The Chartered Accountant | Audit September 2024 • Pages 83–87

Personal Data as Audit Evidence: Exploring the Impact of DPDPA on Audits

CA. Chetan Lunkar
Member of the Institute
With the implementation of India's Digital Personal Data Protection Act ("DPDPA"), data privacy in India will undergo a transformational change. The DPDPA, India's first comprehensive and cross-sectoral data privacy law, is a principles-based legislation that borrows significantly from the General Data Protection Regulation, 2018 ("GDPR") of the European Union. It applies to all entities processing personal data digitally, regardless of size or nature. This article analyses the potential impact of the DPDPA on Chartered Accountants ("Auditor") during financial statement audits.

Overview of DPDPA

The DPDPA applies to personal data of individuals processed in digitised form, referred to as Personally Identifiable Information ("PII"), and the individuals to whom the PII relates are designated as Data Principals. PII is broadly defined as any data about an individual identifiable by or in relation to such data, including contact numbers, email addresses, IP addresses, or credit card information.

Processing encompasses collection, use, sharing, storage, and erasure of PII. In an audit context, transcribing PII in work papers, performing substantive testing on datasets containing PII, or archiving files with PII constitutes processing.

  • Data Fiduciaries: Entities that determine the purpose and means of processing PII.
  • Data Processors: Entities that process PII on behalf of Data Fiduciaries pursuant to a contract (e.g., payroll service providers).
  • Significant Data Fiduciaries (SDF): Certain Data Fiduciaries notified based on specific criteria with enhanced obligations, such as appointing a Data Protection Officer and conducting periodic audits and Data Protection Impact Assessments.

Under DPDPA, PII can be processed based on the consent of the Data Principal or under prescribed grounds for "legitimate uses". Compared to GDPR, non-consent grounds under DPDPA are restricted mostly to government functions or health/public emergencies. Consequently, consent is the primary ground for commercial operations, requiring explicit notice prior to or upon obtaining consent. Non-compliance carries severe financial penalties, reaching up to INR 250 Crores for data breaches.

Audit Evidence

Auditors perform audits in compliance with Standards on Auditing ("SA") prescribed by the Institute of Chartered Accountants of India ("ICAI"). The SAs require auditors to obtain sufficient and appropriate audit evidence to evaluate misstatement risks and formulate an opinion.

Audit evidence includes information from both internal auditee records and external sources. Depending on whether procedure types involve direct inspection or substantive analytical data testing, PII is captured, transcribed, or retained within audit working papers. Common audit scenarios involving PII include:

  • Payroll Testing: Documenting employee names, PAN, and UAN during walkthroughs or substantive tests for Provident Fund compliance.
  • Tax Compliance: Verifying payee PAN details during substantive testing of tax deductions at source (TDS).
  • Whistleblower Review: Reviewing complaints under CARO that include names and personal identifiers of whistleblowers or implicated individuals.
  • Financial Sector Audits: Verifying and archiving Know Your Customer (KYC) documentation of borrowers.

Auditors are required to retain audit files to demonstrate compliance with SAs and legal mandates. To satisfy subjective requirements that an experienced external auditor can understand the conclusions reached, auditors generally adopt a conservative approach by retaining comprehensive audit evidence.

Auditors: Fiduciaries or Processors?

Determining whether an auditor acts as a Data Fiduciary or Data Processor under DPDPA presents distinct structural interpretations:

The Intermediary Conflict: 
Since PII is provided to auditors by auditees pursuant to statutory audit duties, it can be argued the auditee determines the purpose, making the auditee a Data Fiduciary and the auditor a Data Processor acting under an engagement letter. However, the auditor independently determines the means—deciding what data is required, how it is structured, analyzed, stored, and retained.

Under the EU GDPR framework (Guideline 7/2020 by EDPB), auditors are classified as Data Controllers (equivalent to Data Fiduciaries) because statutory independence mandates that auditors control the audit scope, information collection, and technical processing means. Applying this rationale to DPDPA, an Auditor is more likely to be classified as a Data Fiduciary rather than a Data Processor.

Exemptions under DPDPA

While DPDPA offers exemptions for State instrumentalities performing statutory functions or bodies entrusted with regulatory/supervisory roles, auditors likely cannot claim these protections:

  • State Instrumentality Exemption (§7(c)): While ICAI is a statutory body and an instrumentality of the State, individual ICAI members conducting private audits are independent professionals and not instrumentalities of the State.
  • Regulatory/Supervisory Exemption (§17(b)): Although auditors perform functions required by law, individual auditors do not constitute a "body" entrusted with legal regulatory or supervisory functions in the structural sense applicable to ICAI.

Auditor as a Data Fiduciary - Complexities & Challenges

1. Consent Mandates

Unlike GDPR, which provides non-consent legal obligation exemptions for auditors, DPDPA lacks explicit statutory audit exemptions under legitimate use. Obtaining direct consent from every Data Principal (employees, payees, customers) whose data exists in auditee records is operationally impossible for auditors. If a Data Principal refuses consent, an auditor's ability to complete audit procedures would be severely impaired.

2. Right to Erasure vs. Statutory Retention

DPDPA grants Data Principals the right to data erasure, except where retention is mandated by law. Audits governed by statutory provisions (e.g., Section 143 of the Companies Act, 2013 or Section 44AB of the Income Tax Act, 1961) require compliance with SAs mandated under Section 143(10). SAs require audit documentation retention for at least seven years. Where audits are not conducted under explicit statutory mandates, conflicts arise between DPDPA erasure mandates and standard SA documentation requirements.

3. Other Data Principal Rights

Enforcing Data Principal rights to data access, correction, and grievance redressal against auditors provides limited practical utility, as auditors process PII strictly for audit opinion formulation and not for commercial engagement with Data Principals.

Conclusion

Classifying an auditor as a Data Fiduciary introduces operational challenges that could severely impede independent financial audits. While techniques like data anonymization can reduce exposure, complete elimination of PII processing in audits is impossible. Furthermore, classifying auditors as Data Processors conflicts with their independence in determining audit means. The most practical solution would be for the Central Government to exercise its statutory powers under DPDPA to grant explicit audit processing exemptions similar to the GDPR framework.

Key Legal References

1. SA 200 - Overall Objectives of the Independent Auditor and the Conduct of an Audit in Accordance with Standards on Auditing.

2. Digital Personal Data Protection Act, 2023 - Sections 2(i), 2(k), 2(t), 2(x), 3(a), 4(1)(a), 5(1), 6(10), 7, 8, 10(2), 17, 33(1).

3. European Data Protection Board (EDPB) - Guideline 7/2020 on Concepts of Controller and Processor in GDPR.

4. Companies Act, 2013 - Section 143; Income Tax Act, 1961 - Section 44AB.

5. SQC 1 & SA 230 - Audit Documentation Requirements (7-year retention).

Author contact: clunkar@gmail.com | Editorial Board: eboard@icai.in
Published in The Chartered Accountant Journal • September 2024