Legal Register
Part I — Executive Strategy & Legal Perimeter
Part I — Executive Strategy & Legal Perimeter
Chapter 01 · 4,636 words
23 min read

Chapter 1 — DPDP as an Enterprise Transformation Programme

1. Why DPDP is a transformation programme, not a privacy project

The Digital Personal Data Protection Act, 2023 (22 of 2023), read with the Digital Personal Data Protection Rules, 2025 (GSR 846(E)) and the commencement notification GSR 843(E) of 13 November 2025, changes how personal data is governed inside the enterprise. The effect is structural, not cosmetic:

  • The commenced core will make personal-data handling subject to defined statutory duties, defined principal rights, and defined enforcement consequences.
  • Responsibility for lawful processing does not sit with a privacy team. Section 8(1) makes the Data Fiduciary responsible irrespective of any agreement to the contrary and irrespective of any processing done on its behalf by a Data Processor. That is a board-level accountability, not a compliance-box.
  • The obligations cut across data, product, engineering, legal, procurement, security, marketing, HR and operations. No single function can discharge them.

A programme lens is therefore required, not a project. The distinctions matter:

ProjectProgramme
Time horizonBounded end-datePersistent / living
OwnerPrivacy/DPO teamExecutive sponsor + cross-functional delivery
Success measure“Go-live”Demonstrable control effectiveness, sustained
Change surfaceOne functionOperating model, architecture, procurement, people
Legal postureReactive to violationsProactive demonstration of accountability

A readiness failure to guard against is treating DPDP as a deliverable that a DPO “hands over”. Because the Act is persistent and systemic, readiness must be framed as an ongoing operating discipline with named owners, funded control planes, and testable evidence — the structure this book describes across Chapters 7–36.


Section 1(2) of the Act explicitly provides that different provisions may come into force on different dates. The Central Government exercised that power in GSR 843(E), published 13 November 2025, creating three tranches. This is the single most important fact for programme planning: the organisation has a statutory clock, not an open-ended one.

TrancheEffectiveProvisionsWhat this means for the enterprise
(a) Immediate13 Nov 2025Section 1(2); Section 2 (definitions); Sections 18 to 26 (Board); Section 35; Sections 38 to 43; Section 44(1),(3)Institutional, interpretive and miscellaneous provisions are in force; this does not establish staffed operations or activate the deferred inquiry/penalty powers.
(b) One year13 Nov 2026Section 6(9); Section 27(1)(d)Every Consent Manager must register (Section 6(9)); Section 27(1)(d) addresses a breach of its registration conditions, not SDF records or legitimate uses.
(c) Eighteen months13 May 2027Sections 3 to 5; Section 6(1)–(8),(10); Sections 7 to 10; Sections 11 to 17; Section 27 (except (1)(d)); Sections 28 to 34, 36, 37; Section 44(2)The core operating obligations: applicability, notice, consent, legitimate uses, general fiduciary obligations (including security safeguards, breach, retention/erasure, grievance), children, Significant Data Fiduciary duties, principal rights, cross-border and exemptions all become enforceable.

2.1 What the clock forces

  • The decisions that matter are precommencement decisions. The organisation should design, build and test the tranche-(c) obligations before they are live, so that on 13 May 2027 it is demonstrably operating them rather than racing to catch up.
  • Establishment is not staffed operation. GSR 844(E) establishes the Board; GSR 845(E) specifies composition, not appointments. The actual appointment/headcount evidence remains unresolved (Chapter 6; EST:51–57[6]; MEMBERS:49–52[7]).
  • Transitional processing of legacy consents has real structure. Section 5(2) addresses consent given before commencement: the Data Fiduciary must give the Data Principal a notice describing the personal data and purpose processed, the manner of exercising rights, and how to complain to the Board, and may continue processing until consent is withdrawn. Notice is due as soon as reasonably practicable under Section 5(2), not on an invented consent-expiry date. Section 6(10), in the core tranche, places notice-and-consent proof on the fiduciary when questioned in a proceeding (ACT:182–205,264–268[3]). Programmes should treat “legacy data remediation” as a first-class workstream, not an afterthought.

The Rules have their own verified staging: Rules 1,2,17 to 21 on 13 November 2025; Rule 4 on 13 November 2026; Rules 3,5 to 16,22–23 on 13 May 2027. These dates use the printed Gazette publication date, not the upload code. Rule 1 is read with the corrigendum (COMM:49–59[5]; RULES:1005–1010[4]; CORR:28–30[8]). The early Section 27(1)(d) power versus deferred Sections 28/33 procedure is an interpretation question (QL-006), not a reason to describe all enforcement as early.


3. Applicability: who is in scope (and who is not)

The Act applies (Section 3) to:

  • (a) processing of digital personal data within the territory of India, where the data is collected in digital form, or collected in non-digital form and later digitised; and
  • (b) processing of digital personal data outside India, if that processing is in connection with any activity related to offering goods or services to Data Principals within India.

It does not apply (Section 3(c)) to personal data processed by an individual for personal or domestic purposes, or to personal data made publicly available by the Data Principal or by another person obliged by Indian law to make that personal data public (ACT:146–157[3]).

Key role definitions (Section 2):

  • Data Fiduciary (Section 2(i)): the person who, alone or with others, determines the purpose and means of processing of personal data.
  • Data Principal (Section 2(j)): the individual to whom the personal data relates — and, notably, includes parents/lawful guardians for a child, and lawful guardians for a person with disability where a lawful guardian acts on her behalf; disability alone does not imply substituted decision-making (ACT:73–77[3]).
  • Data Processor (Section 2(k)): any person who processes personal data on behalf of a Data Fiduciary.
  • personal data (Section 2(t)): any data about an individual who is identifiable by or in relation to such data.
  • personal data breach (Section 2(u)): any unauthorised processing or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data that compromises confidentiality, integrity or availability.

The programme must map the entity’s actual processing profile to these definitions before assuming applicability. Chapter 3 supplies the applicability and processing-ground decision trees; this chapter only establishes that applicability is a conditional, entity-specific determination — not something to assume from a vendor’s “DPDP-compliant” marketing claim.


4. The obligations that frame the programme

The transformation programme is, at bottom, a build-out of the control planes that discharge the Act’s obligations. The core obligations (all effective 13 May 2027 except where noted) are summarised here and developed in full in later chapters.

4.1 Grounds for processing (Section 4)

Personal data may be processed only in accordance with the Act and for a lawful purpose (i.e., a purpose not expressly forbidden by law), on one of two grounds:

  • the Data Principal’s consent (Section 6); or
  • certain legitimate uses (Section 7).

This is a different structure from GDPR’s basket of legal bases and must not be imported by analogy. Chapter 8 treats purpose and processing-ground governance.

  • Every consent request must be accompanied or preceded by a notice (Section 5(1)) informing the principal of the personal data and purpose, how to exercise rights, and how to complain to the Board.
  • Consent must be free, specific, informed, unconditional and unambiguous with a clear affirmative action, limited to the personal data necessary for the specified purpose (Section 6(1)); any part of consent constituting an infringement of law is invalid to that extent (Section 6(2)).
  • Consent must be requested in clear, plain language with access in English or an Eighth Schedule language, and must include DPO (where applicable) or authorised-person contact details (Section 6(3)).
  • The principal has a right to withdraw consent, with ease comparable to giving consent under Section 6(4). Section 6(6) requires cessation and causing processor cessation within a reasonable time unless non-consent processing is required or authorised under the Act, Rules or other law (ACT:234–250[3]). Chapter 10 develops the operating design.

4.3 Certain legitimate uses (Section 7)

Section 7 lists nine conditioned uses, not a general commercial reasonable-purpose ground. Clause (a) requires the principal voluntarily to provide her own data for the specified purpose without indicating non-consent. Clauses (b)/(c) concern the State/instrumentalities; (d) a legal obligation to disclose information to the State; (e) qualifying judgments, decrees or orders; (f) medical emergency; (g) epidemic/public-health measures; (h) disaster/public-order assistance; (i) employment or employer protection. Chapter 3 supplies every clause’s exact text, conditions and counterexample (ACT:269–329[3]). Corporate restructuring is instead a conditioned Section 17(1)(e) exemption (ACT:537–542[3]). A named purpose in a notice is not, by itself, authority to process.

4.4 General obligations of the Data Fiduciary (Section 8)

This is the operational heart for the programme. Section 8 obliges the Data Fiduciary to:

  • (1) be responsible for compliance regardless of any agreement to the contrary or failure of the principal to fulfil duties, including for processing by a Data Processor;
  • (2) engage a Data Processor only under a valid contract;
  • (3) ensure completeness, accuracy and consistency of personal data likely to be used to make a decision affecting the principal or to be disclosed to another fiduciary;
  • (4) implement appropriate technical and organisational measures to ensure effective observance of the Act;
  • (5) protect personal data by taking reasonable security safeguards to prevent a personal data breach;
  • (6) intimate the Board and each affected principal of a personal data breach;
  • (7) erase personal data when purpose is served or consent withdrawn (whichever is earlier), subject to lawful retention, and cause the Data Processor to erase data;
  • (9) publish business contact information of the DPO (or authorised person);
  • (10) establish an effective mechanism to redress grievances.

