Pricoris

Is there an official DPDP certification? No. Here is what to do instead.

There is no official DPDP certification in India. As of September 2026, neither the Government of India nor the Data Protection Board of India issues a certificate of compliance with the Digital Personal Data Protection Act 2023, and no body has been accredited to issue one on their behalf. What organisations can obtain today is a compliance letter from an independent assessor, an ISO/IEC 27701 certificate that covers the DPDP Act as an applicable law, or a documented self-declaration. This article explains what each of those is worth, what the Act actually says about audits, and what we do when a client asks us for “the certificate”.

The question we are asked most

It arrives in three forms. “Do you give a DPDP certificate?” “Our customer wants proof that we are DPDP compliant.” And, from organisations that assume any compliance consultancy must be a certifying body, “Which certificate do we get at the end?”

The assumption underneath all three is reasonable. ISO standards come with certificates. PCI DSS has an attestation. GDPR, for all its complexity, at least has supervisory authorities. It is natural to expect the DPDP Act to work the same way. It does not, and the gap between expectation and law is where a lot of money is currently being spent on paper that means less than it appears to.

What the Act and the Rules actually say about DPDP certification

The DPDP Act 2023 does not contain the word “certification” in the sense buyers mean it. What it does contain is an audit obligation, and only for one class of organisation.

Section 10 lets the Central Government notify certain organisations, or classes of them, as Significant Data Fiduciaries, based on the volume and sensitivity of the personal data they process and the risk they pose. Section 10(2)(b) requires a Significant Data Fiduciary to appoint an independent data auditor to evaluate its compliance with the Act. Rule 13 of the DPDP Rules 2025, notified on 13 November 2025, adds the cadence: a Data Protection Impact Assessment and an audit once in every twelve months from the date of notification, with significant observations reported to the Data Protection Board.

Three things follow from that wording, and each of them matters to a buyer.

First, the auditor is appointed by the organisation being audited, not by the Board. There is no panel, no empanelment and no accreditation scheme in the Act or the Rules. Anyone selling “Board-accredited DPDP auditing” today is describing something that does not exist.

Second, the obligation applies only to Significant Data Fiduciaries, and as of September 2026 the Government has not notified a single one. The Section 10 obligations, including the audit, are in the tranche of the Rules that takes effect on 13 May 2027. For every other organisation in India, which is nearly all of them, there is no statutory audit at all.

Third, even when the audit obligation does bite, its output is an audit report, not a certificate. The Act asks for evidence of compliance to be produced; it does not create a badge that proves it.

So the honest position is this: for a Significant Data Fiduciary from 2027, an annual independent audit will be the law. For everyone else, and for everyone until then, compliance is demonstrated, not certified.

What is being sold instead

Because the demand for a certificate is real and the supply is nil, the market has filled the space with substitutes, and what is marketed as DPDP compliance certification is, at best, a compliance letter. They are not all equal.

Training certificates. A certificate that says an individual completed a DPDP course. Useful for the individual, and evidence that the organisation has trained its people, which the Act’s reasonable security safeguards obligation implicitly expects. It says nothing about whether the organisation itself is compliant. Some are presented to customers as if it did.

Compliance certificates from consultancies. A document from a consulting firm stating that the organisation complies with the DPDP Act. The value depends entirely on two things: what work sits behind it, and whether the firm that issued it is the same firm that did the implementation. A firm certifying its own implementation is marking its own homework. We do this work ourselves, and we hold to two rules on it, set out below.

ISO/IEC 27701. The privacy information management system standard, and the closest thing to a recognised certificate that exists. Since the 2025 revision it is a standalone standard: an organisation can certify to ISO 27701:2025 without holding ISO 27001, although the two are designed to sit together. A PIMS built to ISO 27701 has to identify the privacy laws that apply to the organisation and map its controls to them; for an Indian organisation that means the DPDP Act and Rules become part of the scope. A certificate from an accredited certification body, with the DPDP Act named in the statement of applicability, is the strongest third-party evidence currently available. It is also the most work of the four.

Self-declaration. A signed statement by the organisation’s own management that it complies, supported by its own evidence. The Act does not require it, but nothing prevents it, and for a small organisation answering a customer questionnaire it is often proportionate. Its weakness is obvious: it is the organisation vouching for itself.

The ranking, for a buyer who needs to satisfy a customer, an investor or a regulator, is roughly: accredited ISO 27701 certificate, then an independent compliance letter with a real assessment behind it, then a self-declaration with a real evidence pack behind it. A training certificate is not on the list.

What we do when a client asks for the certificate

We do not issue a DPDP compliance certificate. The phrase implies an authority we do not have and a status the law does not recognise. What we issue, where the evidence supports it, is a compliance letter: a statement that on a given date we assessed the organisation against the DPDP Act 2023 and the DPDP Rules 2025 and found it compliant, with the scope and the exceptions written in.

Two rules govern it.

The team that assesses is not the team that implemented. If Pricoris built your DPDP programme, a different Pricoris team assesses it, or we recommend you have someone else assess it. The letter is worth nothing otherwise.

The letter says exactly what was done and no more. It names the scope, the date, the evidence examined and any findings that remained open. It is a compliance letter, not a certificate, and we say so on the document.

Behind the letter is an assessment, and the assessment is where the time goes. We look at:

  • The gap assessment itself, function by function. Human resources alone typically takes two to three days, because it holds a dozen sub-processes that each touch personal data: recruitment, onboarding, payroll, leave, performance, exit. Administration, operations, marketing (campaigns and consent in particular), finance and commercial each follow. A software company building a platform adds the platform itself as a processing activity.
  • The records of processing activities. Whether they exist, whether they are complete, and whether they match what the functions actually do.
  • Consent records and the consent mechanism: notice, capture, withdrawal, and the log.
  • Data Protection Impact Assessments for any high-risk processing, whether or not the organisation is a Significant Data Fiduciary.
  • Policies and notices: privacy notice, consent procedure, legitimate uses, retention, breach response, data principal rights handling.
  • Data processing agreements with every processor, and whether they contain what the Act requires.
  • Audit reports, internal or external, that map to the requirements of the Act and the Rules.

How long the whole exercise takes depends on how much personal data the organisation holds and in how many functions. There is no fixed number and we distrust anyone who quotes one before looking.

A recent example

A client came to us this year asking for “DPDP certification” because a customer’s procurement team had put it on a questionnaire. We had not implemented their programme; another firm had. We told them what is in this article. They engaged us for a gap assessment across all functions. The assessment found the gaps, which was its purpose, and once those were closed we issued a compliance letter describing what we had examined and when. The customer’s procurement team accepted it. The client got something more useful than the certificate they asked for: a list of what was actually missing.

What changes in the next twelve months

The Section 10 obligations commence on 13 May 2027. Before that, the Government has to notify the first Significant Data Fiduciaries, and those organisations will have to appoint independent data auditors and run their first DPIA and audit cycle. That is the point at which audit practice will start to standardise: what an auditor examines, how a report is structured, what the Board expects to see. Until then, any firm claiming its certificate is “the” DPDP certificate is ahead of the law.

What will not change is the underlying logic. The Act asks organisations to be able to demonstrate compliance. A certificate, when one eventually exists in some form, will be evidence of that demonstration, not a substitute for it.

Frequently asked questions

Does the Data Protection Board of India issue DPDP compliance certificates?

No. The Board adjudicates complaints and breaches. It does not certify organisations and it has not accredited anyone to do so.

Is a DPDP training certificate proof of compliance?

No. It shows an individual completed a course. It is useful evidence of staff training, and nothing more.

Will ISO 27701 satisfy a customer asking for DPDP compliance?

Usually, yes, provided the DPDP Act is within the scope of the certified privacy information management system and the certificate is from an accredited body. Check the statement of applicability, not just the certificate.

Can the firm that implemented our DPDP programme also certify it?

It should not. Ask for a separate assessing team or a separate firm. If the same people did both, the letter tells your customer nothing they could not have got from you directly.

We are not a Significant Data Fiduciary. Do we need an audit at all?

Not under the Act. You still need to be able to demonstrate compliance if the Board or a customer asks, which is why a periodic independent assessment is sensible even where it is not mandatory.

How do we know whether we will be notified as a Significant Data Fiduciary?

You do not, until the Government notifies you or your class. The criteria in Section 10 are volume and sensitivity of data, risk to data principals, and factors such as national security and public order. Large platforms, financial services and healthcare are the obvious candidates.


Sandhya Khamesra is the Founder and CEO of Pricoris LLP, a Noida-based consultancy specialising in data privacy, cybersecurity governance and organisational resilience. She brings more than 35 years of experience across information security, privacy and risk management, combining a Chartered Accountant’s discipline with hands-on leadership of ISO implementation programmes.

She has led ISMS, PIMS, BCMS and AI governance programmes in regulated and high-risk environments across more than 35 countries. Her work spans India’s DPDP Act, the GDPR, ISO/IEC 27701 and ISO/IEC 42001, with a consistent focus on making privacy work in day-to-day delivery rather than on paper.

Sandhya is known for translating regulatory and governance requirements into practical, audit-defensible operating practice for global IT services teams. She works regularly with boards, regulators and delivery organisations to establish privacy as a professional discipline, not a legal formality.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top