/Data Protection Audits & Compliance
Stay compliant, not just become compliant.
Compliance drifts. New staff, new tools, new vendors. Our audits catch the drift before a regulator, a client or a journalist does.
Fixed quote after the first callPlain-English deliverables

/What it is
What we do for you
We audit your practices against your own policies and against the Act and Rules. We test controls, sample records, interview teams and check vendors. You get a clear report with findings, ratings and fixes. For Significant Data Fiduciaries, we help you meet the yearly audit duty.
What you get
- An annual or half-yearly compliance audit
- Findings rated by risk, with owners and due dates
- Vendor and Data Processor checks
- Evidence files ready for your board, your clients or the Board
- Support for the independent audit that Significant Data Fiduciaries must arrange
/Is this for you?
This service is a good fit if…
You finished a DPDP project and want to know it stuck
Clients ask you for proof of compliance
You may be a Significant Data Fiduciary
/The law behind this
Read the actual rules, for free
Every part of this service maps to a section of the Act or a rule. Here they are on the DPDP Wiki, word for word, with plain-English notes.

/FAQ
Two quick questions
How often should we audit?
Once a year for most companies. Twice a year if you handle sensitive data or very large volumes.
Can you audit our vendors?
Yes. Vendor checks are part of the standard scope.
/Talk to a person
Ask us about data protection audits and compliance.
Tell us a little about your organisation and what is driving this. A compliance lead replies within one working day with a clear next step and, if you want one, a fixed quote.

- 25 yearsof payroll, finance and statutory compliance
- 1,000+clients across 50+ countries
- 6M+payslips a year, personal data handled with care
- 99%compliance accuracy across engagements


