Skip to main content

The 3rd and main DPDP commencement date is computed as 13 May 2027, which is interpretation until officially confirmed.

Sources last verified on 7 October 2026. Methodology

Data protection audit under the DPDP Act: who must be audited and what the text requires

Compliance

By · Primary sources verified by dpdprules.orgPublished · Last reviewed 11 min read

Who needs a data protection audit under the DPDP Act and what must it cover?

The short answer

Once section 10 and Rule 13 are in force, only a Significant Data Fiduciary, meaning a Data Fiduciary or class notified by the Central Government under section 10, must be audited. Section 10(2)(b) requires it to appoint an independent data auditor who shall evaluate its compliance in accordance with the provisions of the Act, and section 10(2)(c) adds a periodic audit alongside the periodic Data Protection Impact Assessment. Rule 13 sets the cadence: a DPIA and an audit once in every period of 12 months from notification, with a report containing significant observations furnished to the Data Protection Board. The report carries significant observations and not material observations: the word material appears in neither instrument in connection with it. Neither section 10 nor Rule 13, as published on 13 November 2025, prescribes auditor qualifications, an audit standard or a report format. Section 10 and Rule 13 commence on the computed date of 13 May 2027, interpretation until officially confirmed, and no notification of a Significant Data Fiduciary has been located as of 2 September 2026.

More answered questions →

Diagram: Rule 13: the 12 month audit cycle, and the report the Board actually gets. The same diagram appears further down this article, where it is described in full.

Search for DPDPA audit requirements and much of what ranks is vendor content: accreditation regimes, audit frameworks, certification checklists, report templates, all presented as if the law prescribed them. The Gazette text is far sparser than that. This article states exactly what the DPDP Act 2023 and the DPDP Rules 2025 require of a data protection audit, quotes the operative words, and is explicit about what has not been prescribed, so you can tell a statutory duty from a seller's construction.

Who must be audited: only notified Significant Data Fiduciaries

The audit duty lives inside section 10, and section 10 applies only to a Significant Data Fiduciary: "any Data Fiduciary or class of Data Fiduciaries as may be notified by the Central Government under section 10", per the definition in section 2(z). There is no self assessment, no registration and no threshold you can compute for yourself. Either a notification covers you, or the statutory audit duty does not exist for you, whatever your scale.

As of 2 September 2026, no notification of a Data Fiduciary or class as significant has been located, and section 10 and Rule 13 have not commenced, on a computed 13 May 2027 that is interpretation until officially confirmed, so no organisation in India currently carries the statutory data audit obligation. How notification works, and the 2 duties that arrive with the auditor, a board answerable Data Protection Officer and the DPIA, are covered in the Significant Data Fiduciary obligations guide.

One scoping fact worth stating precisely: for Data Fiduciaries, audit obligations appear in exactly 2 places in the framework, section 10 of the Act and Rule 13 of the Rules. The only other audit reference in either Gazette text is item 12 of Part B of the First Schedule, which requires a registered Consent Manager to maintain audit mechanisms and report outcomes to the Board. That is a separate registration regime and does not attach to Data Fiduciaries.

The independent data auditor in section 10(2)(b)

The appointment duty is one clause, continuing the stem of section 10(2), "The Significant Data Fiduciary shall":

DPDP Act 2023, s. 10(2)(b) · Additional obligations of Significant Data Fiduciary · verbatim

"appoint an independent data auditor to carry out data audit, who shall evaluate the compliance of the Significant Data Fiduciary in accordance with the provisions of this Act"

Section 10(2)(b) of the DPDP Act 2023.

The clause asks for 2 things at once. Independence: the auditor cannot be the function marking its own homework. And a yardstick: the evaluation is measured against the provisions of the Act itself, not against an internal policy, a certification scheme or an industry framework. Everything else about the auditor, who qualifies, how independence is tested, whether a firm or an individual, is left unsaid.

The periodic audit in section 10(2)(c)

Section 10(2)(c) then requires the Significant Data Fiduciary to undertake a "periodic Data Protection Impact Assessment", a "periodic audit", and such other measures as may be prescribed. For the audit, that is the entire statutory content: 2 words, with the cadence left to the Rules. The DPIA in the same clause gets a fuller statutory definition, which is unpacked in DPIA under the DPDP Act.

What Rule 13 adds: a 12 month clock and a report to the Board

Rule 13 of the DPDP Rules 2025 turns "periodic" into a schedule and gives the audit its one mandated output.

