RedForge / DPDP Act
India, DPDP Act 2023

Find the gaps before a regulator does.

The Digital Personal Data Protection Act applies to any business handling the personal data of people in India — including companies registered abroad that serve Indian users. There is no small-business exemption and no revenue threshold.

13 Nov 2025
DPDP Rules 2025 notified. The Data Protection Board is established and operational.
13 Nov 2026
Enforcement and penalty machinery becomes operative, along with Consent Manager registration.
13 May 2027
Full compliance required. Rules 3 and 5–16 in force: notice and consent, data principal rights, security safeguards, breach reporting, retention and erasure, children’s data and cross-border conditions.

The one an external test can prove. Of everything in that list, §8(4) and §8(5) — reasonable security safeguards — is the obligation a security assessment can actually evidence, and it carries the largest penalty at ₹250 crore. Consent, retention and governance are organisational work we can review but not test.

Timeline as we read the Digital Personal Data Protection Rules, 2025, notified 13 November 2025 with an eighteen-month phased commencement. Read the Act, the Rules and the official notification rather than our summary before you budget or plan against these dates, and take your own legal advice — we are a security testing firm, not your counsel.

What the Act requires

Six obligations, and what each one costs to miss.

Only one of these is a thing an external security test can actually prove you failed. It is also the one carrying the largest penalty.

Section What it requires of you Maximum penalty
§8(4), §8(5) Reasonable security safeguards. Real technical controls — encryption, access control, logging, backups — not a policy document describing them. This is the one an external test can actually prove you failed. ₹250 crore
§8(6) Breach notification. Every affected person without delay, and the Data Protection Board within 72 hours. ₹200 crore
§9 Children’s data. Verifiable parental consent for anyone under 18, and no tracking or behavioural advertising to them. ₹200 crore
§10 Significant Data Fiduciary duties, if the government notifies you as one: India-based DPO, independent audit, impact assessments. ₹150 crore
§5, §6 Notice and consent. Itemised notice in plain language, and consent as a clear affirmative action that is as easy to withdraw as it was to give. ₹50 crore
§11–§14 Rights. Access, correction, erasure, grievance redressal and nomination — with a working mechanism, not a paragraph. ₹50 crore
How we help

Three pieces of work.

All of it strictly passive unless you authorize otherwise: we review and we advise, and we do not test what has not been authorized.

DPDP readiness assessment ₹85,000

A dated assessment of where you stand against the Act, and the evidence file to show for it.

How it works

We review your privacy notice and consent flow, map which third parties receive your visitors’ data, look for exposed files and public storage, and test the one obligation that can be tested from outside — the §8(4) security safeguards — against a scope you authorize.

How it helps

You end up with the folder a regulator or an enterprise buyer asks for: what was checked, on what date, what was found, and what carries proof. §8(4) is the ₹250 crore obligation and the only one you cannot settle by writing a policy about it.

Personal data exposure testing

The §8(5) work: proving whether one customer can reach another customer’s data.

How it works

We create two accounts of our own and systematically try to reach one account’s data from the other, across every identifier in your application. No real customer’s data is ever touched.

How it helps

Every finding is mapped to the DPDP section it breaches and the penalty attached, so your board sees exposure in rupees rather than in severity labels.

Consent, notice and tracker audit

The §5 and §6 work: what your website does to a visitor before they have agreed to anything.

How it works

We load your site as a first-time visitor who has consented to nothing, and record every third party that receives their data — analytics, advertising pixels, session recorders, chat widgets, embedded fonts. Then we read your privacy notice against the items §5 actually requires it to list.

How it helps

Most consent failures are not decisions anybody made. They are a tag somebody added to the site four years ago that still fires before the banner does.

Consent & notice

Are you collecting valid, revocable consent with a clear notice attached?

Data inventory

Do you know every place personal data lives, and every path it flows along?

Retention & erasure

Can you erase a person’s data on request, and show that you did?

Breach readiness

Can you detect an incident and report it inside the window you are given?

Free to read, nothing to fill in

We wrote the handbook we wanted to hand people.

Ten chapters on what the Act asks of your company, what it costs to ignore, and how to prove you have actually done it — written for founders and executives rather than lawyers. No email gate, no form.

The obligations, one by one

Notice, consent, safeguards, breach, retention, grievance and children — each with the section, the plain-English meaning, and the evidence.

Your first thirty days

A week-by-week order of work, front-loading the obligations that carry the largest penalties and take the longest to build.

What non-compliance costs

The Schedule in full, and why the penalties stack — a single incident can trigger the security failure and the reporting failure together.

The part you cannot self-certify

Most of DPDP is paperwork you can do yourself. One obligation is not, and it is the one carrying the largest fine.

The DPDP Readiness Handbook

India’s data protection law in plain English. Read it, send it to your board, act on it without us — we would rather the work got done than gate it behind a contact form.

Read the handbook
Questions people actually ask

About the Act, and about us.

Does the DPDP Act apply to us? We are a small startup.+

Yes. The Act has no small-business exemption and no revenue threshold. If you handle the digital personal data of people in India you are a Data Fiduciary, whether you are two people or two thousand.

It also reaches companies registered outside India that offer goods or services to people in India. Being incorporated in Singapore or Delaware does not put you outside it.

Is anything free?+

The attack-surface report is. Send us your domain and you get a written report in two working days on what you already expose publicly. It is entirely passive — we send no credentials, submit no data and change nothing — which is exactly why there is nothing for you to authorise and nothing for you to pay.

It is not a DPDP assessment. It tells you what an attacker can see from outside; it does not tell you whether your consent flow meets §6 or whether your safeguards meet §8(4). That is the paid engagement above, and we would rather say so than let a free report read as a clean bill of health.

Does a RedForge assessment make us DPDP compliant?+

No. Compliance is an organisational state covering contracts, policies, staffing and process, most of which is not a security testing question. What we can do is prove or disprove one specific obligation — §8(4) and §8(5), reasonable security safeguards — and give you evidence for the rest.

We are not a certification body, and an assessment from us is not an audit opinion or a compliance statement.

Are you CERT-In empanelled?+

No. If your requirement specifically names a CERT-In empanelled auditor, we will tell you that rather than take the work.

Do you also handle ISO 27001 or SOC 2?+

We map every finding to ISO/IEC 27001:2022, SOC 2 and DPDP 2023 as evidence against named controls, which is the artefact an auditor will ask you for.

That is not an accredited audit. If you need an ISO 27001 certificate or a SOC 2 report for a customer or an investor, you need an accredited auditor, and we will say so rather than let you believe otherwise.

Start where it is useful to start.

Send us your domain and the free attack-surface report tells you what you already expose, in two working days, with nothing touched and nothing signed. If the answer warrants it, the DPDP readiness assessment is the next step and we will say so plainly either way.

Send us your scope