118 free compliance generators — no account required
ComplyKit has added two more free compliance generators: the Singapore PDPA Compliance Checker (117th) and the India DPDP Act Compliance Checklist (118th). Both are live now at /generate. Together they cover the two largest Asia-Pacific privacy law regimes outside Australia and Japan — Singapore's PDPA (5.5M population, major financial hub) and India's DPDP Act (1.4B population, one of the world's fastest-growing digital markets).
Singapore PDPA Compliance Checker (117th generator)
The Singapore PDPA was enacted in 2012 and significantly strengthened by the PDPA Amendment Act 2020 — adding mandatory breach notification, compulsory DPO appointment, deemed consent exceptions, and increased penalties (up to SGD 1M or 10% of annual local turnover for larger organisations). The Singapore PDPA Compliance Checker covers 42 key obligations across six categories:
- Data Protection Obligations (PDPA Part III–IV): Consent (voluntary, specific, not bundled), purpose limitation (specified before collection), notification (DPO contact, purposes, withdrawal right), accuracy obligation, protection obligation (reasonable security), retention limitation (automated deletion), transfer limitation (overseas contracts requiring comparable protection)
- Access, Correction & Withdrawal Rights (PDPA Part V): 30-day access request response, correction right with third-party disclosure, consent withdrawal processing, opt-out from direct marketing, Do Not Call (DNC) Registry checks before telemarketing, request intake process, reasonable fee policy for excessive requests
- Data Breach Notification (PDPA Sections 26C–26D): 30-day breach assessment, 3-business-day PDPC notification for notifiable breaches, individual notification for significant harm breaches, mandatory criteria determination (significant harm / 500+ individuals), breach log, data intermediary notification chain, annual breach response testing
- Accountability & Governance (PDPA Part IIA): DPO appointment and authority, DPO contact published on website, Data Protection Policy documentation, staff PDPA training and records, data inventory / mapping, DPIA for high-risk processing, data intermediary contracts with PDPA-compliant clauses
- Deemed Consent & Legitimate Interests (PDPA 2020 Amendment): Deemed consent by conduct (business improvement), deemed consent by contractual necessity, legitimate interests assessment (three-part test: purpose, necessity, balancing), applicable exceptions documentation, publicly available data assessment, withdrawal impact disclosure, exception usage review
- NRIC / NAS Data & Special Categories (PDPC Advisory Guidelines): NRIC/FIN collection only when legally required or clearly necessary (post-2024 revised PDPC position), NRIC masking and encryption, health and medical data enhanced protection, children's data with parental consent, financial data with PCI DSS alignment, biometric data with explicit consent, criminal record data legal basis
Who it's for: Singapore-incorporated companies; MNCs with Singapore operations; financial institutions subject to MAS regulation alongside PDPA; healthcare providers; e-commerce and SaaS platforms serving Singapore users; DPOs conducting internal audits; legal and compliance teams preparing for PDPC inspections or advisory reviews.
India DPDP Act Compliance Checklist (118th generator)
India's Digital Personal Data Protection Act 2023 — the first standalone data protection law in one of the world's largest digital markets — introduces Data Fiduciary obligations, Significant Data Fiduciary designation, strict children's data rules, and penalties up to ₹250 crore per violation. The India DPDP Act Compliance Checklist covers 42 key obligations across six categories:
- Lawful Processing & Consent (DPDP Act Chapter II): Valid consent (free, specific, informed, unconditional, unambiguous via clear affirmative action), itemised consent notice (English + Eighth Schedule language on request), Consent Manager registration if applicable, deemed consent / legitimate use basis documentation, verifiable parental consent for children, consent withdrawal without friction, consent records maintenance
- Data Principal Rights (DPDP Act Chapter III): Right to information (processing summary on request), right to correction and erasure (within Rules timeframe), right to grievance redressal (48-hour response), right to nominate (death/incapacity delegation), accessible rights request channel, grievance officer details published, proportionate authentication for requests
- Data Fiduciary Obligations (DPDP Act Sections 8–12): Purpose limitation (no secondary use), data minimisation (collect only what's necessary), accuracy obligation, storage limitation with automated erasure, security safeguards (reasonable technical and organisational measures), breach notification to DPBI and data principals, data processor contracts with fiduciary instruction binding
- Significant Data Fiduciary Obligations (DPDP Act Section 10): SDF designation criteria monitoring, India-resident DPO appointment with Board accountability, periodic DPIA for high-risk processing, algorithmic accountability review, children's age-gating and verifiable parental consent, no targeted advertising or behavioural monitoring of children, independent data audit at Board-prescribed intervals
- Cross-Border Data Transfers (DPDP Act Section 16 & Rules): Permitted country whitelist compliance, data localisation monitoring for notified categories, overseas recipient contracts (DPDP-equivalent obligations), data processor contracts with instruction binding and sub-processor controls, cross-border flow inventory, enhanced safeguards for sensitive data transfers, overseas government access request process
- Governance & Data Protection Board Compliance (DPDP Act Chapter V–VI): Named accountability owner/team, DPDP-compliant privacy notice in English (+ Eighth Schedule language option), comprehensive data processor contracts, Data Protection Board engagement process, penalty risk management (up to ₹250 crore), DPDP Rules and notification monitoring, internal DPDP training programme
Who it's for: Indian startups and companies; MNCs with India operations; foreign companies processing Indian personal data; fintech and financial services companies subject to both DPDP and RBI/SEBI frameworks; healthcare and edtech platforms with large Indian user bases; legal and compliance teams preparing for DPBI scrutiny; investors conducting DPDP due diligence on Indian portfolio companies.
Browse all 118 generators
All 118 free compliance generators are at /generate. No account required. Covers GDPR, CCPA, SOC 2, HIPAA, ISO 27001/27701, EU AI Act (GPAI + High-Risk), NIS2, DORA, PSD2/PSD3, FCA Consumer Duty, CSRD, CRA, NIST CSF 2.0, NIST AI RMF, NIST SP 800-53 Rev 5, CMMC 2.0, Digital Markets Act, EU Data Governance Act, EU Data Act, ePrivacy, AI Fairness, SOC 2 Trust Services Criteria, US State Privacy Laws, APRA CPS 230, APRA CPS 234, Singapore PDPA, India DPDP Act, and more.