AMLEGALS — Strategic Lawyering
DPDPA compliance · Independent audit

Independent data audit under DPDPA: who needs one, what it covers and how the report reaches the Board

Section 10 of the DPDPA requires every Significant Data Fiduciary to appoint an independent data auditor. Rule 13 prescribes the audit cycle, the scope and the reporting obligation to the Data Protection Board. This guide maps each step.

Updated · Checked against the DPDP Act, 2023 and the DPDP Rules, 2025 · 6 min read

A gold-accented magnifying glass hovering over a data-flow diagram with compliance checkmarks, set against a dark navy background
Short answer

Under Section 10(2) of the Digital Personal Data Protection Act, 2023, a Data Fiduciary notified as a Significant Data Fiduciary must appoint an independent data auditor to evaluate its compliance with the Act. Rule 13 of the DPDP Rules, 2025 requires the Significant Data Fiduciary to carry out a data protection impact assessment and an audit at least once every twelve months. The person who carries out the assessment and the audit must submit a report of the significant observations to the Data Protection Board. The auditor must be independent of the Significant Data Fiduciary. The Act does not create a panel or registration scheme for auditors; it requires independence.

  • Independent data audit
  • Section 10
  • Rule 13
  • Significant Data Fiduciary
  • DPDP Rules 2025
  • Data Protection Board
  • Annual audit cycle
Who must have one
Every Data Fiduciary notified as a Significant Data Fiduciary under Section 10(1)
Legal basis
Section 10(2) of the DPDPA and Rule 13 of the DPDP Rules, 2025
Frequency
At least once every twelve months (Rule 13)
Report goes to
The Data Protection Board, submitted by the person who carried out the audit

Who must appoint an independent data auditor

Section 10(1) allows the Central Government to notify any Data Fiduciary, or any class of Data Fiduciaries, as a Significant Data Fiduciary. The notification considers factors including the volume and sensitivity of the personal data processed and the risk to the rights of Data Principals.

Once notified, the Significant Data Fiduciary must appoint a Data Protection Officer based in India (Section 10(2)(a)), appoint an independent data auditor (Section 10(2)(b)), carry out periodic data protection impact assessments (Section 10(2)(c)), carry out periodic audits (Section 10(2)(d)), and take other measures as may be prescribed (Section 10(2)(e)).

The duty is on the Significant Data Fiduciary. No other class of Data Fiduciary is required by the Act to appoint an independent data auditor, although any organisation may choose to have one.

What independence means in the Act

The Act uses the term "independent data auditor" but does not define independence or prescribe qualifications. Independence means the auditor is not part of the Significant Data Fiduciary’s management and does not have a conflict of interest that would impair objectivity.

There is no government-maintained panel, licence or registration scheme for independent data auditors under the DPDPA. The Significant Data Fiduciary selects the auditor and must be able to show that the person is independent.

What the audit covers

Section 10(2)(b) says the auditor evaluates the Significant Data Fiduciary’s compliance with the provisions of the Act. Rule 13 adds the data protection impact assessment. In practice, the audit tests every duty that applies to the organisation:

  • Notice and consent (Section 5, Section 6, Rule 3): whether every Data Principal received an itemised notice before or at the time personal data was collected, and whether consent is free, specific, informed, unconditional and unambiguous.
  • Legitimate uses (Section 7): whether processing without consent is limited to the purposes listed in Section 7.
  • General duties (Section 8): security safeguards (Section 8(5), Rule 6), breach notification (Section 8(6), Rule 7), retention and erasure (Section 8(7), Rule 8), accuracy and completeness (Section 8(3)).
  • Children’s data (Section 9, Rule 10): age verification and verifiable parental consent.
  • Additional SDF duties (Section 10, Rule 13): DPO, DPIA, audit, and due diligence on algorithmic software that may affect Data Principals.
  • Rights of Data Principals (Sections 11–14, Rule 14): access, correction, erasure, grievance redressal within prescribed timelines.
  • Transfers outside India (Section 16, Rule 15): whether data is transferred only to countries not restricted by the Central Government.

The annual cycle under Rule 13

Rule 13 requires a data protection impact assessment and an audit at least once every twelve months. The person who carries them out must submit a report of the significant observations to the Data Protection Board.

  1. 01

    Scope and plan

    The Significant Data Fiduciary defines the scope: all processing activities or the activities with the highest risk, and selects an independent data auditor.

  2. 02

    Evidence collection

    The auditor collects evidence: consent logs, notices, processor contracts, security configurations, breach exercise records, rights-request logs, retention schedules, erasure records, transfer records and DPIA reports.

