Ch IPreliminary
S.1 Short title and commencementS.2 DefinitionsS.3 Application and scopeCh IIObligations of Data Fiduciary
S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data FiduciaryCh IIIRights and duties of Data Principal
S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data PrincipalCh IVSpecial provisions
S.16 Transfer outside IndiaS.17 ExemptionsCh VData Protection Board of India
S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the ChairpersonCh VIBoard powers and procedure
S.27 Powers and functions of the BoardS.28 Procedure followed by the BoardCh VIIAppeal and dispute resolution
S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertakingCh VIIIPenalties
S.33 Penalties and the ScheduleS.34 Penalties to Consolidated FundCh IXMiscellaneous
S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other ActsDPDP Privacy Audit · India
A DPDP privacy audit is an independent review of whether the controls you have built for the DPDP Act, 2023 and the DPDP Rules, 2025 operate in practice. It tests notices, consent, rights handling, retention, vendor contracts, security safeguards and breach readiness against evidence, and reports what needs fixing.
Partner-driven, not a one-size-fits-all consultancy. We scope the audit first, then match you with an independent specialist partner only when you ask, so you buy the review you need and nothing more.
Last updated 4 October 2026 · Based on the DPDP Act, 2023 and the DPDP Rules, 2025 · Editorial policy
Why a business needs it
Most organisations that prepare for the DPDP Act write notices, add consent screens and sign vendor terms. Few check afterwards whether the notice matches what is collected, whether a withdrawal of consent reaches every system, or whether a rights request can be answered in time. An audit answers that with evidence, before a Data Principal complaint, a vendor incident or a Board inquiry answers it for you.
Definition
A DPDP privacy audit is a structured, evidence-based review of whether an organisation’s processing of digital personal data follows the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, and whether the controls it relies on operate as designed. It samples real records, systems and processes, then reports findings that management can act on.
The Act does not set out a general audit procedure. Section 10(2) and Rule 13 describe the audit duty of a Significant Data Fiduciary. For everyone else, an audit is a voluntary assurance step that helps show the reasonable security safeguards and responsibility the Act expects under Section 8.
Is it required?
The duty depends on whether you are notified as a Significant Data Fiduciary under Section 10. We found no provision in the Act or the Rules that requires an audit for a Data Fiduciary that is not one.
| Provision | What it says in practice | Status |
|---|---|---|
| Section 10(2)(b) | A Significant Data Fiduciary must appoint an independent data auditor to evaluate its compliance | Statutory SDF only |
| Section 10(2)(c) | A Significant Data Fiduciary must carry out periodic Data Protection Impact Assessments and periodic audits | Statutory SDF only |
| Rule 13(1) | Once in every period of twelve months from notification as a Significant Data Fiduciary, undertake a DPIA and an audit | Rule SDF only |
| Rule 13(2) | The person carrying out the DPIA and audit gives the Board a report with significant observations | Rule SDF only |
| Section 8(1) and 8(5) | The Data Fiduciary is responsible for compliance and must take reasonable security safeguards. An audit is one way to show this, not a stated requirement | Statutory All Data Fiduciaries |
By the numbers
What the Act and Rules say, and what they do not.
Audit coverage
Eight areas an auditor typically tests, with the evidence they ask for. Use it as a self-check before you commission one. Scope is always agreed up front.
SECTION 5
Tests: notice matches real collection and purposes. Evidence: live notices, collection forms, data map.
SECTION 6
Tests: consent is specific, withdrawable and acted on. Evidence: consent logs, withdrawal tickets, vendor stop proof.
SECTION 9
Tests: verifiable parental consent where children are served. Evidence: age and consent flow, sign-up samples.
SECTIONS 11 TO 14
Tests: requests answered fully and on time. Evidence: request log, sampled cases, grievance records.
SECTION 8(7)
Tests: data erased when the purpose ends, in every copy. Evidence: retention schedule, deletion logs, backup handling.
SECTION 8(2)
Tests: contracts exist and match practice. Evidence: vendor list, signed terms, access reviews.
S.8(5), RULE 6
Tests: reasonable safeguards operate, not only exist. Evidence: access controls, encryption, logs, test reports.
S.8(6), RULE 7
Tests: detection, escalation and notification work. Evidence: incident plan, breach register, drill results.
Need the evidence in one place? Start with our free worksheets or the Compliance Toolkit. We found no official Government template for an audit report.
Who needs it
One group has a legal duty. The others choose it for assurance.
If you have not yet built the controls, start with a DPDP compliance assessment instead. An audit is most useful once there is something running to test.
When to do it
Sections 18 to 26 commenced, establishing the Data Protection Board framework.
Run a first audit once notices, consent, rights, retention and vendor controls are live, so findings can be fixed before the duties commence.
Section 8 and Rules 6 and 7 commence, as does Rule 13 for any Significant Data Fiduciary.
For a Significant Data Fiduciary, the twelve-month cycle in Rule 13(1) runs from the date of notification. For other organisations there is no prescribed cycle. Many choose to repeat the review each year and after a major system, vendor or business change. That is a choice, not a rule.
What the engagement involves
The exact method is set by the auditor. This is the sequence most engagements follow.
Fix the entities, systems, processes and period covered, and the DPDP provisions the audit will test against.
Gather policies, notices, consent records, contracts, logs and your data map and RoPA for review.
Sample real records, trace data through systems, check vendors and interview the people who run each control.
Rate each finding by risk, tie it to the provision involved and agree factual accuracy with management.
Work through the fix list, then retest the controls that failed, if the scope includes follow-up.
Deliverables
Depending on scope, outputs may include:
What a result looks like
An illustrative extract, not a real client result. Each control is rated, tied to a provision and given a fix.
| Control tested | What the auditor did | Result | Risk |
|---|---|---|---|
| Privacy notice (S.5) | Compared the notice with 10 live collection forms | Partly operating | Medium |
| Consent withdrawal (S.6) | Traced 15 withdrawals to CRM and email vendor | Not operating | High |
| Access requests (S.11) | Sampled 20 requests from the log | Operating | Low |
| Retention (S.8(7)) | Checked deletion in production, exports and backups | Partly operating | Medium |
| Processor terms (S.8(2)) | Reviewed contracts for 12 vendors | Partly operating | Medium |
| Breach plan (S.8(6)) | Ran a tabletop exercise with the response team | Not operating | High |
What the provider needs from you
Having these to hand shortens the scoping step and makes quotes easier to compare.
No data map yet? That is a finding in itself, and a good reason to begin with data mapping. Our free worksheets help you gather several of these inputs.
Scope and complexity
Providers set their own fees. We do not publish prices, because scope drives them. These are the factors that move an audit from light to extended.
| Factor | Lighter scope | Extended scope |
|---|---|---|
| Entities and locations | One entity, one location | Several entities, group companies or multiple states |
| Systems | A handful of core tools | Many systems, legacy platforms, unmanaged SaaS |
| Vendors | Few processors with standard terms | Many processors, sub-processors and cross-border flows |
| Data sensitivity and volume | Limited customer or employee data | Large volumes, financial, health or children’s data |
| Legal duty | Voluntary assurance | Significant Data Fiduciary with a report to the Board |
| Documentation | Data map, RoPA and policies in place | Little documentation, so evidence must be reconstructed |
| Depth of testing | Document and process review | Technical testing, sampling at scale and retest |
Where it fits
An audit works best as the fourth step, once there is something running to test.
Test whether those controls work, with evidence. You are here.
Fix findings, retest and keep the controls running.
Know the difference
Three different tools, often confused. The descriptions below reflect common practice; only the audit and DPIA for Significant Data Fiduciaries are defined as duties in the Act and Rules.
| Compliance assessment | Privacy audit | DPIA | |
|---|---|---|---|
| Main question | Where are our gaps against the DPDP Act? | Do the controls we built actually work? | What risks does this processing create for Data Principals? |
| Looks at | Current state against requirements | Evidence that controls operate | A specific processing activity |
| Typically done | Before or during build | After controls are running | Before and during a high-risk activity |
| Independence | Helpful | Central to the value | Depends on the context |
| Legal duty | None found | Significant Data Fiduciaries only | Significant Data Fiduciaries only |
| Our page | DPDP Compliance Assessment | This page | See the FAQ below |
Partner-driven delivery
DPDPActIndia is a partner-driven platform. We don’t audit your organisation ourselves and we don’t sell a one-size-fits-all package. We define the audit first and then, only when you ask, match you with an independent specialist partner suited to your sector and systems.
STEP 1
Tell us about your organisation, or start with the free assessment.
STEP 2
We turn it into a defined brief covering scope, evidence and depth.
STEP 3
We identify auditors with no stake in building your controls.
STEP 4
You stay in control of whether to work with any provider introduced.
Choosing a provider
Ask these questions of any auditor, whether introduced by us or found elsewhere.
We found no prescribed qualification or empanelment scheme for the independent data auditor in the Act or the Rules as notified. Check for any later notification before you appoint.
Not sure?
Tell us about your organisation and we’ll help you identify whether this workstream is relevant and what type of specialist you may need. There is no obligation, and you decide whether to go further.
Coming next: a short requirements check that maps your answers to the DPDP workstreams that matter for you, such as data mapping, vendor review and consent review. Until it launches, the free assessment is the quickest way to see where you stand.
Avoid these
By sector
Systems, vendors and regulators differ by sector. See what the DPDP Act means for yours.
Questions
Sources
This page is educational and is not legal advice. Confirm against the enacted Act and Rules, or take professional advice.
Ten minutes now shows which areas need attention first, including whether an audit is the right next step.
Related services
Consultant-led and partner-backed.