dpdpbot.com

Readiness report

www.mehfilandco.example

Mehfil & Co, spices delivered

Scan another

Thin public signals

Deductions come from 2 high, 2 medium, 2 low. A higher number means more of the public signals we look for were present. It is not a certificate under the DPDP Act.

Fictional example. Mehfil & Co is not a real shop.

How this score is made

Requested
https://www.mehfilandco.example
Fetched
15 Sept 2026, 3:00 pm
Time
2.4s
Report id
sample

DPDP Bot reads public pages and reports observable signals. It is not legal advice, not a finding that anyone complies or fails to comply with the Digital Personal Data Protection Act, 2023 or the DPDP Rules, 2025, and not a substitute for a review of what an organisation actually does with personal data.

Findings

7 items

  1. highform-without-notice

    A form asks for personal data without a notice cue beside it

    If a form collects personal data on the basis of consent, the notice has to accompany or precede that request. These fields look like name, email, or phone, and neither form mentions privacy, consent, or terms. The footer link to the notice was not counted, because it sits away from the form.

    Evidence

    • POST www.mehfilandco.example/newsletter asks for email.
    • POST www.mehfilandco.example/checkout asks for name, mobile, address.

    What to change

    Next to each form, state why those fields are collected and link the privacy notice. Where consent is the ground, ask for a clear affirmative action for that purpose.

  2. highgrievance-contact

    No grievance or privacy contact was visible

    Rights go nowhere if there is no one to write to. This fictional notice never names a contact. A real fiduciary would publish a role a person can reach.

    Evidence

    • The notice names “the company” and gives no grievance officer, Data Protection Officer, or email.

    What to change

    Publish a Grievance Officer, or a Data Protection Officer where one is required, with a monitored email on the notice and in the footer.

  3. mediumnotice-rights

    Data Principal rights are hard to find in the notice

    The Act gives Data Principals rights to access information about their personal data, to correct and erase it, to have a grievance heard, and to nominate another person. The Mehfil notice explains an order purpose and then stops.

    Evidence

    • Matched 0 of access, correction, erasure, and nomination.

    What to change

    Add a rights section: how to ask for access, correction, and erasure, and how to nominate someone. Point to the grievance contact in the same place.

  4. mediumthird-party-tags

    Third-party tags load on the public homepage

    These hosts can receive identifiers or page data from the visitor’s browser. The notice does not mention sharing, service providers, or other recipients. CleverTap is called out because it is a common Indian marketing tag, not because the scan has a special rule for one vendor. Seeing a tag is a review cue, not proof of a breach.

    Evidence

    • Google Tag Manager (tag-manager) via https://www.googletagmanager.com/gtm.js
    • CleverTap (marketing, India stack) via https://in1.wzrkt.com/js
    • Meta Pixel (advertising) via https://connect.facebook.net/en_US/fbevents.js
    • Razorpay (payments, India stack) via https://checkout.razorpay.com/v1/checkout.js

    What to change

    List each recipient, or a category that does not hide them, in the notice. Drop tags you cannot explain. Where consent is the ground, load non-essential tags only after a valid consent.

  5. lowconsent-withdraw

    The notice does not say how consent is withdrawn

    Where processing relies on consent, withdrawal has to be as easy as giving it. The CookieYes banner on the homepage is not a description of that path. Some processing may be a legitimate use under Section 7, so this is a gap to review.

    Evidence

    • No withdrawal-of-consent wording was matched.

    What to change

    State how a person withdraws consent, and make that path no harder than the original request.

  6. lowsecurity-headers

    Browser security headers are thin

    Reasonable security safeguards are a duty under the Act. Headers are only the public slice a browser can see. They say nothing about how orders are stored once they arrive.

    Evidence

    • Strict-Transport-Security was not set on the homepage response.
    • Content-Security-Policy was not set on the homepage response.
    • Referrer-Policy was not set on the homepage response.

    What to change

    Serve HSTS, a Content-Security-Policy you have tested, and a Referrer-Policy on HTML responses.

  7. infonotice-children

    Children’s data is not mentioned

    Section 9 restricts processing of children’s personal data. A spice shop may not intend to sell to children. The notice should still say whether that is the case.

    Evidence

    • No wording about children, minors, or parental consent was matched.

    What to change

    If you do not knowingly process children’s data, say so. If you might, describe the parental-consent path and the tracking limits you apply.

Signals observed
  • A privacy notice link opened

    https://www.mehfilandco.example/privacy.

  • Notice language matched some DPDP topics

    Observed: purpose, personal data.

  • A consent or cookie interface was observed

    CookieYes on the homepage. A banner is not itself DPDP consent. Consent still has to be free, specific, informed, unconditional, and unambiguous, with withdrawal as easy as the original choice.

  • The public page loaded over HTTPS

    https://www.mehfilandco.example/

Pages fetched
  • homepage

    https://www.mehfilandco.example/

    HTTP 200 · text/html; charset=utf-8

  • privacy notice

    https://www.mehfilandco.example/privacy

    HTTP 200 · text/html; charset=utf-8

Anyone with this link can open the report. Scans are not listed in a public directory.

Check this site again later

This report is one fetch. A later version can rescan on a schedule, diff the notice, and flag a new tag. Leave a work email if you want that for a site you are responsible for. Nothing is sent, and this build does not bill anyone.

Sample DPDP report for a fictional shop