DPDP Audits

DPDP Audit Checklist: What an Auditor Will Test

A practical DPDP Act 2023 audit checklist covering notice, consent, security safeguards, breach response, data principal rights, children's data and cross-border transfers.

By Ram Krishan Dudeja, CISA CAIIB · Last reviewed 25 September 2026

A DPDP audit tests whether an organisation's actual practice — not just its policies — meets the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025. The checklist below reflects the areas covered in a DPDP Audits engagement, which maps 67 controls across 21 sections of the Act. Use it as a self-assessment before an independent audit.

How to use this checklist

For each question, ask what evidence would prove the answer: a screenshot of the consent screen, an export of access logs, a signed processor contract, a closed DSAR ticket. A policy that says something happens is not evidence that it does.

Applicability and data inventory

  • Is there a current inventory of personal data by system, purpose and owner?
  • Are all Data Processors (vendors, cloud, SaaS) identified and under contract?
  • Has the organisation assessed whether it may be notified as a Significant Data Fiduciary?

Notice and consent (Sections 5 and 6)

  • Does every collection point show a standalone notice with an itemised list of data and purposes?
  • Is consent free, specific, informed, unconditional and unambiguous, with a clear affirmative action?
  • Can consent be withdrawn as easily as it was given, and is withdrawal honoured downstream?
  • Is there an auditable record of when and how each consent was obtained?

Legitimate uses (Section 7)

  • Where processing relies on a legitimate use instead of consent, is the basis documented?

Data Fiduciary obligations (Section 8)

  • Is personal data accurate and complete where it is used for decisions or shared?
  • Are retention periods defined, and is data erased when the purpose is served?
  • Is a contact person (or DPO) published for data protection queries?

Security safeguards (Section 8(5))

  • Is personal data encrypted, masked or tokenised at rest and in transit?
  • Are access rights role-based, reviewed periodically and revoked on exit?
  • Are access logs kept for at least one year and actually monitored?
  • Do processor contracts require equivalent safeguards?

Breach management (Section 8(6))

  • Is there a tested incident response plan covering Board and Data Principal notification?
  • Can the organisation produce a detailed breach report within 72 hours?

Children's data (Section 9)

  • Is age identified at onboarding, and is verifiable parental consent obtained for under-18s?
  • Are tracking, behavioural monitoring and targeted advertising aimed at children blocked?

Data Principal rights (Sections 11–14)

  • Can individuals request access, correction, completion and erasure through a published channel?
  • Are requests logged, tracked and closed within the prescribed timeline?
  • Is there a grievance redressal mechanism, and a nomination facility?

Cross-border transfers (Section 16)

  • Is every transfer of personal data outside India identified, with destination and recipient?
  • Are transfers checked against any country restrictions notified by the Government?

Consent Managers (Rules)

  • If a Consent Manager is used, is it registered and are integrations documented?

What an independent audit adds

Self-assessment finds the obvious gaps. An independent auditor tests evidence against each control, records deviations with a chain of custody, and gives you a prioritised remediation roadmap signed off by a CISA-certified professional — the kind of record that stands up if the Data Protection Board ever asks questions.

For the timeline these controls must meet, read DPDP Rules 2025 explained.

Need an independent DPDP audit?

67 controls, auditor-signed findings, and a remediation roadmap you can act on.

Book a Free Consultation

Related guides

This guide is general information, not legal advice. Refer to the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025 as notified for the authoritative text.