The cycle. Rule 13(1) requires the Significant Data Fiduciary, "once in every period of twelve months from the date on which it is notified as such or is included in the class of Data Fiduciaries notified as such", to undertake a Data Protection Impact Assessment and an audit "to ensure effective observance of the provisions of this Act and the rules made thereunder". The clock starts at notification, not at a financial year end, and the audit travels together with the DPIA as one annual exercise aimed at the whole framework.

The report. Rule 13(2) is one sentence, and it is the whole of what the Board is told:

DPDP Rules 2025, r. 13, (2) · Additional obligations of Significant Data Fiduciary · verbatim

"A Significant Data Fiduciary shall cause the person carrying out the Data Protection Impact Assessment and audit to furnish to the Board a report containing significant observations in the Data Protection Impact Assessment and audit."

Rule 13(2) of the DPDP Rules 2025.

The findings do not stay internal: the Data Protection Board of India receives the significant observations every cycle. On this site's reading the sub rule leaves no residual risk filter, which the next section takes up.

Rule 13 also carries 2 neighbouring duties on the same tier, algorithmic due diligence under Rule 13(3) and a conditional localisation restriction under Rule 13(4), covered in the Significant Data Fiduciary obligations guide.

One thing worth knowing about the page this rule is printed on. The corrigenda of 10 December 2025 correct Gazette pages 24, 29, 32, 34 and 38 of the Rules, and page 29 is where Rule 13 sits, so a reader checking the print needs to know which words moved. Exactly one correction lands there: item (ii), which replaces "Department" with "Departments" at line 44, inside the Rule 13(5) definition of the committee behind the Rule 13(4) localisation restriction. The audit cycle in Rule 13(1) and the report in Rule 13(2) are as first printed, uncorrected.

Diagram headed "Rule 13: the 12 month audit cycle, and the report the Board actually gets", with a subtitle recording that the audit duty exists only for a Data Fiduciary the Central Government has notified under section 10 and that no such notification has been located. A band across the top prints Rule 13(2) in full from Gazette issue No. 760 at page 29: a Significant Data Fiduciary shall cause the person carrying out the Data Protection Impact Assessment and audit to furnish to the Board a report containing significant observations in the Data Protection Impact Assessment and audit. A note underneath records that Rule 13(1) sets the clock, both exercises once in every period of twelve months from the date on which it is notified as such, quoted to that point and spelled as printed. The left panel is headed as what section 10(2) asks of a notified Significant Data Fiduciary and follows the Act's own lettering: (a) a Data Protection Officer in India, answerable to the governing body; (b) an independent data auditor, to evaluate compliance with the Act; (c)(i) a periodic Data Protection Impact Assessment; (c)(ii) a periodic audit, and those 2 words are its whole content; and (c)(iii) such other measures, consistent with the Act, as prescribed. It closes with a line typed as this site's reading: that Rule 13 is the only prescription so far, and that it fixes cadence and reporting rather than method, standard or format. The right panel is headed as what a summary drops and as this site's reading, and it carries 3 items. Significant, not material: Rule 13(2) fixes the contents of the report as significant observations, a phrase neither instrument defines. Notified, not large: section 2(z) makes a Significant Data Fiduciary whoever the Central Government notifies under section 10, so no threshold is yours to compute. Nothing else prescribed: no auditor qualification, accreditation or empanelment, no named standard, no report format and no filing timeline. A band across the foot, labelled not in force, records that section 10 of the Act and Rule 13 of the Rules both sit in the group commencing 18 months after publication, computed at 13 May 2027 and interpretation until officially confirmed, and that no notification of a Data Fiduciary or class as significant has been located as at 2 September 2026, and because section 10 has not commenced the audit duty reaches nobody today. The footer records that the draft Rules of 3 January 2025 carried this duty as Rule 12 on draft Gazette page 34 with sub rules (1) and (2) notified unchanged, so significant observations is the wording of both, and that the corrigenda of 10 December 2025 reach page 29 at Rule 13(5) only.

Significant observations, not material observations

The phrase Rule 13(2) uses for the contents of the report is "significant observations", and neither the Act nor the Rules define it. The word an audit summary tends to reach for instead, material, appears in neither instrument in connection with this report at all. It appears exactly once in each. In the Act it is a duty of the individual, not of the fiduciary: section 15(c) asks a Data Principal "not to suppress any material information" while providing personal data for a State issued document. In the Rules it is a conflict of interest test for a different regime: item 10 of Part B of the First Schedule asks a Consent Manager to prevent a "material pecuniary relationship" with the Data Fiduciaries on its platform.

