AMLEGALS — Strategic Lawyering
DPDPA compliance · Audit

DPDPA compliance audit: what it checks, how it rates gaps and what it produces

How a DPDPA compliance audit works: the 12 areas it tests, the provision behind each one, the evidence it asks for, how each gap is rated and the documents it should leave behind.

Updated · Checked against the DPDP Act, 2023 and the DPDP Rules, 2025 · 8 min read

A brass magnifying glass over data-flow diagrams and a checklist with gold ticks, beside a laptop showing bar charts
Short answer

A DPDPA compliance audit compares what an organisation actually does with each duty in the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, and checks the evidence for each one. It covers the data map, notices and consent, security safeguards, breach response, processor contracts, retention, rights and grievances, children's data and transfers outside India. The output is a gap register that rates each gap by the penalty ceiling it falls under and the effort needed to close it, a plan with owners and dates, and an index of evidence. Only a Significant Data Fiduciary is required by law to have a periodic audit by an independent data auditor (Section 10 and Rule 13). For other organisations, an audit is a way to find gaps before the core duties apply on 13 May 2027.

  • DPDPA compliance audit
  • Gap assessment
  • Evidence of compliance
  • Section 10
  • Rule 13
  • Significant Data Fiduciary
  • Penalty ceilings
  • DPDP Rules 2025
Required by law for
Significant Data Fiduciaries: an audit by an independent data auditor, and an audit every 12 months (Section 10, Rule 13)
Useful for
Every Data Fiduciary preparing for 13 May 2027, when the core duties apply
Areas checked
12, from the data map to transfers outside India
Main output
A gap register rated by penalty ceiling and effort, with a plan and an evidence index

What a DPDPA compliance audit is

A DPDPA compliance audit is a structured check of how an organisation processes personal data, measured against the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. For each duty it asks three questions: what does the organisation do, does it work in practice, and is there a record that shows it.

The terms gap assessment and readiness review are often used for the same exercise before a law applies. The method is the same: compare practice with each Section and Rule, and record the difference.

The Act and the Rules do not set up a certification scheme for DPDPA compliance. An audit report states the position on a date. It is not a certificate issued under the law, and it does not bind the Data Protection Board.

The 12 areas an audit checks and the evidence asked for

Each row lists an area, the provision it is tested against and the evidence an auditor usually asks to see. Evidence means records made at the time, such as logs, signed contracts and dated screenshots. A policy on its own shows intent, not practice.

DPDPA audit areas mapped to provisions and evidence
AreaProvisionEvidence asked for
Data mapSections 4 to 8A register of personal data sets with purpose, lawful ground, systems, vendors, retention period and owner
NoticeSection 5; Rule 3Copies of each notice shown to people, with dates, and the languages offered
Consent and withdrawalSection 6; Section 6(4)Consent logs showing what was shown and what was chosen, and a test of withdrawal
Legitimate usesSection 7A list of purposes processed without consent, with the clause of Section 7 relied on for each
Security safeguardsSection 8(5); Rule 6Access control lists, encryption settings, monitoring records, and logs kept for at least one year
Breach responseSection 8(6); Rule 7The breach plan, contact routes for the Board and affected people, and the record of the last exercise
ProcessorsSection 8(1) and 8(2)A signed contract with each Data Processor and a current vendor register
Retention and erasureSection 8(7); Rule 8A retention schedule, erasure records, and the law cited for any data kept longer than its purpose
Contact detailsRule 9Published business contact details of the Data Protection Officer or of the person who answers questions on processing
Rights and grievancesSections 11 to 14; Rule 14The request log, response times, and grievances closed within 90 days at most
Children's dataSection 9; Rule 10How age is checked, and records of verifiable consent of a parent or lawful guardian
Transfers outside IndiaSection 16; Rule 15A list of each transfer outside India, with the destination, the recipient and the purpose

If the organisation has been notified as a Significant Data Fiduciary, the audit also checks the duties in Section 10 and Rule 13: an India-based Data Protection Officer, an independent data auditor, a data protection impact assessment and an audit every 12 months, and due diligence on algorithmic software.

How each finding is rated

Each duty receives one of four ratings. The rating describes what the auditor saw, not what was planned.

  • In place: the step is taken in practice and a record shows it.
  • Partly in place: the step exists but does not cover every system, data set or vendor, or the record is incomplete.
  • Not in place: the step is not taken, or there is no record that it is.
  • Not applicable: the duty does not apply, for example Section 9 where no children's data is processed. The reason is written down.

Each gap is then rated on two scales. The first is the penalty ceiling it falls under in the Schedule to the Act: up to ₹250 crore for failing to take reasonable security safeguards, up to ₹200 crore for failing to notify a breach, up to ₹200 crore for the duties on children's data, up to ₹150 crore for the additional duties of a Significant Data Fiduciary, and up to ₹50 crore for other breaches of the Act or the Rules. The second is the effort needed to close it. Gaps with a high ceiling and low effort are usually closed first.

The Board decides the actual penalty after an inquiry, having regard to the factors in Section 33(2). The ceilings show which gaps the law treats as most serious. They are not a forecast of any penalty.

What the audit produces

An audit should leave documents that people keep using after it ends.

  • A gap register: each finding with its provision, rating, penalty ceiling, effort and owner.
  • A remediation plan: tasks in order, with owners and target dates before 13 May 2027.
  • An evidence index: where the record for each duty is kept, so it can be produced if the Board asks.
  • A short summary for the board of directors or management: the number of gaps by rating and the decisions that need their approval.

The evidence index matters because records are hard to recreate later. Under Section 33(2), the Board considers whether the organisation took steps to reduce the effects of a breach, and how quickly and how well it took them. Records made at the time are how those steps are shown.

How this differs from the audit a Significant Data Fiduciary must have

Under Section 10, the Central Government may notify a Data Fiduciary or a class of Data Fiduciaries as Significant Data Fiduciaries, considering factors such as the volume and sensitivity of the personal data processed and the risk to the rights of Data Principals.

A Significant Data Fiduciary must appoint an independent data auditor to evaluate its compliance with the Act (Section 10(2)). Rule 13 requires it to carry out a data protection impact assessment and an audit once every 12 months, and to have the person who carries them out give the Board a report of the significant observations.

For other Data Fiduciaries, the law sets no form, frequency or auditor for a voluntary audit. Following the same structure makes the move easier if the organisation is later notified as a Significant Data Fiduciary.

When to run it and how often

Before 13 May 2027, an audit is most useful early, because vendor contracts and system changes take the longest to complete. After that date it is repeated on a cycle and after any major change.

  • Once before 13 May 2027, early enough to close the gaps it finds.
  • After a new product, a new vendor that receives personal data, a new country of transfer, or a personal data breach.
  • Every 12 months for a Significant Data Fiduciary, as Rule 13 requires. Other organisations can follow the same yearly cycle.

Who carries out the audit at AMLEGALS

AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder & Managing Partner. The team includes Rohit Lalwani, Associate Partner, who works on DPDPA compliance.

To scope an audit, the team needs your sector, your role (Data Fiduciary, Data Processor or both), the approximate number of people whose data you hold, your main systems and vendors, any children's data, any transfers outside India, and any past incident.

Questions and answers

DPDPA Compliance Audit: common questions

Is a DPDPA compliance audit mandatory?

Only for a Significant Data Fiduciary. Section 10 requires it to appoint an independent data auditor, and Rule 13 requires a data protection impact assessment and an audit every 12 months. For other Data Fiduciaries the law does not require an audit, but each one must still meet the duties an audit would test.

What is the difference between a DPDPA audit and a gap assessment?

They use the same method. A gap assessment is usually done before a law applies, to find what is missing. An audit is usually done once the duties apply, to test whether the steps work in practice. Both compare practice with each Section and Rule and record the evidence.

What evidence does a DPDPA audit ask for?

Records made at the time: consent logs, dated copies of notices, signed processor contracts, logs kept for at least one year (Rule 6), the breach plan and exercise records, the rights request log, retention schedules and erasure records.

Is there a DPDPA certification in India?

No. The Act and the DPDP Rules, 2025 do not set up a certification scheme. An audit report records the position on a date. It is not a certificate issued under the law.

Who can carry out a DPDPA audit?

For a Significant Data Fiduciary, the audit is carried out by an independent data auditor (Section 10). For other organisations, the law does not say who carries out a voluntary audit. It can be an internal team or an outside adviser.

How long does a DPDPA compliance audit take?

It depends on the number of systems, data sets and vendors in scope. Collecting evidence from vendors usually takes the longest. Listing the systems and vendors first gives a firmer timeline.

What happens after the audit?

The gap register becomes a remediation plan with owners and dates. Gaps under the higher penalty ceilings, such as security safeguards (up to ₹250 crore) and breach notification (up to ₹200 crore), are usually closed first. The evidence index is kept up to date so records can be produced if the Board asks.

Contact

Discuss the scope of a DPDPA compliance audit

Tell us your sector, your role (Data Fiduciary, Data Processor or both) and which systems you want covered. Your message goes to the AMLEGALS data privacy team.

Or write to [email protected]

Your details

Name and email are enough to start. The reply comes from [email protected].

Your information is handled in accordance with our privacy obligations. No spam, ever.

DPDPA Compliance Audit: questions and answers

What is the legal framework for data protection in India?

India's framework is the Digital Personal Data Protection Act, 2023 (Presidential assent 11 August 2023; 44 sections) read with the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 (G.S.R. 846(E)) with 23 Rules and 7 Schedules.

When do DPDPA obligations apply to businesses?

The Act and Rules follow phased commencement. Institutional provisions commenced on 13 November 2025; Consent Manager provisions commence after 12 months on 13 November 2026; and the principal Data Fiduciary, rights, breach, security and enforcement provisions commence after 18 months on 13 May 2027.

What is the maximum penalty under DPDPA?

Highest listed maximum for a specified contravention: ₹250 crore under the Schedule to the Act. Penalties are imposed by the Data Protection Board of India after an inquiry, and Section 33(2) requires the Board to consider factors such as the nature, gravity and duration of the breach, the type of personal data affected, repetition, mitigation steps and proportionality.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to DPDPA Compliance Audit?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on DPDPA Compliance Audit under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on DPDPA Compliance Audit under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on DPDPA Compliance Audit?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for DPDPA Compliance Audit rather than a generic checklist.

How do I get a first view of my DPDPA exposure on DPDPA Compliance Audit?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about DPDPA Compliance Audit · DPDPA Exposure Assessment