Compliance
Data protection audit under the DPDP Act: who must be audited and what the text requires
Only notified Significant Data Fiduciaries need a DPDP audit: the independent auditor in section 10(2)(b), on the 12 month Rule 13 cycle.
Sources last verified on 24 August 2026. Methodology
Archive
43 articles on the DPDP Act 2023 and the DPDP Rules 2025, newest first. Every legal claim cites the official source it rests on.
Compliance
Only notified Significant Data Fiduciaries need a DPDP audit: the independent auditor in section 10(2)(b), on the 12 month Rule 13 cycle.
Notice
Section 5(3) gives the Data Principal the option of English or any Eighth Schedule language. A readiness duty, not 22 published versions.
Compliance
What section 10 adds once you are notified: an India based DPO answerable to the board, an independent auditor, and the 12 month Rule 13 DPIA and audit cycle.
Compliance
Only notified Significant Data Fiduciaries must run a DPIA, on the 12 month Rule 13 cycle. What section 10(2)(c) defines, and what GDPR habits do not carry.
Compliance
Section 7(i) of the DPDP Act lets employers process employee personal data for the purposes of employment without consent, but the exemption has edges: it does not cover everything HR touches, and the general obligations still apply.
Compliance
A ten step DPDP compliance checklist sized for small Indian businesses: map your data, pick the ground for each purpose, fix your notice and consent, prepare for breaches and rights requests, each step cited to the exact provision.
Breach response
What to do when your organisation becomes aware of a personal data breach: contain and anchor the clock, run the two Rule 7 duties in parallel, file the 72 hour Board submission, then stabilise.
Definitions
DPDP का फुल फॉर्म है Digital Personal Data Protection। DPDP Act 2023 भारत का डेटा संरक्षण कानून है और DPDP Rules 2025 इसे लागू करते हैं। यह कब से लागू है, किस पर लागू होता है और जुर्माने कितने हैं, आधिकारिक राजपत्र के संदर्भ के साथ।
Breach response
India runs two separate breach clocks: DPDP Rule 7 gives 72 hours for the detailed Board submission, while the CERT In directions require reporting cyber incidents within 6 hours. Who reports what, to whom, on which clock.