Twelve episodes of foundations — the countdown, the constitutional history, the cast of characters, the exemptions, the penalties, the regulator, the state's wide lane. Today, theory faces you. Nine questions about your own organisation, each answerable in a minute, each revealing something the foundations arc taught — and by the end, you'll hold what organisations pay consultants lakhs to produce and still don't get straight: an honest picture of your starting line. The nine, scored green, amber or red as things are — not as they're planned: Do we actually know which of our data is digital personal data under this Act? For each data relationship, do we know which character we're playing? Could we produce a current record of what we hold, where, why and with whom it's shared? Can we name the lawful basis behind each processing activity? If a customer demanded access, correction or erasure tomorrow, could we execute? If data leaked tonight, do named people know their roles on the two clocks? Does every vendor touching our data operate under a proper contract? Is there one named human accountable for DPDP compliance? And if the Board asked us to demonstrate our efforts, what could we physically produce today? Then the tally guidance for each profile — and a worked example from advisory work: a two-hundred-person consumer services firm scoring two green, four amber, three red, why that profile is roughly the median serious Indian mid-market company in 2026, and how its first three moves wrote themselves. Why progress in compliance is rarely dramatic — it's ambers eating reds, quarter after quarter. Plus the habit that turns thirty minutes into a governance instrument: date the scorecard, re-score quarterly, file it in the evidence trail. The foundations are laid. Tomorrow, a new arc opens: the Act itself, section by section — beginning with Section 4, the two lawful bases, and the story of why India deliberately refused the "legitimate interest" ground the rest of the world relies on. DPDP Daily takes India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 out of the statute book and into real life — for compliance officers, lawyers, founders, small business owners and citizens. One practical episode every day, no jargon. I'm Harmeet Singh Kapoor, author of the DPDP Act Compliance Handbook: From Law to Ground Reality. Keywords: DPDP self-assessment, DPDP gap assessment, compliance checklist, data mapping, RoPA, lawful basis, breach readiness, vendor contracts, DPDP compliance owner, data protection audit India. Connect with me:💼 LinkedIn: https://www.linkedin.com/in/hskapoor/📄 Facebook: https://www.facebook.com/satarkintelligence▶️ YouTube: https://www.youtube.com/@DPDPdaily🎙️ Apple Podcasts: https://podcasts.apple.com/us/podcast/dpdp-daily/id6793257111𝕏 X: https://x.com/TheOtherKapoor One practical DPDP insight every morning on LinkedIn, Facebook and X — and the DPDP Act Compliance Handbook: From Law to Ground Reality coming soon. This episode is educational commentary, not legal advice. The DPDP framework is in phased implementation and positions described may evolve through notifications, Board publications and judicial interpretation. For decisions affecting your organisation or your rights, consult a qualified professional with your specific facts.