Sector Guide 9 min read 25 July 2026

The DPDP Audit Checklist for CAs: 25 Checks to Run on Every Client

A practical DPDP audit checklist for chartered accountants and auditors — 25 obligation-by-obligation checks mapped to exact DPDP Act sections and Rules 2025 provisions, with a printable working paper.

PDF ↓ Download the free one-page guide Branded PDF summary with a QR code back to this guide — print it for your desk or team. PDF →

Your SMB clients will not read the DPDP Act. They will ask you whether they're compliant. This checklist turns that question into 25 concrete checks, each mapped to the section or rule it tests — run it like you'd run any compliance review: evidence first, assurances second.

Prefer a working paper? Download the printable one-page version above, or the client-readiness scorecard (PDF) for scoring a client engagement by engagement. The client-facing version of this exercise is our interactive DPDP compliance checklist.

A. Applicability & Data Mapping (Checks 1–4)

  1. Applicability confirmed. The client has established the Act applies (digital personal data, or digitised paper data — Section 3) and documented the conclusion.
  2. Data inventory exists. A current register of what personal data is collected, where it's stored, who accesses it, who it's shared with.
  3. Processors listed. Every third-party tool or service handling customer data is identified (Section 8(2) makes the client responsible for processing done on its behalf).
  4. Children's data flagged. If any customers may be under 18, the client knows it — this changes the risk profile entirely (Section 9).

B. Notice & Consent (Checks 5–10)

  1. A compliant notice exists — standalone, plain language, itemising the data and purposes, with links to withdraw, exercise rights, and complain to the Board (Section 5(1), Rule 3).
  2. The notice is served before or with every consent request, on every collection channel — web, WhatsApp, offline.
  3. Language option honoured. The notice is accessible in the languages the client's customers actually use (Section 5(3)).
  4. Consent is a clear affirmative action — no pre-ticked boxes, no bundled "agree to everything" (Section 6(1)).
  5. Withdrawal works and is as easy as giving consent (Section 6(4)) — test it as a customer would.
  6. Existing customers re-noticed. Customers acquired before the Act have been sent a Section 5(2) notice, or a plan exists.

C. Rights & Requests (Checks 11–14)

  1. A request channel exists for access, correction and erasure (Sections 11–12) — and someone owns it.
  2. Timelines are published — how to exercise rights and how fast the client responds (Rule 14) — and actually met.
  3. Grievance redressal is readily available (Section 13), before customers can escalate to the Board.
  4. Requests are logged with received/resolved timestamps — the evidence trail.

D. Security & Breach (Checks 15–19)

  1. Reasonable safeguards implemented — encryption/obfuscation, access control, backups (Section 8(5), Rule 6).
  2. Logs retained at least one year and monitored for unauthorised access (Rule 6).
  3. A written breach plan exists matching the Rule 7 sequence: affected customers and the Board informed without delay, detailed Board filing within 72 hours.
  4. The team knows the plan — ask a staff member what they'd do on discovering a leak.
  5. Processor contracts contain data-protection clauses (Section 8(2)) — sample and read them.

E. High-Risk Areas (Checks 20–22)

  1. Verifiable parental consent operates wherever children's data is processed (Section 9, Rule 10) — the ₹200 crore exposure.
  2. No tracking or targeted advertising directed at children (Section 9(3)).
  3. Retention policy applied. Data is erased when its purpose ends or law no longer requires it (Section 8(7)) — check something has actually been deleted.

F. Evidence & Governance (Checks 23–25)

  1. Consent records are producible — who, what purposes, when, which language, which notice version (Section 6 burden of proof). See what consent records must contain.
  2. Staff training documented — sessions, attendance, materials.
  3. The evidence exports. Whether from an audit-log system or disciplined files, the client can hand you the record set in one pass.

Turning the Audit Into an Engagement

Most clients will fail several checks on the first pass — that's the advisory opportunity, not a crisis. Sequence remediation using the 14-step checklist, price the ongoing monitoring, and see DPDP for chartered accountants and the EasyDP partner programme for how firms are packaging this.

References & Sources

  1. Ministry of Electronics & IT — The Digital Personal Data Protection Act, 2023 (Sections 3, 5, 6, 8, 9, 11–13; the Schedule).
  2. The Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)) — Rule 3 (notice), Rule 6 (security safeguards), Rule 7 (breach intimation), Rule 8 (erasure), Rule 10 (children's verifiable consent), Rule 13 (Significant Data Fiduciaries), Rule 14 (rights of Data Principals).
  3. ICAI — Data Protection Compliance & Audit Certification programme announcements.

General information for professional advisors, not legal advice. Verify each provision against the notified text before relying on it in an engagement.

CAAuditorAudit ChecklistDPDPCompliance

Check Your DPDP Compliance

Free 2-minute checker — get your specific obligations and penalty exposure.