Join a discussion on the new concept of DPDPA Audit for Banks … and other entities with multiple Data Processing units.
Naavi
Join a discussion on the new concept of DPDPA Audit for Banks … and other entities with multiple Data Processing units.
Naavi
As part of the new developments in FDPPI, a new system of Data audit for large organizations involving multiple Branch units has been introduced.
Many major Banks like Canara Bank and SBI have already announced substantial investments in software for compliance. Many of them have also engaged the services of Big4 auditing agencies.
We are aware that neither the software companies nor the Big4 audit firms have fully integrated the concepts that FDPPI is proposing. They may also defend their current software or systems as adequate for organizations like SBI or Canara Bank.
We at FDPPI have however decided that such enterprise level audits have to follow the model of “Aggreagtion of Branch level Audits” . FDPPI has prepared its audit system for this purpose and introduced the standard procedures to make such audits to be conducted on a common standard and under a common organizational control of AIDAI.
AIDAI has actually published a new Code of Ethics for its empanelled Data Auditors which incorproates the principles of Lead Enterprise Data Auditor and Compenent Data Auditors.
We expect the Big4 to follow suit.
We hope the Banks posess the necessary knowledge to ask the right questions with their consultants to ensure that they are not finalizing compliance decisions solely because the audit is being performed by an organization which has large turnover. Going by some of the developments at NABARD and Bank of Baroda, it is difficult to be confident that there is a satisfatory level of understanding of the DPDPA problem at some of these Banks before they entered into multi crore contracts at public cost.
It will be after 2 years that we will be reviewing the effectiveness of the current decisions made by these Banks when customer complaints may start showing up at DPB.
Many of these banks may require “Peer Audit” either before completing their exercise of initial audit before 13th May 2027 or there after.
AIDAI/FDPPI however believes that we need to build a strong army of data auditors who can undertake the audits of multiple compliance units which can be aggregated into an enterprise level audit.
We are also conducting a specific training program to introduce the framework AIDAI-SOP-DA 600 and the modified Code of Ethics in our special Jnaana Vardhini session on 16th September 2026.
These will be the standards for the future and defining the course of DPDPA Compliance in India.
Naavi
(Comments are welcome)
Software is a necessary requirement of DPDPA compliance but neither it is sufficient nor the first priority.
Going by newspaper reports it appears that Banks in India are showcasing their DPDPA compliance by installing the necessary software and hardware to enable DPDPA compliance.
A report in Business Standard today indicates that SBI is targeting its compliance program to be completed by end of 2026, five months ahead of the due date for implementation. The report highlights that SBI has “Procured” software and hardware as part of its preparations for compliance and installation and deployment eis expected to be completed by Decmber.
Similarly, Canara Bank recently announced that it has awarded a contract of Rs 52 crores to a software company for DPDPA compliance.
While it is encouarging to note the large investments being committed and the desire to meet the deadline, it is not clear if Banks are adopting a path to compliance which is likely to lead them to a software dependent business model.
Most of the Banks have not completed their employee awareness program and now if they are already committing to the purchase of software, they are likely to encounter problems sooner or later when the dynamic industry needs to make changes.
Banks in India have a unique problem in DPDPA compliance since data processing occurs at hundreds of branches while the compliance may be focussed on the CBS system as if the Data Center is the unit of compliance.
What the Banks may be initially doing is to send out notices to all their current customers like the renewal of KYC and most of the investments may represent this cost. This is only one part of the requirement. What is more critical is the abilit to meet the Data Access Requests, Grievance redressal etc.
We need to be war of some of the Banking giants creating a wrong path to compliance and claiming that what they are doing only is the correct path. It will require some complaints and enquiry by DPB and appeals at TDSAT and Supreme Court before their approach gets a validity.
Let us wait and see how things proceed…
Naavi

The Digital Personal Data Protection Act, 2023 (DPDPA) recognizes a legal entity as a single Data Fiduciary or Significant Data Fiduciary. But in practice, a large organization may have hundreds or even thousands of branches, subsidiaries, regional offices, functional divisions and operational units. Each of these units may independently collect, use, store, disclose and otherwise process personal data.
