115 questions · DPDPA 2023 · Rules 2025

Questions on DPDPA,answered plainly.

Each answer stands on its own, cites the section it rests on, and says only what the Act and Rules say.

Your data estateHover to inspect
Argument 01Resilience, not implementation →

What is the difference between DPDPA implementation and DPDPA resilience?

Implementation produces the artefacts the Act requires: notices, consent flows, contracts, policies. Resilience is whether those artefacts hold under stress, such as a breach, a mass withdrawal of consent or a Board inquiry. The Act's penalties are triggered by failures in practice, so resilience is what reduces exposure.

When do most DPDPA obligations take effect?

The DPDP Rules, 2025 were notified in November 2025 with a phased timeline. Provisions on the Data Protection Board applied at once, consent manager registration follows after twelve months, and most Data Fiduciary obligations apply eighteen months after notification.

Does DPDPA require a breach response plan?

The Act requires reasonable security safeguards and intimation of a personal data breach to the Board and to each affected Data Principal. The Rules require a detailed report to the Board within 72 hours. Meeting that without a rehearsed plan is unrealistic.

Argument 02Unclear thinking is the first breach →

Does DPDPA apply to B2B companies?

Yes. DPDPA applies to digital personal data of any individual, including employees, job candidates, client contacts and vendor staff. A B2B business model does not remove those Data Principals from scope.

Is consent the only lawful basis under DPDPA?

No. Section 7 sets out certain legitimate uses, including specified employment purposes, compliance with law and medical emergencies. Everything else generally needs consent that is free, specific, informed, unconditional and unambiguous.

Can a company keep personal data indefinitely under DPDPA?

Generally no. Section 8(7) requires erasure once the specified purpose is no longer served, unless retention is necessary to comply with law. The Rules add fixed timelines for certain large platforms.

Argument 03You cannot protect what you have not named →

Is a data map mandatory under DPDPA?

The Act does not use the term, but its obligations on notice, purpose limitation, security, erasure and Data Principal rights cannot be met without knowing where personal data sits. Significant Data Fiduciaries must also carry out data protection impact assessments, which depend on one.

What should a DPDPA data inventory contain?

At minimum: the category of Data Principal, data fields, source, purpose, legal basis, storage location, processors, cross-border transfers, retention period and accountable owner.

Argument 04Consent is a contract you have to prove →

What makes consent valid under DPDPA?

Section 6 requires consent to be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to personal data necessary for the specified purpose. It must be as easy to withdraw as to give.

Does DPDPA allow pre-ticked consent boxes?

Consent must be signified by a clear affirmative action. A pre-ticked box is not an action by the Data Principal and is unlikely to meet the standard.

Who are consent managers under DPDPA?

Consent managers are entities registered with the Data Protection Board that let Data Principals give, manage, review and withdraw consent through an accessible, interoperable platform. They act on behalf of the Data Principal.

Argument 05The first 72 hours →

What is the breach notification timeline under DPDPA?

Under the DPDP Rules, 2025 a Data Fiduciary must intimate the Board and each affected Data Principal without delay on becoming aware of a personal data breach, and give the Board a detailed report within 72 hours, or a longer period the Board allows.

What is the penalty for failing to notify a breach under DPDPA?

Failure to give the Board or affected Data Principals intimation of a personal data breach attracts a penalty of up to ₹200 crore under the Schedule to the Act.

Argument 06Your vendor is your liability →

Is a Data Fiduciary liable for its Data Processor under DPDPA?

Yes. Section 8(1) makes the Data Fiduciary responsible for complying with the Act in respect of processing undertaken by it or on its behalf by a Data Processor.

Does DPDPA require a contract with Data Processors?

Yes. Section 8(2) allows a Data Fiduciary to engage a Data Processor only under a valid contract.

Argument 07The board question →

What is a Significant Data Fiduciary under DPDPA?

A Significant Data Fiduciary is a Data Fiduciary or class notified by the Central Government under Section 10, considering factors such as volume and sensitivity of data, risk to Data Principals, and impact on sovereignty, security and public order.

What are the obligations of a Significant Data Fiduciary?

It must appoint a Data Protection Officer based in India who is responsible to the board, appoint an independent data auditor, and carry out periodic data protection impact assessments and audits, along with measures in the Rules.

