A DPDP audit tests whether an organisation's actual practice — not just its policies — meets the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025. The checklist below reflects the areas covered in a DPDP Audits engagement, which maps 67 controls across 21 sections of the Act. Use it as a self-assessment before an independent audit.
How to use this checklist
For each question, ask what evidence would prove the answer: a screenshot of the consent screen, an export of access logs, a signed processor contract, a closed DSAR ticket. A policy that says something happens is not evidence that it does.
Applicability and data inventory
- Is there a current inventory of personal data by system, purpose and owner?
- Are all Data Processors (vendors, cloud, SaaS) identified and under contract?
- Has the organisation assessed whether it may be notified as a Significant Data Fiduciary?
Notice and consent (Sections 5 and 6)
- Does every collection point show a standalone notice with an itemised list of data and purposes?
- Is consent free, specific, informed, unconditional and unambiguous, with a clear affirmative action?
- Can consent be withdrawn as easily as it was given, and is withdrawal honoured downstream?
- Is there an auditable record of when and how each consent was obtained?
Legitimate uses (Section 7)
- Where processing relies on a legitimate use instead of consent, is the basis documented?
Data Fiduciary obligations (Section 8)
- Is personal data accurate and complete where it is used for decisions or shared?
- Are retention periods defined, and is data erased when the purpose is served?
- Is a contact person (or DPO) published for data protection queries?
Security safeguards (Section 8(5))
- Is personal data encrypted, masked or tokenised at rest and in transit?
- Are access rights role-based, reviewed periodically and revoked on exit?
- Are access logs kept for at least one year and actually monitored?
- Do processor contracts require equivalent safeguards?
Breach management (Section 8(6))
- Is there a tested incident response plan covering Board and Data Principal notification?
- Can the organisation produce a detailed breach report within 72 hours?
Children's data (Section 9)
- Is age identified at onboarding, and is verifiable parental consent obtained for under-18s?
- Are tracking, behavioural monitoring and targeted advertising aimed at children blocked?
Data Principal rights (Sections 11–14)
- Can individuals request access, correction, completion and erasure through a published channel?
- Are requests logged, tracked and closed within the prescribed timeline?
- Is there a grievance redressal mechanism, and a nomination facility?
Cross-border transfers (Section 16)
- Is every transfer of personal data outside India identified, with destination and recipient?
- Are transfers checked against any country restrictions notified by the Government?
Consent Managers (Rules)
- If a Consent Manager is used, is it registered and are integrations documented?
What an independent audit adds
Self-assessment finds the obvious gaps. An independent auditor tests evidence against each control, records deviations with a chain of custody, and gives you a prioritised remediation roadmap signed off by a CISA-certified professional — the kind of record that stands up if the Data Protection Board ever asks questions.
For the timeline these controls must meet, read DPDP Rules 2025 explained.
