Appendix A — Registry of Sections and Rules
A.1 Reading and maintaining the canonical view
This appendix and Chapter 2’s operational-alias view are generated from research/legal/CANONICAL_PROVISION_REGISTER.json. Every displayed row resolves to a full record containing exact primary passage, physical newline range, URL, source version, instrument date, PDF/text SHA-256, commencement source, actor, trigger, conditions, exceptions, author interpretation and review status. Physical source lines are counted by newline; a PDF form feed does not create another numbered line. The small table is navigation to this populated register, not a replacement for its exact legal text.
A hash establishes source identity, not correctness of interpretation. author primary-text checked is not counsel approval. No claimed portal operation, appointment, supplier test or customer outcome can be established by these hashes. Implementation evidence must be supplied separately. The source manifest in out/remediation/Q02/source-manifest.json preserves reviewed URLs, dates and actual file hashes without altering Q01’s retained originals.
The Act’s first tranche is Section 1(2), Section 2, Sections 18 to 26, Section 35, Sections 38 to 43 and Section 44(1),(3), from 13 November 2025. The register’s whole-section summaries for Sections 1/6/27/44 must be read with these sub-provision splits: Section 6(9) and Section 27(1)(d) are scheduled for 13 November 2026; Sections 3 to 5, Section 6(1)–(8),(10), Sections 7 to 17, Section 27 except (1)(d), Sections 28 to 34, Sections 36 to 37 and Section 44(2) for 13 May 2027. A generic whole-section date is not authority to erase a mixed commencement (COMM:49–59[5]).
Rules 1,2,17–21 commence on publication, 13 November 2025; Rule 4 one year later; Rules 3,5–16,22,23 eighteen months later. The printed Gazette date controls this retained baseline, not an upload code. A designation-dependent duty can have a scheduled commencement but remain inapplicable to an undesignated entity. Conversely, an institution can be legally established without proof that named members were appointed or a receiving channel operates.
All following table summaries are author paraphrases with statutory commencement baselines. The exact factor quotation is separately labelled. Chapter references are navigation to the book’s intended operating discussion, not an assertion that every downstream chapter has completed remediation.
A.2 Act sections 1–44
| ID / provision | Actor; trigger | Conditions and limits (author paraphrase) | Commencement |
|---|---|---|---|
| ACT-1 / Section 1 | Central Government; Commencement by Gazette notification | Different provisions may have different dates; reference to commencement follows the provision. No blanket commencement inferred. | 2025-11-13 |
| ACT-2 / Section 2 | All statutory actors; Interpretation of defined terms | Child: below 18; fiduciary: alone or jointly determines purpose and means; processor: acts on behalf; breach: CIA-compromising unauthorised processing or specified accidental events. Unless context otherwise requires. | 2025-11-13 |
| ACT-3 / Section 3 | Person processing digital personal data; India processing or offshore goods/services connection | Includes later-digitised collection; offshore nexus is principals within India, not Indian citizenship. Individual personal/domestic use; principal-made public data or legally obliged publication by another. | 2027-05-13 |
| ACT-4 / Section 4 | Person processing personal data; Processing | Lawful purpose plus consent or a section 7 use. Subject to other applicable provisions and exemptions. | 2027-05-13 |
| ACT-5 / Section 5 | Data Fiduciary; Consent request; prior consent before commencement | Notice data/purpose, withdrawal/grievance and Board-complaint means; legacy notice as soon as reasonably practicable; English/Eighth Schedule option. s5(2)(b) permits legacy processing until withdrawal; applicable s17 exemptions. | 2027-05-13 |
| ACT-6 / Section 6 | Data Principal; Data Fiduciary; Consent Manager; Consent-based processing, withdrawal, CM registration, or disputed consent | Specific informed affirmative necessary-data consent; comparable ease of withdrawal; reasonable-time cessation with lawful exceptions; separate registration and burden of proof. Invalid consent parts ineffective; prior processing remains lawful; s6(6) permits required/authorised non-consent processing. | mixed: s6(9) 2026-11-13; s6(1)-(8),(10) 2027-05-13 |
| ACT-7 / Section 7 | Data Fiduciary; State-specific actors in (b)/(c); Facts satisfy a listed use | Complete (a)-(i) subrows govern; there is no s7(1)(h). No open-ended commercial legitimate-interest ground. | 2027-05-13 |
| ACT-8 / Section 8 | Data Fiduciary; Processing by it or its processor | Responsibility despite agreements/principal default; valid processor contract; conditional data accuracy; safeguards; breach intimation; erasure; contact and grievance mechanism. s8(7) lawful-retention exception; s17 preserves s8(1),(5) under subsection (1). | 2027-05-13 |
| ACT-9 / Section 9 | Data Fiduciary; Central Government for notifications; Child data or covered disability/guardian processing | Verifiable parent/guardian consent before processing; no detrimental child effect; no tracking/behavioural monitoring/targeted child advertising. s9(4) prescribed classes/purposes/conditions and s9(5) notified verifiably safe processing relax only (1)/(3), not (2). | 2027-05-13 |
| ACT-10 / Section 10 | Central Government; notified SDF; Notification of fiduciary or class following relevant-factor assessment | India-based individual DPO responsible to governing body; independent auditor; periodic DPIA/audit and prescribed measures. Not automatic from scale/sensitivity; designation and effective timing matter. | 2027-05-13 |
| ACT-11 / Section 11 | Data Principal; said Data Fiduciary; Request after prior consent including s7(a) | Summary of data/activities; identities and shared-data description; prescribed further information. s11(2) excludes (1)(b)/(c) for qualifying written requests by law-authorised fiduciaries for specified offence/cyber purposes. | 2027-05-13 |