Rule 8(3) separately requires personal data, associated traffic data and other processing logs to be retained for at least one year from processing for Seventh Schedule purposes; Rule 6(1)(e) separately addresses security-purpose retention. Cessation of marketing is not permission to destroy these records or reuse the archive commercially. Copy/reset interpretation remains scoped in QL-001 (RULES:1101–1106,1153–1166[4]).

These statutory outcomes inform the recommended control planes named in this book: processing inventory, notice/consent, rights and grievance, breach and incident, retention/erasure, and processor control.

4.5 Children (Section 9)

Before processing a child’s personal data, the fiduciary must obtain verifiable consent of the parent or lawful guardian (Section 9(1)); must not undertake processing likely to cause detrimental effect on the child’s well-being (Section 9(2)); and must not undertake tracking or behavioural monitoring of children, or targeted advertising directed at children (Section 9(3)). The Central Government may designate, by notification, an age above which a fiduciary verifiably ensuring safe processing is exempt from some of the Section 9(1)/(3) obligations (Section 9(5)). Rule 12 and the Fourth Schedule also provide conditional class/purpose relief under Section 9(4); neither removes the Section 9(2) detrimental-effect bar. A parent grant alone cannot authorise child targeting (ACT:386–403[3]). Chapter 13 treats this in full, including the engineering of age and guardian assurance without over-collecting data.

4.6 Significant Data Fiduciaries (Section 10)

The Central Government may notify a fiduciary or class as a Significant Data Fiduciary based on volume and sensitivity of data, risk to rights, impact on sovereignty/integrity of India, risk to electoral democracy, security of the State and public order (Section 10(1)). An SDF must (Section 10(2)):

  • appoint a Data Protection Officer who is based in India, responsible to the board, and the point of contact for grievance redressal;
  • appoint an independent data auditor to evaluate compliance; and
  • undertake periodic Data Protection Impact Assessments, periodic audits, and such other measures as prescribed. Rule 13 requires DPIA and audit once in each twelve-month period from notification, a significant-observations report by the person carrying them out, algorithmic technical-measure diligence, and a conditional specified-data/traffic transfer restriction (RULES:1276–1293[4]).

Chapter 19 treats SDF readiness. A programme should determine SDF status early: it materially raises governance costs and sets a different bar.

4.7 Data Principal rights and duties (Sections 11 to 15)

Rights:

  • Right to access information (Section 11): summary of processed data, processing activities, and identities of other fiduciaries/processors with whom data was shared, with shared-data descriptions and the Section 11(2) exception. Access and Section 12 rights concern prior-consent processing, including Section 7(a), not every ground indiscriminately (ACT:441–476[3]).
  • Right to correction and erasure (Section 12): correction, completion, updating and erasure of personal data for which consent was given, subject to lawful retention.
  • Right of grievance redressal (Section 13): a readily available means of redressal, with a reasonable published grievance-response period not exceeding ninety days under Rule 14(3), not a universal rights deadline; the principal must exhaust this route before approaching the Board.
  • Right to nominate (Section 14): nominate another individual to exercise rights in the event of death or incapacity.

Duties of the Data Principal (Section 15) include complying with law while exercising rights, not impersonating; not suppressing material information while providing personal data for a State/instrumentality-issued document, identifier, proof of identity or proof of address; not registering false/frivolous grievances or complaints with a fiduciary or Board; and furnishing only verifiably authentic information for correction or erasure (ACT:496–509[3]).

4.8 Cross-border and exemptions (Sections 16 to 17)

  • Section 16(1) permits notified destination restrictions; Section 16(2) separately preserves higher transfer protection/restrictions under other Indian law. Rule 15 concerns Government requirements for foreign-State/controlled-entity access, and Rule 13(4) adds conditional SDF specified-data restrictions. None is a universal DPDP localisation rule (ACT:515–522[3]; RULES:1287–1290,1319–1323[4]).
  • Section 17(1)(a)–(f) covers legal claims, specified adjudicatory/regulatory functions, offences or legal contraventions, qualifying export processing, approved corporate schemes and specified defaulted-loan information. It disapplies Chapter II except Section 8(1),(5), Chapter III and Section 16. Sections 17(2)–(5) have different effects, including conditioned Act-level exemptions and notification-dependent relief; Chapter 3 gives the complete decision table (ACT:523–583[3]).
  • Under Section 38, compatible laws apply additionally and DPDP prevails to the extent of actual conflict. Do not replace this with “stricter sector law always wins”; the transfer saving is specific (ACT:887–892[3]).

