Is your website ready for India's DPDP Act?
We look at what your site actually does — which trackers run before anyone consents, whether a grievance officer is named, whether your forms record what people agreed to — and give you the list. Free, no sign-up, about fifteen seconds.
We request your home page and your privacy notice, the way any visitor would, and read what came back. We do not scan for vulnerabilities, we do not log in, and we do not touch anything. Our request identifies itself as Servertorch in your access log.
What we check
Eleven things, each one an obligation somebody can point at. These are the ones visible from outside — which is also how a regulator, a customer or a competitor would see them.
Cookies before consent
Whether analytics and advertising cookies are set on arrival, before anyone has agreed to anything.
Who receives your visitors
Every third party running on your page, named — analytics, advertising, session recording, chat.
Consent, not notice
Whether there is a mechanism that records a decision, or only a banner that announces one.
Grievance officer
DPDP requires a named, contactable person. Almost no Indian site has one yet.
Retention
Whether your notice says how long you keep things, and when you erase them.
Forms
Fields that collect personal data with no consent checkbox and nothing recorded.
Transport
HTTPS, HSTS, and whether your headers advertise which versions you run.
Breach detection
DPDP requires you to report a breach. That assumes you would know.
Children
Whether your notice addresses under-18s, where DPDP is strictest.
What this check cannot tell you
It is a web request. It sees what your site does to a visitor, which is roughly half of what either law is about.
- It cannot see your contracts with the people who process data for you.
- It cannot see where your backups live, or who can read them.
- It cannot see whether anyone would notice a breach, or how long it would take.
- It cannot see what your staff do with an export, or who has access to your database.
And it is not legal advice
We will never tell you that you are compliant, because compliance is a conclusion about your whole organisation and we can only see your website. What we give you is evidence: dated, specific, and checkable by anyone — including you, right now, with your browser's developer tools. Take it to your lawyer rather than instead of one.
A website check sees the front door. The personal data lives in your code.
Aadhaar numbers saved in plain text, phone numbers in log files, an account nobody can delete, a payment key committed by mistake — none of it is visible from outside. Code audit reads your repository and lists every gap, mapped to the DPDP Rules, with the fix.
What it found
database/seeders/demo_users.sql · Rule 6(1)(a)Customer.php:42 · aadhaar_number · Rule 6(1)(a)KycController.php:88 · phone, email · Rule 6(1)(c)routes/web.php · Section 8(7) · Rule 8config/logging.php · 14 days · Rule 6(1)(e)PaymentGateway.php:12 · rzp_live_•••• · Section 8(5)What a scan looks like. The repository is illustrative; the checks and their wording are the real ones.
- Every personal-data field, found Aadhaar, PAN, phone, email, bank, health and biometric fields — where they are stored, logged and sent.
- Mapped to the DPDP Rules and GDPR Each finding names the obligation it breaks — safeguards, retention, erasure, rights — and the penalty band.
- The fix, not just the problem A plain-language explanation and a code-level fix for each gap, so a developer can start the same day.
- Security leaks too SQL injection, secrets committed to the repo, vulnerable packages — the breaches that turn into ₹250 crore questions.
- A report you can hand over Download the full list as CSV, JSON or a printable report for your auditor, board or client.
- Checked again on every push New gaps reach you by email; fixed ones close by themselves. Your evidence of “we were watching”.
Website check — free
- Privacy notice and grievance contact
- Consent banner and trackers before consent
- Forms that collect data without a consent record
- HTTPS and security headers
Code audit — the part only your code can show
- How Aadhaar, PAN, health and bank data is stored — encrypted or not
- Personal data leaking into logs, URLs and third-party SDKs
- Whether people can see, export and delete their data (Rules 8 and 14)
- Log retention, breach detection and vulnerable packages
-
1
Connect
Give read-only access to the repository on GitHub or Bitbucket. Two minutes.
-
2
Scan
We read the code on our server. The copy is deleted when the scan ends.
-
3
Fix
Get the list with fixes and rule references — and walk through it with us on a call.
Why not wait
221 days to 13 May 2027
Penalties reach ₹250 crore for failing to protect personal data. Website fixes take an afternoon; code fixes take sprints — the earlier you have the list, the calmer May is.
A 30-minute call; we run the first scan with you. No card, nothing to install.
Read-only access · the code copy is deleted after each scan · findings show masked values, never full numbers · a list of gaps and fixes, not a legal opinion or a compliance certificate.
The dates that matter
13 Nov 2025
Rules published
The DPDP Rules were notified, starting an 18-month runway for most obligations.
Nov 2026
Consent managers
Rules for registered consent managers take effect.
13 May 2027
Full obligations
Notices, security, breach reporting, retention and rights apply. Penalties run to ₹250 crore.
Most of what needs fixing takes an afternoon. The part that takes longer is being able to show, later, that you were watching — which is why breach detection is on the list above and why we built the rest of this product.