Legal Register
Visual Infographic
I-12 Programme Delivery ๐Ÿ‘ค Programme Directors & Enterprise Transformation Leads

Dependency Chain of the Programme

10-Phase Topological Delivery Roadmap: Register to Board Assurance

DPDP transformation cannot be executed in arbitrary parallel workstreams; it has strict mathematical dependencies. You cannot draft an accurate Section 5 Notice without knowing your Data Inventory and Purposes; you cannot build a Withdrawal Engine without a Consent Ledger; you cannot automate Deletion without mapping Processors and Backup architectures. This roadmap defines the critical path for enterprise delivery.

Statutory Source: Ch. 23, Ch. 35 ยง3
Archetype: dependency pipeline
I-12 DiagramArchetype: DEPENDENCY PIPELINE

Dependency Chain of the Programme

10-Phase Topological Delivery Roadmap
01Deps: None
Statutory Register

Anchor Act & Rules obligations (OBL-01..54)

02Deps: Step 01
Data Discovery & Inventory

Map schemas DS-001..010 & systems SYS-001..014

03Deps: Step 02
Purpose & Legal Basis

Assign s.6 vs s.7 legal bases to all data fields

04Deps: Step 03
Notice & Consent Gateway

Deploy multilingual notices & Consent Ledger (SYS-010)

05Deps: Step 04
Withdrawal & Retention Engine

State machine for purpose blocking & lawful holds

06Deps: Step 05
DSAR & Grievance Portal

Deploy Principal Portal (SYS-011) with SLA tracking

07Deps: Step 02
Dual-Clock Incident Manager

CERT-In 6h & DPDP Rule 7 response orchestration

08Deps: Step 02
Processor & Vendor DPA

Execute Section 8(2) contracts across all suppliers

09Deps: Steps 04-08
SDF & DPIA Governance

Resident DPO, periodic audit & DPIA workflows

10Deps: Steps 01-09
Board Assurance & Audit

Automated control testing & executive dashboard

๐Ÿ’ก Core Architectural Insights & Takeaways

Key technical and regulatory takeaways established by this architecture diagram.

โœฆ Skipping steps (e.g. attempting consent notice before data inventory) causes massive rework.
โœฆ Vendor contract remediation (Step 08) has the longest organizational lead time.
โœฆ Testing and assurance (Step 10) must run continuously before the May 2027 cliff.

๐Ÿ“œ Statutory Grounding & Legal Perimeter

Primary Act and subordinate Rule provisions establishing the enforceable legal mandate for this diagram.

Enforceable Provisions:
Sections 3 to 17Sections 27 to 34Rules 3 to 23

๐Ÿ—๏ธ Target Architecture & Impacted Systems

Enterprise nodes and store topologies impacted by this architectural pattern.

View Complete Topology (SYS-001..014) โ†’
SYS-001 Details โ†’
Customer App & Web Portal

Public client boundary & untrusted intake surface for notices and consent capture

SYS-002 Details โ†’
Core Lending Monolith & Transaction Store

Domestic production database and primary system of record for loan servicing

SYS-003 Details โ†’
Marketing Automation Engine

Processor-operated messaging engine (ENT-004) gated by optional consent

SYS-004 Details โ†’
Enterprise Cloud Data Warehouse

Purpose-partitioned analytical warehouse staging operational reporting

SYS-005 Details โ†’
Analytics & AI/ML Training Environment

Model training and algorithm development node gated against unconsented data

SYS-006 Details โ†’
HRMS & Applicant Tracking System

Internal employer database holding employee payroll and candidate records

SYS-007 Details โ†’
Digitized Legacy Document Archive

Cold physical and scanned document store subject to statutory retention schedules

SYS-008 Details โ†’
Foreign-Region Secondary Backup Replica

Offshore disaster recovery replica; isolated pending cross-border transfer checks

SYS-009 Details โ†’
Overseas Analytics Cluster

Third-party international BI environment (ENT-005); prohibited unconsented reuse

SYS-010 Details โ†’
Consent Ledger & Policy Decision Point

Immutable consent event store and Policy Decision Point issuing authority tokens

SYS-011 Details โ†’
Principal Rights & Grievance Service

Self-service orchestration service for managing DSARs and grievance redressal

SYS-012 Details โ†’
SIEM & Security Telemetry Store

Security log repository preserving tamper-evident dual-clock audit trails

SYS-013 Details โ†’
Processor Orchestration Gateway & Queue

Integration pipeline tracking downstream processor instructions and acknowledgements

SYS-014 Details โ†’
Restore Quarantine & Sandbox Store

Isolated test environment ensuring recovered backups pass tombstone replay

โš™๏ธ Associated Operational Controls

Control Master Matrix obligations enforcing the standards illustrated in this infographic.

Open Control Matrix โ†’

๐Ÿ› ๏ธ Implementation Guidance & Traps

Recommended technical sequencing and operational failure modes to avoid.

Recommended Implementation Sequence

  1. Establish a PMO tracking dependencies using this 10-phase sequence.
  2. Lock down Data Inventory before finalizing notice text.
  3. Run quarterly readiness checkpoints against the transformation roadmap.

Enterprise Traps & Failure Modes

  • โš ๏ธ Buying a consent tool before understanding underlying backend data flows.
  • โš ๏ธ Treating legal DPA updates as separate from technical processor deletion integrations.

๐Ÿ“ Verifiable Evidence Artifacts Vault

Required evidentiary workpapers for regulatory inspections and SDF audits.

๐Ÿ“„ Programme Critical Path Work Breakdown Structure
๐Ÿ“„ Milestone Completion Sign-Off Sheets (M01โ€“M15)
๐Ÿ“„ Readiness Governance Dashboard