Legal Register
Case Study Dossier
CASE-001 Dossier Fixed-ID Reference Pack

CASE-001: The Worked Enterprise Transformation

An exhaustive, multi-stage reference implementation following FinDistributor India Ltd (ENT-001) — a mid-tier non-banking financial company & retail distributor — through 15 chronological transformation milestones from initial statutory mapping to independent assurance handoff.

Target Entity: FinDistributor India Ltd (ENT-001)
Systems in Scope: 14 Core Systems (SYS-001..014)
Controls Tested: 54 OBL Obligations

Entity Profile & Statutory Scope

Corporate structure, data volumes, processing grounds, and regulatory perimeter for ENT-001.

Non-SDF Baseline
Corporate Identity & Operations

ENT-001 operates retail loan distribution, point-of-sale financial products, and an online borrower portal across 18 Indian states. Customer base: ~450,000 active borrowers.

Statutory Role & Grounds

Acts primarily as a Data Fiduciary for borrower applications, and as a Data Processor for bank co-lending partners. Processing grounds: Section 6(1) Consent & Section 7 Certain Legitimate Uses.

Enforcement Perimeter

Subject to Section 8 mandatory obligations, Rule 3 notice standards, Rule 7 dual-clock breach intimation, and RBI Outsourcing & Master Directions overlay.

15 Transformation Milestones (M01–M15)

Dependency-ordered execution sequence spanning legal, engineering, and assurance workstreams.

Phase 1: Inception & Statutory Perimeter

M01 Section 3 / Section 4
Statutory Obligation Register & Baseline Scoping

Enacted 102 provisions in canonical register; classified 54 operational obligations and established non-SDF baseline.

Ref: Ch. 2 / OBL-01
M02 Section 8(9) / Rule 9
Programme Governance Charter & DPO Appointment

Chartered cross-functional privacy steering committee, designated Indian DPO reporting directly to Board.

Ref: Ch. 6 / OBL-20
M03 Section 8(5)
Transformation Budget & Economic Model (COST-001)

Calculated 6 workforce/infrastructure investment scenarios across 14 enterprise systems.

Ref: Ch. 29 / COST-001

Phase 2: Discovery & Notice Architecture

M04 Section 8(1)
14-System Inventory & Data Flow Map (INV-001)

Completed bounded discovery of SYS-001..014, 10 personal datasets, and 10 cross-boundary data flows.

Ref: Ch. 7 / INV-001
M05 Section 5(1) / Rule 3
Section 5 Multilingual Itemized Notice Rollout

Redesigned customer notice into standalone bilingual (EN/HI) itemized notices with 13 mandatory points.

Ref: Ch. 9 / C-01
M06 Section 5(2)
Legacy Pre-Commencement Notice Protocol (s.5(2))

Automated batch notice dispatch to 450,000 existing customers prior to enforcement cliff.

Ref: Ch. 9 §2 / OBL-10

Phase 3: Consent & Deletion Lifecycle

M07 Section 6(1)
Section 6 Consent Capture & Re-architecture

Eliminated bundled consent and pre-ticked boxes across web/mobile; integrated Consent Ledger (SYS-010).

Ref: Ch. 9 / C-02
M08 Section 6(4)
Consent Withdrawal Parity State Machine (WITHDRAW-001)

Engineered real-time withdrawal cascade propagating stops to databases, analytics, and marketing engines.

Ref: Ch. 10 / C-05
M09 Section 8(2)
Vendor Data Processor Agreements (DPA) Execution

Executed Section 8(2) flow-down contracts and deletion ACK verifications with all third-party processors.

Ref: Ch. 17 / C-14

Phase 4: Rights & Incident Management

M10 Section 11–Section 14
Principal Rights & Grievance Service (SYS-011)

Deployed 3-tier grievance portal handling Access, Correction, Erasure, and Nomination within 30 days.

Ref: Ch. 12 / C-11
M11 Section 8(6) / Rule 7
Dual-Clock Breach Incident Management Drill

Validated parallel CERT-In 6-hour and DPDP Rule 7 notification pipelines through simulated live fire drill.

