Code_of_ethics_v2.0

Following the recommended introduction of a standard procedure for DPDPA audit in organizations which require multi unit audit through (AIDAI-SOP-DA-v1.2), the code of ethics has been revised. Following is the code of ethics applicable for the empanelled Independent Data Auditors of AIDAI with effect from 15th September 2026.

We request all the empanelled Data Auditors to go through and express their acceptance.

AIDAI Code of Professional Ethics for Independent Data Auditors (IDA)

Version V16092026 (Revised edition, superseding V18042026 Incorporating the conduct requirements of AIDAI-SOP-DA-v1.1)

Marking used in this document: clauses marked NEW do not appear in version V18042026; clauses marked AMENDED appear there in a different form; unmarked clauses are carried forward without change of meaning. A schedule of every change appears at the end.

Objectives

The purpose of this Code of Ethics is to guide the professional and personal conduct of AIDAI Empanelled Independent Data Auditors as they fulfil their statutory roles under the Digital Personal Data Protection Act (DPDPA) 2023.

The primary role of Independent Data Auditors is to evaluate the compliance of a Data Fiduciary with the provisions of the DPDPA 2023 and to file a report with the management of the Data Fiduciary.

However, the underlying role of the IDA is to ensure that the Data Fiduciary is in conformity with his duties as a “Fiduciary” of the “Data Principal”.

The IDA is also required to verify the technical measures, including algorithmic software, adopted by the Data Fiduciary for the processing of personal data under the scope of DPDPA 2023.

Also, the IDA is the eyes and ears of the Data Protection Board and is required to report any significant observations during the audit that have an adverse impact on the national interest and on the interests of Data Principals at large.

The IDA himself is considered as the “Fiduciary of the Data Fiduciaries” and has a duty cast on him or her to ensure that the objectives of DPDPA 2023 are fulfilled.

(NEW)  The law recognises a single enterprise-level Data Audit. But where the entity under audit conducts its personal data processing through multiple subordinate Data Processing Units , such as a bank and its branches, a university and its departments, a hospital group and its units, or any comparable structure, the enterprise audit must cover the processing at those Units before it is consolidated with the functions of the regional or central office. Such an audit ensures that where that work is divided among more than one Empanelled Data Auditor, it is governed by AIDAI-DA–SOP600, and the obligations of this Code attach to each auditor individually and are not diluted by the division of work between them.

Terminology used in this Code ( NEW SECTION)

“Lead Enterprise Data Auditor” means the Empanelled Data Auditor responsible for issuing the Data Audit Report on an entity as a whole where that report incorporates the results of the Data Audit of one or more Data Processing Units conducted by another Empanelled Data Auditor. The expression is used in DGPSI-SOP600, and in this Code, to distinguish that role from a “Lead Data Auditor”, which is the apt description where a group of data auditors of the same firm undertake an audit led by one senior person. Both are addressed by this Code; where a clause speaks of the Lead Enterprise Data Auditor it addresses the auditor who consolidates the work of auditors outside his own firm.

“Component Data Auditor” means an Empanelled Data Auditor, other than the Lead Enterprise Data Auditor, responsible for the Data Audit of a Data Processing Unit whose results are included in the consolidated report. The expressions “Central Auditor” and “Sub-Unit Auditor”, used in AIDAI’s introductory note to DGPSI-SOP600, carry the same meanings respectively.

References in this Code to DGPSI include the sectoral and functional frameworks issued under it, among them DGPSI-Banks, DGPSI-Hospital, DGPSI-Education, DGPSI-HR and DGPSI-AI.

Core Ethical Principles

Data Auditors must internalise and uphold these five foundational principles.

  • Integrity: Auditors must be straightforward and honest in all professional relationships, establishing trust as the basis for reliance on their judgment.
  • Objectivity and Independence: Professional judgments should not be compromised by bias, conflict of interest, or the undue influence of the Data Fiduciary being audited.
  • Confidentiality: Auditors must respect the value and ownership of the information they receive, ensuring it is not disclosed to unauthorised parties or used for personal gain.
  • Professional Competence and Due Care: There is a continuing duty to maintain the high-level “Techno-Legal” knowledge required to evaluate complex data governance systems.
  • National and Professional Interest: Auditors must place the interests of the nation and the profession above personal, political or religious beliefs.

