Free outside-in readiness assessment

See your website the way the regulator will.

Your website is the one part of a DPDP programme that anyone can inspect without asking. DPDP Lens loads it as a first-time visitor and reads what it does — the tags that fire, the forms that collect, the notice it shows and the signals that protect. Then it places you against India’s top 1,500 websites and tells you what to fix, in order.

Free. One website. About ninety seconds. You receive the executive view on screen and the detailed report to download.

Nothing is probed. No account is used. We observe only what an ordinary browser receives.

The state of Indian Inc. · September 2026

What India’s top 1,500 websites show their customers — and the regulator — before the Act’s core obligations take effect.

91%
of leading sites are not yet ready
80%
fire trackers before cookie consent
8%
show a cookie consent banner
55%
do not enforce email security

Every assessment is benchmarked against this study, and against your own industry. You will know where you stand, not just what you have.

Privacient Research · September 2026

DPDP Act — State of the Union 2026.

The outside-in perspective: what India’s top 1,500 websites show their customers, and the regulator, eight months before the Act’s core obligations take effect.

  • 1,500 websites examined across 11 industry groups — the most-visited, and those of the largest companies.
  • Six areas, measured not surveyed: cookie consent, consent on forms, the privacy notice, consent withdrawal, Data Principal rights and security signals.
  • Where each industry stands, the regulatory layers above the Act, the need-to-act matrix, and five moves before May 2027.

This research is based on websites. The organisations studied may operate several platforms — mobile apps, customer portals, branches and call centres — so a website is not the ultimate truth on how many organisations meet a given obligation. Shares describe what the public website showed on the day.

Download the report

Receive your copy

We ask for a work email so we can send you the report and keep it to organisations.

What we assess

Six areas. One visitor’s view.

Each area is measured, not guessed. Roughly ninety per cent of the checks are deterministic and reproducible.

01

Cookie Consent

What fires before a visitor chooses. Trackers, pixels, session recorders and the banner — measured in a fresh browser, not inferred from a policy.

02

Consent

Every form that collects personal data, and whether it asks properly at the point of collection. Purpose stated. Choice recorded.

03

Data privacy notice

Whether a notice exists, whether it is written for the DPDP Act or borrowed from another law, whether it states retention, and whether your customers can read it in their language.

04

Consent withdrawal

Whether consent can be taken back as easily as it was given: a persistent control on the site, and a route named in the notice — the section 6(4) test.

05

Data Principal rights

Whether the five DPDP rights are described, a request channel is published, a grievance contact is named, and a response period is stated.

06

Security posture

The public signals that protect: email authentication, transport security and browser headers — the basics of the Rule 6 safeguards duty.

What you receive

An executive read first. The detail behind it.

Written for the people who decide, and for the teams who fix.

Layer one · On screen

The executive view

Every finding in one structure: what we observed, what it means, the impact on the business, and the specific outcome to aim for. Each is benchmarked against your industry and against Indian Inc., with how regulators abroad have treated the same behaviour shown at the point it appears.

Layer two · Downloadable

The detailed report

The evidence: every cookie and tracker, every form and field, every data flow and its destination, the notice analysis, the security scorecard, and the engineering guidance your web and security teams need to close each gap.

How it works

Three steps. About ninety seconds.

1

Enter your website address

One URL. We identify the organisation from your work email.

2

Verify it is yours

A one-time code confirms you are assessing your own site.

3

Read the executive view

In about ninety seconds: what we observed, what it means, the impact, and the outcome to aim for — benchmarked against your sector.

Start here

Start with the view from outside.

Enter your website address. We will ask for a work email to send you the report and to confirm you are assessing your own organisation’s site.

Free. One website. About ninety seconds. You receive the executive view on screen and the detailed report to download.

A readiness assessment, not legal advice. The core obligations under the DPDP Act take effect in May 2027.