Transparency
How our DPDP readiness score and scanner are calculated
ProtectComply gives you two independent scores: a readiness score from your assessment answers, and a scanner score from an automated scan of your public website. We publish this methodology so you can see exactly what each score measures — and defend it in an audit.
1. The DPDP readiness score
The readiness assessment presents 350+ sectoral questions across the two paid tiers (Protect Pro and Protect Max). Every question is mapped to a specific DPDP obligation — a section of the Act or a Rule notified in January 2025. Your answers roll up into a percentage using three inputs:
- Obligation weight. Questions tied to statutory duties with penalty exposure (consent, notice, breach notification, grievance) carry more weight than best-practice items.
- Answer state. Each control is scored as met, partially met, or not met — partial credit reflects work in progress rather than a binary pass/fail.
- Evidence quality. Answers backed by uploaded evidence (and, on Protect Max, AI vision validation of that evidence) score higher than self-attestation alone.
The result is a weighted percentage, plus a gap list ordered by obligation severity — so you always know which missing control to close first.
2. The website scanner score
The scanner runs 60+ automated checks against a public URL and groups them into 10 weighted DPDP domains. Each domain contributes to the final grade in proportion to its legal importance:
| Domain | Weight | Why it matters |
|---|---|---|
| Consent & cookie banners | High | §6 requires free, specific, informed, unconditional consent — the banner and its refusal path are checked first. |
| Privacy notice presence & quality | High | §5(3) mandates an itemised notice; we check it exists, is reachable, and covers the required elements. |
| Grievance & DSR contact | High | §13 and Rule 13 require a reachable grievance/redressal contact and process. |
| Data-collection surface | Medium | Forms, trackers and third-party scripts that collect personal data before consent. |
| Children's data signals | Medium | §9 / Rule 9 — age-gating and verifiable parental consent indicators. |
| Security & transport | Medium | HTTPS, HSTS and mixed-content — baseline safeguards under §8(5). |
| Cross-border & third parties | Medium | Third-party endpoints that may transfer personal data outside declared boundaries. |
| Policy discoverability | Low | Whether policies and contact details are linked and crawlable. |
| Accessibility of rights | Low | Whether data-principal rights (access, correction, erasure) are surfaced to visitors. |
| Retention & metadata hygiene | Low | Signals around stated retention and data minimisation. |
A domain’s score is the share of its checks that pass. Domains are then combined by weight into a single 0–100 score with a letter grade. The scanner only inspects publicly reachable pages — it never accesses anything behind a login.
3. Why the two scores differ
The scanner tells you what a regulator or data principal can observe from the outside in seconds. The readiness assessment tells you whether the controls behind that surface actually exist and are evidenced. A site can pass the scanner while still failing readiness (or vice-versa) — which is exactly why we keep them separate.
Sources
Weightings are derived from the text of the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules notified in January 2025. Where the Act assigns explicit penalties (for example, up to ₹250 crore for failure to safeguard personal data), the associated controls are weighted highest.