A DPDP compliance simulator. Read the notice and mark any lines you believe are not compliant
1NimbusCart
Online Shopping App
In Progress
2Wellspring National School
Parent Connect App
Locked
3Bright City Hospital
Patient Portal App
Locked
4QuestForge Games
QuestForge Play App
Locked
5Meridian Bank Ltd.
Meridian NetBank App
Locked
Case File No. 07 · Stage 1 of 5
NimbusCart Technologies Pvt. Ltd.
Exhibit A · Privacy Notice, as published on the NimbusCart shopping app · Reviewed against the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025
NimbusCart is a fictional online shopping app. What follows is its Privacy Notice, 26 clauses drafted the way real notices are.
Your task: review the notice the way an auditor would, and find any flaws that might exist.
Click (or tap) any line you believe fails the Act or the Rules.
Compliant lines should be left alone.
When you've reviewed the whole notice, submit your findings to see your score and the reasoning behind each clause.
Score at least 75 percent to clear this stage and unlock Stage 2.
This is a fictional company and an educational exercise built independently by dpdpcore.in. It is not legal advice, and is not affiliated with the Data Protection Board of India or any government body.
0 lines marked
Click any clause you believe is not compliant. Score 75 percent or higher to unlock the next notice.
Your Review, Filed
0/12Flaws caught
0Flaws missed
0False flags
All five notices reviewed. Here is your badge.
Save it and share it on LinkedIn if it was useful. LinkedIn
cannot pull an image from a link, so download it first and attach it to your post.
For organisations. These simulations are free, and they stay free. If you want one built around your own policies, your sector and your systems, so your team works through the decisions they will actually face, write to contact@dpdpcore.in.
For organisations. These simulations are free, and they stay free. If you want one built around your own policies, your sector and your systems, so your team works through the decisions they will actually face, write to contact@dpdpcore.in.
Privacy Notice
NimbusCart Technologies Pvt. Ltd., last updated for this exercise
Read each clause below. Click a line to mark it as a flaw. Nothing is scored until you press Submit Findings.
I. About This Notice
1.
This Privacy Notice explains how NimbusCart Technologies Pvt. Ltd. ("NimbusCart", "we", "us") collects, uses, stores, and protects your personal data when you use the NimbusCart shopping app.
2.
This Notice forms part of, and must be read together with, our Terms of Service, Refund Policy, and Community Guidelines; accepting any one of these documents is deemed acceptance of all, including this Notice.
II. What Personal Data We Collect
3.
We collect the following personal data, each for the stated purpose: your name and mobile number (to create your account), delivery address (to fulfil orders), and payment transaction ID (to process refunds).
4.
We may also collect any other information about you that we consider necessary from time to time, including data obtained from third parties, without further notice to you.
III. How We Use Your Data
5.
Your personal data is used only to process orders, arrange delivery, handle payments, and respond to customer support queries, as described at the time we sought your consent.
6.
By downloading or opening the NimbusCart app, you automatically agree to all data processing described in this Notice, and no further action is required from you.
IV. Consent
7.
Where we seek your consent for a new purpose, such as location access for live delivery tracking, we will ask separately and explain why it is needed. You may decline without affecting your ability to place orders.
8.
To use our photo filters feature, you must also consent to our accessing your entire contact list and call history; declining will disable the app entirely.
9.
You can withdraw consent at any time from Settings > Privacy > Manage Consent, the same two tap process it takes to give consent.
10.
To withdraw consent, you must send a notarised letter by registered post to our corporate office; withdrawal takes effect only once we receive and process the letter, which may take up to 60 days.
11.
By accepting this Privacy Notice, you also waive your right to file a complaint against us with the Data Protection Board of India.
V. Children's Data
12.
If you are under 18, you may create an account only with the verifiable consent of your parent or lawful guardian, obtained through our parental consent flow.
13.
We do not carry out behavioural tracking of users identified as children, nor do we show them targeted advertisements.
