DPDP technical readiness
Check your code against India’s DPDP Act.
Policies say what a team intends to do with personal data. The code shows what it actually does. VibeDoctor maps that data and checks 38 technical controls, locally, in one command.
npx @neuralaxis/vibedoctor dpdp scan --full Who it’s for
Developers who got asked “are we DPDP ready?”
If your app handles personal data of people in India, the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 apply to how it collects, stores, shares, and deletes that data. Most checklists are questionnaires. This one reads your code.
It gives engineering, product, security, and legal the same evidence, and it separates what the code proves from what a person still has to answer.
What you get
Evidence files, written to .vibedoctor/dpdp/.
| File | What it’s for |
|---|---|
| data-map.json | Where personal data is collected, stored, logged, and sent. |
| control-matrix.json | Status of all 38 controls, with evidence. |
| evidence-ledger.json | Every piece of evidence, with file and line. |
| review-queue.md | Questions for product, security, or legal. |
| agent-handoff.md | Ordered fixes for a coding agent. |
| readiness-report.html | A readable report for the whole team. JSON and Markdown too. |
The checklist
All 38 controls.
Each control is VERIFIED, VIOLATED, PARTIAL, NOT_OBSERVED, NEEDS_CONTEXT, or NOT_APPLICABLE. A missing piece of evidence is never marked verified, and a skipped scanner is never a pass.
- Deterministic
- A concrete pattern in the code decides the result, such as personal data in a log call.
- Signal
- The code suggests a control exists or is missing, such as a consent or deletion route.
- Human review
- Code can’t answer it. It goes to the review queue as a question.
- Declared
- Evidence you record yourself, such as processor contracts, in .vibedoctor/dpdp/.
Notice and consent 6
- DPDP-NOTICE-001 Notice presentation technical signal Signal
- DPDP-CONSENT-001 Consent capture implementation Signal
- DPDP-CONSENT-002 Consent metadata completeness Deterministic
- DPDP-WITHDRAW-001 Consent withdrawal path Signal
- DPDP-PURPOSE-001 Purpose identifier technical binding Signal
- DPDP-NOTICE-002 Notice and consent adequacy Human review
Security safeguards 12
- DPDP-SEC-001 PII in application logs Deterministic
- DPDP-SEC-002 PII in LLM prompts or embeddings Deterministic
- DPDP-SEC-003 PII in URLs or query strings Deterministic
- DPDP-SEC-004 Browser storage of personal data Deterministic
- DPDP-SEC-005 Insecure HTTP transmission of personal data Deterministic
- DPDP-SEC-006 Authentication on personal-data routes Signal
- DPDP-SEC-007 Hardcoded production personal data or sensitive fixtures Deterministic
- DPDP-SEC-008 Debug endpoints exposing personal records Deterministic
- DPDP-SEC-009 Weak or reversible masking of identifiers Signal
- DPDP-SEC-010 Missing audit signals on sensitive operations Signal
- DPDP-EXPORT-001 Unprotected personal-data exports Deterministic
- DPDP-BREACH-001 Breach preparedness signals Signal
Minimisation and accuracy 3
- DPDP-MIN-001 API over-fetching of personal data objects Deterministic
- DPDP-MIN-002 Broad database selection of personal records Signal
- DPDP-ACC-001 Accuracy and correction technical path Signal
Retention and erasure 3
- DPDP-RET-001 Retention or TTL mechanism for personal data stores Deterministic
- DPDP-ERA-001 Erasure / account deletion path Deterministic
- DPDP-ERA-002 Retained personal data without visible deletion path Deterministic
Data Principal rights 5
- DPDP-ACC-RIGHT-001 Access / export endpoint Signal
- DPDP-CORR-001 Correction request implementation Signal
- DPDP-REQ-001 Rights request authentication and tracking Signal
- DPDP-GRIEV-001 Grievance handling technical signal Signal
- DPDP-NOM-001 Nomination-related implementation signal Signal
Children's data 2
- DPDP-CHILD-001 Children's data processing signals Signal
- DPDP-CHILD-002 Guardian / parental consent flow Deterministic
Processors and transfers 4
- DPDP-PROC-001 External processors and recipients inventory Deterministic
- DPDP-THIRD-001 Whole user objects sent to third parties Deterministic
- DPDP-XBR-001 Cross-border or external-service signals Signal
- DPDP-PROC-002 Processor contracts and instructions Declared
Applicability 3
- DPDP-APP-001 Personal data processing inventory from code Deterministic
- DPDP-APP-002 Applicability needs organisational context Human review
- DPDP-SDF-001 Significant Data Fiduciary obligations Human review
Commands
Scan, explain, fix, verify.
The same tools are available over MCP, so a coding agent can run the scan, read the control matrix, and verify its own fixes. Agent setup →
| Command | Purpose |
|---|---|
| dpdp init | Scaffold optional organisation context and declared evidence. |
| dpdp scan --full | Full technical-readiness scan. |
| dpdp scan --changed | Evidence from changed files only. |
| dpdp map | Print the personal-data map. |
| dpdp review-queue | Questions that need a person. |
| dpdp report | JSON, HTML, or Markdown report. |
| dpdp handoff | Ordered fixes for a coding agent. |
| dpdp verify | Re-check after changes. |
| dpdp explain <id> | Explain a control or finding. |