DPDP Independent Audit Readiness Checklist
Rule 13 of the DPDP Rules 2025 requires every Significant Data Fiduciary to undertake a Data Protection Impact Assessment and an independent audit every 12 months from the date of SDF notification, and to submit significant observations to the Data Protection Board of India. The audit examines compliance against every operative provision of the DPDP Act and the Rules — meaning the evidence base is your full processing estate, your full consent chain, your full rights-fulfilment log, your breach log, your vendor DPA inventory, your retention schedule, your localisation posture, and your algorithmic-fairness assessments. For a mid-tier Indian bank, that typically spans 40 to 80 high-risk processing activities, 200 to 600 vendor relationships, and 12 months of consent and rights-request records. The checklist below covers the practitioner-side preparation that must be complete before the independent auditor begins fieldwork.