Ch IPreliminary
S.1 Short title and commencementS.2 DefinitionsS.3 Application and scopeCh IIObligations of Data Fiduciary
S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data FiduciaryCh IIIRights and duties of Data Principal
S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data PrincipalCh IVSpecial provisions
S.16 Transfer outside IndiaS.17 ExemptionsCh VData Protection Board of India
S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the ChairpersonCh VIBoard powers and procedure
S.27 Powers and functions of the BoardS.28 Procedure followed by the BoardCh VIIAppeal and dispute resolution
S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertakingCh VIIIPenalties
S.33 Penalties and the ScheduleS.34 Penalties to Consolidated FundCh IXMiscellaneous
S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other ActsRole
A data auditor is the independent auditor a Significant Data Fiduciary must appoint to evaluate its compliance with the Act.
TL;DR
A data auditor (Section 10(2)(b)) is the independent auditor a Significant Data Fiduciary must appoint to evaluate its compliance with the DPDP Act. The audit sits alongside the periodic Data Protection Impact Assessment, giving the Board and the fiduciary an evidenced view of compliance.
appoint an independent data auditor to carry out data audit, who shall evaluate the compliance of the Significant Data Fiduciary in accordance with the provisions of this Act.
The auditor is an external check. Section 10(2)(b) requires SDFs to appoint an independent data auditor to assess whether the organisation actually meets the Act's requirements.
This sits alongside the periodic Data Protection Impact Assessment and audit obligations, giving the Board and the fiduciary an evidenced view of compliance.
A notified SDF engages an independent auditor each year to review its consent flows, security and breach handling against the Act.
Who needs a data auditor?
Only Significant Data Fiduciaries, under Section 10(2)(b).
Must the auditor be independent?
Yes. The Act requires an independent data auditor.
Consultant-led and partner-backed.