Who must appoint an independent data auditor
Section 10(1) allows the Central Government to notify any Data Fiduciary, or any class of Data Fiduciaries, as a Significant Data Fiduciary. The notification considers factors including the volume and sensitivity of the personal data processed and the risk to the rights of Data Principals.
Once notified, the Significant Data Fiduciary must appoint a Data Protection Officer based in India (Section 10(2)(a)), appoint an independent data auditor (Section 10(2)(b)), carry out periodic data protection impact assessments (Section 10(2)(c)), carry out periodic audits (Section 10(2)(d)), and take other measures as may be prescribed (Section 10(2)(e)).
The duty is on the Significant Data Fiduciary. No other class of Data Fiduciary is required by the Act to appoint an independent data auditor, although any organisation may choose to have one.
What independence means in the Act
The Act uses the term "independent data auditor" but does not define independence or prescribe qualifications. Independence means the auditor is not part of the Significant Data Fiduciary’s management and does not have a conflict of interest that would impair objectivity.
There is no government-maintained panel, licence or registration scheme for independent data auditors under the DPDPA. The Significant Data Fiduciary selects the auditor and must be able to show that the person is independent.
What the audit covers
Section 10(2)(b) says the auditor evaluates the Significant Data Fiduciary’s compliance with the provisions of the Act. Rule 13 adds the data protection impact assessment. In practice, the audit tests every duty that applies to the organisation:
- Notice and consent (Section 5, Section 6, Rule 3): whether every Data Principal received an itemised notice before or at the time personal data was collected, and whether consent is free, specific, informed, unconditional and unambiguous.
- Legitimate uses (Section 7): whether processing without consent is limited to the purposes listed in Section 7.
- General duties (Section 8): security safeguards (Section 8(5), Rule 6), breach notification (Section 8(6), Rule 7), retention and erasure (Section 8(7), Rule 8), accuracy and completeness (Section 8(3)).
- Children’s data (Section 9, Rule 10): age verification and verifiable parental consent.
- Additional SDF duties (Section 10, Rule 13): DPO, DPIA, audit, and due diligence on algorithmic software that may affect Data Principals.
- Rights of Data Principals (Sections 11–14, Rule 14): access, correction, erasure, grievance redressal within prescribed timelines.
- Transfers outside India (Section 16, Rule 15): whether data is transferred only to countries not restricted by the Central Government.
The annual cycle under Rule 13
Rule 13 requires a data protection impact assessment and an audit at least once every twelve months. The person who carries them out must submit a report of the significant observations to the Data Protection Board.
- 01
Scope and plan
The Significant Data Fiduciary defines the scope: all processing activities or the activities with the highest risk, and selects an independent data auditor.
- 02
Evidence collection
The auditor collects evidence: consent logs, notices, processor contracts, security configurations, breach exercise records, rights-request logs, retention schedules, erasure records, transfer records and DPIA reports.
- 03
Testing
Each duty is tested against the evidence. Findings are rated by gap severity, the penalty ceiling under the Schedule and the effort to remediate.
- 04
Report to the Board
The person who carried out the assessment and the audit submits a report of the significant observations to the Data Protection Board (Rule 13).
- 05
Remediation
The Significant Data Fiduciary closes gaps in priority order, updates the evidence index, and the cycle repeats within twelve months.
The data protection impact assessment alongside the audit
Rule 13 links the DPIA and the audit: both must happen at least once every twelve months, and the same person submits the report to the Board. A DPIA identifies risks to the rights of Data Principals before they materialise. An audit checks whether the controls already in place are working.
The two exercises share evidence. Running them together avoids duplicate requests to business teams and produces a single report for the Board.
The penalty ceiling for failing to comply
The Schedule to the Act prescribes a penalty of up to ₹150 crore for breach of the additional obligations of a Significant Data Fiduciary under Section 10. This covers, among other things, the failure to appoint an independent data auditor, the failure to carry out a periodic audit and the failure to submit the report to the Board.
The Board decides the actual penalty after an inquiry, having regard to the factors in Section 33(2): the nature, gravity and duration of the breach, the type and nature of personal data affected, the repetitive nature of the breach, and whether the person took steps to mitigate.
How AMLEGALS conducts the independent data audit
AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder & Managing Partner. The team includes Rohit Lalwani, Associate Partner, who works on DPDPA compliance.
To scope an audit, the team needs your sector, your SDF notification status, the approximate number of Data Principals, your main systems and processors, and the date of the last audit if any.