Argument 08What the Schedule actually costs →

What is the maximum penalty under DPDPA?

The highest ceiling in the Schedule is up to ₹250 crore, for failure of a Data Fiduciary to take reasonable security safeguards to prevent a personal data breach.

How does the Data Protection Board decide the penalty amount?

Under Section 33(2) the Board considers the nature, gravity and duration of the breach, the type of personal data, whether it is repetitive, any gain or loss avoided, mitigation and its timeliness, proportionality, and the likely impact of the penalty.

Sector · Banking & BFSIBanking & BFSI →

Does DPDPA override RBI data retention requirements?

No. Section 8(7) requires erasure when the purpose is served unless retention is necessary for compliance with law. Records a law such as PMLA requires to be kept may be retained for that period and purpose.

Do banks need consent for cross-selling under DPDPA?

Using data collected for account opening to market other products is a new purpose. Unless a legitimate use applies, it generally requires specific consent.

Sector · Fintech & NBFCFintech & NBFC →

Is an Android or iOS permission valid consent under DPDPA?

An operating-system permission grants technical access; it does not by itself provide the notice of purpose and the specific consent Section 5 and Section 6 require. Apps should pair permissions with a clear notice and choice.

Are lending service providers Data Processors under DPDPA?

Where they process borrower data on behalf of a regulated lender, they generally act as Data Processors, and the lender as Data Fiduciary remains responsible under Section 8(1).

Sector · Healthcare & PharmaHealthcare & Pharma →

Does DPDPA have a sensitive personal data category for health data?

No. DPDPA does not create separate categories. However, under Section 33 the Board considers the type and nature of personal data when determining penalties, so health data breaches are likely to be treated as more serious.

Can hospitals process patient data without consent under DPDPA?

Section 7 permits certain processing without consent, including responding to a medical emergency involving a threat to life or health. Routine care, research and marketing should be assessed separately and often need consent.

Sector · EdTechEdTech & children's data →

Who is a child under DPDPA?

Under Section 2(f) a child is an individual who has not completed eighteen years of age.

What does DPDPA require for processing children's data?

Section 9 requires verifiable consent of the parent or lawful guardian, prohibits processing likely to cause detrimental effect on a child's well-being, and bars tracking, behavioural monitoring and targeted advertising directed at children, subject to exemptions in the Rules. Breach can attract a penalty of up to ₹200 crore.

Sector · E-commerce & D2CE-commerce & D2C →

Do e-commerce companies need separate consent for marketing under DPDPA?

Generally yes. Consent must be specific to a purpose. Processing an order and sending marketing are different purposes, so marketing typically requires its own consent that can be refused and withdrawn.

What is the three-year erasure rule in the DPDP Rules?

The Rules require certain classes of large Data Fiduciaries, including e-commerce entities above a user threshold, to erase personal data of users who have not engaged for three years, after notifying them in advance.

Sector · SaaS & IT servicesSaaS & IT services →

Is a SaaS company a Data Fiduciary or Data Processor under DPDPA?

It depends on each activity. Processing client data on the client's instructions is typically as a Data Processor. Processing for the company's own purposes, such as analytics, benchmarking or marketing, makes it a Data Fiduciary for that activity.

Does DPDPA apply to Indian IT companies processing foreign clients' data?

Section 17(1)(d) exempts certain provisions for processing personal data of persons not within India under a contract with a person outside India. Obligations such as security safeguards and the company's own employee data remain relevant.

Sector · TelecomTelecom →

Are telecom companies Significant Data Fiduciaries under DPDPA?

Only the Central Government can notify Significant Data Fiduciaries. Given the volume and sensitivity of subscriber data, large telecom operators are strong candidates and should prepare for Section 10 obligations.

Do retailers who collect SIM KYC count as Data Processors?

Where retailers collect and handle subscriber data on behalf of an operator, they generally act as Data Processors, and the operator remains responsible under Section 8(1).

Sector · InsuranceInsurance →

Are insurance agents and brokers Data Processors under DPDPA?

When they collect and handle customer data on behalf of an insurer, they generally act as Data Processors, and the insurer remains responsible. Some brokers may act as independent fiduciaries for their own purposes.

Can insurers keep claims data indefinitely under DPDPA?

No. Data should be erased once its purpose is served, unless retention is required by law. Insurers should align retention with regulatory requirements and limitation periods.