  3. 03

    Testing

    Each duty is tested against the evidence. Findings are rated by gap severity, the penalty ceiling under the Schedule and the effort to remediate.

  4. 04

    Report to the Board

    The person who carried out the assessment and the audit submits a report of the significant observations to the Data Protection Board (Rule 13).

  5. 05

    Remediation

    The Significant Data Fiduciary closes gaps in priority order, updates the evidence index, and the cycle repeats within twelve months.

The data protection impact assessment alongside the audit

Rule 13 links the DPIA and the audit: both must happen at least once every twelve months, and the same person submits the report to the Board. A DPIA identifies risks to the rights of Data Principals before they materialise. An audit checks whether the controls already in place are working.

The two exercises share evidence. Running them together avoids duplicate requests to business teams and produces a single report for the Board.

The penalty ceiling for failing to comply

The Schedule to the Act prescribes a penalty of up to ₹150 crore for breach of the additional obligations of a Significant Data Fiduciary under Section 10. This covers, among other things, the failure to appoint an independent data auditor, the failure to carry out a periodic audit and the failure to submit the report to the Board.

The Board decides the actual penalty after an inquiry, having regard to the factors in Section 33(2): the nature, gravity and duration of the breach, the type and nature of personal data affected, the repetitive nature of the breach, and whether the person took steps to mitigate.

How AMLEGALS conducts the independent data audit

AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder & Managing Partner. The team includes Rohit Lalwani, Associate Partner, who works on DPDPA compliance.

To scope an audit, the team needs your sector, your SDF notification status, the approximate number of Data Principals, your main systems and processors, and the date of the last audit if any.

Questions and answers

Independent Data Audit: common questions

Is an independent data audit mandatory under the DPDPA?

Yes, but only for a Significant Data Fiduciary. Section 10(2) requires the appointment of an independent data auditor, and Rule 13 requires the audit at least once every twelve months. Other Data Fiduciaries are not required by the Act to have an independent data audit.

Who qualifies as an independent data auditor under DPDPA?

The Act does not prescribe qualifications or maintain a panel. The auditor must be independent of the Significant Data Fiduciary. The organisation selects the auditor and must be able to show that the person has no conflict of interest.

How often must the audit be done?

At least once every twelve months (Rule 13 of the DPDP Rules, 2025). The data protection impact assessment follows the same cycle.

What happens to the audit report?

The person who carries out the data protection impact assessment and the audit submits a report of the significant observations to the Data Protection Board (Rule 13).

What is the penalty for not having the audit?

Up to ₹150 crore for breach of the additional obligations of a Significant Data Fiduciary under Section 10, as determined by the Board after inquiry having regard to Section 33(2) factors.

Can the same person carry out the DPIA and the audit?

Yes. Rule 13 refers to the person who carries out the data protection impact assessment and the audit, and requires that person to submit a single report to the Board.

Contact

Scope an independent data audit for your organisation

Share your SDF notification status, sector and the systems in scope. The AMLEGALS data privacy team will outline the approach and timeline.

Or write to [email protected]

Your details

Name and email are enough to start. The reply comes from [email protected].

Your information is handled in accordance with our privacy obligations. No spam, ever.

Independent Data Audit: questions and answers

What is the legal framework for data protection in India?

India's framework is the Digital Personal Data Protection Act, 2023 (Presidential assent 11 August 2023; 44 sections) read with the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 (G.S.R. 846(E)) with 23 Rules and 7 Schedules.

When do DPDPA obligations apply to businesses?

The Act and Rules follow phased commencement. Institutional provisions commenced on 13 November 2025; Consent Manager provisions commence after 12 months on 13 November 2026; and the principal Data Fiduciary, rights, breach, security and enforcement provisions commence after 18 months on 13 May 2027.

What is the maximum penalty under DPDPA?

Highest listed maximum for a specified contravention: ₹250 crore under the Schedule to the Act. Penalties are imposed by the Data Protection Board of India after an inquiry, and Section 33(2) requires the Board to consider factors such as the nature, gravity and duration of the breach, the type of personal data affected, repetition, mitigation steps and proportionality.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to Independent Data Audit?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on Independent Data Audit under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on Independent Data Audit under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on Independent Data Audit?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for Independent Data Audit rather than a generic checklist.

How do I get a first view of my DPDPA exposure on Independent Data Audit?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about Independent Data Audit · DPDPA Exposure Assessment