SAMPLE — DEMONSTRATION ONLY. No real website was audited and no customer is represented.

What a paid audit report looks like

This is an illustrative report for a fictional retailer, "Example Retail India", built in exactly the structure the real product uses. It shows how every finding is tied to the evidence we read, the requirement it sits under, why it matters and what to do about it.

Overall score

63/100

Grade C · Medium risk

14
areas assessed
47
pages read
9
gaps found
17
points unverifiable

The site publishes a readable privacy notice and clear business details, but tracking runs before consent is taken, the grievance route is not identified, and there is no statement covering children's data. Fixing the three critical and high items below would move the score materially without any change to the site's design.

Where the site stands, area by area

Privacy policy

72
8 met 2 gaps 1 to review 1 not checkable

DPDP Act, 2023

54
7 met 5 gaps 2 to review 3 not checkable

Cookies & trackers

38
3 met 5 gaps 1 to review 0 not checkable

Data collection & forms

61
6 met 3 gaps 1 to review 1 not checkable

Terms & grievance

80
8 met 1 gaps 1 to review 0 not checkable

E-commerce & consumer

66
6 met 2 gaps 2 to review 1 not checkable

Advertising & ASCI

75
6 met 1 gaps 1 to review 2 not checkable

Security & CERT-In

49
4 met 3 gaps 1 to review 4 not checkable

AI & synthetic content

70
4 met 1 gaps 1 to review 2 not checkable

Sector-specific rules

83
5 met 0 gaps 1 to review 2 not checkable

Accessibility

57
4 met 2 gaps 2 to review 1 not checkable

Dark patterns

64
5 met 2 gaps 1 to review 0 not checkable

Children's data

45
2 met 2 gaps 1 to review 2 not checkable

Business disclosures

88
7 met 1 gaps 0 to review 0 not checkable

Findings in full

Every finding in the real report follows the same chain: what we found, the evidence we read, the requirement it sits under, why it matters, and the recommended action.

Critical

Analytics and advertising trackers load before any consent is taken

Evidence we read
On the home page and the product pages we read, a Google Analytics tag and a Meta pixel executed on first load. No consent banner appeared, and no cookie preference was stored before the trackers fired.
Applicable requirement
DPDP Act, 2023 — sections 4 to 7 (lawful basis and consent); IT Act s.43A read with the SPDI Rules, 2011.
Why it matters
Where tracking is not necessary for the service, setting it before consent means personal data is processed without a lawful basis, and there is no record you could show a regulator.
Recommended action
Block non-essential tags until the visitor accepts. Present a consent notice with equally prominent accept and reject options, keep a timestamped record of each choice, and allow withdrawal as easily as consent was given.
High

The privacy notice does not name a Data Protection Officer or grievance contact

Evidence we read
The privacy page lists a generic contact form only. No named officer, postal address, or response timeline appears on the privacy, contact or terms pages we read.
Applicable requirement
DPDP Act, 2023 — section 13; IT Rules, 2021 — rule 3(2).
Why it matters
A data principal must be able to raise a grievance with an identified person and expect a response within the stated timelines. A contact form alone does not satisfy this.
Recommended action
Publish the officer's name, designation, email and postal address on the privacy page and in the footer, and state the acknowledgement and disposal timelines you commit to.
Medium

The newsletter form collects a phone number without stating the purpose

Evidence we read
The footer subscription form requests name, email and mobile number. The adjacent text mentions email updates only; no purpose is given for the phone number.
Applicable requirement
DPDP Act, 2023 — sections 5 and 6 (notice and purpose limitation).
Why it matters
Collecting more than the stated purpose needs its own notice and consent, and unexplained fields are a common cause of complaints.
Recommended action
Either remove the phone field or state clearly what it is used for, make it optional, and record consent for that specific purpose.
Cannot be checked from the website

Breach notification readiness

Evidence we read
Nothing publicly visible shows whether incident logs, reporting timelines and CERT-In contacts are in place internally.
Applicable requirement
CERT-In Directions, 2022 — six-hour incident reporting; DPDP Act, 2023 — section 8(6).
Why it matters
Absence of public evidence is not non-compliance. This needs internal evidence, so it is reported openly instead of counted against your score.
Recommended action
Confirm internally that an incident register, a six-hour reporting route and 180-day log retention exist, and keep the evidence available.

The fix checklist

Ordered by impact, tickable as your team works through it, and downloadable as a PDF.

  • Gate all non-essential tags behind consent and log each choice
  • Publish the grievance officer's name, address and timelines
  • Rewrite the newsletter notice or drop the phone field
  • Add a children's data statement and an age-assurance approach
  • Confirm CERT-In incident reporting and log retention internally

Certificate of assessment

Once the score qualifies, an assessment certificate with a public reference is issued. Anyone can check that reference on our verification page.

LW-SAMPLE-0000

Example Retail India · Illustrative reference · not a valid certificate

See where your own site stands

Run the free rule-based check first, then choose the package that matches how many pages your site has.

This page is a demonstration. The scores, findings, evidence and certificate reference are illustrative and were written for this page; they do not describe any real website, customer or assessment. A real audit reads only what is publicly reachable on your site and produces an automated assessment — it is not legal advice and is not a guarantee of compliance. Every law, rule, direction, guideline and standard we assess against is listed on our framework register.