DPDP Audits
DPDP Rules 2025 Notified — Compliance Due May 2027

Is Your Organisation DPDP Ready?

Independent DPDP Act 2023 compliance audits for Indian organisations — powered by AI-assisted Computer Audit Tools (CAATs). Observations, gap assessments, and DPO advisory by a CISA-certified auditor.

CISA CertifiedCAIIBISACA MemberIIA StandardsEx-SBI AGM
Why Now

The DPDP Rules are notified.
Will you be ready by May 2027?

DPDP Act 2023 is law — DPDP Rules 2025 notified November 2025

Core obligations (notice, consent, security, breach reporting, DSAR) apply from May 2027

Data Protection Board of India provisions are already in force

Data Fiduciaries face penalties of up to ₹250 crore

Services & Pricing

Choose the right level of coverage

Every engagement is auditor-led. CAATs do the data gathering — Ram makes every compliance determination personally.

One-Time

Project-Based DPDP Audit

Full gap assessment against all 67 DPDP controls

₹1.5L – ₹3.5L
per engagement
  • 67-control CAATs-driven assessment
  • Deviation Record Extract (DRX) for auditee
  • Observations report with AI-assisted CAATs
  • Remediation roadmap guidance
  • Auditor sign-off included
  • Evidence log retained 7 years
Start an Audit
Most Popular
Most Popular

Monthly Retainer — DPO Advisory

Ongoing data protection officer support

₹25,000 – ₹45,000
per month
  • Virtual DPO function for your organisation
  • Monthly DSAR review and tracking
  • Policy review and gap updates
  • Incident & breach response advisory
  • Regulatory updates and alerts
  • Priority email + call support
Enquire About Retainer
For CERT-IN Firms

Annual Audit Partner

Sub-contractor DPDP expertise on your client engagements

₹18,000 – ₹28,000
per day · or 20–30% rev-share
  • Sub-contractor IS audit on your clients
  • DPDP module added to existing audit scope
  • CAATs platform shared for engagement
  • Report co-branded with your firm
  • Flexible day-rate or revenue share
  • NDA and engagement agreement provided
Discuss Partnership

All prices are indicative. Final fee depends on organisation size, data volume, and scope. GST applicable as per prevailing rates.

How It Works

From evidence to signed report

A structured, repeatable 4-step process. CAATs do the heavy lifting — the auditor makes every compliance call.

01

Evidence Request

A personalised checklist of 67 DPDP controls is generated for your organisation. AI classifies exactly what evidence is needed per control — policies, logs, screenshots, contracts.

02

Evidence Intake

You submit documents, exports, and URLs. Each file is SHA256-hashed for chain-of-custody. Duplicate detection prevents double-counting. Status dashboard shows coverage at a glance.

03

AI-Assisted Assessment

Claude Sonnet reads your evidence against each control's VALUE_STATEMENT. It reports observations only — never conclusions. Every result is labelled "Preliminary Assessment — Auditor Judgment Required".

04

Auditor Review & Sign-Off

Ram reviews every control, overrides any AI result that doesn't reflect the evidence, and signs the final report. No AI output reaches you without his review and professional sign-off.

Auditor Independence — Always

In line with ISACA and IIA professional standards, all compliance determinations, materiality assessments, and audit opinions rest exclusively with Ram Krishan Dudeja. Automated tools report observations. The auditor decides.

About the Auditor

Ram Krishan Dudeja

Independent DPDP auditor and founder of DPDP Audits. With a career spanning banking supervision, vigilance, and IS audit, Ram brings the rigour of a Big-4-level audit methodology to DPDP Act 2023 compliance — combined with a practical understanding of how Indian organisations actually operate.

CISA
Certified Information Systems Auditor — ISACA
CAIIB
Certified Associate of Indian Institute of Banking
Ex-SBI AGM
Assistant General Manager (Vigilance), State Bank of India
ISACA / IIA
Member — follows IS Audit professional standards

DPDP Audits

Pan-India  ·  [email protected]
dpdpaudits.com

Audit Coverage

All major DPDP sections covered

The audit framework covers 67 controls mapped across 21 DPDP Act sections — from applicability and notice through to breach management, AI governance, and penalty exposure assessment.

  • Section 6 — Consent Validity
  • Section 8 — Data Fiduciary Obligations
  • Section 9 — Children's Data Protection
  • Section 10 — Security Safeguards
  • Section 11 — Data Subject Rights (DSAR)
  • Section 12 — Breach Management
  • Section 16 — Cross-Border Transfers
  • Rules 9–11 — Consent Manager Obligations
67
Controls per audit
21
DPDP sections mapped
7yr
Evidence retention
FAQ

DPDP audit: frequently asked questions

Common questions about DPDP Act 2023 compliance and how an audit works.

What is a DPDP audit?

A DPDP audit is an independent assessment of how your organisation collects, uses, stores and shares digital personal data, measured against the Digital Personal Data Protection Act 2023 and the DPDP Rules. DPDP Audits tests 67 controls mapped across 21 sections of the Act and reports the gaps, with a remediation roadmap signed off by a CISA-certified auditor.

Who needs to comply with the DPDP Act 2023?

Any organisation that processes digital personal data in India, and any organisation outside India that processes such data to offer goods or services to people in India, is a Data Fiduciary under the Act. This covers banks, NBFCs, fintechs, hospitals, e-commerce, EdTech, SaaS and most businesses that hold customer or employee data.

When do DPDP Act obligations come into force?

The DPDP Rules 2025 were notified in November 2025 with a phased rollout. Provisions setting up the Data Protection Board of India took effect immediately, Consent Manager provisions follow after 12 months, and the core Data Fiduciary obligations — notice, consent, security safeguards, breach reporting and data principal rights — apply 18 months after notification, from May 2027.

What are the penalties for non-compliance with the DPDP Act?

The Data Protection Board of India can impose penalties of up to ₹250 crore for a failure to take reasonable security safeguards to prevent a personal data breach, with other penalties scaled by the type of breach under the Schedule to the Act.

How much does a DPDP compliance audit cost?

A one-time, project-based DPDP audit costs ₹1.5 lakh to ₹3.5 lakh per engagement. Ongoing DPO advisory on a monthly retainer costs ₹25,000 to ₹45,000 per month. Prices are indicative; the final fee depends on organisation size, data volume and scope, and GST applies.

Is AI used to reach audit conclusions?

No. AI-assisted Computer Audit Tools (CAATs) gather and organise evidence and report observations only. Every compliance determination, materiality assessment and audit opinion is made personally by Ram Krishan Dudeja, CISA, in line with ISACA and IIA professional standards.

Do you offer DPDP audits across India?

Yes. DPDP Audits works with organisations Pan-India, both remotely and on-site.

Can an IS audit or CERT-IN empanelled firm partner with DPDP Audits?

Yes. Under the Annual Audit Partner model, DPDP Audits works as a sub-contractor adding a DPDP module to your existing client engagements, on a day rate of ₹18,000 to ₹28,000 or a 20–30% revenue share, with the report co-branded with your firm.

Get in Touch

Start your DPDP audit today

Send an enquiry and Ram will respond within one business day. No sales team, you speak directly with the auditor from day one.

Send an Enquiry

We use your name, organisation, email, enquiry type and message only to respond to your enquiry. By sending it you consent to this. You can withdraw consent or ask us to erase your data any time by emailing [email protected]. See our Privacy Policy.

Please verify your email above before submitting.

Responds within 1 business day · No spam · Strictly confidential