Assure · Audit Readiness & Support

Audit readiness under the DPDP Act

Nobody schedules an audit of most businesses. Somebody eventually asks them to prove something, and that is a different problem.

Talk to us What we do, in four steps Evidence gathered as you go, not reconstructed after the question.
What we actually do

The engagement, in four steps

The first step is uncomfortable and it is the one worth paying for. Everything after it is straightforward.

1

We ask what you could produce today

Not what your policy says you do — what you could put in front of somebody this afternoon. The gap between those two is the finding, and it is usually large.

2

We fix the record, not the story

Where the practice is sound but undocumented, we make it provable. Where the practice is missing, we say so plainly rather than papering it with a policy.

3

We assemble the pack

Notices and their version history, consent records, grievances and how they closed, vendor agreements, retention and erasure, logs. Indexed, dated, ready to hand over.

4

We are there when it is asked for

A customer’s auditor, a procurement questionnaire, an insurer, or correspondence from the Board. You are not drafting your first answer under time pressure.

One boundary worth stating early. If we have done your remediation, we cannot then be your independent data auditor under section 10(2)(b) — independent means not the people who built the thing being examined. Where you need one, we help you brief and choose one, which is a different service and an honest one.

Four different askers

Only one of these is statutory

And it applies to Significant Data Fiduciaries alone. The other three are the ones most businesses actually meet.

01

The Data Protection Board

Not on a schedule — on a complaint or a breach. It inquires, and it can require you to produce documents. The likeliest formal examination you will face.

02

Your customer’s auditor

The commercially frequent one. A large client’s risk team, an annual review clause in your contract, or forty questions with a deadline attached.

03

A certification body

ISO 27001 or 27701, or an equivalent your customers ask for. Different standard, but much of the same evidence answers both.

04

An independent data auditor

Section 10(2)(b), and only if the government has designated you a Significant Data Fiduciary. Rule 13 then sets the twelve-month cycle. Most businesses are not here.

Which is why “audit readiness” sold as a statutory obligation is the wrong framing for most readers. The obligation is not to be audited. It is to be able to answer, and that one applies to everybody.

§27 · §28

The Board does not audit. It inquires

A distinction worth picturing correctly, because the two arrive very differently.

What an audit is like

  • Scheduled, with a date you agreed and time to prepare
  • Scoped in advance, so you know what will be looked at
  • Conducted by someone whose job is to help you pass
  • Ends in findings and a remediation period

What an inquiry is like

  • Triggered by a complaint or a breach intimation, not a calendar
  • Scoped by them, around the thing that went wrong
  • Backed by the powers of a civil court to require documents and inspect
  • Ends in a penalty decision, with section 33(2) weighing what you can show

You do not prepare for this on the day it arrives. You prepared for it months earlier, or you did not.

The part people miss

The Act already requires you to prove things

Evidence is not something you assemble for an audit. Several provisions make being able to demonstrate it a standing obligation.

§6(10)₹50 Cr

You must be able to demonstrate that notice was given and consent was given. Having collected it is not the same as being able to show it.

Consent
Rule 6₹250 Cr

Logs, monitoring and review, retained for one year. Which is also the only way to answer what happened, months after it happened.

Logs
Rule 7(2)(b)₹200 Cr

A report on the intimations given to affected people. You have to evidence that you told them, and when you told them.

Breach
§13 · Rule 14(3)₹50 Cr

Grievances answered inside ninety days. A period you cannot prove you met is a period you are treated as having missed.

Grievances
§8(2)₹50 Cr

A valid contract with every processor. The document is the evidence, and the missing ones are found by looking, not by remembering.

Vendors
§33(2)₹50 Cr

What you did, and how quickly, is weighed when a penalty is set. That is only true of what you can actually produce.

Penalty
The difference that matters

Evidence, and things that look like evidence

A record made after the question was asked is a reconstruction, and it reads like one to anybody experienced.

Holds up

  • Written when the thing happened, with the date it happened on
  • The version of the notice that was live that day, not today’s
  • A decision recorded with its reason, including the ones you got wrong
  • Logs you cannot quietly edit, and can show you cannot edit
  • Gaps acknowledged in writing, with what you decided to do about them

Does not

  • A policy describing what should have happened, with nothing showing it did
  • A folder assembled the week the question arrived
  • Screenshots with no date, or dated the day you took them
  • A spreadsheet somebody maintains from memory each quarter
  • Perfect records with no gaps at all, which invites the obvious question

The last one is real. Nobody’s year has no gaps, and a file that claims otherwise gets read more carefully rather than less.

