DPDPA 2023 — From Awareness to Compliance
Module 9 of 9 · 6 min read

Auditor's checklist — what evidence to keep

A control-by-control checklist you can hand to internal audit or an ISO auditor.

How to use this

Each line is a control an auditor (internal, ISO 27001/27701, or an SDF independent data auditor) will test. Keep the evidence artefact named beside it. Tick the box only when the artefact exists and is current.

A. Governance

  • Accountable executive and (if SDF) India-based DPO appointed — board minutes, appointment letter
  • Privacy policy and internal data-protection policy approved — versioned documents
  • Training delivered to staff handling personal data — attendance + assessment scores

B. Inventory & purpose

  • Record of processing keyed by purpose, incl. retention and sharing — data inventory
  • Children's data and employee data identified — inventory tags
  • Legal-hold / statutory retention register — register

C. Notice & consent

  • Notice per purpose, standalone, in required languages, with withdrawal and Board-complaint instructions — notice templates + screenshots
  • Consent captured by affirmative action, unbundled — UI evidence
  • Consent ledger records notice version, purpose, timestamp, channel — ledger extract
  • Withdrawal as easy as giving; propagates to Processors — withdrawal test record
  • Legacy data served notice — campaign report

D. Rights

  • Intake channel published; identity verification defined — policy + form
  • Access report can list downstream sharing — sample report
  • Correction/erasure propagates to Processors with confirmation — ticket samples
  • Nomination captured — UI evidence
  • Grievance SLA met — ticket metrics

E. Security safeguards (Rules minimum)

  • Encryption/masking/tokenisation applied — control mapping + config evidence
  • Access control — IAM reviews
  • Logging & monitoring, logs retained ≥ 1 year — SIEM retention config
  • Backups & restore tested — restore test report
  • Processor contracts carry safeguards + breach clauses — signed addenda

F. Breach management

  • Runbook contains DPDPA (72 h) and CERT-In (6 h) clocks — runbook
  • Templates for Principal and Board notifications — templates
  • Annual table-top exercise — exercise report
  • Breach register (including "no notification needed" decisions with reasons) — register

G. SDF-only

  • Annual DPIA — DPIA report
  • Annual independent data audit filed with the Board — audit report
  • Algorithmic risk verification — assessment
  • Localisation conditions honoured — data-flow evidence

H. Cross-border

  • Transfers checked against Government-restricted list — review record
  • Sectoral localisation (RBI etc.) still met — sector compliance evidence