Sector · HR & StaffingHR & Staffing →

Does DPDPA require consent for employee data?

Section 7(i) allows processing without consent for employment purposes and to safeguard the employer from loss or liability, among other listed purposes. Processing outside those purposes may require consent.

How long can employers keep candidate data under DPDPA?

Only as long as needed for the purpose, such as the recruitment for which it was provided, unless law requires longer. Employers should set and apply a retention period for unsuccessful candidates.

Sector · Hospitality & TravelHospitality & Travel →

Can hotels keep copies of guest IDs under DPDPA?

Hotels may collect and keep ID where a law requires it, for the period it requires. Retaining ID copies beyond that, or collecting more than required, is difficult to justify under Section 8(7).

Does DPDPA allow travel companies to transfer data abroad?

Section 16 permits transfers outside India except to countries restricted by Government notification. Contracts and safeguards are still expected, and sectoral rules may add requirements.

Sector · GamingGaming →

How does DPDPA affect online gaming companies?

Gaming platforms must obtain verifiable parental consent for users under 18, avoid tracking, behavioural monitoring and targeted advertising directed at children, and, for large gaming intermediaries, erase data of users inactive for three years under the Rules.

Is a self-declared age gate enough under DPDPA?

The Rules require Data Fiduciaries to adopt appropriate measures to ensure verifiable parental consent. A self-declared birth year alone is unlikely to be seen as sufficient where children are likely users.

Sector · Government vendorsGovernment vendors →

Does the government exemption under DPDPA apply to contractors?

Section 17(2)(a) lets the Central Government exempt notified instrumentalities of the State in specified interests. It does not automatically exempt private vendors, and the scope of any exemption depends on the notification.

Are government IT vendors Data Processors under DPDPA?

Where they process personal data on a department's instructions, they generally act as Data Processors. Where they use the data for their own purposes, they may be Data Fiduciaries.

Banking & BFSI · Deep diveThree reporting clocks →

Does a bank need to report a data breach to both CERT-In and the Data Protection Board?

A cyber incident may need reporting to CERT-In under its 2022 directions, and a personal data breach must also be intimated to the Data Protection Board and each affected Data Principal under DPDPA and the Rules. Sectoral reporting to the RBI may apply as well.

What is the CERT-In reporting timeline?

CERT-In's April 2022 directions require specified cyber security incidents to be reported within six hours of noticing them.

Banking & BFSI · Deep diveRetention versus erasure →

Can banks refuse a DPDPA erasure request because of PMLA?

Where the law requires retention, such as KYC and transaction records under PMLA, the bank may retain those records for the required period. Data not covered by a legal requirement should be erased once its purpose is served.

How long must banks keep KYC records?

Under the PMLA framework, records are generally kept for five years after the business relationship ends or the transaction, subject to the specific rule. Banks should confirm the period applicable to each record type.

Banking & BFSI · Deep diveAgents and partners →

Are collection agents Data Processors under DPDPA?

When they process borrower data on behalf of a bank or NBFC, they generally act as Data Processors. The lender, as Data Fiduciary, remains responsible for compliance under Section 8(1).

Can a lender call a borrower's references or relatives?

Processing a third person's personal data needs a lawful basis of its own. Lenders should limit collection and use of reference contacts and follow applicable RBI conduct rules.

Fintech & NBFC · Deep diveApp permissions →

Is an app permission valid consent under DPDPA?

No, not by itself. A permission grants technical access. DPDPA requires a notice of the purpose and consent that is free, specific, informed and unambiguous. Apps should show their own notice alongside permissions.

Can a lending app access a borrower's contact list?

RBI's digital lending rules restrict access to contacts, media and call logs. DPDPA separately requires the data to be necessary for the stated purpose.

Fintech & NBFC · Deep diveAlternative-data scoring →

Can fintechs use SMS data for credit scoring under DPDPA?

Only if the purpose was clearly notified and the customer gave specific consent for it, and subject to RBI rules on app data access. Data collected for another purpose cannot be repurposed without a new basis.

Do customers have a right to know what data a lender used?

Section 11 gives Data Principals the right to obtain a summary of personal data being processed and the processing activities undertaken.

Fintech & NBFC · Deep diveThe consent model that exists →

How does the account aggregator framework relate to DPDPA?