Find out what you could produce today.

It takes one conversation, the answer is usually uncomfortable, and it is far cheaper to hear from us than from somebody with a deadline attached.

Questions

Straight answers

Does the DPDP Act require us to be audited?

Only if you are a Significant Data Fiduciary. Section 10(2)(b) requires an SDF to appoint an independent data auditor to carry out a data audit, and Rule 13 sets a twelve-month cycle for that audit and the impact assessment alongside it. Designation is by the Central Government under section 10(1), so it is not something you opt into — and most businesses are not designated. What binds everybody is narrower and more useful: several provisions require you to be able to demonstrate things, which is a standing duty rather than an audit one.

Can you be our independent data auditor?

Not if we have done the work being audited, and we would rather say so than take the fee. Independence means not examining what you yourself built — if we ran your gap assessment, wrote your notices or fixed your contracts, we are the wrong people to certify that they are sound. What we can do is prepare you for an audit, brief the auditor's scope so the engagement is useful rather than performative, and help you choose one. If a firm offers to both remediate and independently audit the same estate, that is worth a question.

What does the Data Protection Board actually do?

It inquires rather than audits, and the distinction matters. Under section 27 it acts on a breach intimation or a complaint — not on a schedule — and under section 28 it has, for discharging its functions, the powers of a civil court, including requiring the discovery and production of documents and inspecting them. So the scope is set by whatever went wrong rather than agreed with you in advance, and you get no preparation window. The preparation happened months earlier or it did not happen.

Our customers audit us. Is that the same evidence?

Largely, and that is the practical case for doing this once properly. A customer's risk team, an ISO 27701 assessment and a Board inquiry ask overlapping questions in different formats: what data you hold, on what basis, who else touches it, how long you keep it, and what happens when somebody asks or something goes wrong. Businesses commonly answer that four separate times from scratch. The pack is built once and reshaped for whoever is asking.

We know our records have gaps. Should we wait until they are fixed?

No — and a documented gap is in a much better position than an undocumented one. Section 33(2) weighs what you did and how promptly when a penalty is set, so a gap you identified, recorded and had a plan for reads very differently from the same gap discovered by somebody else. It is also worth knowing that a file with no gaps at all invites scrutiny rather than deflecting it. Nobody's year is perfect, and an account claiming otherwise gets read more carefully.

Is this not just what the platform already does?

The platform collects the evidence as the work happens — consent records, notice versions, grievance timelines, vendor status — which is the part that cannot be done retrospectively. This service is the human half: establishing what you could actually produce today, deciding what a particular asker needs, filling the gaps that predate the platform, and sitting with you when the questions arrive. If you already run the platform properly, this is a shorter engagement and we will scope it that way.

In their words

What compliance teams tell us

“We always thought DPDP compliance was the client’s responsibility since we were only executing services. The evaluation made it clear that how we handle client data creates risk on our side too. It changed how we work internally.”
DSFounderDigital services firm
“We had a basic understanding of DPDP requirements, but the scorecard highlighted gaps we hadn’t identified internally — especially around consent handling and data visibility. It gave us a much clearer starting point.”
BSFounderB2B SaaS company
“The DPDP score was surprisingly insightful. Within minutes we could see where we stood and what needed immediate attention. It simplified something that initially felt quite complex.”
FPProduct HeadFintech platform
“After reviewing our score we opted for a consultation. The discussion was very practical — we got clear direction on what to fix first and how to approach DPDP compliance in a structured way.”
LGFounderLogistics company

Real client quotes, attributed by role and sector — we never name a client.

Insights

DPDP, explained properly

All articles

Working across

Healthcare & HospitalsDiagnostics & Labs Education & EdtechBFSI & Fintech InsuranceLogistics & Mobility Retail & E-commerceIT & SaaS ManufacturingReal Estate
Hospitality & TravelMedia & Publishing Professional ServicesStaffing & HR TelecomOnline Gaming NGO & Non-profitGovernment & PSU Pharma & Life SciencesAutomotive

Proof is built early or not at all.

Everything that matters here has to be written down on the day it happens. There is no version of this you can do afterwards.