4.9 Enforcement and penalties (Section 33 and the Schedule)

If the Board determines, on conclusion of an inquiry, that a breach is significant, it may, after an opportunity of being heard, impose a monetary penalty from the Schedule (Section 33(1)), having regard to the nature, gravity and duration of the breach, type of data, repetitiveness, whether the person gained or avoided loss, mitigation action, timeliness and effectiveness, proportionate and effective deterrence, and likely penalty impact on the person (Section 33(2)).

The Schedule (penalty ceilings — “may extend to”):

Sl.BreachPenalty ceiling
1Failure to take reasonable security safeguards to prevent data breach (Section 8(5))₹250 crore
2Failure to give Board/principals notice of a breach (Section 8(6))₹200 crore
3Breach of children obligations (Section 9)₹200 crore
4Breach of Significant Data Fiduciary obligations (Section 10)₹150 crore
5Breach of Data Principal duties (Section 15)₹10,000
6Breach of a voluntary-undertaking term accepted by the Board (Section 32)Up to the penalty for the underlying breach
7Breach of any other provision of the Act or Rules₹50 crore

Two framing cautions for boards:

  • These are ceilings, not expected losses. Using maximum penalties as the risk-model input as though it were an expected award misstates what is known (see Chapter 6). A separately labelled extreme stress case is different.
  • The Board retains discretion over significance and amount; the real exposure is multi-dimensional (penalty + mandated remedy + reputational + operational disruption).

5. Programme design

5.1 Charter essentials

The author recommends an explicit programme charter covering:

  1. Business exposure and rationale: how customer trust, revenue and regulatory relationships depend on lawful personal-data handling.
  2. Decision rights: who owns data-acquisition, purpose-setting, retention and disclosure decisions; who may deviate (exception authority).
  3. Outcomes and success measures: demonstrable, testable control effectiveness (Chapter 22), not a “compliance ticked” artefact.
  4. Separation of mandatory compliance from good practice: deliver mandatory controls first, with evidence; treat “broader good practice” as an incremental layer. Do not let a vendor’s broad privacy-suite pitch substitute for the mandatory control set.
  5. Governance: an executive sponsor (Accountable), a programme delivery team (Responsible), privacy/DPO and legal (Consulted), board (Informed on material risk and resourcing). Per the operating-model RACI templates.

5.2 Control planes to fund up-front

The programme should stand up, and fund, the following control-plane seams rather than bolt them onto systems later:

Control planeAct basisLater chapter
Processing inventory (structured, unstructured, SaaS, shadow IT, derived)Sections 3 to 4, 8Ch.7
Purpose & processing-ground governanceSections 4, 7Ch.8
Notice & consent capture/versioningSections 5 to 6Ch.9
Consent withdrawal & downstream cessationSection 6Ch.10
Consent Manager / consent-software distinctionSection 2(g), Section 6(7)–(10), Rule 4 / First Schedule; different actors and tranchesCh.11
Rights, grievances, identity, nominationSections 11 to 15Ch.12
Children & guardian assuranceSection 9Ch.13
Retention, deletion, backups, legal holdsSection 8(7)–(8)Ch.14
Security safeguards & access controlSection 8(4)–(5)Ch.15
Breach detection & responseSection 8(5)–(6)Ch.16
Processors & third-party riskSection 8(1)–(2),(7)Ch.17
Transfers, cloud & reference architectureSection 16Ch.18
SDF governance (DPO, auditor, DPIA, audit)Section 10Ch.19
Impact assessmentsSection 10Ch.20
AI, analytics, profiling, derived dataSections 3 to 4, 8(3), and applicable ground; Rule 13 if SDFCh.21
Control testing, audit evidence, effectivenessSections 8, 10Ch.22

5.3 Sequencing against the statutory clock

Recommended programme phases, tied to GSR 843(E):

  • Foundation, from the current planning date: appoint the sponsor, establish the register and inventory ownership, and assess notification-dependent SDF status. Governance and incident readiness begin in parallel; discovery is not permission to postpone security or response.
  • 2026 build work: scope notice, consent, rights, retention and processor interfaces. An applicant Consent Manager targets the 13 November 2026 registration/Rule 4 regime. An ordinary fiduciary is not an SDF recordkeeper under Section 6(9), and no universal early CM integration duty is inferred.
  • Through 13 May 2027: test applicable core controls with positive, negative, race, restore and processor-failure cases; complete independent readiness review before operation relies on them.
  • Sustained operation: monitor legal change, investigate incidents, exercise rights services and reassess controls. Mandatory duties cannot be waived by a budget owner; voluntary SDF-style readiness is distinct from notified SDF obligations.

