Short Answer
A DPDP audit trail must capture every consent event, withdrawal, rights request, data access, and vendor share — tamper-evident, time-stamped, and retrievable on demand by the Data Protection Board.
Audit trails are the single most important evidence businesses produce during a DPDP inquiry. A compliant audit trail records:
Consent events — who consented, to what purpose, through which channel, in which language, with what notice version, at what time.
Withdrawals and preference changes — captured with the same fidelity as consent, plus the downstream suppression confirmation.
Rights requests — access, correction, deletion, and nomination requests, with SLA timers and resolution evidence.
Data access logs — who in the organisation viewed or exported personal data, and why.
Vendor data shares — every onward transfer, with purpose, lawful basis, and DPA reference.
Breach events — detection, containment, notification, and remediation timeline.
These logs must be tamper-evident (append-only, hash-chained or signed), retained for the legally required period, and exportable in machine-readable format for the Board.
Law Reference
Section 8 – Accountability of Data Fiduciary
Without an audit trail, even fully compliant businesses cannot defend themselves in inquiry. The platform-of-record approach (CMP plus immutable logs) is now considered the baseline standard.
During an inquiry, a retailer produces a 90-day audit log proving every WhatsApp campaign was sent only to users with timestamped, purpose-specific consent, closing the case in days rather than months.
Was this answer helpful?
Our team is here to help you with any questions about DPDP compliance.