Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment

DPDP Privacy Audit · India

DPDP Privacy Audit Services: Check Whether Your Data Protection Controls Actually Work

A DPDP privacy audit is an independent review of whether the controls you have built for the DPDP Act, 2023 and the DPDP Rules, 2025 operate in practice. It tests notices, consent, rights handling, retention, vendor contracts, security safeguards and breach readiness against evidence, and reports what needs fixing.

Partner-driven, not a one-size-fits-all consultancy. We scope the audit first, then match you with an independent specialist partner only when you ask, so you buy the review you need and nothing more.

Privacy audit: controls you built are tested and produce findings Notices, consent, rights requests, retention and vendor terms are tested by an independent audit using evidence, interviews and testing. The audit produces findings, risk ratings, a fix list and a retest. CONTROLS YOU BUILT WHAT YOU GET NoticesConsentRights requestsRetentionVendor terms Independentaudit FindingsRisk ratingsFix listRetest EvidenceInterviewsTestingReport Controls tested against evidence, not just policies
ForCompliance, legal, IT and security leads
ScopeNotices to breach readiness, with evidence
OutputAudit report, risk ratings and fix list
DeliveryIndependent specialist partners matched to your scope
Statutory statusMandatory for Significant Data Fiduciaries; otherwise voluntary

DPDP privacy audit in short

What it is
An independent check that the controls you built for the DPDP Act work as intended, tested against documents, system evidence and interviews.
Is it required?
Yes for a Significant Data Fiduciary: an independent data auditor under Section 10(2)(b) and an audit once every twelve months under Rule 13(1). We found no such requirement for other Data Fiduciaries.
What you get
An audit report, risk-rated findings, a prioritised fix list and, where agreed, a retest.
Who does the work
An independent auditor. DPDPActIndia scopes the audit and matches specialist partners on request. You decide whether to proceed.
When
After your controls are built and running, and for a Significant Data Fiduciary, as the Rule 13 duty commences on 13 May 2027.

Last updated 4 October 2026 · Based on the DPDP Act, 2023 and the DPDP Rules, 2025 · Editorial policy

Why a business needs it

A policy on paper is not a control that works.

Most organisations that prepare for the DPDP Act write notices, add consent screens and sign vendor terms. Few check afterwards whether the notice matches what is collected, whether a withdrawal of consent reaches every system, or whether a rights request can be answered in time. An audit answers that with evidence, before a Data Principal complaint, a vendor incident or a Board inquiry answers it for you.

What an audit tends to find

  • Notices that no longer match the data actually collected
  • Consent withdrawal that stops marketing but not the vendors behind it
  • Erasure that misses exports, backups and shared drives
  • Vendor contracts that were signed but never checked against practice
  • A breach plan that nobody has rehearsed

Definition

What is a DPDP privacy audit?

A DPDP privacy audit is a structured, evidence-based review of whether an organisation’s processing of digital personal data follows the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, and whether the controls it relies on operate as designed. It samples real records, systems and processes, then reports findings that management can act on.

At a glance

  • Also called: DPDP compliance audit, privacy compliance review, data protection audit
  • Typical owner: compliance, legal or the DPO, with IT and security
  • Main output: audit report with risk-rated findings
  • Legal status: mandatory for Significant Data Fiduciaries only
  • Builds on: your data map and RoPA

Is it required?

When the DPDP Act requires an audit, and when it does not.

The duty depends on whether you are notified as a Significant Data Fiduciary under Section 10. We found no provision in the Act or the Rules that requires an audit for a Data Fiduciary that is not one.

