Skip to main content

Sources last verified on 20 August 2026. Methodology

Data protection audit under the DPDP Act: who must be audited and what the text requires

Compliance

By Abhijeet Singh · Reviewed by dpdprules.org source verificationPublished · Last reviewed 6 min read

The short answer

Only a Significant Data Fiduciary, meaning a Data Fiduciary or class notified by the Central Government under section 10, must be audited. Section 10(2)(b) requires it to appoint an independent data auditor who shall evaluate its compliance in accordance with the provisions of the Act, and section 10(2)(c) adds a periodic audit alongside the periodic Data Protection Impact Assessment. Rule 13 sets the cadence: a DPIA and an audit once in every period of 12 months from notification, with a report containing significant observations furnished to the Data Protection Board. No auditor qualifications, audit standard or report format has been prescribed. Section 10 and Rule 13 commence on the computed date of 13 May 2027, interpretation until officially confirmed, and no Significant Data Fiduciary has been notified as of 23 August 2026.

TL;DR infographic answering: Who needs a data protection audit under the DPDP Act and what must it cover?

Search for DPDPA audit requirements and much of what ranks is vendor content: accreditation regimes, audit frameworks, certification checklists, report templates, all presented as if the law prescribed them. The Gazette text is far sparser than that. This article states exactly what the DPDP Act 2023 and the DPDP Rules 2025 require of a data protection audit, quotes the operative words, and is explicit about what has not been prescribed, so you can tell a statutory duty from a seller's construction.

Who must be audited: only notified Significant Data Fiduciaries

The audit duty lives inside section 10, and section 10 applies only to a Significant Data Fiduciary: "any Data Fiduciary or class of Data Fiduciaries as may be notified by the Central Government under section 10", per the definition in section 2(z). There is no self assessment, no registration and no threshold you can compute for yourself. Either a notification covers you, or the statutory audit duty does not exist for you, whatever your scale.

As of 23 August 2026, no Data Fiduciary or class has been notified as significant, so no organisation in India currently carries the statutory data audit obligation. How notification works, and the two duties that arrive with the auditor, a board answerable Data Protection Officer and the DPIA, are covered in the Significant Data Fiduciary obligations guide.

One scoping fact worth stating precisely: for Data Fiduciaries, audit obligations appear in exactly two places in the framework, section 10 of the Act and Rule 13 of the Rules. The only other audit reference in either Gazette text is item 12 of Part B of the First Schedule, which requires a registered Consent Manager to maintain audit mechanisms and report outcomes to the Board. That is a separate registration regime and does not attach to Data Fiduciaries.

The independent data auditor in section 10(2)(b)

The appointment duty is one sentence:

Official requirement · verbatim

"appoint an independent data auditor to carry out data audit, who shall evaluate the compliance of the Significant Data Fiduciary in accordance with the provisions of this Act"

Section 10(2)(b) of the DPDP Act 2023.

The sentence asks for two things at once. Independence: the auditor cannot be the function marking its own homework. And a yardstick: the evaluation is measured against the provisions of the Act itself, not against an internal policy, a certification scheme or an industry framework. Everything else about the auditor, who qualifies, how independence is tested, whether a firm or an individual, is left unsaid.

The periodic audit in section 10(2)(c)

Section 10(2)(c) then requires the Significant Data Fiduciary to undertake a "periodic Data Protection Impact Assessment", a "periodic audit", and such other measures as may be prescribed. For the audit, that is the entire statutory content: two words, with the cadence left to the Rules. The DPIA in the same clause gets a fuller statutory definition, which is unpacked in DPIA under the DPDP Act.

What Rule 13 adds: a 12 month clock and a report to the Board

Rule 13 of the DPDP Rules 2025 turns "periodic" into a schedule and gives the audit its one mandated output.

The cycle. Rule 13(1) requires the Significant Data Fiduciary, "once in every period of 12 months from the date on which it is notified as such or is included in the class of Data Fiduciaries notified as such", to undertake a Data Protection Impact Assessment and an audit "to ensure effective observance of the provisions of this Act and the rules made thereunder". The clock starts at notification, not at a financial year end, and the audit travels together with the DPIA as one annual exercise aimed at the whole framework.

The report. Rule 13(2) requires the Significant Data Fiduciary to cause "the person carrying out the Data Protection Impact Assessment and audit to furnish to the Board a report containing significant observations". The findings do not stay internal: the Data Protection Board of India receives the significant observations every cycle, as a matter of course, with no residual risk filter.

Rule 13 also carries two neighbouring duties on the same tier, algorithmic due diligence under Rule 13(3) and a conditional localisation restriction under Rule 13(4), covered in the Significant Data Fiduciary obligations guide.

How the audit differs from the DPIA

The two duties share a clock and a report but are not the same exercise. The audit evaluates compliance: did the organisation observe the Act and the Rules. The DPIA is a defined process aimed at people: a description of the rights of Data Principals, the purpose of processing, and assessment and management of the risk to those rights. The express independence requirement in section 10(2)(b) attaches to the auditor; the Act does not say who conducts the DPIA. One textual detail: Rule 13(2) speaks of "the person carrying out the Data Protection Impact Assessment and audit" in the singular, which reads naturally as one appointee running both, but the Rules never state expressly that this person must be the section 10(2)(b) auditor. That reading is interpretation, not text.

What the text fixes, and what it leaves open

RequirementSourceWhat the text saysWhat is not prescribed
Independent data auditorSection 10(2)(b)Appoint an independent data auditor to carry out data audit, who shall evaluate compliance in accordance with the provisions of the ActWho may act as auditor, any qualification or accreditation, how independence is tested
Periodic auditSection 10(2)(c)(ii)The words "periodic audit", with cadence left to the RulesScope, method, any named audit standard
12 month cycleRule 13(1)A DPIA and an audit once in every period of 12 months from notification, to ensure effective observance of the Act and the rulesAudit standard, methodology, checklist or evidence requirements
Report to the BoardRule 13(2)The person carrying out the DPIA and audit furnishes to the Board a report containing significant observationsReport format or template, filing timeline, definition of significant observations

The honest gap statement, then: as of 23 August 2026 there is no auditor accreditation regime, no empanelment list, no named audit standard, no prescribed methodology and no report template anywhere in the Act or the Rules. Section 10(2)(c)(iii) leaves a hook for "such other measures, consistent with the provisions of this Act, as may be prescribed", but the only prescription so far is Rule 13, and Rule 13 fixes cadence and reporting, not method. Any product that presents a specific framework, certification or report format as a DPDPA legal requirement is selling its own construction.

When the duty starts, and what a breach costs

Notification G.S.R. 843(E) places section 10 in the group that comes into force 18 months from publication of the commencement gazette, and Rule 1(4) places Rule 13 in the matching 18 month group of the Rules. Both compute to 13 May 2027, which is interpretation until officially confirmed. Even after that date, the duty reaches only organisations the Central Government has notified. The stakes once it does: the Act's Schedule pairs breach of the section 10 obligations with a penalty that may extend to 150 crore rupees.

How to prepare, offered as recommendation

Nothing below is a statutory audit requirement; the Act and Rules prescribe no preparation file. It is this site's recommendation, built from the yardstick the auditor must use: compliance "in accordance with the provisions of this Act". An evaluation against the Act will ask for evidence of the duties you already carry, so the cheapest preparation is keeping that evidence as you go:

  • a record of processing: what personal data you hold, each purpose, and the ground behind it
  • the notice and consent artefacts behind your consent based processing
  • contracts with every Data Processor, since section 8(2) permits engaging one for any activity related to offering of goods or services to Data Principals only under a valid contract
  • a breach register holding each incident and the intimations sent under Rule 7
  • a retention and erasure schedule implementing section 8(7)

The company compliance plan generates this as a tracked action list with the official source behind every action, the starter templates cover the processor contract clauses, and the small business checklist sequences the underlying duties. The official texts live at section 10 and Rule 13, each with its Gazette citation.

Section 10, official textRule 13, official textDPIA under the DPDP Act: who must do one, what it contains, when it startsAdditional obligations of a Significant Data Fiduciary: DPO, auditor, DPIA

Sources cited on this page

  1. [1]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 10, p. 8. Published 11 August 2023. Official source ↗ · Official requirement · Verified 23 August 2026Section 10(2)(b): the duty to appoint an independent data auditor to carry out data audit, who shall evaluate the compliance of the Significant Data Fiduciary in accordance with the provisions of the Act. Section 10(2)(c)(ii): the periodic audit. Section 10 begins on Gazette page 8 and concludes on page 9.
  2. [2]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 2, p. 2. Published 11 August 2023. Official source ↗ · Official requirement · Verified 23 August 2026Section 2(z) defines Significant Data Fiduciary as any Data Fiduciary or class of Data Fiduciaries notified by the Central Government under section 10. Section 2 begins on Gazette page 2 and concludes on page 3; clause (z) appears on page 3.
  3. [3]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 13, p. 29. Published 13 November 2025. Official source ↗ · Official requirement · Verified 23 August 2026Rule 13(1): the DPIA and audit once in every period of 12 months from notification, to ensure effective observance of the Act and the rules. Rule 13(2): the report containing significant observations furnished to the Board. Rule 13(3) and 13(4): algorithmic due diligence and the conditional localisation restriction.
  4. [4]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), First Schedule Schedule, p. 32. Published 13 November 2025. Official source ↗ · Official requirement · Verified 23 August 2026Item 12 of Part B of the First Schedule requires a registered Consent Manager to have effective audit mechanisms and to report audit outcomes to the Board. This is the only audit provision in either Gazette text outside section 10 and Rule 13, and it attaches to Consent Managers, not to Data Fiduciaries. The First Schedule begins on Gazette page 32 and concludes on page 34.
  5. [5]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), The Schedule Schedule, p. 21. Published 11 August 2023. Official source ↗ · Official requirement · Verified 23 August 2026The Schedule pairs breach of the additional obligations of a Significant Data Fiduciary under section 10 with a penalty that may extend to 150 crore rupees.
  6. [6]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 8, p. 7. Published 11 August 2023. Official source ↗ · Official requirement · Verified 23 August 2026Section 8: the general obligations of every Data Fiduciary that an auditor evaluating compliance with the Act would look at, including engaging a Data Processor for any activity related to offering of goods or services to Data Principals only under a valid contract (8(2)) and erasure when consent is withdrawn or the purpose is no longer served (8(7)). Section 8 begins on Gazette page 7 and concludes on page 8.
  7. [7]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 7, p. 26. Published 13 November 2025. Official source ↗ · Official requirement · Verified 23 August 2026Rule 7: breach intimation to every affected Data Principal and to the Board, with detailed Board information within 72 hours of awareness. Cited as the duty behind the recommended breach register.
  8. [8]Commencement notification for the Digital Personal Data Protection Act, 2023 (G.S.R. 843(E)), (c), p. 2. Published 13 November 2025. Official source ↗ · Official requirement · Verified 23 August 2026Notification G.S.R. 843(E) names section 10 in the group that comes into force 18 months from the date of publication of the notification gazette.
  9. [9]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 1, (4), p. 24. Published 13 November 2025. Official source ↗ · Official requirement · Verified 23 August 2026Rule 1(4) places Rule 13 in the group of rules that come into force 18 months after publication.
  10. [10]Commencement notification for the Digital Personal Data Protection Act, 2023 (G.S.R. 843(E)), p. 1. Published 13 November 2025. Official source ↗ · Interpretation, requires judgment · Verified 23 August 2026The calendar date 13 May 2027 for section 10 is computed from the publication date printed on Gazette issue No. 757 and is presented as interpretation until officially confirmed.
  11. [11]Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)), p. 1. Published 13 November 2025. Official source ↗ · Interpretation, requires judgment · Verified 23 August 2026The calendar date 13 May 2027 for Rule 13 is computed from the publication date printed on Gazette issue No. 760 and is presented as interpretation until officially confirmed.
  12. [12]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 10, p. 8. Published 11 August 2023. Official source ↗ · Interpretation, requires judgment · Verified 23 August 2026The statement that no Significant Data Fiduciary has been notified reflects the dpdprules.org source registry and timeline, which record no such notification as of the 23 August 2026 verification. Under sections 2(z) and 10(1), the status exists only by Central Government notification.
  13. [13]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 13, p. 29. Published 13 November 2025. Official source ↗ · Interpretation, requires judgment · Verified 23 August 2026The absence statements reflect the dpdprules.org provision registry, which ingests the full Gazette texts of the Act and the DPDP Rules 2025 as corrected: no provision prescribes auditor qualifications, an accreditation regime or empanelment list, a named audit standard, an audit methodology, a report format or a filing timeline for the Rule 13(2) report, and the Rules do not expressly state whether the person carrying out the DPIA and audit under Rule 13(2) must be the independent data auditor appointed under section 10(2)(b), as of the 23 August 2026 verification. For Data Fiduciaries, audit obligations appear only in section 10 and Rule 13; the sole other audit reference in either text is the Consent Manager audit mechanism in the First Schedule.
  14. [14]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 10, p. 8. Published 11 August 2023. Official source ↗ · Practical recommendation · Verified 23 August 2026The preparation guidance, including the record of processing, consent artefacts, breach register, processor contract file and retention schedule, is a recommendation of this site about evidencing compliance with existing duties. The Act and Rules do not prescribe an audit preparation file.

auditsignificant data fiduciarydpiarule 13

Share this: