Readiness report
www.mehfilandco.example
Mehfil & Co, spices delivered
Thin public signals
Deductions come from 2 high, 2 medium, 2 low. A higher number means more of the public signals we look for were present. It is not a certificate under the DPDP Act.
Fictional example. Mehfil & Co is not a real shop.
- Requested
- https://www.mehfilandco.example
- Fetched
- 15 Sept 2026, 3:00 pm
- Time
- 2.4s
- Report id
- sample
DPDP Bot reads public pages and reports observable signals. It is not legal advice, not a finding that anyone complies or fails to comply with the Digital Personal Data Protection Act, 2023 or the DPDP Rules, 2025, and not a substitute for a review of what an organisation actually does with personal data.
Findings
7 items
- highform-without-notice
A form asks for personal data without a notice cue beside it
If a form collects personal data on the basis of consent, the notice has to accompany or precede that request. These fields look like name, email, or phone, and neither form mentions privacy, consent, or terms. The footer link to the notice was not counted, because it sits away from the form.
Evidence
- POST www.mehfilandco.example/newsletter asks for email.
- POST www.mehfilandco.example/checkout asks for name, mobile, address.
What to change
Next to each form, state why those fields are collected and link the privacy notice. Where consent is the ground, ask for a clear affirmative action for that purpose.
- highgrievance-contact
No grievance or privacy contact was visible
Rights go nowhere if there is no one to write to. This fictional notice never names a contact. A real fiduciary would publish a role a person can reach.
Evidence
- The notice names “the company” and gives no grievance officer, Data Protection Officer, or email.
What to change
Publish a Grievance Officer, or a Data Protection Officer where one is required, with a monitored email on the notice and in the footer.
- mediumnotice-rights
Data Principal rights are hard to find in the notice
The Act gives Data Principals rights to access information about their personal data, to correct and erase it, to have a grievance heard, and to nominate another person. The Mehfil notice explains an order purpose and then stops.
Evidence
- Matched 0 of access, correction, erasure, and nomination.
What to change
Add a rights section: how to ask for access, correction, and erasure, and how to nominate someone. Point to the grievance contact in the same place.
- mediumthird-party-tags
Third-party tags load on the public homepage
These hosts can receive identifiers or page data from the visitor’s browser. The notice does not mention sharing, service providers, or other recipients. CleverTap is called out because it is a common Indian marketing tag, not because the scan has a special rule for one vendor. Seeing a tag is a review cue, not proof of a breach.
Evidence
- Google Tag Manager (tag-manager) via https://www.googletagmanager.com/gtm.js
- CleverTap (marketing, India stack) via https://in1.wzrkt.com/js
- Meta Pixel (advertising) via https://connect.facebook.net/en_US/fbevents.js
- Razorpay (payments, India stack) via https://checkout.razorpay.com/v1/checkout.js
What to change
List each recipient, or a category that does not hide them, in the notice. Drop tags you cannot explain. Where consent is the ground, load non-essential tags only after a valid consent.
- lowconsent-withdraw
The notice does not say how consent is withdrawn
Where processing relies on consent, withdrawal has to be as easy as giving it. The CookieYes banner on the homepage is not a description of that path. Some processing may be a legitimate use under Section 7, so this is a gap to review.
Evidence
- No withdrawal-of-consent wording was matched.
What to change
State how a person withdraws consent, and make that path no harder than the original request.
- lowsecurity-headers
Browser security headers are thin
Reasonable security safeguards are a duty under the Act. Headers are only the public slice a browser can see. They say nothing about how orders are stored once they arrive.
Evidence
- Strict-Transport-Security was not set on the homepage response.
- Content-Security-Policy was not set on the homepage response.
- Referrer-Policy was not set on the homepage response.
What to change
Serve HSTS, a Content-Security-Policy you have tested, and a Referrer-Policy on HTML responses.
- infonotice-children
Children’s data is not mentioned
Section 9 restricts processing of children’s personal data. A spice shop may not intend to sell to children. The notice should still say whether that is the case.
Evidence
- No wording about children, minors, or parental consent was matched.
What to change
If you do not knowingly process children’s data, say so. If you might, describe the parental-consent path and the tracking limits you apply.
Check this site again later
This report is one fetch. A later version can rescan on a schedule, diff the notice, and flag a new tag. Leave a work email if you want that for a site you are responsible for. Nothing is sent, and this build does not bill anyone.