(This is a guest post)
Introduction
India’s Digital Personal Data Protection Act, 2023 (‘DPDPA’ or ‘the Act’) represents a significant transformation in the legal framework governing the collection, processing[1], storage, sharing and protection of digital personal data. The Act seeks to establish a framework in which the interests and rights of Data Principals are balanced with the legitimate purposes for which personal data may be processed. For organisations, however, the enactment of a law is only the beginning. The real challenge lies in translating ‘statutory obligations’ into ‘operational processes, technological safeguards, governance structures, documented procedures and measurable outcomes.
The Digital Personal Data Protection (DPDP) Rules, 2025 further operationalise important aspects of the DPDPA framework. Particularly significant is the architecture applicable to Significant Data Fiduciaries (SDFs)[2]. Section 10 of the DPDP Act requires an SDF to appoint a Data Protection Officer (DPO)[3], appoint an Independent Data Auditor (IDA) and undertake periodic Data Protection Impact Assessments (DPIAs) and audits. Rule 13 of the DPDP Rules, 2025 provides that ‘an SDF shall, once in every period of twelve months from the date on which it is notified as such or is included in the class of Data Fiduciaries notified as such, undertake a DPIAs and an audit to ensure effective observance of the provisions of this Act and the rules made thereunder’ and ‘furnish a report containing significant observations to the Data Protection Board’. This development marks an important movement from privacy compliance as a matter of policy to privacy compliance as a matter of demonstrable accountability.
It is in this emerging environment that the Data Governance and Protection Standard of India (DGPSI)[4] developed by the Foundation of Data Protection Professionals in India (FDPPI)[5], and the emerging ecosystem of the Association of Independent Data Auditors of India (AIDAI)[6], assume importance. DGPSI seeks to provide an operational framework through which organisations can structure data governance and protection compliance, while AIDAI is developing an ecosystem for professionals engaged in independent data auditing. FDPPI describes DGPSI as a unified framework for assessing compliance with the DPDPA, the General Data Protection Regulation (GDPR) and other applicable data-protection requirements.
The distinction between the statutory and professional dimensions is important. The DPDP Act and Rules create legal obligations. DGPSI provides a voluntary implementation and assurance framework. The DPO and management administer internal compliance. The IDA provides independent assurance. AIDAI and professional programmes such as Certified Independent Data Auditor (CIDA) programme[7] contribute to the emerging professional ecosystem. Together, these elements have the potential to create an accountability architecture capable of converting statutory principles into demonstrable organisational practice.
From Privacy Policies to Demonstrable Accountability
Privacy compliance can no longer be reduced to the publication of a privacy policy, obtaining consent or adopting a set of information-security controls. A mature data-protection programme must address the entire lifecycle of personal data, – ‘starting from collection to deletion’. An organisation should have a clear understanding of the personal data it collects, the reasons for its collection, and the purposes for which it is processed. It should know where the data is stored, who has access to it, with whom it is shared, and which data processors are involved in processing it. The organisation should also determine how long the data is retained and identify the security safeguards put in place to protect it. It should have appropriate mechanisms to address and facilitate the rights of Data Principals and should clearly determine what happens to the personal data once the purpose for which it was processed has been completed. The central transformation is therefore from policy-based compliance to system-based compliance. A privacy policy may state what an organisation intends to do. Accountability requires the organisation to demonstrate that it actually does what it claims.
This distinction becomes especially important for an auditor. If an organisation states that access to personal data is restricted to authorised employees, the auditor should be able to examine role-based access controls, authorisation records and relevant logs. If an organisation states that personal data is deleted after the expiry of the retention period, the auditor should examine whether the technical and organisational systems actually support such deletion. Compliance must therefore become evidence-based.
DPDP Statutory Architecture for SDFs
Section 10 of the DPDP Act creates a distinct accountability framework for SDFs. An SDF is required to appoint a DPO who is based in India, is responsible to the Board or similar governing body and acts as a point of contact for grievance redressal. The SDF must separately appoint an independent data auditor to carry out a data audit and evaluate its compliance with the Act. Section 10 also requires periodic DPIAs and periodic audits.
The DPDP Rules, 2025 strengthen this architecture. Rule 13 requires an SDF to undertake a DPIA and audit once every twelve months from the date of its notification as an SDF or inclusion in a notified class. The person carrying out the DPIA and audit must furnish to the Board a report containing significant observations.
