Introducing DGPSI-SOP600 for enterproselevel audits

The Digital Personal Data Protection Act, 2023 (DPDPA) recognizes a legal entity as a single Data Fiduciary or Significant Data Fiduciary. But in practice,  a large organization may have hundreds or even thousands of branches, subsidiaries, regional offices, functional divisions and operational units. Each of these units may independently collect, use, store, disclose and otherwise process personal data.

In such contexts, the legal entity may be one. The data-processing reality may be many.

This creates a fundamental question for the DPDPA audit:

How does an auditor audit one enterprise when the enterprise itself operates as a collection of autonomous data-processing units?

This is the question that has led to the development of DGPSI-SOP600, a proposed Standard Operating Procedure for conducting enterprise-level data audits where a Significant Data Fiduciary has multiple sub-units.

The concept of an Independent Data Auditor is going to become an important professional function in India’s emerging data protection ecosystem.

The Association of Independent Data Auditors (AIDAI), a division of the Foundation of Data Protection Professionals in India (FDPPI), has been created with the objective of developing this professional ecosystem.

AIDAI is working towards establishing professional standards under which individuals can be trained and certified as Certified Independent Data Auditors, capable of undertaking DPDPA compliance audits and related assignments such as Data Protection Impact Assessments and Algorithmic Audits.

The objective is not merely to create another certification. The larger objective is to create confidence in the audit process itself.

One enterprise does not necessarily mean one data environment

Consider a large bank. Legally, the bank may be one entity. Operationally, however, it could have thousands of branches. Each branch may interact with customers, employees, vendors and other individuals. Each branch may generate and process personal data through its own operational processes.

The same situation can arise in:

  • hospitals and healthcare networks;
  • universities and educational institutions;
  • insurance companies;
  • large retail chains;
  • manufacturing enterprises;
  • government and public-sector organizations;
  • technology companies with multiple business divisions; and
  • multinational organizations operating through regional entities.

Some of these units may perform relatively routine processing.

Others may undertake extensive or high-risk processing.

Some may themselves have characteristics that could potentially make their operations relevant to the determination of Significant Data Fiduciary obligations.

Yet the DPDPA compliance obligation ultimately has to be viewed at the level of the legal entity to which the law applies. This creates a practical audit problem. The Central Auditor cannot simply look at the corporate headquarters and conclude that the enterprise is compliant.

The auditor needs reasonable assurance that the data-processing activities occurring across the organization have also been appropriately examined.

The “Central Auditor – Sub Unit Auditor” model

This is where the concept underlying DGPSI-SOP600 becomes important.

The proposed model distinguishes between:

1. Central or Enterprise Auditor

The Central Auditor is responsible for the overall enterprise-level audit.

The Central Auditor has to understand:

  • the organization’s governance framework;
  • enterprise-wide policies;
  • common technology platforms;
  • central data-processing activities;
  • common vendors and processors;
  • enterprise-wide security controls;
  • HR and employee-data practices;
  • privacy notices and consent mechanisms;
  • data retention and deletion practices;
  • data principal rights management;
  • incident and breach management;
  • DPIA and risk-management mechanisms; and
  • the manner in which individual business units implement these requirements.

But the Central Auditor may not be able to personally audit every operational location.

A bank with 5,000 branches cannot reasonably expect one audit team to physically conduct a complete independent audit of every branch within the annual audit cycle.

2. Sub-Unit Auditor

The Sub-Unit Auditor undertakes the audit of an identified branch, subsidiary, regional office, functional division or other autonomous data-processing unit. The Sub-Unit Auditor works against a common audit standard. The findings are then communicated to the Central Auditor in a prescribed format.

The Central Auditor can therefore use the work of appropriately qualified and independent Sub-Unit Auditors as an input into the enterprise-level audit.

This is a mechanism for creating audit scalability without sacrificing standardization.

The importance of a common audit standard

There is, however, an obvious problem to be resolved. If 1,000 branches are audited by 100 different auditors using 100 different methodologies, the Central Auditor will receive 100 different interpretations of “compliance.”

The answer lies in standardization.

