Nobody schedules an audit of most businesses. Somebody eventually asks them to prove something, and that is a different problem.
The first step is uncomfortable and it is the one worth paying for. Everything after it is straightforward.
Not what your policy says you do — what you could put in front of somebody this afternoon. The gap between those two is the finding, and it is usually large.
Where the practice is sound but undocumented, we make it provable. Where the practice is missing, we say so plainly rather than papering it with a policy.
Notices and their version history, consent records, grievances and how they closed, vendor agreements, retention and erasure, logs. Indexed, dated, ready to hand over.
A customer’s auditor, a procurement questionnaire, an insurer, or correspondence from the Board. You are not drafting your first answer under time pressure.
One boundary worth stating early. If we have done your remediation, we cannot then be your independent data auditor under section 10(2)(b) — independent means not the people who built the thing being examined. Where you need one, we help you brief and choose one, which is a different service and an honest one.
And it applies to Significant Data Fiduciaries alone. The other three are the ones most businesses actually meet.
Not on a schedule — on a complaint or a breach. It inquires, and it can require you to produce documents. The likeliest formal examination you will face.
The commercially frequent one. A large client’s risk team, an annual review clause in your contract, or forty questions with a deadline attached.
ISO 27001 or 27701, or an equivalent your customers ask for. Different standard, but much of the same evidence answers both.
Section 10(2)(b), and only if the government has designated you a Significant Data Fiduciary. Rule 13 then sets the twelve-month cycle. Most businesses are not here.
Which is why “audit readiness” sold as a statutory obligation is the wrong framing for most readers. The obligation is not to be audited. It is to be able to answer, and that one applies to everybody.
A distinction worth picturing correctly, because the two arrive very differently.
You do not prepare for this on the day it arrives. You prepared for it months earlier, or you did not.
Evidence is not something you assemble for an audit. Several provisions make being able to demonstrate it a standing obligation.
You must be able to demonstrate that notice was given and consent was given. Having collected it is not the same as being able to show it.
ConsentLogs, monitoring and review, retained for one year. Which is also the only way to answer what happened, months after it happened.
LogsA report on the intimations given to affected people. You have to evidence that you told them, and when you told them.
BreachGrievances answered inside ninety days. A period you cannot prove you met is a period you are treated as having missed.
GrievancesA valid contract with every processor. The document is the evidence, and the missing ones are found by looking, not by remembering.
VendorsWhat you did, and how quickly, is weighed when a penalty is set. That is only true of what you can actually produce.
PenaltyA record made after the question was asked is a reconstruction, and it reads like one to anybody experienced.
The last one is real. Nobody’s year has no gaps, and a file that claims otherwise gets read more carefully rather than less.
It takes one conversation, the answer is usually uncomfortable, and it is far cheaper to hear from us than from somebody with a deadline attached.
Only if you are a Significant Data Fiduciary. Section 10(2)(b) requires an SDF to appoint an independent data auditor to carry out a data audit, and Rule 13 sets a twelve-month cycle for that audit and the impact assessment alongside it. Designation is by the Central Government under section 10(1), so it is not something you opt into — and most businesses are not designated. What binds everybody is narrower and more useful: several provisions require you to be able to demonstrate things, which is a standing duty rather than an audit one.
Not if we have done the work being audited, and we would rather say so than take the fee. Independence means not examining what you yourself built — if we ran your gap assessment, wrote your notices or fixed your contracts, we are the wrong people to certify that they are sound. What we can do is prepare you for an audit, brief the auditor's scope so the engagement is useful rather than performative, and help you choose one. If a firm offers to both remediate and independently audit the same estate, that is worth a question.
It inquires rather than audits, and the distinction matters. Under section 27 it acts on a breach intimation or a complaint — not on a schedule — and under section 28 it has, for discharging its functions, the powers of a civil court, including requiring the discovery and production of documents and inspecting them. So the scope is set by whatever went wrong rather than agreed with you in advance, and you get no preparation window. The preparation happened months earlier or it did not happen.
Largely, and that is the practical case for doing this once properly. A customer's risk team, an ISO 27701 assessment and a Board inquiry ask overlapping questions in different formats: what data you hold, on what basis, who else touches it, how long you keep it, and what happens when somebody asks or something goes wrong. Businesses commonly answer that four separate times from scratch. The pack is built once and reshaped for whoever is asking.
No — and a documented gap is in a much better position than an undocumented one. Section 33(2) weighs what you did and how promptly when a penalty is set, so a gap you identified, recorded and had a plan for reads very differently from the same gap discovered by somebody else. It is also worth knowing that a file with no gaps at all invites scrutiny rather than deflecting it. Nobody's year is perfect, and an account claiming otherwise gets read more carefully.
The platform collects the evidence as the work happens — consent records, notice versions, grievance timelines, vendor status — which is the part that cannot be done retrospectively. This service is the human half: establishing what you could actually produce today, deciding what a particular asker needs, filling the gaps that predate the platform, and sitting with you when the questions arrive. If you already run the platform properly, this is a shorter engagement and we will scope it that way.
Real client quotes, attributed by role and sector — we never name a client.
Working across
Everything that matters here has to be written down on the day it happens. There is no version of this you can do afterwards.
Thank you — we have it. Someone will reply by email, usually within one working day.
Nothing else is needed from you. If it is urgent, email tushar@ruleexpert.com and it will reach the same people.