Legal Register
Visual Infographic
I-01 Legal Architecture ๐Ÿ‘ค Legal Counsel & DPO

The DPDP Stack

Five-Layer Instrument Architecture: Act, Rules, Commencement, Corrigenda, and Board Adjudications

DPDP is not a single static legal document; it operates as an interdependent five-layer normative stack. Layer 1 (The DPDP Act 2023) establishes primary statutory duties and penalty maxima. Layer 2 (The DPDP Rules) specifies operational mechanics, notice requirements, and breach parameters. Layer 3 (Commencement Notifications) regulates when specific sections become enforceable across 3 discrete tranches. Layer 4 (Ministry Corrigenda) rectifies official gazette texts and dates. Layer 5 (DPBI Adjudications & Standard Operating Procedures) sets binding precedent and inquiry procedures.

Statutory Source: Ch. 2 ยง1, Appendix A.1
Archetype: layers
I-01 DiagramArchetype: LAYERS

The DPDP Stack

Normative Stack Hierarchy (Top to Bottom Authority)
Layer 5

DPBI Guidelines & Adjudications

Binding procedural codes, inquiry standards, voluntary undertakings approval, and penalty calculations.

Authority: Data Protection Board of India (ss.18โ€“26, 27โ€“34)
Enforcement & Precedent
Layer 4

Ministry Corrigenda & Clarifications

Gazetted rectifications to rule text, dates, and transitional drafting cross-references.

Authority: MeitY Statutory Gazettes (G.S.R. 892(E), etc.)
Text Integrity
Layer 3

Commencement Notifications (Tranches 1โ€“3)

Staged enforcement schedule: 13 Nov 2025 (Board setup) -> 13 Nov 2026 (Rule 4) -> 13 May 2027 (Substantive Cliff).

Authority: Central Government Orders under s.1(2) & r.1(2)
Temporal Validity
Layer 2

Subordinate DPDP Rules (Rules 1โ€“24)

Prescribes notice templates (r.3), retention periods (r.5), breach notification forms (r.7), VPC criteria (r.8), and CM standards (r.11).

Authority: Executive Rulemaking under s.40
Operational Mechanics
Layer 1

Primary DPDP Act, 2023 (Act No. 22 of 2023)

Core statutory definitions (s.2), ground rules for processing (s.4-7), fiduciary duties (s.8-10), principal rights (s.11-14), and penalty schedule (s.33).

Authority: Parliament of India (ss.1โ€“44)
Primary Statute

๐Ÿ’ก Core Architectural Insights & Takeaways

Key technical and regulatory takeaways established by this architecture diagram.

โœฆ No single document provides the complete rulebook; an obligation requires cross-referencing all 5 layers.
โœฆ An Act provision is inert until its corresponding Commencement Notification activates it.
โœฆ Rules cannot expand statutory mandates beyond the delegated powers granted under Section 40.
โœฆ Gazette corrigenda alter legal text retrospectively or prospectively as published.

๐Ÿ“œ Statutory Grounding & Legal Perimeter

Primary Act and subordinate Rule provisions establishing the enforceable legal mandate for this diagram.

Enforceable Provisions:
Section 1(2)Section 2Sections 18 to 26Section 35Sections 38 to 43Section 44

๐Ÿ—๏ธ Target Architecture & Impacted Systems

Enterprise nodes and store topologies impacted by this architectural pattern.

View Complete Topology (SYS-001..014) โ†’

โš™๏ธ Associated Operational Controls

Control Master Matrix obligations enforcing the standards illustrated in this infographic.

Open Control Matrix โ†’

๐Ÿ› ๏ธ Implementation Guidance & Traps

Recommended technical sequencing and operational failure modes to avoid.

Recommended Implementation Sequence

  1. Anchor the enterprise legal register to specific Gazette notification hashes and dates.
  2. Map each system data flow to both primary statutory limbs and subordinate rule provisions.
  3. Set up an automated Gazette surveillance pipeline to capture Layer 4 corrigenda and Layer 5 Board circulars.
  4. Distinguish institutional readiness from substantive compliance obligations.

Enterprise Traps & Failure Modes

  • โš ๏ธ Assuming the entire DPDP Act is immediately live upon presidential assent.
  • โš ๏ธ Relying on unofficial blog posts or draft bills instead of the Gazette publication baseline.
  • โš ๏ธ Treating Board recruitment advertisements as operational adjudication channels.

๐Ÿ“ Verifiable Evidence Artifacts Vault

Required evidentiary workpapers for regulatory inspections and SDF audits.

๐Ÿ“„ Gazette Notification SHA-256 Hashes (CANONICAL_PROVISION_REGISTER.json)
๐Ÿ“„ Enterprise Regulatory Register (OBL-01 to OBL-54)
๐Ÿ“„ Legal Baseline Audit Memo