CORAA

Data Privacy (DPDP Act 2023) Compliance Audit Checklist

Tests an entity's readiness against the Digital Personal Data Protection Act 2023 — consent management, data fiduciary obligations, breach notification, and data-principal rights handling.

Free · CORAA original — SA-aligned
Updated 28 Jul 2026
Governing law
Digital Personal Data Protection Act, 2023
Role tested
Data Fiduciary obligations
Key risk
Bundled consent, no breach-notification process
Format
Microsoft Word (.docx)
Share this template
Your firm — letterhead
Appears at the top of the document as the audit firm letterhead.
Used as the letterhead block.
Engagement details
The client and period this document is for.
What’s inside

An excerpt from the template.

DATA PRIVACY (DPDP ACT 2023) — COMPLIANCE AUDIT CHECKLIST

Entity: ___ · Period: ___

Scope: tests the entity's controls as a Data Fiduciary under the Digital Personal Data Protection Act 2023 — verify the applicable provisions and their notified effective dates against the current Ministry of Electronics & IT (MeitY) notifications before relying on this for a live engagement, as the Act's rules have been notified in phases.

Conclusion

↑ Excerpt only — the full template is what you download as Word
About this template

What you’re downloading, and when to use it.

This template follows the format published by the Institute of Chartered Accountants of India (ICAI) in the AASB Audit Working Paper Templates (June 2023), the authoritative reference for Indian statutory-audit documentation. Fill in your firm’s letterhead and the engagement details on the form above, click Download Word file, and you’ll get a fully formatted .docx ready to use.

Everything is generated in your browser and on a stateless API endpoint — no account, nothing stored on our servers. We’ll ask for a work email once before your first download so we can send you the file and the occasional relevant update; after that, downloads on this device are instant. Edit freely in Word, Google Docs or Pages before sending to your client.

Common questions

FAQs.

What is a "Data Fiduciary" under the DPDP Act 2023?
A Data Fiduciary is any person or entity that, alone or with others, determines the purpose and means of processing personal data — broadly equivalent to a "data controller" in other data-protection regimes. Most companies processing customer, employee or vendor personal data are Data Fiduciaries and carry obligations around notice, consent, purpose limitation, security safeguards and breach notification.
What makes an entity a "Significant Data Fiduciary" and why does it matter?
The Central Government can notify certain Data Fiduciaries as Significant based on factors like the volume and sensitivity of personal data processed, risk to data-principal rights, and impact on India's sovereignty and electoral democracy. A Significant Data Fiduciary carries additional obligations — appointing a Data Protection Officer, conducting Data Protection Impact Assessments, and periodic independent audits — that ordinary Data Fiduciaries don't have.
Is consent bundled into general terms-of-service acceptable under the DPDP Act?
No — the Act requires consent to be specific to the stated purpose, not a blanket acceptance bundled with unrelated terms. A notice must be given in clear and plain language describing the personal data being collected and the purpose, and consent must be capable of being given, or withdrawn, with the same ease as it was given.
Related templates

You might also need.

IT General Controls (ITGC) Checklist
Free IT General Controls (ITGC) checklist for internal audit. Access management, change management, SoD, backu
Vendor Management Internal Audit Checklist
Free vendor management internal audit checklist. Tests vendor onboarding KYC, master data controls, price appr
Whistleblower / Vigil Mechanism Review Checklist — Section 177
Free whistleblower / vigil mechanism review checklist. Tests Section 177(9)-(10) Companies Act compliance — po