| ACT-12 / Section 12 | Data Principal; Data Fiduciary; Correction/completion/update/erasure request within prior-consent including s7(a) scope | Correct inaccurate/misleading data; complete and update; erase on prescribed request. Retention necessary for specified purpose or compliance with law in (3). | 2027-05-13 |
| ACT-13 / Section 13 | Data Fiduciary or Consent Manager; Data Principal; Grievance about obligations or rights | Readily available grievance means; respond within prescribed period; exhaust opportunity before Board. Applicable exemptions; not a uniform deadline for all rights services. | 2027-05-13 |
| ACT-14 / Section 14 | Data Principal and nominated individual; Death or incapacity activates nomination | Nominee exercises principal rights; incapacity defined by inability due to unsound mind/infirmity of body. Rule14(4), terms of service and applicable law govern implementation. | 2027-05-13 |
| ACT-15 / Section 15 | Data Principal; Exercise of rights and provision of data | Comply with laws; no impersonation, suppression of specified material information, false/frivolous complaint; authentic correction/erasure information. Does not remove fiduciary responsibility: s8(1). | 2027-05-13 |
| ACT-16 / Section 16 | Central Government; Data Fiduciary; Offshore processing/transfer | Government may notify destination restrictions. s16(2) preserves higher protection/restriction in other Indian law for transfers. | 2027-05-13 |
| ACT-17 / Section 17 | Actors specified in exemption subrows; Clause-specific conditions or notifications | Differently scoped disapplications in (1)-(5); see complete subrows. Not all exemptions are partial, and not all have an identical necessity test. | 2027-05-13 |
| ACT-18 / Section 18 | Central Government; Board; Notified establishment | Corporate body; notified headquarters. Institutional establishment does not commence all substantive powers. | 2025-11-13 |
| ACT-19 / Section 19 | Central Government; Chairperson and Members; Composition and appointment | Chairperson plus notified other membership; prescribed appointments; listed expertise, at least one law expert. No individual appointed by composition notification alone. | 2025-11-13 |
| ACT-20 / Section 20 | Chairperson and Members; Appointment/service | Prescribed remuneration not varied to disadvantage; two-year term, reappointment eligible. Other service rules apply. | 2025-11-13 |
| ACT-21 / Section 21 | Central Government; Chairperson and Members; Disqualification/removal | Specified insolvency, conviction, incapacity, interests, abuse grounds; hearing before removal. Conviction involves moral turpitude in Government opinion. | 2025-11-13 |
| ACT-22 / Section 22 | Chairperson, Members; Central Government; Resignation, vacancy, cessation | Effective at earliest listed event; fresh appointment; one-year employment restriction/approval and later fiduciary-employment disclosure. Prior Government approval exception. | 2025-11-13 |
| ACT-23 / Section 23 | Board; Chairperson and Members; Meetings/proceedings; Chairperson inability | Prescribed meeting/authentication procedure; senior-most Member acts during inability. Listed defects do not invalidate merely by their existence. | 2025-11-13 |
| ACT-24 / Section 24 | Board; Central Government; Officers/employees appointment | Previous Central Government approval and prescribed conditions. Not an unrestricted hiring power. | 2025-11-13 |
| ACT-25 / Section 25 | Chairperson, Members, officers/employees; Acting/purporting to act under Act | Deemed public servants under cited law. Classification provision, not a new general criminal offence. | 2025-11-13 |
| ACT-26 / Section 26 | Chairperson; Board administration/case allocation | Superintendence; authorise scrutiny and allocate functions/proceedings. Underlying function still needs applicable statutory power/commencement. | 2025-11-13 |
| ACT-27 / Section 27 | Board; Listed intimation, complaint, reference or court direction | Breach mitigation/inquiry/penalty functions; consent-manager complaint vs registration breach are distinct; hearing/reasons for directions. s27(1)(d) separately commences; later penalties/procedure remain staged. | mixed: s27(1)(d) 2026-11-13; remainder 2027-05-13 |
| ACT-28 / Section 28 | Board; Receipt of s27 material and sufficient grounds for inquiry | Independent digital design; recorded reasons/natural justice; listed civil-court powers; hearing and completion route to s33. No premises-access prevention or equipment custody adversely affecting day-to-day functioning; insufficient grounds close; frivolous complaints costs/warning. | 2027-05-13 |
| ACT-29 / Section 29 | Aggrieved person; Appellate Tribunal; Board order/direction appeal | 60 days from receipt; prescribed form/fee; hearing; endeavour disposal in six months; digital design. Late appeal if sufficient cause; record reasons beyond six months. | 2027-05-13 |
| ACT-30 / Section 30 | Appellate Tribunal; civil court; Execution of tribunal order | Executable as decree; may transmit to competent local civil court. Read within specified execution route. | 2027-05-13 |
| ACT-31 / Section 31 | Board; parties; mediator; Board considers complaint mediable | May direct attempted mediation with mutually agreed/statutory mediator. Not mandatory settlement or erasure of other duties. | 2027-05-13 |
| ACT-32 / Section 32 | Board; person giving undertaking; During s28 proceeding | Voluntary action/abstention/publicity undertaking; consensual variation; bar on proceedings as to contents. Breach of accepted term is deemed breach; hearing then s33 route. | 2027-05-13 |
| ACT-33 / Section 33 | Board; person found in significant breach; Conclusion of inquiry, significant breach and hearing | May impose scheduled penalty; seven statutory factors. Discretionary maximum, no fixed multiplier from mitigation. | 2027-05-13 |
| ACT-34 / Section 34 | Board / public treasury; Penalty sums realised | Credit Consolidated Fund of India. Not compensation payable to affected principals under this provision. | 2027-05-13 |
