The DPDP Act 2023 for Auditors
Most obligations start in May 2027. The controls they require are worth testing now.
The Digital Personal Data Protection Act, 2023 (DPDP Act) governs how organisations process digital personal data in India. For an IS auditor it matters in two ways: it turns several familiar controls (access, logging, encryption, retention, breach response) into legal duties with penalties attached, and it creates a new engagement, the independent data audit of a significant data fiduciary.
Timing is the first thing to get right. The Act and the DPDP Rules, 2025 were brought into force in phases from 13 November 2025, and most of the obligations on businesses are not yet in force in October 2026. The DISA 3.0 background material predates the Act and still refers to the earlier Personal Data Protection Bill.
You save ₹450
- Full-length timed mocks
- Module-wise practice
- Emerging-tech coverage
One payment, no subscription · Valid for 2 months
What Is in Force, and When
Per the commencement notification G.S.R. 843(E) and rule 1 of the DPDP Rules, both dated 13 November 2025.
| From | What starts |
|---|---|
| 13 November 2025 | Definitions (s.2); the Data Protection Board and its procedure (ss.18-26 and related provisions); Rules 1, 2 and 17-21 |
| One year later (November 2026) | Consent manager provisions (s.6(9)) and the Board's related power; Rule 4 on consent manager registration |
| Eighteen months later (May 2027) | Applicability, notice and consent, data fiduciary obligations, children's data, significant data fiduciaries, data principal rights (ss.3-17); penalties (s.33); omission of IT Act s.43A (s.44(2)); Rules 3, 5-16, 22 and 23 |
The Parties
- Data Principal
- The individual the personal data relates to (for a child, including the parent or lawful guardian).
- Data Fiduciary
- Whoever, alone or with others, decides the purpose and means of processing. A bank, an employer or an e-commerce company for its customers' data.
- Data Processor
- Anyone processing on a fiduciary's behalf: a payroll vendor, a cloud provider, an audit firm holding a data extract. The fiduciary stays responsible for processing done on its behalf (s.8(1)) and may engage a processor only under a valid contract (s.8(2)).
- Significant Data Fiduciary (SDF)
- A fiduciary or class the Central Government notifies, based on factors such as volume and sensitivity of data and risk to data principals (s.10(1)).
Obligations That Become Audit Tests
s.8(5) and Rule 6
What it requires
Reasonable security safeguards; at minimum encryption, masking or tokenisation, access control, logs with monitoring and review, backups for continuity, safeguard clauses in processor contracts
What the auditor tests
Encryption settings, access reviews, log review evidence, backup restores, processor contracts
Rule 6(1)(e) and Rule 8(3)
What it requires
Retain relevant logs and personal data for one year (unless another law requires otherwise)
What the auditor tests
Log retention configuration against the requirement and against other laws
s.8(6) and Rule 7
What it requires
Intimate each affected data principal and the Board of a breach; detailed report to the Board within 72 hours of becoming aware (or longer if the Board allows)
What the auditor tests
Incident response plan, breach register, timeline evidence from past incidents
s.8(7)
What it requires
Erase data once consent is withdrawn or the purpose is no longer served, unless law requires retention; make processors erase too
What the auditor tests
Retention schedule, deletion jobs, evidence of processor deletion
s.10(2) and Rule 13
What it requires
SDF: a Data Protection Officer based in India and answerable to the board; an independent data auditor; periodic DPIA and audit, once every twelve months under Rule 13, with a report of significant observations to the Board
What the auditor tests
Appointment records, DPIA, audit report and remediation tracking
| Provision | What it requires | What the auditor tests |
|---|---|---|
| s.8(5) and Rule 6 | Reasonable security safeguards; at minimum encryption, masking or tokenisation, access control, logs with monitoring and review, backups for continuity, safeguard clauses in processor contracts | Encryption settings, access reviews, log review evidence, backup restores, processor contracts |
| Rule 6(1)(e) and Rule 8(3) | Retain relevant logs and personal data for one year (unless another law requires otherwise) | Log retention configuration against the requirement and against other laws |
| s.8(6) and Rule 7 | Intimate each affected data principal and the Board of a breach; detailed report to the Board within 72 hours of becoming aware (or longer if the Board allows) | Incident response plan, breach register, timeline evidence from past incidents |
| s.8(7) | Erase data once consent is withdrawn or the purpose is no longer served, unless law requires retention; make processors erase too | Retention schedule, deletion jobs, evidence of processor deletion |
| s.10(2) and Rule 13 | SDF: a Data Protection Officer based in India and answerable to the board; an independent data auditor; periodic DPIA and audit, once every twelve months under Rule 13, with a report of significant observations to the Board | Appointment records, DPIA, audit report and remediation tracking |
Quick practice on audit concepts. No signup.
Penalties in the Schedule
Maximum amounts the Board may impose (s.33). They apply once the relevant provisions commence.
| Breach | Up to |
|---|---|
| Failure to take reasonable security safeguards (s.8(5)) | ₹250 crore |
| Failure to notify the Board or data principals of a breach (s.8(6)) | ₹200 crore |
| Breach of children's data obligations (s.9) | ₹200 crore |
| Breach of SDF obligations (s.10) | ₹150 crore |
| Breach of data principal duties (s.15) | ₹10,000 |
| Any other provision | ₹50 crore |
How the DISA Assessment Test Tests This
The DISA 3.0 material predates the Act, so whether and how the AT covers it is not public. Where it appears, expect:
- check_circleRole identification: a payroll vendor processing employees' data is a data processor; the employer is the data fiduciary and stays responsible.
- check_circleTimelines: the 72-hour window is for the detailed report to the Board under Rule 7, not for the first intimation, which is 'without delay'. Mixing it up with CERT-In's separate 6-hour reporting window is a classic trap.
- check_circleWho must appoint an independent data auditor: only a significant data fiduciary, not every fiduciary.
- check_circleIn force or not: in October 2026 most fiduciary obligations and the penalties are not yet in force.
FAQs
Is the DPDP Act in force?expand_more
In phases. The Board provisions started on 13 November 2025, consent manager provisions start a year later, and most data fiduciary obligations and the penalties start eighteen months after 13 November 2025, which falls in May 2027.
Who needs a data audit under the DPDP Act?expand_more
A significant data fiduciary must appoint an independent data auditor, and under Rule 13 carry out a DPIA and an audit once in every twelve months, sending the Board a report of significant observations.
What is the penalty for a data breach under the DPDP Act?expand_more
Failing to take reasonable security safeguards can attract up to ₹250 crore, and failing to notify a breach up to ₹200 crore, per the Act's Schedule.
Does the DPDP Act replace section 43A of the IT Act?expand_more
Yes, eventually. Section 44(2) of the DPDP Act omits section 43A, but that provision commences eighteen months after 13 November 2025, so section 43A still applies until then.
Next steps
Take a full DISA mock testAssessment Test format, timed and scored.