ProvisionWhat it says in practiceStatus
Section 10(2)(b)A Significant Data Fiduciary must appoint an independent data auditor to evaluate its complianceStatutory SDF only
Section 10(2)(c)A Significant Data Fiduciary must carry out periodic Data Protection Impact Assessments and periodic auditsStatutory SDF only
Rule 13(1)Once in every period of twelve months from notification as a Significant Data Fiduciary, undertake a DPIA and an auditRule SDF only
Rule 13(2)The person carrying out the DPIA and audit gives the Board a report with significant observationsRule SDF only
Section 8(1) and 8(5)The Data Fiduciary is responsible for compliance and must take reasonable security safeguards. An audit is one way to show this, not a stated requirementStatutory All Data Fiduciaries
A Significant Data Fiduciary is designated by Central Government notification, based on factors such as the volume and sensitivity of personal data processed and the risk to Data Principals. It is not something an organisation declares for itself. See Significant Data Fiduciary.

By the numbers

The DPDP audit duty in four facts.

What the Act and Rules say, and what they do not.

12 monthsLongest gap between audits for a Significant Data Fiduciary, counted from notification (Rule 13(1))
13 May 2027Date Rule 13 commences, along with Section 8 and Rules 6 and 7
0Audit duties we found for a Data Fiduciary that is not a Significant Data Fiduciary
Rs 250 croreCeiling for failing to take reasonable security safeguards. The Board sets any penalty case by case, so it is not a fixed fine

Audit coverage

What does a DPDP privacy audit cover?

Eight areas an auditor typically tests, with the evidence they ask for. Use it as a self-check before you commission one. Scope is always agreed up front.

SECTION 5

Notice

Tests: notice matches real collection and purposes. Evidence: live notices, collection forms, data map.

SECTION 6

Consent

Tests: consent is specific, withdrawable and acted on. Evidence: consent logs, withdrawal tickets, vendor stop proof.

SECTION 9

Children’s data

Tests: verifiable parental consent where children are served. Evidence: age and consent flow, sign-up samples.

SECTIONS 11 TO 14

Rights and grievances

Tests: requests answered fully and on time. Evidence: request log, sampled cases, grievance records.

SECTION 8(7)

Retention and erasure

Tests: data erased when the purpose ends, in every copy. Evidence: retention schedule, deletion logs, backup handling.

SECTION 8(2)

Vendors and processors

Tests: contracts exist and match practice. Evidence: vendor list, signed terms, access reviews.

S.8(5), RULE 6

Security safeguards

Tests: reasonable safeguards operate, not only exist. Evidence: access controls, encryption, logs, test reports.

S.8(6), RULE 7

Breach readiness

Tests: detection, escalation and notification work. Evidence: incident plan, breach register, drill results.

Need the evidence in one place? Start with our free worksheets or the Compliance Toolkit. We found no official Government template for an audit report.

Who needs it

Who should commission a DPDP privacy audit?

One group has a legal duty. The others choose it for assurance.

Required: Significant Data Fiduciaries

  • Organisations notified by the Central Government as Significant Data Fiduciaries
  • Audit by an independent data auditor, once in every twelve months from notification
  • Report of significant observations to the Board

Sensible: other Data Fiduciaries

  • Organisations that have built notices, consent and rights processes and want proof they work
  • Businesses that rely on many vendors or process large volumes of customer data
  • Companies answering customer, investor or partner due-diligence questions about data protection
  • Groups that have grown through acquisitions or added new products and systems

If you have not yet built the controls, start with a DPDP compliance assessment instead. An audit is most useful once there is something running to test.

When to do it

Timing a DPDP privacy audit.

13 Nov 2025

Board framework

Sections 18 to 26 commenced, establishing the Data Protection Board framework.

Before 13 May 2027

Build, then test

Run a first audit once notices, consent, rights, retention and vendor controls are live, so findings can be fixed before the duties commence.

13 May 2027

Main duties commence

Section 8 and Rules 6 and 7 commence, as does Rule 13 for any Significant Data Fiduciary.

What the engagement involves

How a DPDP privacy audit runs, step by step.

The exact method is set by the auditor. This is the sequence most engagements follow.

1

Agree scope and criteria

Fix the entities, systems, processes and period covered, and the DPDP provisions the audit will test against.

2

Collect evidence

Gather policies, notices, consent records, contracts, logs and your data map and RoPA for review.

3

Test the controls

Sample real records, trace data through systems, check vendors and interview the people who run each control.

4

Report findings

Rate each finding by risk, tie it to the provision involved and agree factual accuracy with management.

5

Fix and retest

Work through the fix list, then retest the controls that failed, if the scope includes follow-up.

Deliverables

What you should receive.

Depending on scope, outputs may include:

  • Audit scope, criteria and method statement
  • Findings register tied to the DPDP provision involved
  • Risk rating for each finding
  • Control-by-control result: operating, partly operating or not operating
  • Prioritised remediation plan with owners
  • Management summary for leadership
  • Report in a form that can be shared with the Board, where the duty applies
  • Retest results for items that were fixed

What a result looks like

What does a privacy audit result look like?

An illustrative extract, not a real client result. Each control is rated, tied to a provision and given a fix.

Control testedWhat the auditor didResultRisk
Privacy notice (S.5)Compared the notice with 10 live collection formsPartly operatingMedium
Consent withdrawal (S.6)Traced 15 withdrawals to CRM and email vendorNot operatingHigh
Access requests (S.11)Sampled 20 requests from the logOperatingLow
Retention (S.8(7))Checked deletion in production, exports and backupsPartly operatingMedium
Processor terms (S.8(2))Reviewed contracts for 12 vendorsPartly operatingMedium
Breach plan (S.8(6))Ran a tabletop exercise with the response teamNot operatingHigh

What the provider needs from you

Information to have ready.

Having these to hand shortens the scoping step and makes quotes easier to compare.

About your organisation

  • Legal entities, locations and business lines in scope
  • Approximate volume and types of personal data, including any children’s data
  • Whether you have been notified as a Significant Data Fiduciary
  • Sector regulators and other frameworks you already follow
  • Who owns data protection today, including any DPO

Documents and systems

  • Privacy notices, consent screens and consent records
  • Data map, inventory or RoPA, if you have one
  • Vendor list and processor contracts
  • Rights request log, retention schedule and breach register
  • Security policies, access controls and recent assessment reports

No data map yet? That is a finding in itself, and a good reason to begin with data mapping. Our free worksheets help you gather several of these inputs.

Scope and complexity

What makes one audit bigger than another.

Providers set their own fees. We do not publish prices, because scope drives them. These are the factors that move an audit from light to extended.

FactorLighter scopeExtended scope
Entities and locationsOne entity, one locationSeveral entities, group companies or multiple states
SystemsA handful of core toolsMany systems, legacy platforms, unmanaged SaaS
VendorsFew processors with standard termsMany processors, sub-processors and cross-border flows
Data sensitivity and volumeLimited customer or employee dataLarge volumes, financial, health or children’s data
Legal dutyVoluntary assuranceSignificant Data Fiduciary with a report to the Board
DocumentationData map, RoPA and policies in placeLittle documentation, so evidence must be reconstructed
Depth of testingDocument and process reviewTechnical testing, sampling at scale and retest

Where it fits

Where does a privacy audit fit in your DPDP journey?

An audit works best as the fourth step, once there is something running to test.

1

Assess

Find your gaps against the Act and Rules.

2

Map

Record your data, flows and vendors, then your RoPA.

3

Build

Put notices, consent, rights, retention and vendor terms in place.

4

Audit

Test whether those controls work, with evidence. You are here.

5

Operate

Fix findings, retest and keep the controls running.

Know the difference

Privacy audit vs compliance assessment vs DPIA.

Three different tools, often confused. The descriptions below reflect common practice; only the audit and DPIA for Significant Data Fiduciaries are defined as duties in the Act and Rules.

Compliance assessmentPrivacy auditDPIA
Main questionWhere are our gaps against the DPDP Act?Do the controls we built actually work?What risks does this processing create for Data Principals?
Looks atCurrent state against requirementsEvidence that controls operateA specific processing activity
Typically doneBefore or during buildAfter controls are runningBefore and during a high-risk activity
IndependenceHelpfulCentral to the valueDepends on the context
Legal dutyNone foundSignificant Data Fiduciaries onlySignificant Data Fiduciaries only
Our pageDPDP Compliance AssessmentThis pageSee the FAQ below

Partner-driven delivery

We scope it. Independent specialists deliver it. You decide.

DPDPActIndia is a partner-driven platform. We don’t audit your organisation ourselves and we don’t sell a one-size-fits-all package. We define the audit first and then, only when you ask, match you with an independent specialist partner suited to your sector and systems.

STEP 1

You describe the need

Tell us about your organisation, or start with the free assessment.

STEP 2

We scope the audit

We turn it into a defined brief covering scope, evidence and depth.

STEP 3

We match an independent partner

We identify auditors with no stake in building your controls.

STEP 4

You decide whether to proceed

You stay in control of whether to work with any provider introduced.

Which specialist for which part

  • Legal compliance against the Act and Rules: privacy and legal specialist
  • Security safeguards and technical testing: cybersecurity specialist
  • Process, records and governance review: audit and risk specialist
  • Ongoing ownership of findings or a DPO appointment: appropriate DPO specialist via DPOIndia
We may work with specialist service and technology providers depending on the requirement. Organisations remain free to decide whether to proceed with any provider introduced through the platform. Looking for one now? Find your DPDP Act implementation partner.

Choosing a provider

How to select the right audit provider.

Ask these questions of any auditor, whether introduced by us or found elsewhere.

  • Independence: the auditor did not design or run the controls being tested. This matters most where Section 10(2)(b) applies (see data auditor)
  • DPDP depth: they can map findings to specific provisions of the Act and Rules, not only to a generic privacy framework
  • Method: they explain how they sample, what evidence they accept and how they rate risk
  • Sector experience: they know the systems and regulators in your industry
  • Technical reach: they can test security safeguards or bring a partner who can
  • Clear scope and output: the quote states entities, systems, depth, report format and whether a retest is included
  • Conflicts and confidentiality: they disclose other work for you and handle your records under a written agreement

We found no prescribed qualification or empanelment scheme for the independent data auditor in the Act or the Rules as notified. Check for any later notification before you appoint.

Not sure?

Not sure whether you need a privacy audit?

Tell us about your organisation and we’ll help you identify whether this workstream is relevant and what type of specialist you may need. There is no obligation, and you decide whether to go further.

What the check looks at

  • Whether you may be, or could become, a Significant Data Fiduciary
  • Whether your controls are live enough to test
  • How many systems, vendors and entities are involved
  • What documentation already exists

Coming next: a short requirements check that maps your answers to the DPDP workstreams that matter for you, such as data mapping, vendor review and consent review. Until it launches, the free assessment is the quickest way to see where you stand.

Avoid these

Common privacy audit mistakes.

  • Auditing before any controls exist, which only produces a list of what is missing
  • Asking the team that built the controls to audit them
  • Reviewing policies only, without sampling real records and systems
  • Leaving vendors and sub-processors out of scope
  • Treating the report as the finish line instead of fixing and retesting
  • Assuming an audit report is a certificate of compliance

By sector

Privacy audits by sector.

Systems, vendors and regulators differ by sector. See what the DPDP Act means for yours.

Questions

Frequently asked questions about DPDP privacy audits.

