DPDP Act 2023 · Website Audit

How to Perform a 5-Minute DPDP Website Audit for Your Business

Published 30 July 2026 · 6 min read · By Ronin Works Team
Short Answer

Most Indian MSME websites violate the DPDP Act 2023 in four key places: 1) Tracking scripts firing before consent; 2) Cookie banners missing an equal-prominence Reject button; 3) Generic privacy policies missing itemized Section 5 purposes; and 4) Lack of published Grievance Redressal Officer contact details. You can test your site in 60 seconds using our Free DPDP Website Scanner.

With MeitY notifying the final DPDP Rules in November 2025 and the 18-month clock ticking down to the 13 May 2027 full compliance deadline, Indian businesses can no longer treat privacy as a footnote on their website footer.

Statutory maximum penalties under Section 33 reach up to ₹250 crore per instance for failing to implement reasonable security safeguards, and ₹200 crore for failing to notify personal data breaches. Your public website is the first place auditors, competitors, and consumers look.

Step 1: Check Pre-Consent Script Trackers

Under Section 6(1) of the DPDP Act, personal data processing requires free, specific, informed, and unambiguous consent. If your website loads Google Analytics (`gtag`), Facebook Pixel (`fbevents.js`), Hotjar, or LinkedIn Insight tags before a user clicks "Accept", you are collecting IP addresses and device identifiers without statutory consent.

How to test: Open your website in an Incognito window, open Chrome Developer Tools (F12) → Network tab, and check if third-party tracking calls fire before any banner interaction.

Step 2: Inspect Your Cookie Consent Banner

Rule 3 of the DPDP Rules 2025 mandates that consent requests must give equal prominence to accepting and rejecting choices. Dark patterns — such as hiding the "Reject" option inside a deep settings sub-menu while highlighting a giant red "Accept All" button — violate Rule 3.

If you don't have a compliant banner yet, you can configure itemized opt-ins using our Ronin Consent B2B Platform or generate custom notices using our Section 5 Notice Generator.

Step 3: Verify Section 8(10) Grievance Officer Disclosures

Section 8(10) mandates that every Data Fiduciary must publish the name, designation, physical address, and email contact of a designated Grievance Redressal Officer (GRO). Furthermore, the 2025 Rules enforce a strict 90-day response cap on all user grievances.

If your website currently lists a generic `info@company.com` or has no Grievance Officer name, generate signature-ready appointment letters and website HTML cards using our free Grievance Officer Kit.

Step 4: Audit Vendor Contracts & Data Processors

Section 8(8) states that Data Fiduciaries may engage third-party processors only under a valid written contract executed under Rule 6(f). If your agency, SaaS provider, or web developer touches customer data without a signed DPA, your business bears full statutory liability.

Generate a signature-ready B2B Data Processing Agreement in under 2 minutes with our Rule 6(f) DPA Generator.

The B2B & B2C Connection: Ronin Works ↔ Saaph.in

While Ronin Works helps Indian businesses audit compliance and deploy consent managers, consumer platforms like Saaph.in empower individual citizens to exercise Section 12 data deletion rights.

When an individual uses Saaph.in to request personal data erasure, Saaph's rights engine routes the request directly to your published Grievance Officer. Having your 62 DPDP Audit Prerequisites completed ensures your business handles consumer rights seamlessly without regulatory exposure.

Run Your Automated DPDP Audit Today

Rather than manually checking every script and policy page, run a live scan using our free Website DPDP Compliance Scanner. It fetches your live website HTML, evaluates 10 statutory categories, and provides an instant 0–100 score with exact one-sentence legal fixes.

Legal Disclaimer: This article provides general administrative information regarding DPDP Act 2023 compliance for Indian businesses. It does not constitute legal advice. For formal legal opinion, consult a qualified attorney.
Ronin Works DPDP Readiness

Need Help Getting Your MSME Audit-Ready?

We run full DPDP readiness programmes — data discovery, consent governance, grievance systems, vendor DPAs, and employee training.

Something went wrong. Email contact@roninworks.in directly.
✓ Received! A Ronin Works compliance lead will respond within 1 business day.