Account aggregators operate under RBI regulation using consent artefacts that specify purpose, duration and revocation. The model closely reflects DPDPA's requirements for specific, informed and withdrawable consent.

Are account aggregators consent managers under DPDPA?

They are distinct concepts. Consent managers are registered with the Data Protection Board under DPDPA. The Rules set their registration conditions.

Healthcare & Pharma · Deep diveCare versus commerce →

Can hospitals use patient data for marketing under DPDPA?

Marketing is a separate purpose from treatment. It generally requires specific, freely given consent that the patient can refuse without affecting care.

When can health data be processed without consent under DPDPA?

Section 7 allows processing for responding to a medical emergency involving a threat to life or immediate threat to health, and for certain health services during epidemics or public health threats, among other listed uses.

Healthcare & Pharma · Deep diveReports on messaging apps →

Is it lawful to send medical reports over WhatsApp under DPDPA?

DPDPA does not ban specific apps, but the Data Fiduciary must take reasonable security safeguards. Uncontrolled copies on staff and third-party devices make it harder to meet that duty and to respond to a breach.

What counts as a personal data breach in a hospital?

Under DPDPA a breach includes unauthorised processing, accidental disclosure, loss of access and similar events that compromise confidentiality, integrity or availability of personal data. A report sent to the wrong person can qualify.

Healthcare & Pharma · Deep diveTrials and research →

Can pharma companies reuse clinical trial data for marketing?

Using trial participants' personal data for marketing is a new purpose. It would generally require fresh, specific consent under DPDPA.

Is a CRO a Data Processor under DPDPA?

Where a CRO processes participant data on the sponsor's instructions, it generally acts as a Data Processor, and the sponsor as Data Fiduciary remains responsible.

EdTech & children's data · Deep diveVerifiable parental consent →

What is verifiable parental consent under DPDPA?

It is consent from a child's parent or lawful guardian that the Data Fiduciary has taken reasonable steps to verify, as prescribed by the DPDP Rules, including checking that the person is an identifiable adult.

What is the penalty for breaching children's data obligations?

Breach of the additional obligations for children under Section 9 can attract a penalty of up to ₹200 crore.

EdTech & children's data · Deep divePersonalisation or monitoring →

Does DPDPA ban adaptive learning for children?

Section 9(3) bars tracking, behavioural monitoring and targeted advertising directed at children, subject to exemptions notified in the Rules. Adaptive features must fit within an exemption or be redesigned.

Is online exam proctoring allowed under DPDPA?

Proctoring involves monitoring. For children it must fit the Section 9 framework and any Rules exemption, be limited to its purpose, and be secured and erased appropriately.

EdTech & children's data · Deep diveSchools and exemptions →

Are schools exempt from DPDPA?

No. The Rules exempt certain processing of children's data by educational institutions for specified purposes, such as educational activities and safety, from some Section 9 requirements. Other obligations continue to apply.

Do EdTech vendors benefit from a school's exemption?

Only to the extent they process data for the school's exempt purpose on its behalf. Processing for the vendor's own purposes needs its own lawful basis.

E-commerce & D2C · Deep divePixels and SDKs →

Are advertising pixels subject to DPDPA?

Yes, where they process personal data such as identifiers, device data or hashed emails. The brand generally acts as Data Fiduciary and should have a basis, a notice and appropriate contracts.

Is hashed email data personal data under DPDPA?

Hashed data that can be matched back to an individual remains data about an identifiable person and should be treated as personal data.

E-commerce & D2C · Deep diveDark patterns and consent →

Are pre-ticked boxes valid consent under DPDPA?

Consent must be signified by a clear affirmative action. A pre-ticked box is not an action by the user and is unlikely to meet the standard.

What are dark patterns under Indian law?

The Central Consumer Protection Authority's 2023 guidelines identify deceptive design practices such as false urgency, basket sneaking and confirm-shaming as unfair trade practices.

E-commerce & D2C · Deep diveDormant accounts →

What is the three-year erasure rule for e-commerce under the DPDP Rules?

The Rules require certain e-commerce entities above a registered-user threshold in India to erase personal data of users who have not engaged for three years, after informing them at least 48 hours in advance, unless retention is required by law.

Can e-commerce companies keep invoices after erasing accounts?

Yes, where tax or other law requires retention. Only data required by law should be retained, for the period required.

SaaS & IT services · Deep diveProcessor or fiduciary →

How do I know if my company is a Data Fiduciary or Data Processor?

A Data Fiduciary determines the purpose and means of processing. A Data Processor processes on behalf of a fiduciary. A company can be both, for different activities.

Do Data Processors have direct obligations under DPDPA?

DPDPA places obligations primarily on Data Fiduciaries, who must ensure processors comply through contract. Processors should expect those obligations to flow down in their contracts.

SaaS & IT services · Deep diveThe sub-processor chain →

What is a sub-processor under DPDPA?

DPDPA does not use the term, but a processor engaging another entity to process data on the fiduciary's behalf creates a chain that the fiduciary remains responsible for. Contracts should govern each link.

Do SaaS logs contain personal data?

Often. Logs, error traces and support tickets can capture identifiers and content. They should be minimised, secured and included in data maps.

SaaS & IT services · Deep diveWinning the security review →

What DPDPA questions do enterprise buyers ask vendors?

Common questions cover the vendor's role, breach notification timelines, sub-processors, data location and transfers, security safeguards, retention and support for Data Principal rights.

Does SOC 2 or ISO 27001 prove DPDPA compliance?

No. They evidence security controls, which support Section 8(5), but do not address roles, consent, notice, rights or other DPDPA obligations.

Telecom · Deep diveKYC at the retail edge →

Are telecom retailers Data Processors under DPDPA?

Where they collect subscriber KYC on behalf of an operator, they generally act as Data Processors. The operator remains responsible under Section 8(1).

What should telecom operators do about ID copies at retail points?

Limit capture to the official process, prohibit local copies, audit devices and contractually bind distributors and retailers to security and deletion obligations.

Telecom · Deep diveSDF readiness →

What must a Significant Data Fiduciary do under the DPDP Rules?

Beyond Section 10's DPO, independent auditor, DPIA and audit requirements, the Rules require an annual DPIA and audit and due diligence that algorithmic software does not pose risks to Data Principals' rights, among other measures.

What is the penalty for breaching SDF obligations?

Breach of the additional obligations of a Significant Data Fiduciary can attract a penalty of up to ₹150 crore.

Telecom · Deep diveRights at scale →

What rights do Data Principals have under DPDPA?

Sections 11 to 14 provide rights to access information, correction and erasure, grievance redressal and to nominate another person, alongside the right to withdraw consent.

Must individuals complain to the company before the Data Protection Board?

Yes. Section 13 requires a Data Principal to exhaust the grievance redressal opportunity with the Data Fiduciary or consent manager before approaching the Board.

Insurance · Deep diveAgents and brokers →

Are insurance agents responsible for customer data under DPDPA?

Where agents collect and handle data for an insurer, they generally act as its Data Processors, and the insurer remains responsible. Agreements should impose security and deletion duties.

What should insurers do when an agent leaves?

Require return or destruction of all customer personal data held by the agent, revoke access and document confirmation.

Insurance · Deep diveClaims and health data →

Are TPAs Data Processors for insurers under DPDPA?

When processing claims data on an insurer's behalf, TPAs generally act as Data Processors. The insurer remains responsible for compliance.

Is health data given extra protection under DPDPA?

DPDPA does not create a separate category, but the Board considers the type and nature of personal data when determining penalties, so breaches of health data are likely to be viewed seriously.

Insurance · Deep diveUnderwriting minimisation →

Does DPDPA require data minimisation?

Section 6 limits consent to personal data necessary for the specified purpose, and Section 8(7) requires erasure when the purpose is served. Together they require collecting and keeping only what is needed.

Can insurers collect data for future cross-selling?

Collecting data for an unspecified future purpose is hard to reconcile with DPDPA's purpose-specific consent. Cross-selling should be a separate, notified purpose with its own consent.

HR & Staffing · Deep diveCandidate data →

Can companies keep CVs of rejected candidates under DPDPA?

Only as long as needed for the recruitment purpose, unless the candidate consents to longer retention, for example for future roles. Data should be erased once the purpose is served.

Does the employment exemption cover job applicants?

Section 7(i) permits processing for employment purposes. Whether it extends to candidates who never become employees is not settled; relying on consent for talent pools is safer.