6. Operating model and governance

6.1 Roles and RACI

Per the operating-model templates (OPERATION_TEMPLATE.md; RACI_MATRICES.xlsx):

  • Executive/board sponsor (A): owns the outcome, funding, and residual risk decisions.
  • Privacy/DPO-type role (R): day-to-day delivery of obligations; point of contact.
  • Legal (C): consulted on every obligation boundary, exemptions, and penalty framing.
  • Business/engineering/procurement (C/R): execute the controls.
  • Board (I): informed on material risk and significant-change decisions.

6.2 Exception authority

Define who may deviate from an approved control, and under what approval. A fail-closed posture (consistent with the security-first mindset) means: ambiguous liabilities or insufficient evidence should halt the relevant process until a named authority decides — not silently proceed. This is a recommended uncertainty gate: neither the sponsor nor counsel can waive an applicable statutory prohibition.

6.3 Metrics and ongoing operations

  • Track demonstrated control effectiveness, not just “controls exist”.
  • Run the metrics defined in Chapter 24 (staffing, budget, BAU assurance, operational metrics).
  • Revalidate at a publication/source cutoff and on every regulatory change (the process in Chapter 2 and Chapter 36).

7. Control testing and evidence

The programme should adopt the obligation → control → test → evidence pattern (Chapter 22; ENGINEERING_EVIDENCE_TEMPLATE.md) from the start:

  1. Name the obligation (provision + rule).
  2. Specify the control that discharges it.
  3. Define the test and pass criteria (positive, negative, race, restore, processor, adversarial).
  4. Capture evidence (artifacts, logs, checksums) with a named owner.
  5. Gate: any obligation may move to “implemented” only with a verified test and named evidence owner.

The readiness assessment at programme start should grade every obligation using the A–F rubric so the programme has a quantified baseline and a dependency-ordered backlog.


8. Procurement and build-versus-buy

Where external DPDP capabilities are to be bought:

  • Use the solution landscape (dpdp_solution_landscape.xlsx) and the RFP scorecard (RFP_SCORECARD_TEMPLATE.xlsx) to distinguish vendors that evidence DPDP-specific capability from those offering generic privacy/security that must be remapped.
  • Do not accept “DPDP-compliant” assertions without demonstrated control-test evidence.
  • Treat processor contracts (Section 8(1)–(2),(7)) as mandatory control surfaces, not boilerplate. Chapter 17 and the RFP/PoV chapters (25–30) develop this.

9. Sector implications

Applicable sector regulation can change the timeline and control set. Chapter 5 supplies sourced CERT-In and RBI payment-system examples; lending, insurance distribution, securities, health and telecom are additional candidate overlays requiring exact instrument and entity-role checks, not universal obligations on the Company. Chapters 31–34 and SECTOR_OVERRIDES.xlsx remain downstream research/repair surfaces. The programme should run a sector-conflict scan (a first pass is in SECTOR_OVERRIDES.xlsx) before resourcing decisions are frozen, and should not flatten conflicts — they must be reconciled explicitly.


10. Board deliverable: the transformation brief

A practical output of this chapter is a board decision brief containing:

  1. Readiness baseline — an obligation-by-obligation grade (A–F).
  2. Statutory timeline — the GSR 843(E) tranche table with the entity’s commitments per tranche.
  3. Materiality framing — exposure expressed as a scenario model, explicitly noting that Schedule ceilings are not expected losses (Chapter 6).
  4. Resourcing and funding — the control planes to fund, with sequencing.
  5. Governance — sponsor, RACI, exception authority, escalation.
  6. Success measures — demonstrated control effectiveness, breach-readiness, and bounded independent review of the stated controls; no certification is implied.
  7. Residual decisions requiring board/counsel sign-off (below).

Completed board brief — CASE-001 / EVT-001

This is a synthetic decision specimen for ENT-001, the fictional NBFC lender with insurance distribution in the dossier contract, at 15 September 2026. It has 200 employees, 100,000 adult registered customers and 20,000 active loans as sizing assumptions, not observations. Its SDF status is not_designated; SYS-010 is enterprise consent software, not a registered Consent Manager. The Company is not assumed to be an insurer or payment-system provider.

The sponsor’s proposed decision is to fund a six-week foundations package: 120 legal-analysis hours at an illustrative ₹3,000/hour, 240 engineering hours at ₹2,000/hour, and 80 operations hours at ₹1,500/hour. The direct request is ₹9.60 lakh; an illustrative 15% contingency gives a ₹11.04 lakh ceiling. These are incremental planning assumptions for this package, not the whole programme budget or market rate evidence. The local arithmetic and sensitivity record is out/remediation/Q02/calculations.json.

Alternative A, policy-only purchase, is rejected because it cannot demonstrate FLOW-008 withdrawal propagation or explain FLOW-004’s foreign backup. Alternative B, a full-suite purchase before scope discovery, is deferred because licences would be selected before acceptance criteria exist. The recommended package funds inventory and ground decisions, incident readiness, and a narrow failure-path prototype in parallel. It does not approve training PUR-003, overseas vendor own-product reuse, or the unreviewed backup flow. DEC-001, DEC-004 and DEC-005 stay stops/restrictions; marketing consent cannot authorise model training.

Acceptance conditions are concrete: identify owners for every known system and a separately owned unknown set; map PUR-001/PUR-002/PUR-003 independently; demonstrate a revoked-marketing denial without destroying required evidence; retain an actual failed-acknowledgement case; and furnish a source-backed sector decision before reopening FLOW-004. A slide claiming completion or an unsigned processor promise does not satisfy these conditions. Finance releases later procurement money only after the defined package review, but incident containment is not delayed by that gate.

The brief records approval status as proposed_synthetic, not an actual board resolution. Counsel’s entity-specific licence/ground/retention decisions remain required before deployment; the retained Rules dates and breach clocks are not unread homework. QL-003/004 preserve the Board evidence and update-search limitations. Chapter 6 separates statutory maxima from the operational cost exposure the sponsor can estimate.

Remaining entity decisions

  1. Establish actual Section 3 facts and any specific Section 17 exemption evidence.
  2. Verify any designation or sector instrument applicable to the real entity; do not infer SDF status from scale.
  3. Resolve the scoped retention, transfer and CM-procedure interpretation questions in the canonical residual register.
  4. Obtain independent programme acceptance. The blank sign-off table below is a working template, not evidence that anyone approved this specimen.

Sign-off

RoleNameDateDecision
Legal/counsel
DPO / privacy owner
Business sponsor
Board sponsor

References (sources)

  • DPDP Act 2023 (22 of 2023), Official Gazette — research/legal/evidence/01_dpdp_act_2023_gazette.txt (provisions quoted: Sections 1(2), 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 33 and the Schedule).
  • Commencement notification GSR 843(E), 13 November 2025 — research/legal/evidence/02_gsr_843e_commencement.txt.
  • DPDP Rules 2025, GSR 846(E) — research/legal/evidence/05_gsr_846e_dpdp_rules_2025.txt (English operative text and corrigendum mapped in the canonical register).
  • Corrigendum GSR 892(E) — research/legal/evidence/06_gsr_892e_corrigendum.txt.
  • Board establishment GSR 844(E) and membership GSR 845(E) — research/legal/evidence/03_gsr_844e_board_establishment.txt, 04_gsr_845e_board_members.txt.

Source key and provenance legend

Physical references use newline-based line numbers in the following retained source paths; each numbered reference resolves to its original source URL. Review date: 15 September 2026. Full calculated hashes and source versions: out/remediation/Q02/source-manifest.json. The Q01 baseline and its bounded official-update limitations remain controlling; no later-law absence or entity certification is asserted.

Sources

[3] https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf [4] https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf [5] https://www.meity.gov.in/static/uploads/2025/11/c56ceae6c383460ca69577428d36828b.pdf [6] https://www.meity.gov.in/static/uploads/2025/11/cc217843dc3bcb37b2b05bcc3b4e031f.pdf [7] https://www.meity.gov.in/static/uploads/2025/11/f6c0837972422cf79d890bfe84cc04d6.pdf [8] https://www.meity.gov.in/static/uploads/2025/12/3c7ebbae0e5456f493f486e6845df86b.pdf [9] https://www.meity.gov.in/static/uploads/2026/05/53b1bcf01cab9a0adde463e73fbc3417.pdf


Contents · Reader guide and citation conventions · Artifact index