DPDP Product Portfolio Architecture
Hub-and-Spoke Topology of Eight Product Blueprints (P01–P08) Centered on the Obligations Register
The DPDP enterprise product portfolio is organized as an integrated hub-and-spoke ecosystem revolving around the core Obligations Register (P01). Eight specialized software products feed from and report to the central register: P01 (Statutory Register Engine), P02 (Multilingual Consent Gateway), P03 (Proof-of-Erasure Orchestrator), P04 (DSAR & Grievance Manager), P05 (Dual-Clock Incident Responder), P06 (Vendor & Processor Risk Assessor), P07 (Child Safety & VPC Gatekeeper), and P08 (Executive & Board Assurance Cockpit).
DPDP Product Portfolio Architecture
P01: Central Obligations Register
Single source of statutory truth (54 OBLs, Tranches, Citations)
Consent Gateway
Multilingual notice, affirmative capture & Consent Ledger
Erasure Orchestrator
6-plane automated deletion & cryptographic receipts
DSAR & Grievance Portal
Principal rights workflow & Rule 13 SLA tracking
Dual-Clock Incident Responder
CERT-In 6h & DPDP Rule 7 breach notification
Vendor Risk Assessor
PoV evaluation & Section 8(2) DPA management
Child Safety Gatekeeper
Age classification, VPC verification & ad blocking
Board Assurance Cockpit
Automated control testing & real-time compliance score
💡 Core Architectural Insights & Takeaways
Key technical and regulatory takeaways established by this architecture diagram.
📜 Statutory Grounding & Legal Perimeter
Primary Act and subordinate Rule provisions establishing the enforceable legal mandate for this diagram.
🏗️ Target Architecture & Impacted Systems
Enterprise nodes and store topologies impacted by this architectural pattern.
Public client boundary & untrusted intake surface for notices and consent capture
Domestic production database and primary system of record for loan servicing
Processor-operated messaging engine (ENT-004) gated by optional consent
Purpose-partitioned analytical warehouse staging operational reporting
Model training and algorithm development node gated against unconsented data
Internal employer database holding employee payroll and candidate records
Cold physical and scanned document store subject to statutory retention schedules
Offshore disaster recovery replica; isolated pending cross-border transfer checks
Third-party international BI environment (ENT-005); prohibited unconsented reuse
Immutable consent event store and Policy Decision Point issuing authority tokens
Self-service orchestration service for managing DSARs and grievance redressal
Security log repository preserving tamper-evident dual-clock audit trails
Integration pipeline tracking downstream processor instructions and acknowledgements
Isolated test environment ensuring recovered backups pass tombstone replay
⚙️ Associated Operational Controls
Control Master Matrix obligations enforcing the standards illustrated in this infographic.
🛠️ Implementation Guidance & Traps
Recommended technical sequencing and operational failure modes to avoid.
Recommended Implementation Sequence
- Deploy P01 Obligations Register as the core data model.
- Implement customer-facing products (P02, P04, P07) in Phase 1.
- Implement backend data orchestrators (P03, P05, P06, P08) in Phase 2.
Enterprise Traps & Failure Modes
- ⚠️ Building isolated point solutions that create conflicting consent records across channels.
- ⚠️ Failing to feed incident and erasure telemetry back into the central assurance register.
📁 Verifiable Evidence Artifacts Vault
Required evidentiary workpapers for regulatory inspections and SDF audits.