14.
Users below 18 may see personalised product recommendations and targeted advertisements based on their browsing and purchase history, just like adult users.
VI. Your Rights
15.
You have the right to obtain a summary of the personal data we hold about you and the processing activities we undertake with it, on request.
16.
You may request correction, completion, updating, or erasure of your personal data at any time; we will act on such requests unless retention is required by law.
17.
For any grievance about how your personal data is processed, please use the general "Contact Us" form on our website; we do not designate a specific Data Protection Officer or contact person for this purpose.
18.
Our Data Protection Officer can be reached at dpo@nimbuscart.example.com or +91 XXXXXXXXXX for any question about how your personal data is processed.
VII. Data Retention
19.
We retain your personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by law, after which it is erased.
20.
We retain all personal data indefinitely, even after you close your account or withdraw consent, so that we may use it for future business opportunities.
VIII. Security & Breach Notification
21.
We implement reasonable security safeguards, including encryption, access controls, and monitoring logs, and retain breach detection logs for at least one year.
22.
In the event of a personal data breach, we will decide at our sole discretion whether to inform you or the Data Protection Board of India, depending on the severity of the breach.
IX. Language & Accessibility
23.
This Notice, and every consent request, is available to you in English and in any language listed in the Eighth Schedule to the Constitution of India, from the language selector in the app.
24.
This Privacy Notice is available only in English; users who do not understand English should ask a friend or family member to translate it for them.
X. Cross Border Transfers & Changes to This Notice
25.
We may share your personal data with processors and partners located outside India, subject to any restrictions specific to a country that the Central Government may notify from time to time.
26.
We may update this Notice at any time without informing you; continued use of the app after any change counts as your consent to the updated processing, including for new purposes we have not previously disclosed.
Correctly assessed Missed or wrongly flagged
Case File No. 08 · Stage 2 of 5
Wellspring National School
Exhibit B · Privacy Notice, as published on the Parent Connect app · Reviewed against the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025
Wellspring is a fictional school. Parent Connect is the app it uses to share attendance, marks, transport tracking, and messages with parents and guardians. This notice covers how the school processes a child's personal data, an area the Act and Rules treat with particular care.
Your task: review this notice the same way, and find any flaws that might exist.
Click (or tap) any line you believe fails the Act or the Rules.
Compliant lines should be left alone.
Several clauses here turn on the exemptions the Rules give schools for safety and educational tracking, so read each one closely rather than assuming a pattern from Stage 1.
Privacy Notice
Wellspring National School, last updated for this exercise
Read each clause below. Click a line to mark it as a flaw. Nothing is scored until you press Submit Findings.
I. About This Notice
1.
This Privacy Notice explains how Wellspring National School ("Wellspring", "we", "us") processes personal data of enrolled students and their parents or guardians through the Parent Connect app and related school systems.
2.
By enrolling your child at Wellspring, you consent on behalf of your child to all present and future processing of personal data described in this Notice, including any purposes we may add later.
II. What We Collect and From Whom
3.
We collect your child's name, date of birth, class and section, attendance records, and academic marks, each used only for the purposes explained in this Notice.
4.
We may also collect information about your child from any source we consider useful, including social media profiles, without informing you.
III. Verifiable Parental Consent
5.
Before creating your child's Parent Connect account, we verify that you are an identifiable adult and the child's parent or lawful guardian, using identity and age details you provide or, where you agree, through a Digital Locker service.
6.
Any adult who downloads the Parent Connect app and enters a child's admission number may access that child's full academic and health record without further verification.
IV. Tracking, Monitoring, and Safety
7.
We use campus CCTV and the school bus GPS tracker to monitor your child's safety on school premises and during transport to and from school.
8.
We also combine the school bus GPS and CCTV data with your child's browsing activity on the school issued tablet to build a behavioural profile, which we share with retail partners to serve personalised advertisements to your child.
9.
