Are You Ready for the Cliff? (20-Point Readiness)
Executive 20-point enterprise readiness scorecard assessing full statutory compliance before the Tranche 3 substantive enforcement cliff (13 May 2027).
Are You Ready for the Cliff? (20-Point Readiness)
Score yourself against the commencement date
Statutory Grounding & Legal Perimeter
Mandatory statutory clauses, rules, and gazette requirements enforceable under this checklist.
Target Architecture & Impacted Systems
Enterprise applications, stores, and integration surfaces evaluated by this checklist.
Public client boundary & untrusted intake surface for notices and consent capture
Domestic production database and primary system of record for loan servicing
Processor-operated messaging engine (ENT-004) gated by optional consent
Purpose-partitioned analytical warehouse staging operational reporting
Model training and algorithm development node gated against unconsented data
Internal employer database holding employee payroll and candidate records
Cold physical and scanned document store subject to statutory retention schedules
Offshore disaster recovery replica; isolated pending cross-border transfer checks
Third-party international BI environment (ENT-005); prohibited unconsented reuse
Immutable consent event store and Policy Decision Point issuing authority tokens
Self-service orchestration service for managing DSARs and grievance redressal
Security log repository preserving tamper-evident dual-clock audit trails
Integration pipeline tracking downstream processor instructions and acknowledgements
Isolated test environment ensuring recovered backups pass tombstone replay
Associated Operational Controls (54 OBLs)
Control Master Matrix obligations directly tested by this checklist.
Audit & Implementation Guidance
Best practices for establishing evidence, avoiding traps, and conducting periodic assurance.
Do not rely solely on policy documents or statements of intent. Ensure verifiable evidence artifacts (cryptographic logs, test manifests, signed DPA agreements, or automated crawler receipts) are archived for at least 1 year.
Avoid declaring compliance based on frontend UI alone. The Data Protection Board evaluates the full data pipeline, including database persistence, read replicas, cache invalidation, and third-party processor synchronization.