A quarterly report on how Indian organisations are tracking against the DPDP Act and Rules — measured from what their public web presence actually shows, not from what anyone says in a questionnaire. Published as sector aggregates only. No organisation is ever named.
FIRST EDITION: Q3 2026 · EXPECTED OCTOBER 2026 · QUARTERLY THEREAFTER
The organisations we observe come from public regulatory registers — RBI, CERT-In, IRDAI, SEBI, FIU-IND — not from a purchased list or a convenience sample. Every row in the panel carries its source register, so the population each statistic describes is a matter of record, not of trust.
Registry-sourced · provenance recorded per organisationSignals are measured by the same outside-in scanner our platform runs every day: privacy notice presence and contents, a published grievance contact, a DPO contact, an Indian-language notice option, consent banner behaviour, a withdrawal control, trackers loading before consent, TLS. The check set is frozen for each edition and versioned in the methodology — trend lines only ever compare like with like.
Instrument version + validation results published per editionEvery statistic accounts for three states — signal present, signal absent, and could not assess — and all three are published, on the chart, not in a footnote. A sector appears only when enough organisations were actually assessed for a percentage to mean something; below that floor we print “insufficient panel this quarter”, never a number.
Minimum panel per published statistic: 30 organisationsCompliance readers get scared for a living. This series is built on the opposite premise, and these rules are permanent:
No best-in-sector or worst-in-sector callouts, no quotes from any website, no cell sizes small enough to point a finger. Aggregates only, permanently.
A site we couldn’t assess is published as exactly that. It never inflates a failure rate, and it visibly degrades our own headline instead of quietly disappearing.
No fine-amount headlines, no countdown clocks. Each finding ships with what good looks like — prevalence plus a path, not a threat.
DPDP compliance runs far deeper than any outside-in scan can see — consent records, retention, breach process. This is a sector barometer of public signals, stated as such. It is not an audit, and it carries no statutory recognition.
Nothing in it is self-reported. Every statistic is an observation of a public surface, reproducible from the published methodology — check us.
The Q3 2026 baseline edition is expected in October 2026 and will appear on this page, as will every edition after it — each with its full methodology, instrument version and validation results, and the complete aggregate table as a download. Nothing is published yet, and we’d rather skip a quarter than publish a thin one.
Organisations may ask to be permanently excluded from the panel — honoured forever, no questions, at hello@consentree.in. The same address will tell you when the first edition lands.