HR & Staffing · Deep diveEmployee monitoring →

Is employee monitoring allowed under DPDPA?

Section 7(i) allows processing for employment purposes and to safeguard the employer from loss or liability. Monitoring should be necessary and proportionate to those purposes.

Is employee consent valid for monitoring?

Consent must be free. In an employment relationship that can be difficult to show, so employers should rely on a clearly applicable legitimate use and limit monitoring to it.

HR & Staffing · Deep diveBackground verification →

Is a background verification vendor a Data Processor under DPDPA?

Generally yes, when it verifies candidates on the employer's instructions. The employer remains responsible for the processing.

What can employers check about candidates under DPDPA?

Only what is necessary for the stated purpose of the role, with notice to the candidate. Checks should be proportionate and data retained only as needed.

Hospitality & Travel · Deep diveGuest ID copies →

Can hotels keep copies of guest IDs under DPDPA?

Hotels may collect and retain ID where law requires it, such as for foreign guest reporting, for the period required. Retaining copies beyond that is difficult to justify under Section 8(7).

Should hotels store Aadhaar copies?

Hotels should avoid storing Aadhaar copies where not required, use masked Aadhaar or verification methods, and follow Aadhaar-specific legal restrictions.

Hospitality & Travel · Deep diveLoyalty and profiling →

Do loyalty programmes need consent under DPDPA?

Yes, for purposes beyond the programme's core function. Profiling for marketing and sharing with partners are separate purposes requiring specific consent.

Can hotels share guest data with partner brands?

Sharing with partners for their own purposes typically needs clear notice and specific consent. Sharing with processors needs a contract.

Hospitality & Travel · Deep diveCCTV and guest Wi-Fi →

Is CCTV footage personal data under DPDPA?

Yes, where individuals can be identified. It should be collected for a stated purpose, secured, access-controlled and retained only as long as needed.

Do hotels need consent for guest Wi-Fi data?

Collecting login data should be limited to what is needed to provide the service, with clear notice. Use for marketing would need specific consent.

Gaming · Deep diveAge assurance →

Do gaming platforms need age verification under DPDPA?

Where children are likely users, platforms must obtain verifiable parental consent before processing their data, which requires reasonable steps to establish age and parental identity.

Is a self-declared age gate compliant with DPDPA?

A self-declared birth year alone is unlikely to be sufficient where children are likely users, given the Rules' requirement for due diligence in verifying parental consent.

Gaming · Deep divePlayer telemetry →

Is game telemetry personal data under DPDPA?

Where it is linked to an account, device identifier or other data that identifies a player, it is personal data and subject to DPDPA.

Can games use behavioural data to target in-game offers to children?

Section 9(3) bars tracking, behavioural monitoring and targeted advertising directed at children, subject to exemptions. Targeting offers based on a child's behaviour is high risk.

Gaming · Deep diveDormant players →

Does the three-year erasure rule apply to gaming companies?

The DPDP Rules apply it to online gaming intermediaries above a registered-user threshold in India, requiring erasure after three years of inactivity with advance notice, unless law requires retention.

What notice must be given before erasure?

The Rules require informing the Data Principal at least 48 hours before erasure that their data will be erased unless they log in or engage.

Government vendors · Deep diveThe scope of the exemption →

Does DPDPA apply to government departments?

DPDPA applies to the State, but Section 17(2)(a) lets the Central Government exempt notified instrumentalities in specified interests such as sovereignty, security and public order.

Are private vendors covered by government exemptions?

Not automatically. The scope depends on the notification. Vendors should assume DPDPA applies to their own processing and contract accordingly.

Government vendors · Deep diveData at contract end →

What happens to personal data when a government IT contract ends?

As a processor, the vendor should return data to the department and delete remaining copies, including backups and test environments, unless law requires retention. Contracts should specify this.

Should vendors certify deletion?

Yes. A written certificate of deletion, covering all environments and backups, is good practice and evidences compliance.

Government vendors · Deep diveReal citizens in test data →

Can production personal data be used in test environments under DPDPA?

It is not prohibited, but security safeguards apply to every environment. Masking or synthetic data reduces risk and is good practice.

What counts as reasonable security safeguards under DPDPA?

The Rules list measures including encryption, obfuscation or masking, access control, logging and monitoring, backups and contractual safeguards with processors.

Tell us where your data sits.We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner