Legal Register
Visual Infographic
I-27 Portfolio Architecture 👤 Enterprise Product Managers, CTO & Practice Leaders

DPDP Product Portfolio Architecture

Hub-and-Spoke Topology of Eight Product Blueprints (P01–P08) Centered on the Obligations Register

The DPDP enterprise product portfolio is organized as an integrated hub-and-spoke ecosystem revolving around the core Obligations Register (P01). Eight specialized software products feed from and report to the central register: P01 (Statutory Register Engine), P02 (Multilingual Consent Gateway), P03 (Proof-of-Erasure Orchestrator), P04 (DSAR & Grievance Manager), P05 (Dual-Clock Incident Responder), P06 (Vendor & Processor Risk Assessor), P07 (Child Safety & VPC Gatekeeper), and P08 (Executive & Board Assurance Cockpit).

Statutory Source: PORTFOLIO_INDEX, Product Blueprints (P01–P08)
Archetype: portfolio map
I-27 DiagramArchetype: PORTFOLIO MAP

DPDP Product Portfolio Architecture

Central Hub

P01: Central Obligations Register

Single source of statutory truth (54 OBLs, Tranches, Citations)

P02
Consent Gateway

Multilingual notice, affirmative capture & Consent Ledger

P03
Erasure Orchestrator

6-plane automated deletion & cryptographic receipts

P04
DSAR & Grievance Portal

Principal rights workflow & Rule 13 SLA tracking

P05
Dual-Clock Incident Responder

CERT-In 6h & DPDP Rule 7 breach notification

P06
Vendor Risk Assessor

PoV evaluation & Section 8(2) DPA management

P07
Child Safety Gatekeeper

Age classification, VPC verification & ad blocking

P08
Board Assurance Cockpit

Automated control testing & real-time compliance score

💡 Core Architectural Insights & Takeaways

Key technical and regulatory takeaways established by this architecture diagram.

A modular product architecture allows enterprises to modernize privacy controls incrementally.
The central register ensures all 8 products stay synchronized with changing statutory baselines.
Standard APIs connect the portfolio to existing enterprise ERP, CRM, and IAM infrastructure.

📜 Statutory Grounding & Legal Perimeter

Primary Act and subordinate Rule provisions establishing the enforceable legal mandate for this diagram.

Enforceable Provisions:
Sections 3 to 17Sections 27 to 34Rules 3 to 23

🏗️ Target Architecture & Impacted Systems

Enterprise nodes and store topologies impacted by this architectural pattern.

View Complete Topology (SYS-001..014) →
SYS-001 Details →
Customer App & Web Portal

Public client boundary & untrusted intake surface for notices and consent capture

SYS-002 Details →
Core Lending Monolith & Transaction Store

Domestic production database and primary system of record for loan servicing

SYS-003 Details →
Marketing Automation Engine

Processor-operated messaging engine (ENT-004) gated by optional consent

SYS-004 Details →
Enterprise Cloud Data Warehouse

Purpose-partitioned analytical warehouse staging operational reporting

SYS-005 Details →
Analytics & AI/ML Training Environment

Model training and algorithm development node gated against unconsented data

SYS-006 Details →
HRMS & Applicant Tracking System

Internal employer database holding employee payroll and candidate records

SYS-007 Details →
Digitized Legacy Document Archive

Cold physical and scanned document store subject to statutory retention schedules

SYS-008 Details →
Foreign-Region Secondary Backup Replica

Offshore disaster recovery replica; isolated pending cross-border transfer checks

SYS-009 Details →
Overseas Analytics Cluster

Third-party international BI environment (ENT-005); prohibited unconsented reuse

SYS-010 Details →
Consent Ledger & Policy Decision Point

Immutable consent event store and Policy Decision Point issuing authority tokens

SYS-011 Details →
Principal Rights & Grievance Service

Self-service orchestration service for managing DSARs and grievance redressal

SYS-012 Details →
SIEM & Security Telemetry Store

Security log repository preserving tamper-evident dual-clock audit trails

SYS-013 Details →
Processor Orchestration Gateway & Queue

Integration pipeline tracking downstream processor instructions and acknowledgements

SYS-014 Details →
Restore Quarantine & Sandbox Store

Isolated test environment ensuring recovered backups pass tombstone replay

⚙️ Associated Operational Controls

Control Master Matrix obligations enforcing the standards illustrated in this infographic.

Open Control Matrix →

🛠️ Implementation Guidance & Traps

Recommended technical sequencing and operational failure modes to avoid.

Recommended Implementation Sequence

  1. Deploy P01 Obligations Register as the core data model.
  2. Implement customer-facing products (P02, P04, P07) in Phase 1.
  3. Implement backend data orchestrators (P03, P05, P06, P08) in Phase 2.

Enterprise Traps & Failure Modes

  • ⚠️ Building isolated point solutions that create conflicting consent records across channels.
  • ⚠️ Failing to feed incident and erasure telemetry back into the central assurance register.

📁 Verifiable Evidence Artifacts Vault

Required evidentiary workpapers for regulatory inspections and SDF audits.

📄 Enterprise Product Portfolio Architecture Blueprint (/products/)
📄 Product API Integration Specification
📄 Executive Solution Blueprint Master Catalog