Ref: Ch. 16 / C-06
M12 Section 8(7)
Automated Erasure Everywhere Engine (s.8(7))

Automated TTL purging across primary databases, cold archives, and downstream vendor endpoints.

Ref: Ch. 14 / C-13

Phase 5: Procurement & Risk Assessment

M13 Ch. 30
Privacy Suite RFP Evaluation (SCORE-001)

Conducted head-to-head proof-of-value testing against 4 commercial privacy platforms using identical synthetic test data.

Ref: Ch. 30 / C-22
M14 Section 10(2) / Rule 13
Underwriting Model DPIA & Risk Assessment

Executed Section 10(2) Data Protection Impact Assessment for automated credit decisioning algorithms.

Ref: Ch. 20 / C-20

Phase 6: Assurance & BAU Transition

M15 Ch. 22 / A.9
54-Control Workpaper Handoff & BAU Runbook

Delivered audit-ready evidence repository (A.9) to external assurance team and transitioned to monthly watch loop.

Ref: Ch. 22 / Ch. 36

Delivered Working Artifacts Vault (49 Files)

Cryptographically tracked reference models, decision JSONs, specimens, and executable test suites.

out/dossier/CASE-001/
PACK-001 Ledger
manifest.json

Cryptographic SHA-256 manifest verifying delivered bytes and evidence categories.

INV-001 Inventory
inventory.json

Declared systems (SYS-001..014), personal datasets (DS-001..010), and cross-border edges.

GROUND-001 Legal Basis
purpose-decisions.json

Statutory purpose evaluations, allowed/conditional grants, and hard purpose stops.

ARCH-001 Topology
architecture.md

Trust boundaries, API contracts, Decision Invariant DEC-001, and system-level mappings.

NOTICE-PACK Specimen
NOTICE-001-v1.md / hi.md

Itemized Section 5 customer notice specimens in English and Hindi (13 statutory points).

CONSENT-001 Evidence
consent-events.json

Simulated consent transactions with notice version hashes, purpose bitmasks, and timestamps.

WITHDRAW-001 State Machine
withdrawal-state.json

Consent withdrawal execution logs demonstrating real-time propagation across 14 systems.

RIGHTS-001 Case File
rights-case.json / response.md

End-to-end Data Principal Rights request, identity verification, and structured response.

INCIDENT-001 Breach Pack
incident.json / NOTICE-BOARD-001.md

Dual-clock incident notification specimens (CERT-In 6h and DPDP Rule 7 initial/detailed).

DPA-001 Contract
processor-schedule.md

Mandatory Section 8(2) vendor contract flow-down terms, audit covenants, and deletion SLAs.

DPIA-001 Risk Assessment
dpia.md / dpia-decisions.json

Formal Data Protection Impact Assessment for credit scoring ML model under Rule 13.

COST-001 Economics
cost-model.xlsx / cost-model.json

Financial model calculating 6 compliance staffing, tooling, and remediation budget curves.

SCORE-001 Evaluation
bidder-scorecard.xlsx

Standardized RFP evaluation scorecard with hard gating criteria and PoV test results.

TEST-001 Test Harness
tests/results.json

Executable test runner verifying authority, purpose restrictions, and erasure permanence.

In-Scope Systems Topology (SYS-001..014)

14 canonical systems across client boundaries, production core, analytics, and external processors.

Explore Systems Architecture →

Independent Audit Handoff & BAU Transition

Transitioning the one-time transformation programme into a continuous, defensible compliance engine.

Appendix A.9 Control Workpapers

All 54 operational controls are packaged with deterministic test specimens (`SPEC-Q10-*`), cryptographic run logs, and signed DPA schedules ready for external auditor verification.

Monthly Regulatory Watch (Chapter 36)

BAU operating rhythm: Monthly Gazette scan, DPBI portal adjudication review, vendor DPA compliance audits, and bi-annual dual-clock breach simulations.