See What a DPDP Data Breach Would Cost Your Startup
Simulate a realistic breach scenario. Understand the timeline, penalties, and what proof you'd need to survive.
Fintech scenario
Loan onboarding chatbot leaks PAN and Aadhaar to OpenAI
Unredacted KYC identifiers are sent to an overseas model provider without purpose-limited controls.
Estimated Fine
₹50-₹250 crore
Evidence basis
This Fintech scenario is selected from CrewCheck's DPDP breach library because it matches the data types and processor routes common to this sector. The penalty range is tied to the cited DPDP sections, while the proof list below shows the exact records a buyer, board, or Data Protection Board inquiry would expect.
Without Protection
T+0
Aadhaar + PAN leaked to an LLM API
T+72h
Data Protection Board notification clock expires
T+2 weeks
Inquiry notice asks for logs and safeguards
T+3 months
Penalty of ₹50–250 Cr becomes realistic
With CrewCheck
T-0
Prompt intercepted before provider transfer
T-0
Aadhaar + PAN redacted from payload
T-0
Audit event logged with rule and method
Result
Zero exposure. Regulator-ready trail.
Evidence Checklist
What the Data Protection Board would request.
| Board request | CrewCheck provides |
|---|---|
| Exact prompt that leaked | Original, redacted, and blocked prompt payload |
| Detection method | Regex, checksum, context, Hinglish, and rule metadata |
| When the team knew | Timestamped gateway decision and audit row |
| Safeguards in place | Policy pack, redaction mode, and provider route proof |
| Remediation timeline | Exportable compliance report and action history |