Legal Register
Interactive Checklist
C-03 Executive Governance Board & Executive Sponsor

Are You Ready for the Cliff? (20-Point Readiness)

Executive 20-point enterprise readiness scorecard assessing full statutory compliance before the Tranche 3 substantive enforcement cliff (13 May 2027).

Statutory Source: Ch. 1/23: the pre-13-May-2027 gate criteria — register, inventory, consent, withdrawal machine, breach drill, processor contracts
Total Verification Points: 20 Audit Checks
C-03Ch. 1/23: the pre-13-May-2027 gate criteria — register, inventory, consent, withdrawal machine, breach drill, processor contracts

Are You Ready for the Cliff? (20-Point Readiness)

Score yourself against the commencement date

Readiness Score
0 / 20 checks
0%
State automatically persisted in browser localStorage

Statutory Grounding & Legal Perimeter

Mandatory statutory clauses, rules, and gazette requirements enforceable under this checklist.

Enforceable Provisions:
Section 1(2)Section 4Section 5Section 6Section 8Section 9Section 10Section 11Section 16Section 33
Statutory Context:
This checklist is directly anchored in Ch. 1/23: the pre-13-May-2027 gate criteria — register, inventory, consent, withdrawal machine, breach drill, processor contracts. Failure to maintain verifiable affirmative proof of compliance exposes the enterprise to severe adjudication penalties under Section 33 (Schedule) of the DPDP Act.

Target Architecture & Impacted Systems

Enterprise applications, stores, and integration surfaces evaluated by this checklist.

View Full Systems Topology (SYS-001..014)
In-Scope System Nodes:
SYS-001 Architecture Spec →
Customer App & Web Portal

Public client boundary & untrusted intake surface for notices and consent capture

SYS-002 Architecture Spec →
Core Lending Monolith & Transaction Store

Domestic production database and primary system of record for loan servicing

SYS-003 Architecture Spec →
Marketing Automation Engine

Processor-operated messaging engine (ENT-004) gated by optional consent

SYS-004 Architecture Spec →
Enterprise Cloud Data Warehouse

Purpose-partitioned analytical warehouse staging operational reporting

SYS-005 Architecture Spec →
Analytics & AI/ML Training Environment

Model training and algorithm development node gated against unconsented data

SYS-006 Architecture Spec →
HRMS & Applicant Tracking System

Internal employer database holding employee payroll and candidate records

SYS-007 Architecture Spec →
Digitized Legacy Document Archive

Cold physical and scanned document store subject to statutory retention schedules

SYS-008 Architecture Spec →
Foreign-Region Secondary Backup Replica

Offshore disaster recovery replica; isolated pending cross-border transfer checks

SYS-009 Architecture Spec →
Overseas Analytics Cluster

Third-party international BI environment (ENT-005); prohibited unconsented reuse

SYS-010 Architecture Spec →
Consent Ledger & Policy Decision Point

Immutable consent event store and Policy Decision Point issuing authority tokens

SYS-011 Architecture Spec →
Principal Rights & Grievance Service

Self-service orchestration service for managing DSARs and grievance redressal

SYS-012 Architecture Spec →
SIEM & Security Telemetry Store

Security log repository preserving tamper-evident dual-clock audit trails

SYS-013 Architecture Spec →
Processor Orchestration Gateway & Queue

Integration pipeline tracking downstream processor instructions and acknowledgements

SYS-014 Architecture Spec →
Restore Quarantine & Sandbox Store

Isolated test environment ensuring recovered backups pass tombstone replay

Associated Operational Controls (54 OBLs)

Control Master Matrix obligations directly tested by this checklist.

Open Control Matrix →

Audit & Implementation Guidance

Best practices for establishing evidence, avoiding traps, and conducting periodic assurance.

Evidence Retention Standard

Do not rely solely on policy documents or statements of intent. Ensure verifiable evidence artifacts (cryptographic logs, test manifests, signed DPA agreements, or automated crawler receipts) are archived for at least 1 year.

Common Implementation Trap

Avoid declaring compliance based on frontend UI alone. The Data Protection Board evaluates the full data pipeline, including database persistence, read replicas, cache invalidation, and third-party processor synchronization.