Data Privacy Audit · India
Data Privacy Audit in India
Independent privacy audits against the Digital Personal Data Protection Act 2023 — consent, notice, data principal rights, breach response and Significant Data Fiduciary duties — for organisations in Bengaluru, Mumbai, Delhi NCR, Hyderabad, Chennai and Pune.
Reviewed by Sharwan Jha, CyberSigma — CERT-In Empanelled & PCI QSA Authorised firm
A data privacy audit in India is an independent assessment of how you collect, use, store and share personal data against the Digital Personal Data Protection Act, 2023 — the notice and consent regime, data principal rights, security safeguards, breach reporting to the Data Protection Board, and the additional duties placed on a Significant Data Fiduciary, which include an independent data audit. CyberSigma is CERT-In empanelled and PCI QSA authorised (CEMEA, Asia Pacific and the USA); we map your actual data flows, test the controls that protect them, and give you a remediation plan you can put in front of a board or a regulator.
What the DPDP Act actually requires of you
The DPDP Act 2023 is principles-based, and most of the work of complying with it is operational rather than legal. These are the obligations an audit tests against:
- Notice and consent — a clear, itemised notice and free, specific, informed and unambiguous consent for each purpose, with withdrawal made as easy as giving consent. Consent managers are a defined role under the Act.
- Purpose limitation and erasure — personal data kept only for the specified purpose, and erased when consent is withdrawn or the purpose is served, unless retention is legally required.
- Data principal rights — access, correction, completion, updating, erasure, grievance redressal and nomination. Each needs a working process, not just a policy paragraph.
- Security safeguards — reasonable security measures to prevent personal data breaches, which is where a privacy audit and a security audit meet.
- Breach reporting — notification of a personal data breach to the Data Protection Board and to affected data principals. This runs alongside, and does not replace, the CERT-In six-hour incident reporting obligation.
- Significant Data Fiduciary duties — a Data Protection Officer based in India, data protection impact assessments, and an independent data audit. If you are notified as an SDF, that audit is a statutory requirement.
- Children's data — verifiable parental consent, and prohibitions on tracking, behavioural monitoring and targeted advertising directed at children.
When do the DPDP obligations actually bite?
The Act is being brought into force in phases alongside the DPDP Rules, 2025, which were notified on 13 November 2025. The provisions establishing the Data Protection Board took effect on notification; verification of parental consent and the publication duty under section 27(1)(d) follow one year later; and the substantive obligations most organisations care about — notice and consent standards, data fiduciary duties, children's data and data principal rights — commence at the end of an eighteen-month runway, in May 2027. That runway is the point: the organisations that will struggle are the ones treating it as a deadline to start rather than a period to work through.
Two things are already true regardless of the phase dates. First, the Data Protection Board exists and its provisions are in force. Second, a data map, working consent and rights processes, and a defensible retention position take months to build in a real organisation — which is why we scope privacy audits now against the full obligation set rather than only the provisions currently commenced. Where you sit in the phasing changes urgency; it does not change what you will eventually have to evidence.
What a CyberSigma privacy audit covers
Privacy failures are almost always data-flow failures — the organisation does not know where personal data actually goes. So we start there:
- Build or validate the record of processing: what personal data you hold, where it came from, why you hold it, who you share it with, and where it physically sits.
- Test the consent and notice layer against the Act — including whether withdrawal genuinely works end to end, and whether pre-existing data has a lawful basis to continue.
- Walk the data principal rights processes as a data principal would, and time them.
- Assess the security safeguards protecting personal data: access control, encryption, logging, retention and deletion, and third-party and processor contracts.
- Review breach readiness against both the DPDP notification duty and the CERT-In six-hour window, because the same incident triggers both.
- Check cross-border transfer arrangements and any sectoral localisation obligations that apply to you, such as the RBI's storage requirements for payment system data.
- Deliver a gap register mapped to the Act's obligations, ordered by risk, with an owner and a remediation route for each item.
Representative engagement: a healthtech platform preparing for enterprise customers
A healthtech platform selling into hospital groups was being asked the same privacy questions in every procurement cycle and answering them inconsistently. We mapped their processing end to end, found personal data reaching two analytics processors nobody had contracted for, rebuilt the consent and withdrawal flows, and produced a single evidenced position they could reuse in every customer review. The commercial outcome mattered more than the compliance one: procurement stopped stalling. This example is representative; named client references are available under NDA on request.
How does this relate to GDPR, ISO 27701 and our existing certifications?
If you already run a GDPR programme or hold ISO 27701, you are not starting from zero — the data mapping, rights processes and breach machinery carry over, and we reuse them rather than duplicate them. But the DPDP Act is not GDPR: the consent regime, the Significant Data Fiduciary concept, the role of consent managers and the Data Protection Board's remit are India-specific, and an audit scoped only to GDPR will miss them. Where you serve both markets we assess once and map the evidence to each regime.
Why CyberSigma for a DPDP audit
We are CERT-In empanelled and PCI QSA authorised, and we run privacy and security assessment as one discipline — which matters under the DPDP Act, where the security-safeguards duty and the breach-reporting duty are the parts most organisations fail on. You get a data map you can actually use, rights processes that have been walked rather than described, and a remediation plan written for the people who have to implement it.
Related services
Cybersecurity audit
Independent audit against CERT-In, RBI, SEBI and ISO 27001.
VAPT & penetration testing
Web, mobile, API, network and cloud penetration testing.
National cyber compliance
CERT-In Directions readiness and sectoral cyber mandates.
AI security
Security and governance for AI and LLM systems.
Frequently asked questions
Who does the DPDP Act apply to?
It applies to the processing of digital personal data within India, and to processing outside India where it relates to offering goods or services to data principals in India. It covers personal data collected digitally, and non-digital personal data subsequently digitised. Certain processing — for example purely personal or domestic use, and some publicly available personal data — sits outside its scope.
When do the DPDP Act's obligations come into force?
In phases. The DPDP Rules, 2025 were notified on 13 November 2025 (G.S.R. 843(E)). The provisions constituting and empowering the Data Protection Board, together with the definitions and procedural rules, took effect on notification. Verification of parental consent under section 6(9) and the publication duty under section 27(1)(d) follow one year on. The substantive framework — notice and consent, data fiduciary duties, children's data and data principal rights — commences at the eighteen-month mark, in May 2027. Confirm the exact dates applicable to your entity with counsel; we scope audits against the full obligation set so nothing is a surprise when a phase lands.
What is a Significant Data Fiduciary, and are we one?
An SDF is a data fiduciary, or class of them, notified by the Central Government based on factors including the volume and sensitivity of personal data processed, risk to data principals, and impact on the sovereignty, integrity, electoral democracy and public order of India. If you are notified, you take on additional duties: an India-based Data Protection Officer, data protection impact assessments and an independent data audit. Part of what our audit does is tell you honestly whether you are likely to fall into that category.
Does the DPDP Act require us to keep data in India?
The DPDP Act itself permits transfer outside India except to territories restricted by the Central Government, so it is not a blanket localisation law. Sectoral rules are stricter and still apply — most notably the RBI's requirement that payment system data be stored in India. We scope your audit to the regime that actually governs your entity rather than assuming the strictest reading.
How is a privacy audit different from a cybersecurity audit?
A cybersecurity audit asks whether your controls protect the system. A privacy audit asks whether your handling of personal data is lawful, and whether a data principal could actually exercise their rights. They overlap at the security-safeguards obligation, which is why we usually run them together and reuse one evidence set.
What happens if we get a data breach notification wrong?
The Act provides for financial penalties, including a substantial maximum for failure to take reasonable security safeguards to prevent a personal data breach, with the Data Protection Board determining penalties on the facts. In practice the operational risk is the same incident triggering both a DPDP notification and CERT-In's six-hour reporting window, and the organisation missing one because the two processes were never joined up. We test that specifically.
Can you help after the audit, or only assess?
Both. We deliver the gap register and then work through remediation with your team where you want that — policies and notices, consent and rights workflows, retention and deletion, processor contracts and breach runbooks — and re-test so you can evidence closure rather than intent.
Sources & references
- Digital Personal Data Protection Act, 2023 — official Gazette text — Act No. 22 of 2023, as published in the Gazette of India
- Digital Personal Data Protection Rules, 2025 — MeitY — notified 13 November 2025 (G.S.R. 843(E)); commences in phases
- MeitY — Data Protection Framework — the administering ministry's own page for the DPDP Act and its rules
- CERT-In (Indian Computer Emergency Response Team) — the national nodal agency under Section 70B of the IT Act 2000
- CERT-In Directions under Section 70B(6), 28 April 2022 — the binding directions text — incident reporting, log retention and NTP synchronisation
- Reserve Bank of India — IT governance, cyber security and outsourcing directions for regulated entities
- ISO/IEC 27001 — information security management — the international baseline most Indian enterprises certify against

QSA Authorised
CEMEA · Asia Pacific · USA
Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne — see all locations & addresses →
