DPDP Audits: Who Gets Audited and What Is Checked
The mandatory audit reaches fewer organisations than expected, and goes further than expected for those it reaches.
Who is in scope
The mandatory audit applies to Significant Data Fiduciaries. Section 10(2)(b) requires appointment of an independent data auditor to evaluate compliance, and Rule 13(1) sets the cycle at once every twelve months from the date of notification.
If you have not been notified, there is no mandatory DPDP audit. That does not mean no assessment is worthwhile, only that none is compelled.
What the cycle covers
- A Data Protection Impact Assessment, which section 10(2)(c)(i) describes as a process comprising a description of the rights of Data Principals and the purpose of processing, and assessment and management of risk to those rights.
- An audit to ensure effective observance of the Act and the rules.
- Algorithmic due diligence under Rule 13(3), verifying that technical measures including algorithmic software used for hosting, display, upload, modification, publishing, transmission, storage, updating or sharing of personal data are not likely to pose a risk to Data Principals' rights.
- Localisation under Rule 13(4), ensuring personal data specified by the Central Government, and the traffic data on its flow, is not transferred outside India.
Independence is the constraint
Section 10(2)(b) requires an independent data auditor. An internal team assessing its own controls does not meet that, and neither, arguably, does the firm that implemented them.
If you are not an SDF
A voluntary assessment against Rule 6 is still the most useful thing you can do, because it carries the largest penalty head and it is a concrete list. You just do it on your own timetable, and the output stays yours.
For a Significant Data Fiduciary the twelve month clock starts at notification, not when you feel ready. A first assessment on systems that were never mapped takes longer than twelve months suggests.
Infosek Team
Common questions
Who must undergo a DPDP audit?
A Significant Data Fiduciary. Under Rule 13(1) it must undertake a Data Protection Impact Assessment and an audit once every twelve months from the date it is notified as such, and under section 10(2)(b) it must appoint an independent data auditor.
Do audit findings go to the regulator?
Yes. Rule 13(2) requires the Significant Data Fiduciary to cause the person carrying out the Data Protection Impact Assessment and audit to furnish to the Board a report containing significant observations.
Preparing for an audit cycle?
Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.
Book Free 30-Min Assessment