| ACT-35 / Section 35 | Government, Board and specified officials; Good-faith action/intended action | Protection from suit/prosecution/other proceedings. Good-faith and statutory-action scope. | 2025-11-13 |
| ACT-36 / Section 36 | Central Government; Board/fiduciary/intermediary recipients; Government calls information for Act purposes | May require listed recipients to furnish information. Not a Board power under this section. | 2027-05-13 |
| ACT-37 / Section 37 | Central Government/authorised officer; intermediary; Written Board reference on two or more penalties plus public-interest blocking advice | Fiduciary hearing; necessity/expediency; written reasons; blocking direction; intermediary compliance. Not an automatic shutdown following a single breach. | 2027-05-13 |
| ACT-38 / Section 38 | Concurrent-law decision maker; Concurrent law; actual conflict | Act in addition/not derogation; Act prevails to extent of conflict. s16(2) is a separate transfer-specific saving. | 2025-11-13 |
| ACT-39 / Section 39 | Civil courts/courts/other authorities; Matter Board empowered to address or action under Act powers | Civil-jurisdiction bar and injunction restriction as written. Do not infer exclusion of constitutional judicial review from this author summary. | 2025-11-13 |
| ACT-40 / Section 40 | Central Government; Rulemaking | Notification subject to previous publication; rules not inconsistent; delegated subjects listed. Delegated subject list does not itself create a substantive clock. | 2025-11-13 |
| ACT-41 / Section 41 | Central Government; Parliament; Rules and ss16/42 notifications | Lay before both Houses for total 30 days; modification/annulment process. Prior acts protected as specified. | 2025-11-13 |
| ACT-42 / Section 42 | Central Government; Gazette amendment of penalty Schedule | Maximum increase capped at twice originally enacted penalty; effective date of notification. Requires notification, not s33 mitigation arithmetic. | 2025-11-13 |
| ACT-43 / Section 43 | Central Government; Difficulty implementing Act | Gazetted consistent provisions; order laid before Houses. No order after three years from applicable commencement. | 2025-11-13 |
| ACT-44 / Section 44 | Legislature / affected enactments; Phased consequential amendments | TDSAT, IT Act and RTI amendments. 44(2) delayed; 44(1),(3) immediate tranche. | mixed: s44(1),(3) 2025-11-13; s44(2) 2027-05-13 |
A.3 Decision-critical subrows: registration, grounds and exemptions
Section 6(9) concerns every Consent Manager registering with the Board. Section 6(10) separately places notice/consent proof on the fiduciary when questioned in a proceeding. Neither is an SDF-only consent-record provision. Section 7 is (a)–(i), not an invented subsection list; exact clauses and rejection examples are in Chapter 3. Corporate restructuring belongs in conditioned Section 17(1)(e).
| ID / provision | Actor; trigger | Conditions and limits (author paraphrase) | Commencement |
|---|---|---|---|
| ACT-6(9) / Section 6(9) | Consent Manager; Seeking/holding statutory CM status | Every Consent Manager registered with Board under prescribed conditions. Registration and rights-channel tranches differ. | 2026-11-13 |
| ACT-6(10) / Section 6(10) | Data Fiduciary; Consent basis questioned in a proceeding | Prove notice and consent in accordance with Act/Rules. Not universally imposed on SDF alone. | 2027-05-13 |
| ACT-7(a) / Section 7(a) | Data Fiduciary; Qualifying use under s7 | Specified purpose; principal voluntarily supplied her data; no indication of non-consent. Must satisfy s4 and other applicable obligations; this clause is not blanket immunity. | 2027-05-13 |
| ACT-7(b) / Section 7(b) | State or instrumentality; Qualifying use under s7 | Prescribed subsidy/benefit/service/certificate/licence/permit; prior consent for one such benefit OR data in notified State-maintained document; policy/law standards. Must satisfy s4 and other applicable obligations; this clause is not blanket immunity. | 2027-05-13 |
| ACT-7(c) / Section 7(c) | State or instrumentality; Qualifying use under s7 | Function under Indian law OR sovereignty/integrity/security interest. Must satisfy s4 and other applicable obligations; this clause is not blanket immunity. | 2027-05-13 |
| ACT-7(d) / Section 7(d) | Person under disclosure obligation; Qualifying use under s7 | Indian law requires disclosure to State/instrumentality; comply with other law disclosure provisions. Must satisfy s4 and other applicable obligations; this clause is not blanket immunity. | 2027-05-13 |
| ACT-7(e) / Section 7(e) | Person complying with judgment/decree/order; Qualifying use under s7 | Indian-law judgment/decree/order OR foreign judgment/order concerning contractual/civil claims. Must satisfy s4 and other applicable obligations; this clause is not blanket immunity. | 2027-05-13 |
| ACT-7(f) / Section 7(f) | Data Fiduciary responding to emergency; Qualifying use under s7 | Threat to life or immediate health threat to principal or another individual. Must satisfy s4 and other applicable obligations; this clause is not blanket immunity. | 2027-05-13 |
| ACT-7(g) / Section 7(g) | Data Fiduciary taking health measures; Qualifying use under s7 | Medical treatment/health services during epidemic, outbreak or other public-health threat. Must satisfy s4 and other applicable obligations; this clause is not blanket immunity. | 2027-05-13 |
| ACT-7(h) / Section 7(h) | Data Fiduciary taking safety/assistance measures; Qualifying use under s7 | Disaster per referenced statute or public-order breakdown. Must satisfy s4 and other applicable obligations; this clause is not blanket immunity. | 2027-05-13 |
| ACT-7(i) / Section 7(i) | Data Fiduciary processing for employment/employer protection; Qualifying use under s7 | Employment or safeguarding employer from loss/liability, with listed examples and employee-sought service/benefit. Must satisfy s4 and other applicable obligations; this clause is not blanket immunity. | 2027-05-13 |
| ACT-17(1)(a) / Section 17(1)(a) | Person enforcing legal right/claim; Qualifying processing | Necessary to enforce any legal right or claim. Chapter II except s8(1),(5), Chapter III and s16 disapplied; s8(1),(5) remain. | 2027-05-13 |
| ACT-17(1)(b) / Section 17(1)(b) | Indian court, tribunal or legally entrusted judicial/quasi-judicial/regulatory/supervisory body; Qualifying processing | Necessary to perform that function. Chapter II except s8(1),(5), Chapter III and s16 disapplied; s8(1),(5) remain. | 2027-05-13 |
| ACT-17(1)(c) / Section 17(1)(c) | Person processing for stated enforcement interest; Qualifying processing | Interest of prevention/detection/investigation/prosecution of offence OR contravention of Indian law. Chapter II except s8(1),(5), Chapter III and s16 disapplied; s8(1),(5) remain. | 2027-05-13 |
| ACT-17(1)(d) / Section 17(1)(d) | Person based in India; Qualifying processing | Data principals not within India; contract with person outside India; processing pursuant to it. Chapter II except s8(1),(5), Chapter III and s16 disapplied; s8(1),(5) remain. | 2027-05-13 |
| ACT-17(1)(e) / Section 17(1)(e) | Person implementing qualified corporate scheme; Qualifying processing | Necessary for listed restructuring scheme approved by competent court/tribunal/authority. Chapter II except s8(1),(5), Chapter III and s16 disapplied; s8(1),(5) remain. | 2027-05-13 |
| ACT-17(1)(f) / Section 17(1)(f) | Person ascertaining specified default information; Qualifying processing | Financial information/assets/liabilities of loan/advance defaulter; financial institution/default as IBC-defined; comply with other-law disclosure provisions. Chapter II except s8(1),(5), Chapter III and s16 disapplied; s8(1),(5) remain. | 2027-05-13 |
| ACT-17(2)(a) / Section 17(2)(a) | Notified State instrumentality and Central Government receiving its data; Specified notification/security/public-order interests | Instrumentality must be notified for listed interests; includes Government processing furnished data. Act-level exemption for qualifying processing. | 2027-05-13 |
| ACT-17(2)(b) / Section 17(2)(b) | Research/archiving/statistics processor; Necessary research, archiving or statistical processing | No principal-specific decision; prescribed standards (r16/Second Schedule). Act-level exemption only if conditions met. | 2027-05-13 |
| ACT-17(3) / Section 17(3) | Central Government; notified fiduciary/class including eligible startup; Notification considering volume/nature | s5,s8(3),(7),s10,s11 disapplied for notified class. Startup recognition alone not exemption. | 2027-05-13 |
| ACT-17(4) / Section 17(4) | State or instrumentality; State processing | s8(7) and s12(3) disapplied; s12(2) also disapplied where no principal-affecting decision. Other duties not generally removed here. | 2027-05-13 |
| ACT-17(5) / Section 17(5) | Central Government; notified fiduciary/class; Time-limited notification power | Before five years from applicable commencement; specified provisions and period. Only notified scope and duration. | 2027-05-13 |
A.4 General-obligation and SDF anatomy
The following is a more operational dissection, not additional statutory wording. Each limb resolves to ACT-8 or ACT-10 and its exact passage in the canonical register.
| Limb | Statutory scope (paraphrase) | Recommended evidence; book chapter |
|---|---|---|
| Section 8(1) | Fiduciary responsibility for its/on-behalf processing regardless of contrary agreement or principal default | Per-activity responsibility map; 17 |
| Section 8(2) | Engage the covered processor only under valid contract | Executed applicable contract and actual processing scope; 17 |
| Section 8(3) | Completeness, accuracy and consistency where data likely used for principal-affecting decision OR disclosed to another fiduciary | Decision/disclosure quality checks; 8,21 |
| Section 8(4) | Appropriate technical/organisational measures for effective observance | Scoped control-to-test records, not a policy-only claim; 15,22 |
| Section 8(5) | Reasonable safeguards to prevent breach, including on-behalf processing | Threat/control/evidence mapping with limits; 15 |
| Section 8(6) | Breach intimation to Board and affected principals in prescribed form/manner | Separate clocks/content/delivery results under Rule 7; 16 |
| Section 8(7)(a),(b) | Unless necessary for compliance with law, erase on withdrawal or reasonable assumption purpose no longer served, whichever earlier; cause processor erasure | Per-copy lawful retention and cessation decisions, including Rule 8(3), not universal immediate deletion; 10,14,17 |
| Section 8(8) | Purpose deemed no longer served after prescribed non-approach/non-exercise period | Exact class/purpose/last-event test and Rule 8(2) warning; 14 |
| Section 8(9) | Publish DPO if applicable or responsible person’s contact | Actual business channel, including Rule 9 response contact; 4 |
| Section 8(10) | Effective grievance mechanism | Published reasonable period and real response evidence; 12 |
| Section 10(1) | Government notification based on listed factors | Authenticated notification, entity/class fit, date; no automatic designation; 19 |
| Section 10(2)(a) | SDF’s India-based DPO responsible to board/similar governing body, grievance contact | Mandate, reporting/access and contact evidence; 19 |
| Section 10(2)(b) | Independent data auditor evaluates compliance | Appointment, independence, actual scope/results; 19 |
| Section 10(2)(c) | Periodic DPIA/audit and prescribed measures | Rule 13 cycle, assessor/auditor report, algorithmic diligence and conditional specified-data restriction; 19,20 |
These clauses direct the fiduciary; processor performance is supported through applicable contracts/law rather than changing Section 8(2)/(7)(b) into direct statutory processor wording. A new contract cannot transform independent vendor purpose-setting into on-behalf processing. The Company remains not_designated; a voluntary privacy owner is not automatically the statutory SDF DPO.
A.5 Rules 1–23
The English operative text has been read with GSR 892(E); numerical clocks below are not secondary-source rumours or deferred reader homework.
| ID / provision | Actor; trigger | Conditions and limits (author paraphrase) | Commencement |
|---|---|---|---|
| RULE-1 / Rule 1 | Rulemaker / all actors; Commencement | rr1,2,17-21 publication; r4 one year; rr3,5-16,22,23 eighteen months. Read corrigendum replacing publication wording. | 2025-11-13 |
| RULE-2 / Rule 2 | All actors; Definitions | User account extends to listed presences; verifiable consent refers r10/11; Act definitions apply. Unless context otherwise requires. | 2025-11-13 |
| RULE-3 / Rule 3 | Data Fiduciary; Notice | Independent understandable clear/plain notice, itemised data, purposes and goods/services/uses description; withdrawal/rights/complaint links and other means. Read s5 and s6 language options. | 2027-05-13 |
| RULE-4 / Rule 4 | Applicant Consent Manager; Board; registered CM; Application/registration/non-adherence | First Schedule eligibility; published application particulars; Board inquiry/reasoned rejection; obligations; hearing and suspension/cancellation/directions; information power. No universal unauthenticated interoperability mandate. | 2026-11-13 |
| RULE-5 / Rule 5 | State and instrumentalities; Prescribed benefits processing | Second Schedule standards; law/policy/public-fund meanings specified. Also satisfy s7(b) facts. | 2027-05-13 |
| RULE-6 / Rule 6 | Data Fiduciary; processors by contractual propagation; Protection of possessed/controlled data | Minimum security, access, visibility, continuity/backup, one-year security data/log retention, contract safeguards, organisational/technical measures. r6(1)(e): unless compliance with law requires otherwise. | 2027-05-13 |
| RULE-7 / Rule 7 | Data Fiduciary; Awareness of any personal-data breach | Without-delay notices to each affected principal and initial Board notice; 72-hour detailed update; prescribed fields. Board may allow longer update period on written request; no severity exemption stated. | 2027-05-13 |
| RULE-8 / Rule 8 | Data Fiduciary (processing itself or through processor); Class inactivity or any processing for r8(3) | Third Schedule class/purpose/period; 48-hour warning; separate minimum one-year personal/traffic/other-log retention from processing for Seventh Schedule purposes. Legal-retention exception; further retention under other law or Government notification in (3). | 2027-05-13 |
| RULE-9 / Rule 9 | Data Fiduciary; Website/app and every rights communication response | Prominent business contact of DPO if applicable or responsible person. DPO not universally mandated. | 2027-05-13 |
| RULE-10 / Rule 10 | Data Fiduciary; individual identifying as parent; Before child processing | Appropriate measures and identifiable-adult due diligence; reliable held identity/age or voluntarily supplied details/authorised token; illustrations. r12/s9(4)/(5) qualifying relief; adult defined 18. | 2027-05-13 |
| RULE-11 / Rule 11 | Data Fiduciary; claimed lawful guardian; Covered disability guardian consent | Verify lawful appointment by court/designated authority/local committee under defined guardianship laws. Covered disability definition includes inability despite adequate appropriate support. | 2027-05-13 |
| RULE-12 / Rule 12 | Specified fiduciaries/purpose actors; Fourth Schedule conditions met | Relief from s9(1),(3) for PartA classes or PartB purposes. Does not remove s9(2). | 2027-05-13 |
| RULE-13 / Rule 13 | Notified SDF; assessment/audit person; Central Government; Designation; algorithms; Government data specification | DPIA and audit once each twelve-month period from notification; significant observations report by assessor/auditor; algorithmic technical-measure diligence; specified data/traffic not abroad. Data restriction requires specification on committee recommendation; no general all-data localisation. | 2027-05-13 |
| RULE-14 / Rule 14 | Data Fiduciary; applicable CM; principal; Rights and grievance services | Publish means/identifiers; prior-consent request; publish reasonable grievance-response period <=90 days and measures; one/more nominees per terms/law. Not general 48/72/90-day access/correction/erasure SLA. | 2027-05-13 |
| RULE-15 / Rule 15 | Data Fiduciary; Central Government; Foreign transfer/access | Meet general/special order requirements for making personal data available to foreign State/controlled person/entity/agency. Also s16 and conditional r13(4), plus sector duties. | 2027-05-13 |
| RULE-16 / Rule 16 | Qualifying research/archiving/statistical processor; Exemption | Necessary processing and Second Schedule standards. Read s17(2)(b) no-principal-specific-decision condition. | 2027-05-13 |
| RULE-17 / Rule 17 | Central Government; Search-cum-Selection Committees; Appointments | Different committee chairs/membership for Chairperson vs other members; Government considers recommendations and appoints. Committee vacancies/absences/defects alone do not invalidate. | 2025-11-13 |
| RULE-18 / Rule 18 | Chairperson and Members; Service | Fifth Schedule salary/allowances/conditions. Not an appointment notification. | 2025-11-13 |
| RULE-19 / Rule 19 | Board; Chairperson; Members; Meetings and inquiry | Quorum one-third; majority/casting vote; conflicts; urgent action notified within seven days/ratification; authenticate; six-month inquiry extendible three months at a time with reasons. Underlying s27/28 commencement remains separate. | 2025-11-13 |
| RULE-20 / Rule 20 | Board; Digital functioning | Digital office may use techno-legal measures avoiding physical presence. Summoning/examining on oath power preserved. | 2025-11-13 |
| RULE-21 / Rule 21 | Board; Central Government; Staff appointment | Prior approval; Sixth Schedule service conditions. Separate from member composition. | 2025-11-13 |
| RULE-22 / Rule 22 | Aggrieved appellant; Tribunal; Appeal | Digital form/fee; fee waiver/reduction discretion; natural justice; digital office. CPC not binding; powers preserved. | 2027-05-13 |
| RULE-23 / Rule 23 | Central Government through authorised person; fiduciary/intermediary; Information call for Seventh Schedule purposes | Furnish within period given in such order (corrigendum); secrecy requirement for stated prejudicial effects. Disclosure exception only with authorised person written permission. | 2027-05-13 |
A.6 All seven Rules schedules
| ID / provision | Actor; trigger | Conditions and limits (author paraphrase) | Commencement |
|---|---|---|---|
| RULE-SCHEDULE-I / r.SCHEDULE-I | CM applicant and registered CM; Board; r4 eligibility/operation | PartA nine eligibility items incl Indian company, >=INR2 crore net worth, independent certification; PartB13 obligations incl onboarded fiduciaries, unreadable data, records/export >=7 years, nondelegation, conflicts, audit/control transfer. Record term may be longer by agreement/law; control transfer needs Board approval. | 2026-11-13 |
| RULE-SCHEDULE-II / r.SCHEDULE-II | State/qualifying research processor; r5(1)/r16 | Lawfulness, specified use, necessity, reasonable data quality, retention, safeguards, State-use intimation/contact/rights/policy standards, accountability. s17(2)(b) no principal-specific decision remains. | 2027-05-13 |
| RULE-SCHEDULE-III / r.SCHEDULE-III | Threshold-qualified e-commerce/gaming/social-media fiduciary; r8(1) inactivity | E-commerce >=2 crore India registered users; gaming >=50 lakh; social >=2 crore; three years latest qualifying contact/rights event or Rules commencement; account/token-access purposes excluded. Definitions/excluded marketplace seller and r8 legal-retention qualification. | 2027-05-13 |
| RULE-SCHEDULE-IV / r.SCHEDULE-IV | Listed child-processing classes/purposes; r12 | Five PartA classes and six PartB purposes with exact scope conditions; definitions corrected to (a)-(g). Relief only s9(1),(3); s9(2) remains. | 2027-05-13 |
| RULE-SCHEDULE-V / r.SCHEDULE-V | Chairperson and other Members; r18 service | Consolidated monthly salary 4.5 lakh / 4 lakh; PF, no pension/gratuity, travel, medical, leave/LTC, conduct/conflict terms, pay-matrix definition. Detailed qualifications in passage; no house/car facility, sitting fee or sumptuary allowance. | 2025-11-13 |
| RULE-SCHEDULE-VI / r.SCHEDULE-VI | Board officers and employees; r21(2) | Deputation categories up to five years; gratuity/travel/medical/leave/LTC/conduct/discipline and unresolved service matters. Government approval and specified conditions. | 2025-11-13 |
| RULE-SCHEDULE-VII / r.SCHEDULE-VII | Government authorised persons; fiduciaries under r8(3); r23(1) information purposes and r8(3) retention purposes | State sovereignty/security use; State statutory functions/disclosure; assessment for SDF notification; corresponding designated officers/persons. Authority must match row; does not itself establish an SDF designation. | 2027-05-13 |
The First Schedule’s CM records retain notices, grants/refusals/withdrawals and sharing records for at least seven years or longer by agreement/law; the data shared through the platform must not be readable by the CM. These obligations concern registered CMs, not every enterprise consent software product. Read the nine eligibility items and thirteen obligations in the retained passage before vendor acceptance.
The Third Schedule is a class/purpose/period test, not a blanket three-year retention rule for all companies. Its listed e-commerce and social-media thresholds are two crore registered users in India, and online gaming fifty lakh; the three-year inactivity period uses the latest specified approach/rights event or Rules commencement, with account-access/token purposes excluded as written. Rule 8(3)‘s separate minimum one-year processing-record layer is not limited to those threshold classes. Rule 6(1)(e) separately concerns security data/logs; purpose, retention and permitted use need separate decisions (RULES:1142–1166,1598–1680[4]).
Fourth Schedule relief under Rule 12 concerns Section 9(1),(3), not the Section 9(2) detrimental-effect prohibition. Its classes and purposes are conditional, not a broad health/education/parent-token licence. Fifth and Sixth Schedules concern Board personnel, not data-principal services. The Seventh Schedule concerns Rule 23(1) and Rule 8(3), including specified State uses and SDF assessment with corresponding authorised persons. Nomination is Section 14/Rule 14(4); it has no separate schedule. These distinctions prevent a display-heading error from becoming an unsafe operating rule.
A.7 Penalties and exact factors
| Item | Breach (paraphrase) | Statutory maximum, not expected loss | Control discussion |
|---|---|---|---|
| 1 | Failure to take reasonable security safeguards under Section 8(5) | ₹250 crore | 15 |
| 2 | Failure to give the Board or affected Data Principal breach intimation under Section 8(6) | ₹200 crore | 16 |
| 3 | Additional obligations in relation to children under Section 9 | ₹200 crore | 13 |
| 4 | Additional SDF obligations under Section 10 | ₹150 crore | 19 |
| 5 | Data Principal duties under Section 15 | ₹10,000 | 4,12 |
| 6 | Breach of an accepted voluntary undertaking under Section 32 | Up to the extent applicable for the breach in respect of which the Section 28 proceeding was instituted | 6 |
| 7 | Any other provision of the Act or Rules | ₹50 crore | 2,6 |
Source: ACT-SCHEDULE — research/legal/evidence/01_dpdp_act_2023_gazette.txt:1010–1045; Section 33 process/factors apply.
| Clause | Exact Section 33(2) wording |
|---|---|
| (a) | the nature, gravity and duration of the breach; |
| (b) | the type and nature of the personal data affected by the breach; |
| (c) | repetitive nature of the breach; |
| (d) | whether the person, as a result of the breach, has realised a gain or avoided any loss; |
| (e) | whether the person took any action to mitigate the effects and consequences of the breach, and the timeliness and effectiveness of such action; |
| (f) | whether the monetary penalty to be imposed is proportionate and effective, having regard to the need to secure observance of and deter breach of the provisions of this Act; and |
| (g) | the likely impact of the imposition of the monetary penalty on the person. |
Source: ACT:836–846[3]. These are not weighted model coefficients.
No factor introduces a fixed intention/knowledge multiplier or generic catch-all aggravation category. No additive ₹450-crore cap is certified here. Section 33 requires a significant-breach determination after inquiry and hearing before a discretionary scheduled monetary penalty. Sections 34 and 42 separately address destination of penalty sums and notification-based Schedule amendment. Chapter 6 keeps assumed operational cost apart from unpredicted statutory awards.
Section 38(1) provides additional compatible application; Section 38(2) makes DPDP prevail to the extent of an actual conflict. Section 16(2) separately preserves higher Indian-law transfer protection/restrictions, not a universal strictest-law hierarchy (ACT:887–892,515–522[3]).
A.8 Notifications, composition and correction history
| ID / provision | Actor; trigger | Conditions and limits (author paraphrase) | Commencement |
|---|---|---|---|
| GSR-843E / GSR-843E | Central Government; Gazette publication | Three Act tranches enumerated exactly. s6(9)/s27(1)(d) not same date as rest. | 2025-11-13 |
| GSR-844E / GSR-844E | Central Government / Board; Gazette publication | Establishes Board; NCR head office. No individual appointments. | 2025-11-13 |
| GSR-845E / GSR-845E | Central Government / Board; Composition notification | Verbatim: Board shall consist of four members. s2(q) includes Chairperson; recruitment states Chairperson plus four others; unresolved instrument inconsistency. | 2025-11-13 |
| GSR-892E / GSR-892E | Rulemaker; Corrigendum to GSR846 | Publication wording; Departments; given in such order; every body; 18 of 2013; Fourth Schedule definition punctuation/lettering. No revised core clocks or schedule-purpose reassignment. | corrigendum dated 2025-12-10; Gazette issue 2025-12-11 |
| BOARD-RECRUITMENT / BOARD-RECRUITMENT | MeitY / applicants; Recruitment notice | States Chairperson plus four other members and invites applications. Not proof of appointment; conflicts with GSR845 wording. | administrative notice; not statutory commencement |
GSR 845(E) specifies composition, not appointments. Its four-member wording and the recruitment notice’s Chairperson-plus-four wording are preserved as an unresolved evidence discrepancy, not silently reconciled. Section 36 is a deferred Central Government power. Neither institution establishment nor recruitment proves retroactive applicability of core obligations, a staffed portal or successful filing.
GSR 892(E) is dated 10 December 2025, in the Gazette issue of 11 December. It replaces publication wording in Rule 1, “Department” with “Departments” in Rule 13(5), “given in such” with “given in such order” in Rule 23(1), “everybody” with “every body” and “18 or 2013” with “18 of 2013” in the First Schedule, and corrects punctuation/definition lettering to (a)–(g) in the Fourth Schedule. The page-38 correction is not a First Schedule definition correction. No new breach clock or nomination schedule results (CORR:24–38[8]).
A.9 Statutory outputs versus recommended artifact content
| Artifact | Statutory requirement / source | Author-recommended implementation, not statutory schema |
|---|---|---|
| Notice | Section 5/Rule 3 itemised data/purpose, prescribed rights/complaint means, clear independent comprehensibility; Section 6(3) language/contact | Version identity, served rendering, purpose links, locale tests |
| Consent evidence | Section 6(1) quality/affirmative necessary-data consent; Section 6(10) fiduciary proof; CM’s own First Schedule records are separate | Subject-purpose binding, grant sequence, authenticated provenance; no invented SDF Section 6(9) field |
| Principal breach notice | Rule 7(1) nature/extent/occurrence, consequences, mitigation, self-protection, business contact; without delay on awareness | Queue identity, retry and actual delivery evidence; never a success merely because prepared |
| Board breach notice/update | Rule 7(2)(a) initial description without delay; (b) detailed facts/measures/findings/principal-notice report within 72 hours unless longer allowed on written request | Separate preparation/send/receipt clocks, unknown attribution, escalation; do not send principal text as if fields identical |
| Access reply | Section 11 prior-consent scope including Section 7(a), summary, recipient identities/data descriptions and prescribed information, scoped (2) exception | Recipient evidence links, unknown-state escalation, clear interim versus final response |
| Correction/erasure decision | Section 12 conditions; Section 8(7), Rule 8 and applicable legal retention | Per-store receipt and restricted-retention status; no total-erasure claim while minimum/failed processor remains |
| Grievance response | Section 13/Rule 14(3), readily available effective mechanism and reasonable published period <=90 days | Case trail, proposed thirty-day policy only where reasonable; no universal access/erasure ninety-day deadline |
| Processor contract | Section 8(2) valid contract; Rule 6(1)(f) safeguards provision for covered processing | Audit, exit, subprocessor and deletion-verification clauses designed to support obligations; not all literally prescribed in Section 8(2) |
| DPIA/audit | Section 10/Rule 13 when designated; statutory assessment content/cadence, assessor/auditor significant observations | Review workpaper, rejection branches, residual tracking; no automatic sponsor override of a prohibition |
| Undertaking | Section 32 accepted terms, action/abstention/publicity and breach route | Delivery milestones, evidence, internal owner; no guaranteed settlement discount |
A.10 Evidence questions and update boundaries
A recommended audit asks for the ground and actual scope; what notice was served; the grant and later withdrawal; the required output and actual response; what retained copies may still do; and which tests support a claimed control. These questions are not predictions of exactly what a future Board inquiry will ask. A signed plan is not a run result, a processor acknowledgement is a supplier assertion, and a local fixture is not production evidence. Preserve failures and unknown sets rather than turning every row green.
Rule 7’s clocks/content, Rule 8’s periods, Rule 13’s cadence, Rule 14’s mechanism, verification routes, all schedules and the corrigendum are now source-checked. Remaining questions are the canonical UNRESOLVED_LEGAL_QUESTIONS.md: retention/copy/reset interpretation, role/application boundaries, actual Board evidence, bounded official-update coverage, early CM enforcement and penalty aggregation among them. An unsuccessful full eGazette search is not proof that no later order exists; no designation, restricted destination or appointment is inferred from silence.
Maintain the register by recording the exact new instrument, publication/effective dates, affected row and independent review status; regenerate this appendix and Chapter 2 together. Keep legal-source closure separate from entity deployment acceptance. The source monitoring cadence and named backup reviewer are author controls, not additional statutory clocks. A source change can require a control change, but neither a regenerated table nor a passing checksum proves the implementation changed.
For CASE-001, this appendix is a reference for the stopped training and vendor-reuse branches, isolated foreign backup, separate withdrawal/retention decisions and incomplete incident-delivery evidence. The full dossier remains owned by later phases. Appendix A does not substitute for promised appendices B–I, an assembled reader export or independent book acceptance; those gates remain outside Q02.
Source key and provenance legend
Physical references use newline-based line numbers in the following retained source paths; each numbered reference resolves to its original source URL. Review date: 15 September 2026. Full calculated hashes and source versions: out/remediation/Q02/source-manifest.json. The Q01 baseline and its bounded official-update limitations remain controlling; no later-law absence or entity certification is asserted.
- ACT:
research/legal/evidence/01_dpdp_act_2023_gazette.txt— Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023).[3] - RULES:
research/legal/evidence/05_gsr_846e_dpdp_rules_2025.txt— Digital Personal Data Protection Rules, 2025, G.S.R. 846(E).[4] - COMM:
research/legal/evidence/02_gsr_843e_commencement.txt— G.S.R. 843(E), DPDP Act commencement notification.[5] - EST:
research/legal/evidence/03_gsr_844e_board_establishment.txt— G.S.R. 844(E), establishment of Data Protection Board of India.[6] - MEMBERS:
research/legal/evidence/04_gsr_845e_board_members.txt— G.S.R. 845(E), number of members of Data Protection Board of India.[7] - CORR:
research/legal/evidence/06_gsr_892e_corrigendum.txt— Corrigenda to G.S.R. 846(E), G.S.R. 892(E).[8] - RECRUIT:
research/legal/evidence/07_board_recruitment_notice_2026.txt— Filling up the post of Chairman & Members in the Data Protection Board of India.[9]
Sources
[3] https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf [4] https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf [5] https://www.meity.gov.in/static/uploads/2025/11/c56ceae6c383460ca69577428d36828b.pdf [6] https://www.meity.gov.in/static/uploads/2025/11/cc217843dc3bcb37b2b05bcc3b4e031f.pdf [7] https://www.meity.gov.in/static/uploads/2025/11/f6c0837972422cf79d890bfe84cc04d6.pdf [8] https://www.meity.gov.in/static/uploads/2025/12/3c7ebbae0e5456f493f486e6845df86b.pdf [9] https://www.meity.gov.in/static/uploads/2026/05/53b1bcf01cab9a0adde463e73fbc3417.pdf
Contents · Reader guide and citation conventions · Artifact index