Readiness assessment
HomeDPDP Templates & DownloadsDPDP Consent Audit Workbook
Free DPDP audit workbook · XLSX

DPDP Consent Audit Workbook: 42 Controls & Evidence Tests

Audit DPDP consent end to end across notice, consent, proof, withdrawal, systems, Processors and retention. Get the free Excel workbook and run a practical internal review.

DPDP-Consent-Audit-Workbook.xlsx
42 Core Controls Sheet 02
Control IDClassificationAudit questionResult
NTC-05StatutoryDo sampled flows satisfy each Section 6(1) element?Not Tested
EVD-01StatutoryCan sampled records reconstruct notice and consent?Not Tested
WDR-04StatutoryDoes a test withdrawal stop the affected processing?Not Tested
SYS-05Good practiceDo restoration and migration tests preserve state?Not Tested
Withdrawal Test Log Sheet 06
Test IDPurpose WithdrawnSystems AffectedResult
WT-001Marketing emailCRM, ESPPass
WT-002RetargetingAd platformFail
WT-003Product analyticsWarehouseNot Tested

Test whether a withdrawal actually stops the processing it should.

Findings & Remediation Sheet 08
FindingControlSeverityStatus
F-01WDR-04CriticalOpen
F-02PRC-02HighIn progress
F-03NTC-02MediumOpen

Turn observations into owned actions with severity and status.

Executive Summary Sheet 09
Finding lensCountGap lensCount
Pass-Statutory-readiness-
Partial-Evidence gaps-
Fail-Operational-control-

Counts, not a score. No single compliance percentage.

Core Controls Withdrawal Log Findings Summary
42 controls across the full consent lifecycle
Evidence, withdrawal and Processor test logs
Findings and remediation tracking
No fabricated compliance score
FREE XLSX

Get the free workbook

Free XLSX · instant download
Download the Workbook (Free XLSX)
Direct download, no sign-up required. Internal self-assessment aid, not certification or legal advice.
Free XLSX · no payment required · internal self-assessment aid · not certification or legal opinion
Beyond a checklist

More than a DPDP consent checklist

A basic checklist asks whether you have consent. A useful audit asks whether you can prove the consent, test withdrawal, trace affected systems, coordinate Data Processors and document what must be remediated.

Legal duty Audit control Evidence Test result Remediation
The workbook separates legal requirements from implementation methods. Evidence examples such as logs, screenshots, system records or workflow tickets are audit evidence options, unless the law expressly prescribes otherwise.
What's inside

What's inside the 42-control audit workbook

01

Audit Scope

Define entity, product, processing purposes, systems, channels and Data Processors.

02

42 Core Consent Controls

Audit controls across the full consent lifecycle, each with its own classification.

03

Conditional Modules

Extra controls for children data, marketing and ad-tech, AI/ML, RBI lending and Rule 8 retention.

04

Evidence Register

Record the artefacts relied on when assessing each control.

05

Withdrawal Test Log

Test whether withdrawal actually causes the affected processing to stop.

06

Data Processor Test Log

Test contract, cessation and erasure capability across relevant Processors.

07

Findings & Remediation

Turn audit observations into owned remediation actions with targets and status.

08

Executive Summary

See Pass, Partial and Fail counts and gap categories, without a fabricated score.

09

Legal Source Mapping

Understand the underlying duty separately from the implementation control.

Coverage

Nine audit domains, end to end

The 42 controls group across nine domains that follow the consent lifecycle, from governance through to testing and remediation.

Governance & Scope Lawful Basis & Purpose Notice & Consent Experience Consent Evidence & Proof Withdrawal & Preference Execution Systems & Data-flow Propagation Data Processor Controls Retention, Erasure & Suppression Testing, Monitoring & Remediation
Sample controls

Real controls from the workbook

A representative set, spanning classifications. Not every control is a statutory requirement, and the workbook keeps that distinction explicit.

NTC-05Valid consent outcomeStatutory

Audit question: Do sampled flows satisfy each Section 6(1) element?

EVD-02Consent record reconstructionImplementation control

Audit question: Do records allow practical reconstruction without relying on unsupported assumptions?

PRC-02Processor cessation capabilityStatutory

Audit question: Can the organisation direct and verify cessation for sampled Processor activity?

SYS-05Backup and migration resilienceGood practice

Audit question: Do restoration and migration tests preserve the withdrawal state?

No vanity score

No "82% DPDP compliant" score

The workbook deliberately does not convert dozens of controls into a single compliance percentage. A critical failure may matter far more than several successful controls. Instead, it lets teams identify:

Statutory-readiness gaps Rules-readiness gaps Regulatory-interaction gaps Evidence gaps Operational-control gaps Good-practice improvements
Who it's for

Built for the people who make consent work

Privacy, compliance, audit and the teams whose systems consent actually touches.

Privacy / DPO Compliance / GRC Internal Audit Legal Product & Engineering Marketing Operations Vendor / Procurement Consultants / vDPOs
Two ways to audit

Workbook or the online tool?

Online consent audit

Assess interactively

Explore the method and run an initial audit in the browser, control by control, with a live finding snapshot.

Excel audit workbook

Take it into your organisation

Run the complete framework across teams, collect evidence, log withdrawal and Processor tests, and track remediation to closure.

FAQ

Questions about the workbook

Is the DPDP Consent Audit Workbook free?

Yes. It is available as a free XLSX download after submitting the short download form.

What format is the workbook?

A Microsoft Excel-compatible XLSX file that you can edit and share internally.

Does the workbook certify DPDP compliance?

No. It is an internal audit and self-assessment aid. It does not provide legal certification or a compliance guarantee.

Are all 42 controls statutory requirements?

No. The workbook distinguishes statutory outcomes, Rules requirements, regulatory interactions, implementation controls and good practices.

Who should use this workbook?

Privacy, DPO, compliance, legal, audit, security, product and marketing teams responsible for DPDP consent operations.

Can consultants use it?

Yes. It works as a structured starting point for client reviews, and it does not itself constitute legal advice or certification.

Primary sources

Legal status and sources

Legal authority for the controls comes from official sources. These are the sources the workbook relies on.

The workbook is an internal audit and self-assessment aid. It is not certification, a compliance score or legal advice. Most substantive DPDP consent duties become operational on 13 May 2027.

Take the audit into your organisation

Move from policy statements to testable consent controls, with the evidence and remediation structure to back them up.

Get the Free Audit Workbook