In such contexts, the legal entity may be one. The data-processing reality may be many.
This creates a fundamental question for the DPDPA audit:
How does an auditor audit one enterprise when the enterprise itself operates as a collection of autonomous data-processing units?
This is the question that has led to the development of DGPSI-SOP600, a proposed Standard Operating Procedure for conducting enterprise-level data audits where a Significant Data Fiduciary has multiple sub-units.
The concept of an Independent Data Auditor is going to become an important professional function in India’s emerging data protection ecosystem.
The Association of Independent Data Auditors (AIDAI), a division of the Foundation of Data Protection Professionals in India (FDPPI), has been created with the objective of developing this professional ecosystem.
AIDAI is working towards establishing professional standards under which individuals can be trained and certified as Certified Independent Data Auditors, capable of undertaking DPDPA compliance audits and related assignments such as Data Protection Impact Assessments and Algorithmic Audits.
The objective is not merely to create another certification. The larger objective is to create confidence in the audit process itself.
Consider a large bank. Legally, the bank may be one entity. Operationally, however, it could have thousands of branches. Each branch may interact with customers, employees, vendors and other individuals. Each branch may generate and process personal data through its own operational processes.
The same situation can arise in:
Some of these units may perform relatively routine processing.
Others may undertake extensive or high-risk processing.
Some may themselves have characteristics that could potentially make their operations relevant to the determination of Significant Data Fiduciary obligations.
Yet the DPDPA compliance obligation ultimately has to be viewed at the level of the legal entity to which the law applies. This creates a practical audit problem. The Central Auditor cannot simply look at the corporate headquarters and conclude that the enterprise is compliant.
The auditor needs reasonable assurance that the data-processing activities occurring across the organization have also been appropriately examined.
This is where the concept underlying DGPSI-SOP600 becomes important.
The proposed model distinguishes between:
The Central Auditor is responsible for the overall enterprise-level audit.
The Central Auditor has to understand:
But the Central Auditor may not be able to personally audit every operational location.
A bank with 5,000 branches cannot reasonably expect one audit team to physically conduct a complete independent audit of every branch within the annual audit cycle.
The Sub-Unit Auditor undertakes the audit of an identified branch, subsidiary, regional office, functional division or other autonomous data-processing unit. The Sub-Unit Auditor works against a common audit standard. The findings are then communicated to the Central Auditor in a prescribed format.
The Central Auditor can therefore use the work of appropriately qualified and independent Sub-Unit Auditors as an input into the enterprise-level audit.
This is a mechanism for creating audit scalability without sacrificing standardization.
There is, however, an obvious problem to be resolved. If 1,000 branches are audited by 100 different auditors using 100 different methodologies, the Central Auditor will receive 100 different interpretations of “compliance.”
The answer lies in standardization.
FDPPI has already been developing the DGPSI – Data Governance and Protection Standard of India framework, including sector-specific and functional standards such as DGPSI-Banks, DGPSI-Hospital, DGPSI-Education, DGPSI-HR and DGPSI-AI.
These standards provide a common vocabulary and a common framework for evaluating data governance and protection practices.
AIDAI proposes to build upon this foundation by establishing a common methodology for coordination between the Central Auditor and Sub-Unit Auditors.
Thus, the objective is:
Different auditors. Different locations. One audit language. One audit methodology. One consolidated assurance framework.
DGPSI-SOP600 is being conceived as the procedural layer that sits above the individual audit standards. The DGPSI framework can tell the auditor what should be examined.
SOP600 seeks to establish how multiple auditors should work together when the organization has multiple autonomous data-processing units.
Among other things, the SOP addresses the expected procedures for:
The detailed standard is currently under development and will be subjected to review by the Governance Body and Advisory Group of AIDAI/FDPPI.
There is another important principle behind this initiative.
The word “independent” in the context of an auditor cannot be reduced merely to the question:
“Is the auditor an employee of the organization?”
Professional independence has a much wider dimension.
The Central Auditor must have confidence that the Sub-Unit Auditor has conducted the assignment objectively. The Sub-Unit Auditor must have confidence that the methodology being followed is consistent with the enterprise audit methodology. The organization must have confidence that different auditors are not applying different standards merely because they have different professional backgrounds.