FDPPI has already been developing the DGPSI – Data Governance and Protection Standard of India framework, including sector-specific and functional standards such as DGPSI-Banks, DGPSI-Hospital, DGPSI-Education, DGPSI-HR and DGPSI-AI.

These standards provide a common vocabulary and a common framework for evaluating data governance and protection practices.

AIDAI proposes to build upon this foundation by establishing a common methodology for coordination between the Central Auditor and Sub-Unit Auditors.

Thus, the objective is:

Different auditors. Different locations. One audit language. One audit methodology. One consolidated assurance framework.

Why SOP600?

DGPSI-SOP600 is being conceived as the procedural layer that sits above the individual audit standards. The DGPSI framework can tell the auditor what should be examined.

SOP600 seeks to establish how multiple auditors should work together when the organization has multiple autonomous data-processing units.

Among other things, the SOP addresses the expected procedures for:

  • identifying the units that require separate audit attention;
  • determining the scope of sub-unit audits;
  • allocation of responsibilities between Central and Sub-Unit Auditors;
  • adoption of common audit standards;
  • communication between auditors;
  • reporting of audit findings;
  • treatment of deficiencies identified at sub-unit level;
  • escalation of significant findings;
  • reliance by the Central Auditor on Sub-Unit Auditor reports;
  • consolidation of findings;
  • documentation of the basis of reliance; and
  • preparation of the final enterprise-level audit report.

The detailed standard is currently under development and will be subjected to review by the Governance Body and Advisory Group of AIDAI/FDPPI.

Independence is not enough

There is another important principle behind this initiative.

The word “independent” in the context of an auditor cannot be reduced merely to the question:

“Is the auditor an employee of the organization?”

Professional independence has a much wider dimension.

The Central Auditor must have confidence that the Sub-Unit Auditor has conducted the assignment objectively. The Sub-Unit Auditor must have confidence that the methodology being followed is consistent with the enterprise audit methodology. The organization must have confidence that different auditors are not applying different standards merely because they have different professional backgrounds.

And ultimately, the Data Protection Board and other stakeholders must be able to place reasonable reliance on the integrity of the audit process.

Therefore, AIDAI’s role as a professional self-regulatory body becomes significant.

Self-regulation as a professional responsibility

AIDAI is not presently a statutory regulator. Nevertheless, a professional body can contribute significantly to the development of professional discipline.

Through:

  • common standards;
  • auditor training;
  • certification;
  • empanelment;
  • ethical requirements;
  • quality expectations;
  • peer review;
  • professional guidance; and
  • appropriate disciplinary measures,

a professional ecosystem can be created in which an auditor’s professional reputation becomes an important component of independence and accountability.

Empanelment can also provide an institutional mechanism for dealing with serious deviations from professional standards, including suspension or dis-empanelment where appropriate.

This is similar in principle to how other professional audit ecosystems have evolved around common professional standards. The objective is not to create bureaucratic control over auditors. The objective is to create trust in the audit profession.

Can the Central Auditor “rely” on another auditor?

If a Central Auditor relies upon the audit conducted by a Sub-Unit Auditor, the Central Auditor cannot simply say:

“The branch has been audited by another auditor, so I have no responsibility.”

At the same time, it would be impractical to expect the Central Auditor to repeat the entire audit conducted by every Sub-Unit Auditor.

There must therefore be a structured basis for reliance.

The Central Auditor needs to know:

  • Who conducted the sub-unit audit?
  • Was the auditor appropriately qualified and independent?
  • What standard was followed?
  • What was the scope?
  • What evidence was examined?
  • What exceptions were identified?
  • Were significant deficiencies escalated?
  • Was the audit completed according to the prescribed methodology?
  • Were there unresolved disagreements?
  • Can the Central Auditor place reliance on the conclusions?

SOP600 seeks to provide the procedural architecture for answering these questions.

The financial audit analogy

The financial audit profession has already faced a similar scalability challenge. Large organizations cannot always be audited by one team examining every transaction and every location personally.

Professional standards and structured audit methodologies allow auditors to work with component auditors and rely, subject to appropriate procedures, on work performed at different components of an organization.

The data protection audit profession can learn from this experience. But there is an important difference namely that  a data audit involves governance, technology, people, contracts, processes, algorithms, security controls and the rights of individuals. T

herefore, the audit methodology has to evolve specifically for the data environment. SOP600 is an attempt to address precisely this emerging requirement.

From “audit of the organization” to “audit of the data ecosystem”

Perhaps the biggest conceptual change is this is that the DPDPA audit cannot remain a headquarters exercise”

The real data governance of an enterprise exists wherever personal data is processed.

The branch employee who collects KYC information.

The hospital employee who accesses patient records.

The HR department processing employee information.

The AI system making decisions based on personal data.

The outsourced processor handling customer information.

The regional office maintaining local records.

All of these are components of the organization’s data ecosystem.

Therefore, enterprise-level assurance must ultimately connect the governance at the centre with the processing at the edges.

DGPSI-SOP600: Building the bridge

DGPSI-SOP600 is being developed as a bridge between these two realities. Enterprise-level legal responsibility and distributed operational data processing.

The principle is simple “Central accountability does not mean centralized processing”.

And therefore, “Enterprise-level audit must be capable of absorbing distributed audit evidence.”

AIDAI’s objective is to create a system in which a Central Auditor can coordinate with qualified Sub-Unit Auditors, use a common methodology, evaluate their work, and consolidate the results into a credible enterprise-level DPDPA compliance assessment.

The challenge is substantial.  India is creating a new data protection regime. Along with it, India also needs to create the professional infrastructure that can make compliance assurance credible, scalable and trustworthy.

DGPSI-SOP600 is one step in that direction.

The detailed standard is presently under development and will be reviewed by the Governance Body and Advisory Group of AIDAI/FDPPI before its finalization.

The objective is not merely to produce another SOP. The objective is to build an audit system that can match the scale and complexity of India’s data-driven enterprises.

Naavi

(Comments are welcome)

Posted in Uncategorized | Leave a comment

IDPS 2026 to kick off at Delhi on September 1, 2026

IDPS or Indian Data Protection Summit is an annual flagship event of FDPPI. IDPS 2026  this year’s version will be conducted as a two location event in Delhi and Bengaluru.

The Delhi leg of IDPS 2026 will be launched on 1st September 2026 and the Bengaluru leg will take place on November 21, 2026.

Contact: enquiry@consentera.in

Posted in Uncategorized | Leave a comment

Beyond the Frontiers of DPDPA..Event in Chennai 28th September 2026

After successfully concluding the three day training program for Certified Independent Data Auditors, FDPPI is moving to Chennai to conduct a day long symposium in association with MMA on “Beyond the Frontiers of DPDPA”.

Interesting topic to be discussed during the program include AIGSI (AI Governance Standard of India), DGPSI-Banks, (Data Governance and Protection Standard of India-Banks”) and “Role of Independent Data Auditors”.

We look forward to your participation.

Naavi

Posted in Uncategorized | Leave a comment

Join the Curtain Raiser on August 16 before the CIDA on August 21

Yes this is a call to induce the FOMO feeling. Some may think I am unethical in invoking the FOMO feeling. But when some thing unique is happening and a deserving person is likely to miss out due to ignorance, it is necessary to take some efforts to ensure that decisions are based on proper information.

The virtual program on August 16 at 10.00 am ( and going upto at least 1.00 pm) is considered a “Curtain Raiser” for the 3 day program on August 21-23 happening at Fairfield Marriott in Bangalore.

Simultaneously it is meant to bridge the knowledge gap for the participants compared to those who have gone through the stage by stage training of FDPPI from CDPP-I, CDPP-G and C.DPO.DA.

Those who went through these modules had the privilege of understanding DPDPA Act, Rules, ITA 2000, GDPR etc before they plunged into C.DPO.DA. which was a common program both for the employment aspirants who wanted to be DPOs and consultants who wanted to be DPDPA auditors.

Since the immediate requirement was for implementation the need for DPOs was more urgent. The time for Independent Data Auditors is after 13th May 2027 and we are now getting ready to understand this new profession. Just as we have been advocating that Companies should start their compliance exercise without waiting for 13th May 2027 since it is a journey that requires time, the Independent Data Auditor activity is also a journey. We have started early talking about it and creating a development road map since it will take time for professionals in this space to blossom.