Rule 13 also introduces an important technology-related responsibility. An SDF must exercise due diligence to verify that technical measures, including algorithmic software used for hosting, displaying, uploading, modifying, publishing, transmitting, storing, updating or sharing personal data, are not likely to pose a risk to the rights of Data Principals.
The statutory framework may therefore be understood through three interconnected aspects. These are Governance, Risk Assessment, and Independent Assurance. Together, they provide a structured approach to compliance and accountability. The DPO represents the internal governance function. DPIA provides a structured mechanism for identifying and managing risks to Data Principals. Independent audit provides an external assurance mechanism.
Converting Legal Obligations into Operational Controls
The principal challenge after enactment of a data-protection law is implementation. Legal provisions have to be translated into business processes, technological controls, documentation, responsibilities and evidence. DGPSI seeks to address this implementation challenge.
FDPPI originally released DGPSI in 2023 as a unified framework intended to enable organisations to develop a Data Governance and Protection Management System capable of assessment and certification. FDPPI subsequently developed variants addressing different organisational and processing environments, including DGPSI-AI, DGPSI-HR and DGPSI-DP, together with sector-specific frameworks such as DGPSI-Hospital and DGPSI-Banks.
The value of such a framework lies in reducing fragmented compliance. Organisations frequently maintain separate programmes for privacy, cybersecurity, information security, data governance and regulatory compliance. A unified framework can bring these areas into a common governance architecture.
DGPSI should, however, be understood correctly. It is not a statutory substitute for the DPDP Act or the Rules. Nor should adoption of DGPSI automatically be equated with statutory compliance. It is better understood as a voluntary framework that can assist organisations in operationalising and assessing their compliance obligations. This distinction is essential for legal accuracy.
Compliance by Design and Data Governance
The most effective approach to data protection is Compliance by Design. Compliance should begin when an organisation conceptualises a new product, service, application, database or business process involving personal data, – not when an audit is announced or a regulatory notice is received.
Before personal data is collected or processed, the organisation should consider what personal data is actually required, the purpose for which it is to be processed, and the applicable legal basis. It should also determine what information must be provided to the Data Principal, who requires access to the data, and whether a Data Processor will be engaged. The organisation should identify the security safeguards required, determine how long the data should be retained, assess the risks arising from the processing, and establish how the data will be deleted or otherwise disposed of when the purpose of processing is completed. These considerations should form part of the organisation’s normal business-process design.
DGPSI can serve as an operational bridge between these legal requirements and organisational processes. Its importance therefore lies not merely in its audit potential but in its ability to encourage organisations to incorporate data governance into their ordinary management systems.
Independent Data Auditor
The Independent Data Auditor represents a new dimension of accountability under India’s data-protection regime. The statutory requirement is clear: an SDF must appoint an independent data auditor to carry out a data audit and evaluate the SDF’s compliance with the DPDP Act.
The auditor’s function must be distinguished from consultancy, DPO functions and internal audit. A consultant may assist an organisation in designing policies and controls. A DPO performs an internal governance and compliance role. An internal auditor examines controls within the organisation’s internal assurance structure. An Independent Data Auditor, by contrast, is expected to provide objective assurance concerning the organisation’s compliance. This makes independence, competence, confidentiality, professional ethics and avoidance of conflicts of interest fundamental to the credibility of the profession.
The statutory requirement for independent audit therefore creates an important professional responsibility: the auditor must be prepared to identify deficiencies even when the findings may be inconvenient to management.
AIDAI and the Emerging Data-Assurance Profession
The emergence of the AIDAI is an important institutional development. The AIDAI was established in April 2026 as a new vertical of FDPPI and described it as a pioneering initiative intended to develop the Independent Data Auditor ecosystem. Its importance lies in addressing a fundamental practical question: Who will undertake the independent data audits contemplated by the DPDP framework?
Independent data auditing requires a combination of disciplines. A competent auditor may need to understand statutory interpretation, data-protection principles, corporate governance, information-security controls, risk assessment, audit methodology, evidence collection, technology architecture, data lifecycle management, contractual arrangements with Data Processors, and organisational processes. Lawyers bring legal and regulatory expertise, while Chartered Accountants and Cost Accountants contribute audit and internal-control expertise. Company Secretaries bring governance expertise, information-security professionals contribute technical competence, and ISO auditors bring established audit methodologies. Data auditing can bring these capabilities together. AIDAI can therefore contribute to the development of a multidisciplinary Indian data-assurance profession.
CIDA and Competency-Based Independent Auditing
The professional architecture is continuing to evolve. FDPPI & AIDAI’s training restructuring distinguishes between implementation-oriented and audit-oriented professional capabilities. The Certified Executive Data Protection Officer (CEDPO) stream focuses on implementation and governance, while the CIDA programme focuses on auditing Data Governance and Protection Management Systems.
FDPPI conducted its first CIDA programme on 21–23 August 2026 in Bengaluru, marking an important step in the development of the independent data-audit profession. FDPPI describes the CIDA programme as covering audit requirements and DGPSI-related audit competencies. The CIDA curriculum also encompasses specialised DGPSI variants, including AI, HR and core DPDPA compliance auditing, together with sector-specific areas such as hospitals and banking. This development is significant because independent data auditing cannot be reduced to a checklist. An auditor must understand the organisation’s context, identify relevant risks, determine appropriate sampling, collect reliable evidence, conduct interviews, examine audit trails and form conclusions based upon objective evidence.
Professional training can therefore provide an important foundation for the development of competent auditors. At the same time, a professional certification should not be confused with a statutory appointment or statutory accreditation unless the applicable law or competent authority expressly provides for such recognition.
The roles of governance, risk assessment and independent assurance should therefore remain distinct but connected. Governance establishes responsibility, risk assessment identifies and evaluates exposure, and independent assurance tests whether the stated controls are operating effectively.
Evidence-Based Audit, DPIA and Algorithmic Governance
An effective data audit must examine the entire personal-data lifecycle. It may further examine the use and sharing of personal data, engagement and oversight of Data Processors, storage and security safeguards, retention practices, management of Data Principal rights, breach response mechanisms, and, finally, deletion or disposal of data in accordance with applicable requirements. The auditor should determine whether documented policies correspond with actual practices.
For example, where an organisation claims that personal data is deleted after a specified retention period, the auditor should examine whether deletion actually occurs. Where access is restricted to authorised personnel, the auditor should examine access permissions and relevant logs.
The audit should therefore distinguish between:
- management representations;
- documented policies;
- implemented controls;
- evidence of operation;
- auditor observations;
- identified deficiencies; and
- professional judgements.
A DPIA should not become a routine form-filling exercise. Its real purpose is to identify, assess and manage risks to the rights of Data Principals arising from high-risk processing activities. The auditor should therefore examine whether the organisation has identified all relevant high-risk processing activities and adequately mapped the flow of personal data. The auditor should also assess whether the risks to Data Principals have been properly evaluated, whether the mitigation measures adopted are proportionate to those risks, and whether the prescribed controls are actually implemented and operational. Finally, the auditor should verify whether any residual risks have been properly identified, documented and reported, so that the organisation can take informed decisions on their acceptance or further mitigation.
Algorithmic Governance
The emergence of artificial intelligence makes this responsibility even more significant. AI systems may process large volumes of personal data, generate inferences, profile individuals and influence decisions. Rule 13(3) specifically requires SDFs to exercise due diligence regarding technical measures, including algorithmic software, so that such measures are not likely to pose a risk to the rights of Data Principals.
Consequently, future data auditors will need to understand not only privacy law and databases but also algorithmic governance, AI risk and responsible use of personal data. The development of DGPSI-AI reflects this growing intersection between data protection and AI governance.
DGPSI-AI and the Emerging AI Accountability Framework
DGPSI-AI[8] represents an important evolution of the DGPSI framework in response to the growing use of artificial intelligence in processing personal data and making decisions affecting Data Principals. Its objective is not to replace DGPSI but to supplement it where AI is deployed, by introducing additional governance considerations relating to unknown risks, accountability, explainability, responsibility, security and ethics. The framework recognises that AI systems may operate with varying degrees of human intervention and may generate predictions, recommendations, inferences or content in ways that are not always fully predictable or transparent. Accordingly, AI governance should identify the person or organisation responsible for deployment, establish meaningful human oversight, assess the risks associated with the AI system, implement appropriate safeguards and guardrails, maintain evidence of the system’s operation and provide mechanisms for intervention when unacceptable risks arise.
DGPSI-AI therefore seeks to extend the principle of accountability from the protection of personal data to the responsible use of AI in the processing of such data. It also emphasises that the deployment of AI should not create an accountability vacuum merely because an algorithm or automated system is involved. The responsibility for lawful, secure and ethical processing must remain traceable to identifiable human and organisational decision-makers. In this sense, DGPSI-AI provides a practical bridge between data-protection governance and emerging AI governance, enabling organisations to move from merely asking whether AI is being used to examining how it is being used, what risks it creates, who remains accountable, what controls operate and whether the organisation can demonstrate responsible and trustworthy use of AI through evidence-based assurance.
Sector-Specific and Proportionate Data Auditing
Personal-data risks differ substantially across sectors. A hospital may process sensitive health-related information. A bank may process financial and identity information. An educational institution may process extensive student information, including children’s data. An employer processes employee information, while an e-commerce platform may process customer, transaction and behavioural information. A uniform checklist may therefore fail to identify sector-specific risks.
The emergence of specialised DGPSI frameworks is significant in this context. FDPPI identifies specialised variants addressing areas such as AI, HR, hospitals and banks.
Sector-specific expertise should, however, operate within common principles of: Independence + Evidence + Risk + Accountability + Continuous Improvement. At the same time, compliance must remain proportionate.
Small and medium enterprises increasingly depend on cloud services, payment platforms, CRM systems, HR applications and outsourced processors. They may process substantial quantities of personal data without maintaining dedicated privacy departments.
A proportionate framework such as DGPSI-Lite can assist smaller organisations in developing structured governance without unnecessarily imposing the architecture of a large enterprise upon them. The objective should be risk-based compliance, not compliance by excess.
Independence, Ethics and Professional Standards
The credibility of independent data auditing will ultimately depend upon the reality of auditor independence. An auditor who designs an organisation’s privacy controls and subsequently audits or certifies those same controls may face a conflict of interest. The separation between implementation and independent assurance must therefore be meaningful.
A professional framework for Independent Data Auditors should comprehensively address the requirements relating to competence and independence, while ensuring appropriate safeguards against conflicts of interest. It should also establish standards for confidentiality, evidence collection, sampling, documentation and audit methodology. The framework should further provide for professional liability, ethical conduct and quality assurance, together with mechanisms for continuing professional education so that auditors remain adequately equipped to respond to evolving legal, technological and data-governance requirements.
The audit report should clearly distinguish between facts established by evidence, management representations, auditor findings, non-compliance, improvement opportunities and matters involving professional judgement.
Such discipline is essential if independent data auditing is to develop the credibility associated with established audit professions.
An audit should not become merely another commercial certification exercise. Its value lies in the willingness of the auditor to report deficiencies objectively and to withstand pressure to dilute adverse findings.
Audit, Assessment, Certification and Consultancy
One of the emerging challenges is the tendency to use the terms audit, assessment, certification and consultancy interchangeably. They are not identical.
Consultancy assists an organisation in designing or implementing controls. Assessment determines the status or maturity of an organisation against specified criteria. Audit involves a systematic and evidence-based examination leading to an assurance conclusion. Certification involves formal attestation against defined certification requirements. This distinction is particularly important in the context of DGPSI.
FDPPI describes DGPSI as a unified framework that can be used to assess an organisation’s compliance with data-protection requirements. FDPPI has also developed a certification ecosystem around the framework; however, its current certification information notes that earlier accreditations have expired and require renewal.
Accordingly, organisations should avoid treating a DGPSI assessment or certificate as automatically equivalent to statutory compliance under the DPDP Act.
The legal test remains compliance with the Act and the Rules. DGPSI can provide a structured mechanism for implementing and evaluating that compliance.
From Audit Findings to Continuous Improvement
The objective of an audit should not be merely to label an organisation “compliant” or “non-compliant”.
A mature audit should not merely record observations but should identify the strengths of the organisation, the deficiencies that require attention, the corresponding levels of risk and their root causes. It should also specify the corrective actions required, identify the responsible officers, prescribe appropriate timelines for implementation, and clearly indicate the evidence required to establish closure of each identified issue. The process should therefore not end with the submission of the audit report, but should extend to effective implementation, verification and closure of the corrective measures.
The audit process should proceed through a structured sequence beginning with the identification of the finding and determination of its root cause, followed by formulation of the appropriate corrective action. This should be followed by implementation of the corrective measures, verification of their effectiveness, and formal closure of the identified issue. The process should thereafter continue through ongoing monitoring to ensure that the corrective measures remain effective and that similar deficiencies do not recur.
This converts the audit from a periodic inspection into a mechanism for organisational learning.
Privacy compliance is not static. A previously compliant organisation may become exposed to new risks following the introduction of an AI system, a new product, a merger, a new vendor, a cybersecurity incident or a change in processing purpose.