And ultimately, the Data Protection Board and other stakeholders must be able to place reasonable reliance on the integrity of the audit process.
Therefore, AIDAI’s role as a professional self-regulatory body becomes significant.
AIDAI is not presently a statutory regulator. Nevertheless, a professional body can contribute significantly to the development of professional discipline.
Through:
a professional ecosystem can be created in which an auditor’s professional reputation becomes an important component of independence and accountability.
Empanelment can also provide an institutional mechanism for dealing with serious deviations from professional standards, including suspension or dis-empanelment where appropriate.
This is similar in principle to how other professional audit ecosystems have evolved around common professional standards. The objective is not to create bureaucratic control over auditors. The objective is to create trust in the audit profession.
If a Central Auditor relies upon the audit conducted by a Sub-Unit Auditor, the Central Auditor cannot simply say:
“The branch has been audited by another auditor, so I have no responsibility.”
At the same time, it would be impractical to expect the Central Auditor to repeat the entire audit conducted by every Sub-Unit Auditor. There must therefore be a structured basis for reliance.
The Central Auditor needs to know:
SOP600 seeks to provide the procedural architecture for answering these questions.
The financial audit profession has already faced a similar scalability challenge. Large organizations cannot always be audited by one team examining every transaction and every location personally.
Professional standards and structured audit methodologies allow auditors to work with component auditors and rely, subject to appropriate procedures, on work performed at different components of an organization.
The data protection audit profession can learn from this experience. But there is an important difference namely that a data audit involves governance, technology, people, contracts, processes, algorithms, security controls and the rights of individuals. T
herefore, the audit methodology has to evolve specifically for the data environment. SOP600 is an attempt to address precisely this emerging requirement.
Perhaps the biggest conceptual change is this is that the DPDPA audit cannot remain a headquarters exercise”
The real data governance of an enterprise exists wherever personal data is processed.
The branch employee who collects KYC information.
The hospital employee who accesses patient records.
The HR department processing employee information.
The AI system making decisions based on personal data.
The outsourced processor handling customer information.
The regional office maintaining local records.
All of these are components of the organization’s data ecosystem.
Therefore, enterprise-level assurance must ultimately connect the governance at the centre with the processing at the edges.
DGPSI-SOP600 is being developed as a bridge between these two realities. Enterprise-level legal responsibility and distributed operational data processing.
The principle is simple “Central accountability does not mean centralized processing”.
And therefore, “Enterprise-level audit must be capable of absorbing distributed audit evidence.”
AIDAI’s objective is to create a system in which a Central Auditor can coordinate with qualified Sub-Unit Auditors, use a common methodology, evaluate their work, and consolidate the results into a credible enterprise-level DPDPA compliance assessment.
The challenge is substantial. India is creating a new data protection regime. Along with it, India also needs to create the professional infrastructure that can make compliance assurance credible, scalable and trustworthy.
DGPSI-SOP600 is one step in that direction.
The detailed standard is presently under development and will be reviewed by the Governance Body and Advisory Group of AIDAI/FDPPI before its finalization.
The objective is not merely to produce another SOP. The objective is to build an audit system that can match the scale and complexity of India’s data-driven enterprises.
Naavi
(Comments are welcome)
Audio Overview
Video Overview
The developments in the IT industry after the DPDPA, represent the second instance where the attitude of people towards intangible assets is undergoing a major change.
The first such instance was when the “IP Mindset” entered the system. Now it is the time of the “Privacy Mindset.” There is an interesting similarity between the two.
The concept of Intellectual Property evolved, among other reasons, from the need to protect the interests of the creator. The objective was that the creativity of an individual should not simply be appropriated and exploited by a larger and more powerful organisation.
Thereafter, it appears that the IP law became institutionalised. Organisations became better equipped than individual creators to understand, interpret and enforce IP contracts. In many situations, what was intended to protect the creator eventually became a contractual mechanism through which the organisation acquired extensive rights over the creator’s output.
The law had not necessarily failed. But the power equation had changed. And with it, something more important was lost.-Trust.
A creative person enters an organisation because he wants to convert an idea into something useful. But if every thought he expresses is immediately viewed through the prism of ownership, assignment, confidentiality and commercial exploitation, the relationship begins to change.