Rules of Conduct

A. Integrity and Professional Behaviour

A.1               Perform all audit duties with honesty, diligence and a high standard of character.

A.2               Observe and comply with all relevant laws, specifically the DPDPA 2023 and ITA 2000, and make all disclosures expected by the law.

A.3               Avoid any conduct that might discredit the profession, or the Foundation of Data Protection Professionals in India (FDPPI), or the Association of Independent Data Auditors of India (AIDAI).

A.4               Refrain from participating in any illegal activity or discreditable act.

A.5               NEW Comply with the Standard Operating Procedures, standards and directions issued by AIDAI from time to time, including DGPSI-SOP600, in every engagement to which they apply. Compliance is a term of empanelment given by undertaking at empanelment and on each renewal, and is not a matter of individual election. [SOP600, paras 30 and 31; Annexure D]

A.6               NEW State the scope and the limitations of an audit accurately. An auditor shall not describe an opinion as covering an entity as a whole when material parts of that entity have not been audited, whether by the auditor or by another Empanelled Data Auditor whose work the auditor has used. [SOP600, paras 27 and 29]

B. Objectivity and Conflict of Interest

B.1               Maintain strict independence from the Data Fiduciary; the auditor must not have any relationship that impairs — or is presumed to impair — an unbiased assessment.

B.2               Identify and address potential threats to objectivity, such as self-interest threats, for example holding a financial interest in the client, or familiarity threats, for example a long association with the audit client.

B.3               Disclose all significant facts known to them that, if withheld, might distort the reporting of compliance results.

B.4               NEW The independence required by this Code is not satisfied merely by the auditor not being an employee of the entity. That is the minimum the law may be read to require; the standard expected of an AIDAI Certified Independent Data Auditor is the fuller independence described in clauses B.1 to B.3, and an auditor shall not represent the statutory minimum as the professional standard.

B.5               NEW In a multi-unit engagement, a Component Data Auditor shall be independent of the management of the Data Processing Unit audited, and not merely of the entity at the apex. An auditor shall decline a component appointment where the auditor’s relationship with the local management of that Unit would impair, or be presumed to impair, an unbiased assessment, notwithstanding that the appointment is made or funded centrally.

B.6               NEW Where an Empanelled Data Auditor has performed the scoping of an engagement or has validated the Implementation Charter recording management-approved deviations, that auditor shall not also conduct the audit against that Charter, save with the written concurrence of AIDAI recorded in advance. The separation exists because management-defined deviations would otherwise determine the scope of the audit that tests them.

B.7               NEW An auditor shall not accept a fee that is contingent upon the opinion expressed, upon the Data Trust Score awarded, or upon the absence of qualifications in the Data Audit Report; nor accept any benefit from the audited entity, or from a Unit of it, beyond the agreed professional fee and reimbursement of expenses.

B.8               NEW A Lead Enterprise Data Auditor shall not accept the nomination of a particular Component Data Auditor by the audited entity where the circumstances of that nomination would compromise the Component Data Auditor’s independence, and shall record the basis on which each Component Data Auditor was accepted. [SOP600, paras 13 and 32]

C. Confidentiality and Information Protection

C.1               Be prudent in protecting both physical and electronic data acquired during the course of an audit.

C.2               Do not use confidential information for personal financial gain, such as using insider knowledge for stock trading or selling proprietary data to competitors.

C.3               Maintain confidentiality even after disassociating with the organisation or finishing an audit engagement.

C.4               NEW Information exchanged between a Lead Enterprise Data Auditor and a Component Data Auditor — co-ordination letters, questionnaires, written summaries of procedures, findings and working papers — is exchanged for the purposes of the engagement alone. Each auditor owes the duty of confidentiality to the audited entity and its Data Principals, and not to the other auditor; neither auditor may use the material for any other client, engagement or purpose. [SOP600, paras 21 to 23; Annexures A and B]

C.5               NEW An auditor shall share personal data of Data Principals with a fellow auditor only to the extent necessary for the audit, preferring pseudonymised or extracted evidence to the disclosure of underlying personal data, and shall record what was shared and why.

C.6               NEW The obligation to retain working papers for the prescribed period and to produce them to AIDAI under a quality review or a disciplinary proceeding is not a breach of confidentiality, and an auditor shall not cite confidentiality to withhold them. Where the entity’s own consent is required by contract, the auditor shall have secured it in the engagement terms. [SOP600, paras 39 and 40]

D. Competence and “Techno-Legal” Excellence

D.1               Only undertake audit activities that can reasonably be completed with the necessary skills and knowledge.

D.2               AMENDED Continuously update professional expertise regarding evolving Indian frameworks, such as DGPSI (the Data Governance and Protection Standard of India) and the sectoral and functional standards issued under it, including DGPSI-Banks, DGPSI-Hospital, DGPSI-Education, DGPSI-HR and DGPSI-AI.

D.3               Contribute to the “Distributed Responsibility” of data protection by educating stakeholders on governance and risk management.

D.4               NEW Before accepting an engagement as Lead Enterprise Data Auditor, satisfy oneself that one’s own participation will be sufficient to support the consolidated opinion, having regard to the materiality of the portion of the entity’s personal data processing footprint to be audited personally, one’s knowledge of the business, data flows and information systems of the Units, the risk of material non-compliance at Units to be audited by a Component Data Auditor, and one’s ability to perform the additional procedures the SOP requires. Accepting the lead role without that capacity is a breach of this Code, whatever the commercial attraction of the engagement. [SOP600, para 11]

D.5               NEW Where a sectoral DGPSI framework applies to the entity or to a Unit within it, an auditor shall not accept the engagement without competence in that framework, and shall not substitute general familiarity with DGPSI for the sectoral standard the engagement requires.

E. Conduct in Multi-Unit Audits under DGPSI-SOP600   NEW SECTION

This Section applies to every engagement conducted under DGPSI-SOP600 and is to be read with that SOP; the paragraph references are to it. Where a Data Processing Unit is itself subdivided and its Component Data Auditor in turn uses the work of a further auditor, this Section applies between them in the same way, the Component Data Auditor then acting in the capacity of a Lead Data Auditor for that sub-tier.

E.1               NEW Reliance is not abdication. A Lead Enterprise Data Auditor who uses the work of a Component Data Auditor remains answerable for the consolidated Data Audit Report, and shall not represent to the entity, to AIDAI or to any other person that reliance on a fellow auditor displaces that responsibility. [paras 14 and 28]

E.2               NEW A Component Data Auditor shall not accept an appointment on terms that so restrict the scope of work that the resulting report would be liable to mislead the Lead Enterprise Data Auditor, and shall disclose any such restriction in writing before accepting it.

E.3               NEW A Lead Enterprise Data Auditor shall advise each Component Data Auditor, at the planning stage, of the use to be made of that auditor’s work and report, of the DGPSI control areas requiring special consideration, of the procedures for identifying inter-Unit personal data flows, and of the timetable. Withholding the context in which the work will be used is a breach of candour. [para 14(a)]

E.4               NEW A Component Data Auditor shall bring significant findings requiring attention at the entity level promptly to the notice of the Lead Enterprise Data Auditor, shall adhere to the agreed timetable, and shall respond to any questionnaire issued under the SOP on a timely basis. Findings shall not be deferred or softened for the convenience of the audited Unit or of the engagement timetable. [paras 22 and 23]

E.5               NEW Both auditors shall use the standard communication procedure prescribed by AIDAI, so that co-ordination between the Central Auditor and the Sub-Unit Auditors is capable of being evidenced. An auditor shall not substitute informal or undocumented communication for the prescribed procedure. [para 21; Annexure A]

E.6               NEW Neither auditor shall seek to influence the professional judgment of the other. A Lead Enterprise Data Auditor shall not press a Component Data Auditor to withdraw, dilute or reclassify a finding, and a Component Data Auditor shall not yield to such pressure. An unresolved difference of professional judgment shall be recorded in the working papers of both auditors and, where it bears on the consolidated opinion, reported to AIDAI.

E.7               NEW A Component Data Auditor shall consider whether the Data Processing Unit audited is itself of a character that would attract Significant Data Fiduciary obligations, and shall report that assessment to the Lead Enterprise Data Auditor. An auditor shall not treat a Unit audit as a lesser exercise by reason only that the Unit is subordinate within the enterprise.

E.8               NEW A Lead Enterprise Data Auditor shall state in the consolidated Data Audit Report the division of responsibility, indicating the extent to which Data Processing Units audited by Component Data Auditors have been included. An auditor shall not obscure that division, nor present a consolidated opinion in terms that imply personal examination of Units the auditor did not examine. [paras 27 and 29]

E.9               NEW Where a Component Data Auditor is not empanelled with AIDAI, or holds an empanelment under suspension, the Lead Enterprise Data Auditor shall independently satisfy itself of that person’s competence and independence and shall document having done so, and does so entirely at its own risk. The Lead Enterprise Data Auditor shall not represent, expressly or by implication, that AIDAI’s empanelment-based assurance extends to that person’s work. [paras 13, 19 and 32]

E.10             NEW An auditor shall not aggregate the results of unit-level audits that were not conducted against the same standard as the enterprise audit. Consistency of scope, procedures, evidence and reporting is the condition on which aggregation is professionally defensible, and an auditor who aggregates without it misrepresents the assurance obtained.

E.11             NEW Where the Lead Enterprise Data Auditor concludes that the work of a Component Data Auditor cannot be used and cannot perform sufficient additional procedures, the Lead Enterprise Data Auditor shall qualify the consolidated report, express the opinion or Data Trust Score subject to a limitation of scope, or decline to express an opinion for the entity as a whole, disclosing the reasons. An auditor shall not resolve such a difficulty by silence. [paras 25 and 26]

E.12             NEW An auditor shall not accept an engagement as Lead Enterprise Data Auditor or Component Data Auditor while the auditor’s empanelment stands suspended, shall not hold out as an AIDAI Empanelled Data Auditor during that period, and shall co-operate in the orderly handover of engagements accepted before the suspension. [paras 32 and 37]

E.13             NEW Each auditor shall retain the working papers, correspondence, questionnaires and representations arising from the engagement for not less than eight years from the date of the consolidated Data Audit Report, or such longer period as AIDAI or the DPDPA Rules may require, and shall produce them to AIDAI on request. [para 39]

E.14             NEW An auditor shall co-operate fully and promptly with any quality review undertaken by AIDAI, whether or not a complaint has been made, and shall not obstruct, delay or seek to limit such a review. [para 40]

F. Professional Conduct Between Empanelled Auditors and on the Service Exchange   NEW SECTION

F.1                NEW An auditor shall not disparage the competence or integrity of a fellow Empanelled Data Auditor to a client, a prospective client or a Data Fiduciary. A professional disagreement shall be addressed to the auditor concerned and, where it is material, to AIDAI — not used as an instrument of competition.

F.2                NEW An auditor shall not solicit the engagement of a fellow auditor in a multi-unit assignment while that engagement subsists, nor offer terms calculated to displace a fellow auditor already appointed to a Unit.

F.3                NEW An auditor who becomes aware, in the course of acting as Lead Enterprise Data Auditor or Component Data Auditor, of a departure by another Empanelled Data Auditor from this Code, from DGPSI-SOP600 or from DGPSI methodology, of a nature that could affect the reliability of a Data Audit Report, shall report the matter to AIDAI in writing within fifteen days of becoming aware of it. Failure to report is itself a breach of this Code. [SOP600, para 33]

F.4                NEW A report made in good faith under clause F.3 shall not be treated as a breach of confidentiality or of professional courtesy. An auditor shall not retaliate against, or seek to disadvantage, a fellow auditor who has made such a report.

F.5                NEW An auditor shall not make a report under clause F.3 that is false, frivolous or made for a competitive purpose; doing so is itself a breach of this Code.

F.6                NEW An auditor who offers services through the AIDAI Service Exchange, or any similar facility by which Data Fiduciaries access the services of Empanelled Data Auditors, shall describe his empanelment status, accreditation, sectoral competence and capacity accurately, and shall not hold out a competence or an availability he does not have.

F.7                NEW An engagement accepted through the Service Exchange shall be performed on the terms accepted. An auditor shall not accept an engagement he is not in a position to perform within the timetable, nor abandon a component engagement in a manner that leaves the Lead Enterprise Data Auditor unable to complete the consolidated audit.

Ethical Decision-Making Framework

In “grey area” situations where the right path is not obvious, auditors should apply a framework that involves:

  1. Identifying the ethical dilemma and the parties affected.
  2. Evaluating whether the action aligns with FDPPI’s goal of building a Secure Information Society.
  3. Consulting the FDPPI-AIDAI Governance Committee or Advisory Board when necessary.
  4. NEW Where the dilemma arises between a Lead Enterprise Data Auditor and a Component Data Auditor and cannot be resolved between them, referring the question to AIDAI before the consolidated Data Audit Report is issued, rather than after.
  5. NEW Recording the dilemma, the reasoning and the course adopted in the working papers, so that the judgment exercised can be reviewed afterwards on the basis on which it was actually made.

Enforcement and Accountability

  1. Voluntary Adoption: Every member shall voluntarily adopt this Code to enhance the intrinsic value of the profession.
  2. AMENDED Contractual Force: This Code and the Standard Operating Procedures issued by AIDAI take effect as terms of empanelment. AIDAI is a self-regulatory body constituted by FDPPI and is not a statutory authority; it derives no authority from an Act of Parliament, cannot compel testimony or the production of documents, cannot impose fines or award damages, and cannot suspend or cancel a statutory professional licence. [SOP600, paras 30 and 35]
  3. AMENDED Disciplinary Action: Failure to comply with this Code may result in investigation and disciplinary measures. Consistently with Section 8 of DGPSI-SOP600, the sanctions available to AIDAI are confined to its contractual control over empanelment: closure with no action, a written advisory or warning recorded on the Auditor’s empanelment file, suspension of empanelment for a specified period, or cancellation of empanelment. [SOP600, paras 35 and 36(d)]
  4. NEW Disciplinary Committee: AIDAI shall constitute a Disciplinary Committee, or refer the matter to any equivalent disciplinary mechanism of FDPPI, to examine complaints or references received under clause F.3, from an audited entity, from a co-Auditor, or on AIDAI’s own quality review. [SOP600, para 34]
  5. NEW Due Process: Disciplinary action shall ordinarily follow a graduated process: preliminary scrutiny to determine whether a prima facie case is disclosed; a show-cause notice giving ordinarily not less than fifteen days to respond; an opportunity of being heard if requested; a reasoned order; and a right of appeal to the Governing Council of AIDAI within thirty days, whose decision shall be final and binding for the purposes of empanelment. [SOP600, para 36]
  6. NEW Interim Suspension: Pending completion of that process, AIDAI may place an empanelment under interim suspension for a period not exceeding sixty days where the matter is serious and the integrity of the Data Audit process so requires, recording reasons in writing and giving the Auditor an opportunity to make a representation within seven days of the interim suspension taking effect. [SOP600, para 38]
  7. AMENDED Reporting Misconduct: Auditors have a duty to prevent breaches of these principles by others and must bring such instances to the notice of the appropriate authorities, and to AIDAI in the manner and within the period set out in clause F.3.
  8. NEW Effect of Suspension: During suspension an Auditor shall not accept any new engagement under DGPSI-SOP600, shall not hold out in any engagement, proposal, report or Data Trust Score certification as an AIDAI Empanelled Data Auditor, and any Data Audit Report signed during that period shall not be recognised by AIDAI as the report of an Empanelled Data Auditor, without prejudice to any liability the Auditor may separately owe to the audited entity or to any other party. Engagements accepted before the suspension shall, wherever practicable, be handed over to another Empanelled Data Auditor nominated by AIDAI, at the suspended Auditor’s cost. [SOP600, para 37]

Acceptance and Engagement Terms

P.S.: Kindly confirm acceptance on the enrolment application. Model engagement Terms are available here

AMENDED All empanelled IDAs may make use of the draft contract of engagement developed by AIDAI as part of the ethical standards. A copy will be provided on request to empanelled Accredited and Certified IDAs and to trainees of the CIDA programme. Auditors accepting an engagement as Lead Enterprise Data Auditor or Component Data Auditor should ensure that the engagement terms reflect the requirements of DGPSI-SOP600, in particular those relating to co-ordination between auditors, the standard communication procedure, retention of working papers for eight years, and their production to AIDAI on request.

Reference: FAQ on Code of Ethics