The program on August 21 will be the first CIDA program. Since some of the participants who are registered will be people who have not gone through the earlier programs on DPDPA and DPO conducted by FDPPI, it was considered our duty to conduct this curtain raiser program to bridge the knowledge gap that may exist. It will also be a refresher for those who have gone through the C.DPO.DA. program earlier.

Hence we are offering this program as complimentary to all those who are registered for the Aug 21 program.

Additionally, we are also offering entry to this program at a fee of Rs 3540/- to those who are not registered for the August 21 program either because they are still undecided or they want to just want to know what it would be like to be a DPO. If some body attends this program as a paid participant and later decides to attend the CIDA program, we will give them a rebate in the fees so that they will not feel that they paid more ..though they will receive more in return.

This kind of offer is unique to FDPPI and it may take time for the market to appreciate the intentions. Hence it is necessary to call out the FOMO feeling.

Let me briefly explain what we are likely to cover in the August 21-23 program.

Day Session Topic
1 1 Introduction, Role of Data Audit, Role of a Data Auditor, Distinction of a DPO and Auditor Role,Code of ethics, Engagement Contract,
1 2 Audit Principles , Evidence Collection, Audit Lifecycle, Audit Challenges in Sectors like Banks and Hospitals.  Audit aggregation. A case study.
2 1 The DPO’s challenges in Implementation of DPDPA . The consent Management framework. Use of Audit tools. Understanding organizational context and business model, stakeholder interview, designing audit checklists, sampling strategy and time budgeting. AI Governance Standard of India
2 2 Discussion on DGPSI Frameworks. A discussion with Industry experts.

DGPSI-Full, DGPSI-Lite, DGPSI-AI, DGPSI-HR, DGPSIO-DP, DGPSI Hospital, DGPSI-Banks

3 1 Lessons from the Data Governance Framework and AI Governance Framework suggested by RBI

Discussions

3 2 Audit Simulation and Role Play

Discussions

Participant feedback

Keeping the above in mind, we want to cover  Fundamentals of DPDPA and DPDPA rules and also the technical challenges faced by DPOs in the implementation such as Setting up a Governance system, Consent Management, Data Principal Rights Management, Data Breach Management, Security of DPD (DPDPA protected data) etc in the crash program on August 16.

We will not be able to repeat the basics of DPDPA and the DPO requirements when we discuss the audit requirements on Aug 21-23.

It is therefore useful for all participants to attend this e hour session to refresh their thoughts.

We are conducting this one week in advance so that during this week, the participants can go through some of the earlier library of reference videos that we will suggest and also the books , Guardians of Privacy, Wisdom companion, DGPSI and DGPSI-AI.

We hope you will not miss out this opportunity.

Naavi

 

Posted in Uncategorized | Leave a comment

Curtain raiser for the CIDA program and crash course on CEDPO.. on August 10

To facilitate that during the CIDA program all will have the required background on DPDPA and its implementation, FDPPI is conducting a curtain raiser program on 10th August 2026 (Virtual) at 10.00 am.

All persons who register for the CIDA event will have a free entry to this mini event. Others can join at a fee of Rs 3540/- including GST.

If the participants of this program later register for CIDA program, there will be a discount of the amount of Rs 3540/- from the amount payable for CIDA.

Kindly contact FDPPI for more details.

Naavi

Posted in Uncategorized | Leave a comment

MYRA-FDPPI signing of MOU..in News

The Hindu report on FDPPI-MYRA signing of MOU.

Report on MYRA-FDPPI MOU signing at knowledgereport.com

Report in Siliconindia on MYRA-FDPPI MOU signing

Report in Indiancockroach.com

Report in SouthDelhi.com

Posted in Uncategorized | Leave a comment

Be a Certified Independent Data Auditor

Posted in Uncategorized | Leave a comment

MYRA and FDPPI exchange MOU in a Press meet at Mysuru

 

Mr M L Kantharaja Urs, Management Trustee of MYRA School of Business and Naavi exchanged the MOU for collaboration, at a simple function at the Press Club, Mysuru.

A Press Release issued in the context is given below.

FDPPI and MYRA School of Business Forge Strategic Partnership to Advance Data Protection and AI Governance Education

Mysuru, 29 July 2026: In a landmark initiative to strengthen India’s capabilities in Data Protection, Privacy, AI Governance, and Digital Trust, the Foundation of Data Protection Professionals in India (FDPPI) and MYRA School of Business, Mysuru, today signed a Memorandum of Understanding (MoU) to collaborate in education, research, professional certification, and capacity building.

The MoU was formally exchanged during a press meet held at Mysuru. The agreement was signed on behalf of MYRA by Mr. M. L. Kantharaja Urs, Managing Trustee, and Dr. Ramasastry Ambarish, Director, while Na. Vijayashankar (“Naavi”), Chairman of FDPPI, represented FDPPI.

The collaboration brings together the complementary strengths of the two institutions. FDPPI, India’s premier not-for-profit professional body dedicated to Data Protection and Privacy, contributes its extensive industry expertise, practical implementation frameworks including the Data Governance and Protection Standard of India (DGPSI), and a nationwide network of professionals. MYRA School of Business, an AICTE-approved institution recognised for academic excellence and innovation in management education, contributes its academic infrastructure, research capabilities, and commitment to developing future business leaders.

Under the partnership, the two organisations will jointly design and deliver co-branded certification programmes, executive education courses, faculty development programmes, seminars, workshops, conferences, and research initiatives covering Data Protection, Privacy, Cyber Law, AI Governance, Digital Trust, and related disciplines.

Speaking on the occasion, Na. Vijayashankar (“Naavi”), Chairman of FDPPI, said:

“India’s Digital Personal Data Protection Act has created an unprecedented demand for professionals who understand the intersection of law, technology, governance, and business. This collaboration with MYRA School of Business marks an important milestone in building a robust ecosystem for high-quality education and professional certification. Together, we aim to create globally competent Data Protection Officers, Independent Data Auditors, AI Governance professionals, and Digital Trust leaders.”

Mr. M. L. Kantharaja Urs, Managing Trustee of MYRA School of Business, observed:

“At MYRA, we believe that management education must continuously evolve to address emerging societal and business challenges. Data has become one of the most valuable assets of every organisation, and responsible governance of data is now a critical leadership competency. Our collaboration with FDPPI enables us to bring industry-driven knowledge into the academic environment and offer programmes that are both relevant and impactful.”

Dr. Ramasastry Ambarish, Director of MYRA School of Business, said:

“The future belongs to professionals who can combine technological understanding with ethical and regulatory awareness. This partnership reflects MYRA’s commitment to interdisciplinary education that prepares students and working professionals for the demands of a digitally governed economy. We look forward to developing innovative learning programmes, research initiatives, and industry engagement activities jointly with FDPPI.”

The collaboration is expected to support:

    • Co-branded professional certification programmes.
    • Executive education and continuing professional development.
    • Industry-oriented curriculum development.
    • Faculty development programmes.
    • Student internships and industry immersion.
    • Collaborative research and publications.
    • Conferences, seminars, and knowledge-sharing initiatives.
    • Capacity-building programmes for industry, government, regulators, and educational institutions.

The partnership is expected to play a significant role in building India’s professional ecosystem for privacy, responsible AI, cybersecurity, and digital governance, while supporting the implementation of the Digital Personal Data Protection Act, 2023, and emerging national and international governance frameworks.

The first series of jointly developed certification programmes is expected to be announced in the coming months.

About FDPPI

The Foundation of Data Protection Professionals in India (FDPPI) is India’s leading not-for-profit professional organisation dedicated to promoting excellence in Data Protection, Privacy, Cyber Law, AI Governance, and Digital Trust. Through initiatives such as the Data Governance and Protection Standard of India (DGPSI), FDPPI has been at the forefront of developing indigenous frameworks, professional certifications, industry guidance, and capacity-building programmes supporting India’s digital transformation.

About MYRA School of Business

MYRA School of Business, Mysuru, is an AICTE-approved institution committed to creating globally competent leaders through innovative management education, research, and industry engagement. MYRA combines academic rigour with practical relevance, preparing students and executives to lead organisations in a rapidly evolving global economy.

