Data protection
DPDP readiness check.
Twelve questions about what your business actually does with personal data. Answer honestly and you get a list of what to fix first. Nothing you type leaves this page.
Readiness questions
- 01
Can you list everywhere personal data of yours is kept, including spreadsheets and phones?critical
- 02
Does your enquiry form say what you collect, why, and for how long — on the form itself?critical
- 03
Can someone contact you without also agreeing to marketing?critical
- 04
Are all your consent boxes unticked by default?
- 05
Can someone withdraw consent as easily as they gave it?critical
- 06
Do you have a stated retention period for each kind of record?
- 07
Is every field on your forms something you actually use?
- 08
If someone asked what data you hold on them, could you answer within a month?
- 09
Is there a named person, published on your site, who answers data questions?critical
- 10
If you hold data on anyone under 18, do you have verifiable parental consent?critical
- 11
Would you know if your data was breached, and do you know who to tell?critical
- 12
Have you written down who else receives this data — couriers, gateways, agencies?
Answered 0 of 12. Your summary appears when all twelve are done — nothing is sent anywhere.
Every answer stays in this browser tab. Nothing is uploaded, stored or logged, and there is nothing to sign up for.
How to use it
Getting a useful result.
- Answer for the business as it works today, not as you intend it to work. The value is in finding the gap, and a hopeful answer just hides one.
- Use "Not sure" freely — it counts the same as "no" on purpose. On a question like verifiable parental consent there is no harmless version of not knowing.
- Work down the critical items first. Those are the ones somebody could complain about tomorrow, and they are usually the cheapest to fix.
- Re-run it after the changes. Most businesses move from the bottom band to the top with a week of work on forms, retention and a named contact.
The DPDP Rules were notified in November 2025 and phase in over eighteen months, with the substantive obligations and the penalty schedule taking effect in May 2027. There is time, but it is the kind of work that touches forms, databases and how staff handle a phone number, so it is not a last-week job.
This checks the part of compliance that lives in your software. A good deal of the Act is organisational — who is allowed to open what, what your staff do with a customer list, what you agreed with your suppliers — and no tool can see any of that.
Scoring is deliberately blunt: every gap counts once, and critical items are simply listed first. Weighting them into a percentage would imply a precision that nobody could defend, and this is a prompt for a conversation rather than an assessment.
Common questions
Is anything I type here sent to Solvey?
No. The questions, your answers and the summary are all generated in your browser and never leave the page. There is no account, no upload and no logging of answers. That matters here more than on most tools — the honest answers to some of these are exactly what a business would never hand to a stranger.
Does a good score mean we are compliant?
No, and be wary of any tool that says otherwise. Twelve questions cover the parts that live in software. Compliance also depends on internal process, staff behaviour and your agreements with suppliers, none of which a browser can inspect. Treat a clean result as 'nothing outstanding on these twelve', not as a clearance.
Does the DPDP Act apply to a small business?
Yes. The Act binds anyone who decides why and how personal data is processed, with no exemption for turnover or headcount. If you keep customer numbers in a spreadsheet or run an enquiry form, you are in scope. What scales with size is how much you hold, not whether the duties apply.
Can you fix these things for us?
The software half, yes — that is what we do. Notice and consent on forms, working withdrawal and deletion routes, retention rules, access requests and breach logging. We are not a law firm and not an auditor, and we will say plainly when a question needs a lawyer rather than a developer.
This checks the surface. Building notice, consent, retention and deletion into the software itself is a different job — DPDP compliance.