Security

    How to Build Audit Trails for DPDP

    Short Answer

    A DPDP audit trail must capture every consent event, withdrawal, rights request, data access, and vendor share — tamper-evident, time-stamped, and retrievable on demand by the Data Protection Board.

    Answer

    Audit trails are the single most important evidence businesses produce during a DPDP inquiry. A compliant audit trail records:

    1

    Consent events — who consented, to what purpose, through which channel, in which language, with what notice version, at what time.

    2

    Withdrawals and preference changes — captured with the same fidelity as consent, plus the downstream suppression confirmation.

    3

    Rights requests — access, correction, deletion, and nomination requests, with SLA timers and resolution evidence.

    4

    Data access logs — who in the organisation viewed or exported personal data, and why.

    5

    Vendor data shares — every onward transfer, with purpose, lawful basis, and DPA reference.

    6

    Breach events — detection, containment, notification, and remediation timeline.

    These logs must be tamper-evident (append-only, hash-chained or signed), retained for the legally required period, and exportable in machine-readable format for the Board.

    Law Reference

    Section 8 – Accountability of Data Fiduciary

    Business Impact

    Without an audit trail, even fully compliant businesses cannot defend themselves in inquiry. The platform-of-record approach (CMP plus immutable logs) is now considered the baseline standard.

    Real-World Example

    During an inquiry, a retailer produces a 90-day audit log proving every WhatsApp campaign was sent only to users with timestamped, purpose-specific consent, closing the case in days rather than months.

    Was this answer helpful?

    Still have questions?

    Our team is here to help you with any questions about DPDP compliance.