On the school issued tablet, we block access to content that could be harmful to your child's well being; this filtering does not require separate consent.
10.
This content filtering system also compiles a permanent log of every website your child visits, which we may use for purposes unrelated to content safety, including research partnerships with third parties.
V. Rights of the Data Principal, Exercised by a Parent
11.
As your child is a minor, you, as parent or lawful guardian, may exercise on her behalf the rights of access, correction, and erasure described in this Notice.
12.
If your child has ever won a school award or represented Wellspring in inter school competitions, we will not act on a request to erase her personal data, as we wish to preserve these records for the school's achievement history indefinitely.
13.
If you request correction of inaccurate academic records, we will correct the data once you provide reasonable supporting evidence.
VI. Data Retention
14.
We retain a student's academic records for the period required under applicable education board regulations, and erase other personal data, such as app login history, once it is no longer needed for the purpose it was collected for.
15.
We retain all data collected through Parent Connect, including chat messages between parents and teachers, indefinitely, as we may wish to use it in future for alumni relations.
VII. Grievance Redressal
16.
If you have a grievance about how we process your child's personal data, you may contact our Data Protection Officer at dpo@wellspringschool.example.in or +91 XXXXXXXXXX, whose details are also displayed on our website.
17.
Grievances about your child's personal data will be reviewed only by the class teacher concerned, and there is no further escalation available within the school.
VIII. Security and Breach Notification
18.
We use encryption and role based access controls to protect student data, and we maintain security incident logs, consistent with the safeguards expected under the Rules.
19.
If student data is compromised, we will assess reputational risk to the school before deciding whether to notify parents or the Data Protection Board of India.
IX. Language and Accessibility
20.
This Notice and all consent requests are available in English and in Hindi and other languages listed in the Eighth Schedule to the Constitution of India, selectable within the Parent Connect app.
21.
This Notice is available only in English, as this is the medium of instruction at Wellspring.
X. Sharing and Legitimate Uses
22.
Where your child is eligible for a government scheme such as a State scholarship or the mid day meal programme, we may share the relevant data with the Education Department for the purpose of determining or providing that benefit.
23.
We share your child's academic performance data with private tuition companies who pay us a referral fee, so they can contact you directly with enrolment offers.
Correctly assessed Missed or wrongly flagged
Case File No. 09 · Stage 3 of 5
Bright City Hospital
Exhibit C · Privacy Notice, as published on the Patient Portal app · Reviewed against the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025
Bright City is a fictional multi speciality hospital, notified as a Significant Data Fiduciary given the volume and sensitivity of the health data it processes. Patient Portal is the app it uses for appointments, records, and billing. This notice brings in provisions the first two stages did not: legitimate uses for medical emergencies and public health, and the additional obligations that apply once a Data Fiduciary is notified as significant.
Your task: review this notice the same way, and find any flaws that might exist.
Click (or tap) any line you believe fails the Act or the Rules.
Compliant lines should be left alone.
Watch for where a genuine legal exception, such as a medical emergency or a child specific health exemption, is stretched to cover something it was never meant to.
Privacy Notice
Bright City Hospital, last updated for this exercise
Read each clause below. Click a line to mark it as a flaw. Nothing is scored until you press Submit Findings.
I. About This Notice
1.
This Privacy Notice explains how Bright City Hospital ("Bright City", "we", "us") processes personal data of patients and their attendants through our Patient Portal app and hospital systems.
2.
By signing our admission form, you are deemed to have accepted this Notice in full, as it forms part of that form and every other policy referenced within it.
II. What We Collect
3.
We collect your name, contact details, medical history, diagnosis, treatment records, and insurance details, each used only for the purposes explained in this Notice.
4.
We may also collect information about you from any source we consider useful, including your social media accounts and fitness tracking apps, without informing you.
III. Legitimate Uses for Emergency and Public Health
5.
Where you are brought to our emergency department unable to give consent, we may process your personal data without consent to the extent necessary to respond to a threat to your life or health.
6.
We also rely on this same emergency ground to process the data of every outpatient who visits for a routine consultation, without seeking consent, because asking for consent slows down our billing process.
7.
During a declared public health outbreak, we may process patient data without individual consent to the extent necessary for measures to treat, contain, or manage the outbreak.
IV. Consent for Non Emergency Care
8.
For non emergency treatment, tests, and procedures, we explain what personal data will be processed and why, and ask for your specific consent before proceeding.
9.
By taking a token number at our reception, you are deemed to have consented to every present and future use of your health data described anywhere on our website.
10.
You may withdraw consent for a specific treatment related use of your data, but doing so requires a fresh written application to our Medical Records Department, reviewed only during the second week of each month.
V. Children in Our Care
11.
Where our paediatric department processes a child's personal data, that processing is restricted to the treatment necessary for protecting the child's health, in keeping with the exemption available to clinical establishments and healthcare professionals under the Rules.
12.
Data collected during a child's paediatric visit, including family medical history, is also shared with our wellness app partner to recommend paid supplements to the child's parents.
VI. Significant Data Fiduciary Obligations
13.
As a Significant Data Fiduciary, we undertake a Data Protection Impact Assessment and an audit at least once every twelve months, and the person carrying these out reports significant observations to the Data Protection Board of India.
14.
Our AI assisted diagnostic tool was licensed from a reputed vendor, so we do not carry out any internal review of whether it could pose a risk to patients' data rights.
15.
Where the Central Government has notified a category of personal data as restricted from transfer outside India, we, as a Significant Data Fiduciary, do not transfer that data, or the traffic data relating to it, outside the country.
VII. Data Retention
16.
We retain clinical records for the period required under applicable medical council and health regulations, and erase other personal data, such as appointment booking history, once it is no longer needed for the purpose it was collected for.
17.
We retain every patient's complete health record permanently, including for patients who visited only once for a minor consultation, because health data may prove useful for research we have not yet planned.
VIII. Rights and Grievance Redressal
18.
You may request a summary of the personal data we hold about you, and request correction or erasure, subject to any retention required by law.
19.
Requests to access or correct your health records must be routed through your treating doctor personally, and will not be entertained if that doctor is on leave or has left the hospital.
20.
Our Data Protection Officer can be reached at dpo@brightcityhospital.example.in or +91 XXXXXXXXXX for any grievance about how your personal data is processed.
IX. Security and Breach Notification
21.
We apply encryption, access controls limited to treating staff, and audit logs to protect patient records, consistent with the safeguards required under the Rules.
22.
Given the sensitivity of health data, we notify affected patients of a breach only if we ourselves judge the leaked information likely to cause them serious harm.
X. Language and Sharing
23.
This Notice and our consent requests are available in English and in Hindi and other Eighth Schedule languages, and our front desk can assist you in accessing them.
24.
Once your records are shared with a diagnostic laboratory located outside India, we consider this fully your responsibility and take on no further obligations under this Notice.
Correctly assessed Missed or wrongly flagged
Case File No. 10 · Stage 4 of 5
QuestForge Games Pvt. Ltd.
Exhibit D · Privacy Notice, as published on the QuestForge Play app · Reviewed against the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025
QuestForge Play is a fictional mobile game with about sixty five lakh registered users in India, which places it above the threshold at which the Rules set a specific, mandatory retention timeline for online gaming intermediaries. This stage brings in that timeline, along with the rules on age based exemptions for children, an area this notice gets only partly right.
Your task: review this notice the same way, and find any flaws that might exist.
Click (or tap) any line you believe fails the Act or the Rules.
Compliant lines should be left alone.
A rule written for one situation, such as the three year retention timeline for a dormant account, is sometimes stretched here to justify something it does not actually cover.
Privacy Notice
QuestForge Games Pvt. Ltd., last updated for this exercise
Read each clause below. Click a line to mark it as a flaw. Nothing is scored until you press Submit Findings.
I. About This Notice
1.
This Privacy Notice explains how QuestForge Games Pvt. Ltd. ("QuestForge", "we", "us") processes personal data of players through the QuestForge Play app.
2.
This Notice is deemed accepted along with our End User License Agreement and Fair Play Policy, and cannot be reviewed on its own.
II. What We Collect
3.
We collect your username, email address, device identifier, gameplay statistics, and payment token, each used only for the purpose explained in this Notice.
4.
We may also collect data about you from other apps on your device and from advertising networks, without informing you, to improve matchmaking.
III. Consent and Bundling
5.
Before enabling voice chat with other players, we ask for your specific consent, and you can decline while still playing the game.
6.
To create a QuestForge account, you must also consent to our accessing your phone's entire contact list, so that we can suggest friends to add.
7.
You can withdraw consent for marketing communications at any time from Settings, and it takes effect immediately.
8.
To withdraw consent for marketing communications, you must mail a written request to our support office, which will only take effect from the first day of the following calendar quarter.
9.
By accepting our Terms, you agree never to file a complaint against us with the Data Protection Board of India, and to resolve all disputes only through arbitration.
IV. Players Who Are Children
10.
Before enabling in app purchases for a user identifying as under 18, we obtain verifiable consent from a parent or guardian, checked against reliable identity and age details or a Digital Locker service.
11.
Any user may self declare their age as 18 or older by ticking a box at signup, and we do not otherwise verify age before enabling in app purchases or matchmaking with adult players.
12.
We have decided, on our own assessment, that QuestForge Play is safe for players above the age of thirteen, and therefore do not seek parental consent for players above that age.
13.
We do not use gameplay data to serve targeted advertisements or conduct behavioural profiling of players we know to be children.
14.
We use a child player's session length, in app purchases, and play patterns to personalise the advertisements shown to them between levels.
V. Data Retention
15.
As an online gaming intermediary with more than fifty lakh registered users in India, we fall within the Third Schedule. If you neither log in nor otherwise contact us for three years, and have not exercised your rights, we will erase your account and gameplay data, other than any virtual token, coin, or in game currency you have not yet used, or the data needed for you to access your account.
16.
At least forty eight hours before erasing your data on this basis, we will notify you so that you may log in or otherwise contact us if you wish to keep your account active.
17.
If you withdraw your consent to processing, we will nonetheless retain your data for three years, as permitted under the Rules for online gaming intermediaries, before erasing it.
18.
We retain transaction logs and related traffic data for at least one year from the date of processing, after which they are erased unless further retention is required by law.
VI. Security and Breach Notification
19.
We apply encryption, access controls, and monitoring logs to protect player data, consistent with the safeguards required under the Rules.
20.
If a data breach exposes players' payment details, we will investigate and notify affected players only if the breach affects more than ten thousand accounts.
VII. Grievance and Language
21.
Our Data Protection Officer can be reached at dpo@questforge.example.com or +91 XXXXXXXXXX for any grievance about how your personal data is processed.
22.
This Notice is available only in English, though the game itself supports several Indian languages during play.
Correctly assessed Missed or wrongly flagged
Case File No. 11 · Stage 5 of 5
Meridian Bank Ltd.
Exhibit E · Privacy Notice, as published on the Meridian NetBank app · Reviewed against the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025
Meridian is a fictional bank. Meridian NetBank is its banking app, and it also lets customers link accounts held at other banks through an Account Aggregator, the kind of Consent Manager the Act specifically provides for. This last stage brings in that consent framework, along with the rules on automated credit decisions, processing a loan defaulter's financial data, and how this Act sits alongside a regulator like the Reserve Bank of India.
Your task: review this notice the same way, and find any flaws that might exist.
Click (or tap) any line you believe fails the Act or the Rules.
Compliant lines should be left alone.
Some clauses lean on a real exemption, such as the one for a loan defaulter's financial data, and stretch it further than the Act allows.
Privacy Notice
Meridian Bank Ltd., last updated for this exercise
Read each clause below. Click a line to mark it as a flaw. Nothing is scored until you press Submit Findings.
I. About This Notice
1.
This Privacy Notice explains how Meridian Bank Ltd. ("Meridian", "we", "us") processes personal data of customers through the Meridian NetBank app and our branch systems.
2.
This Notice is deemed accepted the moment you sign our account opening form, and forms part of that form along with every other policy referenced within it.
II. What We Collect
3.
We collect your name, identity proof details, contact information, account balance, and transaction history, each used only for the purpose explained in this Notice.
4.
We may also collect information about you from any source we consider useful, including data purchased from third party data brokers, without informing you.
III. Consent Through an Account Aggregator
5.
If you choose to link accounts from other banks using an Account Aggregator registered with the Data Protection Board of India as a Consent Manager, you may give, review, and withdraw that consent directly through the Account Aggregator's own interface.
6.
Once you link an account through an Account Aggregator, we may continue pulling fresh transaction data from that account indefinitely, even after you have withdrawn your consent through the Account Aggregator.
7.
We do not act as a Consent Manager ourselves. Where you use one to share data with us, that Consent Manager remains accountable to you for how it manages your consent.
IV. Automated Credit Decisions
8.
Where we use your personal data, including data shared through an Account Aggregator, to make an automated decision on your loan application, we take reasonable steps to ensure that data is complete, accurate, and consistent before relying on it.
9.
Our automated loan approval system uses whatever data happens to be available at the time of the decision, and we do not verify its accuracy or completeness before approving or rejecting an application.
V. Processing a Loan Defaulter's Financial Data
10.
Where you default in repayment of a loan or advance taken from us, we may process your financial information, and your assets and liabilities, to ascertain the same, in the manner permitted for such processing under the Act.
11.
We rely on this same exemption for every customer who has ever paid a credit card bill even one day late, permanently exempting them from all rights under this Notice.
VI. Government Scheme Accounts
12.
Where you hold an account opened under a government financial inclusion scheme, we may process your personal data to enable the State to provide or issue a subsidy or benefit through that account, following the standards prescribed for such processing.
13.
We also use this scheme account data to build customer profiles for cross selling insurance and investment products, without seeking any separate consent.
VII. Rights and Grievance Redressal
14.
You may request a summary of the personal data we hold about you, and request correction or erasure, subject to any retention required by law.
15.
Grievances about your personal data may only be raised by visiting your home branch in person during banking hours, and cannot be raised through our app, website, or phone banking.
16.
Our Data Protection Officer can be reached at dpo@meridianbank.example.in or +91 XXXXXXXXXX for any grievance about how your personal data is processed.
VIII. Data Retention
17.
We retain account and transaction records for the period required under the Reserve Bank of India's applicable retention requirements, and erase other personal data once it is no longer needed for the purpose it was collected for.
18.
We retain all customer data indefinitely, beyond any period required by the Reserve Bank of India, so that we may use it for future analytics projects we have not yet planned.
IX. Security and Breach Notification
19.
We apply encryption, access controls, and monitoring logs to protect customer data, consistent with the safeguards required under the Rules.
20.
We will notify the Board and affected customers only once we have completed our own internal investigation into a breach, which may take several months.
X. Language and Our Relationship With Other Regulators
21.
This Notice and our consent requests are available in English and in any language listed in the Eighth Schedule to the Constitution of India, from the language selector in the app.
22.
This Notice is available only in English, in keeping with standard practice across the banking sector.
23.
This Act applies in addition to our obligations under the Reserve Bank of India's guidelines, and where the two conflict on a matter of data protection, the provisions of this Act will prevail to the extent of that conflict.
24.
Where our obligations under the Reserve Bank of India's guidelines conflict with this Notice, those guidelines will override this Notice in full, including your rights under the Act.