Monthly Archives: June 2026

Peer Review as a Quality Assurance Mechanism for Independent Data Auditors

(This is a continuation of the series of articles on Independent Data Auditors which emanated from the Event on June 6) Financial audit professionals have long relied on a system of Peer Review Audits to preserve the integrity, credibility, and … Continue reading

Posted in Privacy | Leave a comment

Should Management Alone Define the Scope of a DPDPA Audit?

(This is in continuation of the previous article) In the previous article, we discussed the distinction between the objectives of the CISO and the DPO. The same distinction raises a broader question regarding the independence of DPDPA audits. If a … Continue reading

Posted in Privacy | Leave a comment

Why the CISO and DPO May Not Be Natural Substitutes

(ThisĀ  is a continuation of the previous article) During recent discussions on the role of Independent Data Auditors, an interesting debate emerged regarding whether a Chief Information Security Officer (CISO) can effectively discharge the responsibilities of a Data Protection Officer … Continue reading

Posted in Privacy | Leave a comment

Independence in DPDPA Compliance: Two Questions We Need to Answer

The discussions held on June 6th regarding the role of Independent Data Auditors under DPDPA 2023 generated a number of insightful observations. Among them, two issues stood out as being particularly significant for the future evolution of DPDPA compliance and … Continue reading

Posted in Privacy | Leave a comment

Does POSH Compliance clash with DPDPA Compliance?

The potential conflict between the implementation of the Digital Personal Data Protection Act, 2023 (DPDPA 2023) and the Right to Information Act has already been recognized and is currently under consideration before the Supreme Court. However, another important area of … Continue reading

Posted in Privacy | Leave a comment

Independent Data Auditors..Should they be rotated every 2 or 3 years?

In continuation of our discussions on how to maintain independence of the “IndependentĀ  Data Auditors” in a DPDPA compliance scenario, we discussed the need for share holders to approve the appointment so that the auditor does not feel obligated to … Continue reading

Posted in Privacy | Leave a comment