What follows is this site's reading rather than the text. The 2 words are not interchangeable in a compliance document. A report of material observations, which is not what the sub rule asks for, invites a threshold question, namely how large an observation has to be before the Board hears about it, and Rule 13(2) supplies no threshold: it names significant observations, does not define the phrase, sets no residual risk test and gives the fiduciary no express discretion to withhold. Until the Board publishes guidance, the safer reading is that the report follows the words in the rule rather than an imported audit convention. This site's own summary image for this article wrongly printed "Material observations" until 2 September 2026, which is why the point is worth making in the open.

The wording survived consultation. The draft Rules published for consultation on 3 January 2025 carried this duty as Rule 12, on draft Gazette page 34, and sub rules (1) and (2) were notified unchanged, word for word, "significant observations" included. What did move sits either side of them: draft sub rule (3) reached "algorithmic software deployed by it" where the notified Rule 13(3) reaches "technical measures including algorithmic software adopted by it", a wider duty; and Rule 13(5), the definition of the committee, is new in the notified Rules with no counterpart in the draft. So the cycle and the report are the settled part of this rule.

How the audit differs from the DPIA

The 2 duties share a clock and a report but are not the same exercise. The audit evaluates compliance: did the organisation observe the Act and the Rules. The DPIA is a defined process aimed at people: a description of the rights of Data Principals, the purpose of processing, and assessment and management of the risk to those rights. The express independence requirement in section 10(2)(b) attaches to the auditor; the Act does not say who conducts the DPIA. One textual detail: Rule 13(2) speaks of "the person carrying out the Data Protection Impact Assessment and audit" in the singular, which reads naturally as one appointee running both, but the Rules never state expressly that this person must be the section 10(2)(b) auditor. That reading is interpretation, not text.

What the text fixes, and what it leaves open

RequirementSourceWhat the text saysWhat is not prescribed
Independent data auditorSection 10(2)(b)Appoint an independent data auditor to carry out data audit, who shall evaluate compliance in accordance with the provisions of the ActWho may act as auditor, any qualification or accreditation, how independence is tested
Periodic auditSection 10(2)(c)(ii)The words "periodic audit", with cadence left to the RulesScope, method, any named audit standard
12 month cycleRule 13(1)A DPIA and an audit once in every period of 12 months from notification, to ensure effective observance of the Act and the rulesAudit standard, methodology, checklist or evidence requirements
Report to the BoardRule 13(2)The person carrying out the DPIA and audit furnishes to the Board a report containing significant observationsReport format or template, filing timeline, definition of significant observations

The honest gap statement, then: as of 2 September 2026 there is no auditor accreditation regime, no empanelment list, no named audit standard, no prescribed methodology and no report template anywhere in the Act or the Rules. Section 10(2)(c)(iii) leaves a hook for "such other measures, consistent with the provisions of this Act, as may be prescribed", but the only prescription so far is Rule 13, and Rule 13 fixes cadence and reporting, not method. Any product that presents a specific framework, certification or report format as a DPDPA legal requirement is selling its own construction.

When the duty starts, and what a breach costs

Notification G.S.R. 843(E) places section 10 in the group that comes into force 18 months from publication of the commencement gazette, and Rule 1(4) places Rule 13 in the matching 18 month group of the Rules. Both compute to 13 May 2027, which is interpretation until officially confirmed. Even after that date, the duty reaches only organisations the Central Government has notified. The stakes once it does: the Act's Schedule pairs breach of the section 10 obligations with a penalty that may extend to 150 crore rupees.

How to prepare, offered as recommendation

Nothing below is a statutory audit requirement; the Act and Rules prescribe no preparation file. It is this site's recommendation, built from the yardstick the auditor must use: compliance "in accordance with the provisions of this Act". An evaluation against the Act will ask for evidence of the duties you already carry, so the cheapest preparation is keeping that evidence as you go:

  • a record of processing: what personal data you hold, each purpose, and the ground behind it
  • the notice and consent artefacts behind your consent based processing
  • contracts with every Data Processor, since section 8(2) permits engaging one for any activity related to offering of goods or services to Data Principals only under a valid contract
  • a breach register holding each incident and the intimations sent under Rule 7
  • a retention and erasure schedule implementing section 8(7)

The company compliance plan generates this as a tracked action list with the official source behind every action, the starter templates cover the processor contract clauses, and the small business checklist sequences the underlying duties. The official texts live at section 10 and Rule 13, each with its Gazette citation.

Section 10, official text →Rule 13, official text →DPIA under the DPDP Act: who must do one, what it contains, when it starts →Additional obligations of a Significant Data Fiduciary: DPO, auditor, DPIA →DPDP for compliance and data protection officers →

AuditSignificant Data FiduciaryDPIARule 13

Share this: