What a DPDPA compliance audit is
A DPDPA compliance audit is a structured check of how an organisation processes personal data, measured against the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. For each duty it asks three questions: what does the organisation do, does it work in practice, and is there a record that shows it.
The terms gap assessment and readiness review are often used for the same exercise before a law applies. The method is the same: compare practice with each Section and Rule, and record the difference.
The Act and the Rules do not set up a certification scheme for DPDPA compliance. An audit report states the position on a date. It is not a certificate issued under the law, and it does not bind the Data Protection Board.
The 12 areas an audit checks and the evidence asked for
Each row lists an area, the provision it is tested against and the evidence an auditor usually asks to see. Evidence means records made at the time, such as logs, signed contracts and dated screenshots. A policy on its own shows intent, not practice.
| Area | Provision | Evidence asked for |
|---|---|---|
| Data map | Sections 4 to 8 | A register of personal data sets with purpose, lawful ground, systems, vendors, retention period and owner |
| Notice | Section 5; Rule 3 | Copies of each notice shown to people, with dates, and the languages offered |
| Consent and withdrawal | Section 6; Section 6(4) | Consent logs showing what was shown and what was chosen, and a test of withdrawal |
| Legitimate uses | Section 7 | A list of purposes processed without consent, with the clause of Section 7 relied on for each |
| Security safeguards | Section 8(5); Rule 6 | Access control lists, encryption settings, monitoring records, and logs kept for at least one year |
| Breach response | Section 8(6); Rule 7 | The breach plan, contact routes for the Board and affected people, and the record of the last exercise |
| Processors | Section 8(1) and 8(2) | A signed contract with each Data Processor and a current vendor register |
| Retention and erasure | Section 8(7); Rule 8 | A retention schedule, erasure records, and the law cited for any data kept longer than its purpose |
| Contact details | Rule 9 | Published business contact details of the Data Protection Officer or of the person who answers questions on processing |
| Rights and grievances | Sections 11 to 14; Rule 14 | The request log, response times, and grievances closed within 90 days at most |
| Children's data | Section 9; Rule 10 | How age is checked, and records of verifiable consent of a parent or lawful guardian |
| Transfers outside India | Section 16; Rule 15 | A list of each transfer outside India, with the destination, the recipient and the purpose |
If the organisation has been notified as a Significant Data Fiduciary, the audit also checks the duties in Section 10 and Rule 13: an India-based Data Protection Officer, an independent data auditor, a data protection impact assessment and an audit every 12 months, and due diligence on algorithmic software.
How each finding is rated
Each duty receives one of four ratings. The rating describes what the auditor saw, not what was planned.
- In place: the step is taken in practice and a record shows it.
- Partly in place: the step exists but does not cover every system, data set or vendor, or the record is incomplete.
- Not in place: the step is not taken, or there is no record that it is.
- Not applicable: the duty does not apply, for example Section 9 where no children's data is processed. The reason is written down.
Each gap is then rated on two scales. The first is the penalty ceiling it falls under in the Schedule to the Act: up to ₹250 crore for failing to take reasonable security safeguards, up to ₹200 crore for failing to notify a breach, up to ₹200 crore for the duties on children's data, up to ₹150 crore for the additional duties of a Significant Data Fiduciary, and up to ₹50 crore for other breaches of the Act or the Rules. The second is the effort needed to close it. Gaps with a high ceiling and low effort are usually closed first.
The Board decides the actual penalty after an inquiry, having regard to the factors in Section 33(2). The ceilings show which gaps the law treats as most serious. They are not a forecast of any penalty.
What the audit produces
An audit should leave documents that people keep using after it ends.
- A gap register: each finding with its provision, rating, penalty ceiling, effort and owner.
- A remediation plan: tasks in order, with owners and target dates before 13 May 2027.
- An evidence index: where the record for each duty is kept, so it can be produced if the Board asks.
- A short summary for the board of directors or management: the number of gaps by rating and the decisions that need their approval.
The evidence index matters because records are hard to recreate later. Under Section 33(2), the Board considers whether the organisation took steps to reduce the effects of a breach, and how quickly and how well it took them. Records made at the time are how those steps are shown.
How this differs from the audit a Significant Data Fiduciary must have
Under Section 10, the Central Government may notify a Data Fiduciary or a class of Data Fiduciaries as Significant Data Fiduciaries, considering factors such as the volume and sensitivity of the personal data processed and the risk to the rights of Data Principals.
A Significant Data Fiduciary must appoint an independent data auditor to evaluate its compliance with the Act (Section 10(2)). Rule 13 requires it to carry out a data protection impact assessment and an audit once every 12 months, and to have the person who carries them out give the Board a report of the significant observations.
For other Data Fiduciaries, the law sets no form, frequency or auditor for a voluntary audit. Following the same structure makes the move easier if the organisation is later notified as a Significant Data Fiduciary.
When to run it and how often
Before 13 May 2027, an audit is most useful early, because vendor contracts and system changes take the longest to complete. After that date it is repeated on a cycle and after any major change.
- Once before 13 May 2027, early enough to close the gaps it finds.
- After a new product, a new vendor that receives personal data, a new country of transfer, or a personal data breach.
- Every 12 months for a Significant Data Fiduciary, as Rule 13 requires. Other organisations can follow the same yearly cycle.
Who carries out the audit at AMLEGALS
AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder & Managing Partner. The team includes Rohit Lalwani, Associate Partner, who works on DPDPA compliance.
To scope an audit, the team needs your sector, your role (Data Fiduciary, Data Processor or both), the approximate number of people whose data you hold, your main systems and vendors, any children's data, any transfers outside India, and any past incident.