The objective should therefore be continuous compliance rather than one-time certification.
Framework-based maturity measures, including the Data Trust Score concept associated with FDPPI’s DGPSI architecture, may assist organisations in monitoring improvement. Such measures should, however, be regarded as management and maturity indicators rather than statutory measures prescribed by the DPDP Act.
A Practical Organisational Model for Continuous Assurance
An organisation seeking to institutionalise data protection may adopt a nine-stage governance cycle.
Stage 1 — Governance: The Board or senior management establishes responsibility for data governance and identifies the organisation’s obligations as a Data Fiduciary.
Stage 2 — Data Mapping: The organisation identifies personal-data assets, processing activities, Data Principals, purposes, Data Processors, data flows, retention periods and access controls.
Stage 3 — Framework Adoption: An appropriate framework, such as DGPSI or a suitable specialised variant, may be adopted as an internal compliance-management reference.
Stage 4 — Implementation: Privacy notices, procedures, contracts, security safeguards, consent mechanisms where applicable, grievance systems, retention policies and deletion processes are implemented.
Stage 5 — Risk Assessment and DPIA: High-risk processing is identified and subjected to appropriate DPIA and risk-management processes. For SDFs, the annual DPIA and audit requirement under Rule 13 must be incorporated into the governance calendar.
Stage 6 — Internal Governance: The DPO and relevant business, legal, IT, cybersecurity and compliance teams periodically review implementation and initiate corrective action.
Stage 7 — Independent Audit: An appropriately qualified and independent data auditor undertakes the statutory or otherwise applicable data audit.
Stage 8 — Corrective Action: Management responds to audit findings through documented corrective and preventive measures.
Stage 9 — Continuous Monitoring: The organisation monitors the implementation of its data-governance measures, verifies the effectiveness of corrective actions and periodically reassesses its level of data-governance maturity. The resulting cycle may be understood as a continuous process of governing, mapping, assessing, implementing, monitoring, auditing, remediating, verifying and improving data-governance practices. This approach transforms data protection from an annual paperwork exercise into a continuous governance process focused on sustained compliance, accountability and improvement.
The Road Ahead
The year 2026 marks an important stage in the development of India’s data-assurance ecosystem. India will need robust professional standards for data protection auditors. These standards should ensure auditor independence and prescribe clear competency requirements. They should also specify the manner in which audit evidence is collected, samples are selected and audit work is documented. The standards should provide clear requirements for audit reporting and quality review. They should also address confidentiality, conflict-of-interest management and professional liability. Continuous professional education should be required to ensure that auditors remain updated with changes in technology, data protection practices and the legal framework.
In this context, DGPSI and independent data auditing have complementary but distinct roles. DGPSI can provide an operational framework for translating data-protection principles into organisational systems. The DPO and management can administer and monitor those systems. DPIAs can identify and manage risks. Independent Data Auditors can provide objective, evidence-based assurance. AIDAI can contribute to developing the professional ecosystem necessary for this emerging assurance function, while CIDA represents an important step towards structured competency development.
The journey may therefore be understood through seven simple but interconnected propositions: an organisation must first know the data it holds and processes, understand the purpose for which the data is processed, assess the associated risks, implement appropriate controls, preserve adequate evidence of compliance, subject its practices to independent audit and assurance, and continuously improve its data-governance processes. This provides a practical pathway from statutory compliance to demonstrable accountability and, ultimately, from accountability to greater trust in India’s digital economy.
[1] DPDPA, Sec. 2. In this Act, unless the context otherwise requires,- (x) “processing” in relation to personal data, means a wholly or partly automated operation or set of operations performed on digital personal data, and includes operations such as collection, recording, organisation, structuring, storage, adaptation, retrieval, use, alignment or combination, indexing, sharing, disclosure by transmission, dissemination or otherwise making available, restriction, erasure or destruction.
[2] DPDPA, Sec. 2. (z) “Significant Data Fiduciary” means any Data Fiduciary or class of Data Fiduciaries as may be notified by the Central Government under section 10.
[3] DPDPA, Sec. 2. (l) “Data Protection Officer” means an individual appointed by the Significant Data Fiduciary under clause (a) of sub-section (2) of section 10.
[4] Visit https://www.naavi.org/wp/dgpsi/
[5] Visit https://fdppi.in/wp/
[6] Visit https://aidai.org.in/wp/










