Cookie Consent
What fires before a visitor chooses. Trackers, pixels, session recorders and the banner — measured in a fresh browser, not inferred from a policy.
Free outside-in readiness assessment
Your website is the one part of a DPDP programme that anyone can inspect without asking. DPDP Lens loads it as a first-time visitor and reads what it does — the tags that fire, the forms that collect, the notice it shows and the signals that protect. Then it places you against India’s top 1,500 websites and tells you what to fix, in order.
Nothing is probed. No account is used. We observe only what an ordinary browser receives.
What India’s top 1,500 websites show their customers — and the regulator — before the Act’s core obligations take effect.
Every assessment is benchmarked against this study, and against your own industry. You will know where you stand, not just what you have.
The outside-in perspective: what India’s top 1,500 websites show their customers, and the regulator, eight months before the Act’s core obligations take effect.
This research is based on websites. The organisations studied may operate several platforms — mobile apps, customer portals, branches and call centres — so a website is not the ultimate truth on how many organisations meet a given obligation. Shares describe what the public website showed on the day.
Each area is measured, not guessed. Roughly ninety per cent of the checks are deterministic and reproducible.
What fires before a visitor chooses. Trackers, pixels, session recorders and the banner — measured in a fresh browser, not inferred from a policy.
Every form that collects personal data, and whether it asks properly at the point of collection. Purpose stated. Choice recorded.
Whether a notice exists, whether it is written for the DPDP Act or borrowed from another law, whether it states retention, and whether your customers can read it in their language.
Whether consent can be taken back as easily as it was given: a persistent control on the site, and a route named in the notice — the section 6(4) test.
Whether the five DPDP rights are described, a request channel is published, a grievance contact is named, and a response period is stated.
The public signals that protect: email authentication, transport security and browser headers — the basics of the Rule 6 safeguards duty.
Written for the people who decide, and for the teams who fix.
Every finding in one structure: what we observed, what it means, the impact on the business, and the specific outcome to aim for. Each is benchmarked against your industry and against Indian Inc., with how regulators abroad have treated the same behaviour shown at the point it appears.
The evidence: every cookie and tracker, every form and field, every data flow and its destination, the notice analysis, the security scorecard, and the engineering guidance your web and security teams need to close each gap.
One URL. We identify the organisation from your work email.
A one-time code confirms you are assessing your own site.
In about ninety seconds: what we observed, what it means, the impact, and the outcome to aim for — benchmarked against your sector.
Enter your website address. We will ask for a work email to send you the report and to confirm you are assessing your own organisation’s site.
A readiness assessment, not legal advice. The core obligations under the DPDP Act take effect in May 2027.