What is a DPDP privacy audit?
A DPDP privacy audit is an independent, evidence-based review of whether an organisation processes digital personal data in line with the DPDP Act, 2023 and the DPDP Rules, 2025, and whether its controls operate as designed. It samples real records and systems and reports risk-rated findings.
Is a privacy audit mandatory under the DPDP Act?
It is mandatory for a Significant Data Fiduciary. Section 10(2) requires an independent data auditor and periodic audits, and Rule 13(1) requires a Data Protection Impact Assessment and an audit once in every period of twelve months from notification. We found no provision in the Act or the Rules that requires an audit for a Data Fiduciary that is not a Significant Data Fiduciary.
Is there a deadline to fix DPDP audit findings?
We found no provision in Section 10 or Rule 13 that sets a fixed number of days to fix audit findings, or that requires a Data Protection Officer to report non-compliances within a set period. Some online summaries quote periods such as 30 or 15 days; we could not trace these to the Act or the Rules, so treat them as unverified. Agree remediation timelines with your auditor based on risk.
What penalty applies if we do not have a privacy audit?
For a Data Fiduciary that is not a Significant Data Fiduciary we found no audit duty, so no penalty for not having one. The Schedule to the Act sets a maximum penalty of Rs 250 crore for failing to take reasonable security safeguards, and a Significant Data Fiduciary that skips its Section 10 duties may face the Board inquiry and penalty process. Confirm exact penalties with counsel.
Who is a Significant Data Fiduciary?
A Data Fiduciary, or a class of them, notified as such by the Central Government under Section 10, having regard to factors such as the volume and sensitivity of personal data processed and the risk to Data Principals. An organisation does not declare itself one.
What is the difference between a privacy audit and a DPDP compliance assessment?
A compliance assessment is a gap diagnostic: it compares where you are with what the Act requires, usually before or during implementation. An audit is a verification step: it tests whether the controls you have built operate in practice, with evidence. Most organisations do the assessment first and the audit later.
What is the difference between a privacy audit and a DPIA?
A Data Protection Impact Assessment looks at the risks that a specific processing activity creates for Data Principals. An audit looks at whether the organisation as a whole follows the Act and whether its controls work. For a Significant Data Fiduciary, Rule 13(1) requires both, once in every twelve months.
Who can be an independent data auditor?
Section 10(2)(b) requires the auditor to be independent. We did not find a prescribed list of qualifications or an empanelment scheme in the Act or the Rules as notified, so check for any later notification. In practice, look for an auditor who did not design or run the controls, has DPDP-specific knowledge and can explain their method.
How often should we run a privacy audit?
A Significant Data Fiduciary must do so once in every twelve months from notification (Rule 13(1)). For others there is no prescribed frequency. Many organisations choose an annual review and an extra one after a major system, vendor or business change. That is a choice, not a legal rule.
What are the types of DPDP audit?
The Act does not define audit types. In practice there are internal audits by your own team, independent external audits by a third party, the statutory audit by an independent data auditor that Section 10(2)(b) requires of a Significant Data Fiduciary, and vendor audits that test a processor against your contract.
Is there a DPDP audit template?
Use the eight areas covered on this page as a starting point. Our free worksheets and Compliance Toolkit help you gather the evidence. We found no official Government template for an audit report. For a Significant Data Fiduciary, the report to the Board contains significant observations under Rule 13(2).
What documents does an auditor need?
Typically your privacy notices, consent records, data map or RoPA, vendor list and processor contracts, rights request log, retention schedule, breach register, security policies and recent assessment reports. If some do not exist, the auditor records that as a finding.
How long does a privacy audit take and what does it cost?
Both depend on scope: the number of entities, systems and vendors, the sensitivity of the data, how much documentation exists and how deep the testing goes. Fees are set by providers and we do not publish prices. The scoping step produces a written brief you can use to compare quotes and timelines.
Can we audit ourselves with an internal team?
For an organisation that is not a Significant Data Fiduciary, an internal review is a reasonable first pass and the Act does not forbid it. Independence adds credibility, especially with customers, investors and regulators. A Significant Data Fiduciary must appoint an independent data auditor under Section 10(2)(b).
Does an audit report certify DPDP compliance?
No. We found no statutory DPDP certification scheme. An audit report is evidence that a review took place and what it found. It does not stop the Board from inquiring into a breach of the Act, and it is not a clearance from the Board.
What happens to the audit report?
For a Significant Data Fiduciary, Rule 13(2) requires the person carrying out the DPIA and audit to give the Board a report with significant observations. For others, the report stays with management unless you choose to share it.

Sources

Legal references used on this page.

This page is educational and is not legal advice. Confirm against the enacted Act and Rules, or take professional advice.

Start where you actually are.

Ten minutes now shows which areas need attention first, including whether an audit is the right next step.