The organisation starts asking: “How much can we legally own?” but the creator starts asking: “What can I safely say?”
That is a unproductive transformation indicating the breaking of trust. The moment a creative person starts believing that whatever he says may become an asset of the organisation, his natural instinct to experiment gets replaced by caution. He watches his steps firmly planted on the ground instead of flying with imagination. And innovation suffers.
This is where the emerging Privacy Mindset becomes interesting.
We are now entering a data-driven business environment in which personal data has acquired enormous economic value. The law has stepped in because, once again, there is a significant imbalance of power.
On one side is the Data Principal, who provides or generates data about himself. On the other side is the Data Fiduciary, which has the technology, resources, analytics capability and commercial motivation to derive value from that data.
The DPDPA attempts to bring discipline into this relationship. But there is a danger. If the experience of the IP world is any indication, the legal protection provided to the weaker party can gradually become a sophisticated compliance mechanism operated by the stronger party.
Today, we are impressed by the prospect of hefty penalties. Organisations are investing in privacy programmes. Consultants are being appointed. Policies are being drafted. Privacy notices are being rewritten. Consent mechanisms are being redesigned. There is a feeling that the law has finally arrived and that organisations will now think twice before exploiting personal data.
But what happens after the transition period? Will organisations simply absorb the cost of compliance? Or will they seek an ROI on privacy compliance? That is where the real test begins.
There is a specific danger that “consent” itself could become another instrument of commercialisation.
The question may gradually shift from: “Have we obtained meaningful consent?”, to:
“How much commercial value can we extract from the consent we have obtained?”
And once that happens, Privacy notices could become the new IP contracts. The lawyer’s innovation may then be directed towards designing a notice that is technically comprehensive, legally defensible and sufficiently complicated to ensure that almost every conceivable use of the data has been covered.
The individual may click: “I Agree.” And the organisation may later say: “But you consented.”
Legally, the organisation may have a point. But does that necessarily mean that the individual understood what he had agreed to?
This is where transparency and simplicity become critical. A privacy notice should not become a legal hiding place.
A document can be legally exhaustive and still be practically meaningless to the person whose data is being processed. The real question is not merely whether the organisation has obtained a legally valid consent. The question is whether the Data Principal has been given a meaningful opportunity to understand the bargain.
That distinction will determine whether the DPDPA becomes an instrument of empowerment or merely another sophisticated mechanism for legitimising exploitation.
The intention behind data protection legislation is to build trust in the digital economy. We should therefore be careful that the compliance machinery does not produce the opposite result. If a Data Principal begins to feel that his personal data has become an asset which everyone except him can monetise, the law would have achieved only partial success.
The objective is not be to prevent legitimate commercial use of data. There is nothing inherently wrong with commercial harnessing of data. But there is a yellow line between harnessing and exploitation.
We need to mark this yellow line and make the Data Principal see it. This is where organisations such as FDPPI, and frameworks such as DGPSI, have an important role to play.
The objective of Compliance and the Framework should not merely be to help organisations demonstrate that they are compliant. The objective should be to encourage a form of compliance where the organisation’s use of personal data is transparent enough that even when the organisation is commercially benefiting from the data, the Data Principal is not left with a feeling that he has been tricked into giving away something valuable.
That is a much higher standard than mere legal compliance. It is a standard of trust. Perhaps this is the real challenge before the privacy community today.
We need to build a relationship with the data principal where data can be commercially harnessed without commercially exploiting the individual. A relationship where the organisation should ask itself “What should I do with this data if I want the Data Principal to continue trusting me?”
That, is the real test of the Privacy Mindset.
Let us review after a few years and see whether the DPDPA has truly become an instrument of protecting society—or whether, like some aspects of the IP journey, it has merely given exploitation a more sophisticated legal language.
We hope DGPSI will be an instrument that assists in compliance of DPDPA without compromising on the Trust factor.
That is the objective… To make DGPSI a symbol of Trusted Personal Data Processing.
“Compliance without Compromise of Trust” should be the tag line for the DGPSI frameworks….
Naavi
An Audio Review is here: