Abstract:As an important support for the high-quality development of the digital economy in the new era, data compliance auditing focuses on conducting audits on data compliance to establish a cyclic governance system for the entire data lifecycle. This article takes the data lifecycle of ‘source collection—storage and transmission—processing and usage—destruction and archiving’ as the main thread, constructing a theoretical analytical framework for data compliance auditing. Based on a systematic explanation of its conceptual construction and practical dimensions, this article proposes four approaches to address data compliance audit risks: tracing data sources and collection compliance risks through a data map to upgrade passive auditing to active and continuous closed-loop supervision; strengthening the compliance defense of data storage and transmission through a graded authorization system to achieve continuous risk management; standardizing the compliance path of data processing and usage through a log evidence system to transform static compliance checks into dynamic technical supervision; and reinforcing the compliance barrier of data archiving and destruction through an automated management platform to achieve substantive verification at the end of the data lifecycle.