Media Contacts

Foundation of Data Protection Professionals in India (FDPPI)
Website: www.fdppi.in

MYRA School of Business
Website: www.myra.ac.in

Posted in Uncategorized | Leave a comment

Master Class on DPO requirements

On August 21, 22 and 23, FDPPI will be conducting the first CIDA (Certified Independent Data Auditor) program in Bangalore.

It will be a physical event at Fairfield Marriott hotel in Rajaji Nagar, Bangalore (Location).

The curriculum for the event has already been published . 

Earlier we used to conduct a program under the banner C.DPO.DA which was “Certified Data Protection Officer and Data Auditor”. This program was available both for those who were aspiring to be DPOs and those who wanted to be Data Auditors. Now we have two different training and certification programs called CEDPO (Certified Elite DPO) fand CIDA (Certified Independent Data Auditor).

Since an Independent Data Auditor is some body who has to check the work of a DPO, he needs to be as much competent as a DPO in addition to his audit skills.

Considering that many of the participants of the August 21 program might not have gone through the earlier program on DPDPA and DPO requirements. We will supplement the physical CIDA program with a virtual masterclass on CEDO in a compressed form. This will be available free for those who register for CIDA till 9th August 2026. It will be held as a 3 hour session on probably 10th August 2026. (Sunday). Those who attend may also appear for the CEDPO examination by paying an examination fee of Rs 5000/-

Interested persons need to complete the registration for CIDA as early as possible. (Early Bird discount is available till 31st July 2026).

The total fee for CIDA program is Rs 30000+GST of Rs 5400 (Total Rs 35400/-)

The Early bird discounted price is Rs 25000/- +GST of Rs 4500/- (Total Rs 29500/-)

Master class : free for all registrants till 16th August 2026. Time 10.00 am

For those who have not registered for CIDA, there would be a fee of Rs 3540/- including GST. This can be adjusted with the final registration  fee for CIDA.

Examination fee Rs 5000/- (If required.

Request all to make use of this opportunity.

Naavi

Posted in Uncategorized | Leave a comment

The Era of Certified Independent Data Auditor training begins

Venue:

Fairfield Marriott, 59th C Cross, 4th M Block, Rajaji Nagar, Bengaluru, India, 560 010:

Date: August 21,22 and 23, 2026

Location

Tentative Curriculum:

Day 1:

-Introduction to the Course
-Overview of DPPA
-Challenges in implementation of DPDPA

-Challenges in Auditing of Banks

-Role of an Auditor vis-a-vis a DPO or a Consultant
-Professional independence and conflict of interest
-Legal exposure and liability of audit opinions
-Engagement acceptance and scope definition
-Ethical standards and confidentiality obligation
-Audit Principles & Methodology: (Principles of ISO 19001
-Audit lifecycle
-Evidence Collection
-Documentation standards and audit trail
-Audit Engagement Contract

Day 2:

-Understanding organisational context and business model
-Stakeholder interview
-Designing audit checklists
-Sampling strategy and time budgeting

-Frameworks (ISO + DGPSI Architecture)
-Introduction to ISO 27701 privacy information management
-DGPSI as an Indian compliance assurance framework
-DGPSI Principles
-DGPSI Full and DGPSI Lite

Day 3:

DGPSI Variants:
-DGPSI-AI — AI governance assurance
-DGPSI-HR — employee data governance audit
-DGPSI-DP — core DPDPA compliance audit
-DGPSI-Hospital-DPDPA Compliance framework for a hospital
-DGPSI-Banks

–AIGSI-AI Governance and Protection Standard of India

Audit Simulation

Certification

All participants will get participation Certificates

Online examination will be available after 15 days.  Those who pass the cut off will get the completion certification.

Certificate will be issued as FDPPI-MYRA Certified Independent Data Auditor

Fees:

Rs 30000/-+GST (Total Rs 35400/-)

Early Bird Discount Rs 5000/- upto 31st July 2026 Rs 5000/- (Net price Rs 25000+GST, Total Rs 29500/-)

REGISTRATION AND PAYMENT OF FEES

P.S: We shall provide a pre-event master class on “Requirements of being a DPO”.

Naavi

Posted in Uncategorized | Leave a comment