breach Tracker with three countdown timers
Evidence locker with AI review
Controls checklist ordered by penalty exposure
Vendor DPA tracking with direct links
Audit-ready PDF export
No demo call required
Start your assessment

No credit card required

345 days to enforcement — May 13, 2027

Know your number tonight.

Free calculator. No signup. 2 minutes. Find out exactly what you're exposed to under DPDPA 2023.

No demo calls. No sales process. Email: hello@complyoo.com