Legal Register
Part V — Solutions, Accelerators & Build-vs-Buy
Part V — Solutions, Accelerators & Build-vs-Buy
Chapter 30 · 2,705 words
14 min read

Chapter 30 — RFP, Proof of Value and Vendor Acceptance

1. Procurement must preserve a refusal

A well-run procurement can still purchase the wrong scope. Feature lists and prices are easy to compare; missing processor execution and unowned exceptions are harder. The central requirement of this chapter is that a high weighted score must never turn a failed mandatory condition into an acceptable result. First establish legal and operational eligibility. Then compare the remaining proposals on capability, evidence, cost and exit.

The legal floor is not a numerical preference. Section 8(1) preserves the Data Fiduciary’s responsibility for processing undertaken by it or on its behalf, and Section 8(2) requires a valid contract for the specified processor engagement.[1] Lines 330–337. Procurement can allocate work, remedies and evidence duties; it cannot make the fiduciary’s responsibility disappear. Nor can a supplier’s use of correct statutory vocabulary replace execution evidence. A globally named “DSAR” feature may behave correctly, while a “DPDP-native” feature may fail the actual case.

The supplied instrument is out/templates/procurement/RFP_SCORECARD_TEMPLATE.xlsx. Its blank RFP Scorecard sheet is reusable; BID-001 and BID-002 are populated teaching comparisons. PoV Test-data contains proposed isolated scenarios, not supplier test outcomes. Synthetic evidence contains authored workpapers referenced by the two examples. Source inventory remains in dpdp_solution_landscape.xlsx; its provenance grades are not procurement scores.

2. Fix the scope before fixing the weights

CASE-001 is the fictional NBFC/distributor defined in research/legal/DOSSIER_CONTRACT.md: not an insurer, not a registered Consent Manager and not designated as an SDF. The scorecard evaluates an integrated proposal covering the listed capabilities, including voluntary SDF readiness. A narrowly scoped scanner should not be forced through this whole-programme template without revising the scope and documenting which client or supplier owns the remaining controls.

The author-selected weights below total 100 percentage points. They are not regulatory priorities or estimated breach probabilities. The evidence row has a meaningful nonzero weight, and TCO and exit are explicit commercial criteria rather than hidden claims in the prose.

IDCriterionWeight pointsEvaluation scope
C01Consent and notice12Reconstruct receipt and reject stale grant revival.
C02Rights and grievance12Verify actor, preserve subject, complete scoped actions and explain exceptions.
C03Breach workflow8Separate awareness, initial notices, detailed update and failed delivery.
C04Child safeguards6Reject prohibited targeting even with parent token; assess conditional exceptions.
C05Governance and SDF readiness6Client ownership now; SDF measures conditional on actual designation.
C06Processor execution10Propagation, acknowledgement and unresolved-copy handling.
C07Discovery and coverage8Known denominator, unsupported stores and per-class quality.
C08Location and security6Approved data/access paths, safeguards and scoped transfer decision.
C09Retention and restore10Eligible erasure, restricted lawful retention and quarantine/replay.
C10Evidence and auditability10Reconstruct failures, decisions and retests outside the vendor dashboard.
C11Three-year TCO6Native licence meters, client effort, service scope and sensitivity.
C12Exit and operator handover6Neutral import, retained exceptions and removal of vendor access.
Total100Legal minimums remain separate mandatory gates.

In each bidder sheet, the weights are D2:D13. D14 sums them. C10’s evidence weight is D11. I2:I13 contain adjusted-point formulas and I14 is the diagnostic total. B17 is mandatory-gate state, B18 eligibility, and B19 the eligible score. A failed or incomplete proposal has a blank B19, even if its diagnostic total is high. Do not sort disqualified diagnostic scores together with eligible scores.

For a different procurement, publish weights before bids, map the scope and get the applicable floors reviewed. Do not eliminate a duty by setting its preference weight to zero. This fixed workbook requires a positive evidence weight and a total of 100; it does not support an improvised N/A gate. An actual non-applicable requirement needs a documented applicability decision and revised, consistently issued scope rather than an unexplained blank.

3. Capability and evidence are different inputs

Raw scores are integers from zero to five. Zero means absent within the evaluated scope; one means a concept; two means partial capability; three means the core path with material gaps; four means the full scoped requirement; five means that requirement plus the declared resilience/operability behavior. Evaluators must explain the assigned anchor. For commercial rows, “full requirement” means the predeclared cost transparency, scope and exit conditions, not that the cheapest number automatically earns five.

Evidence tiers are an additional author-designed discount, separate from Chapter 25’s provenance classification. Tested has multiplier 1.00: the buyer can reproduce relevant behavior in the agreed scope. Report has 0.70: an inspectable, relevant report exists but has not been reproduced by this evaluation. Promise has 0.40: a contractual commitment only. Attestation has 0.20: a self-assertion. None or a missing reference gives zero credit and leaves the row incomplete. A genuine report must still be checked for product version, period, exclusions, author and relevance.

The formula is:

adjusted points = weight points × raw score / 5 × evidence multiplier

A four-point consent score with weight 12 contributes 9.60 points with Tested evidence, 6.72 with Report, 3.84 with Promise or 1.92 with Attestation. The workbook recomputes these values rather than storing hand-entered totals. It does not claim that every attestation will lose to every demonstration under every combination of raw scores and weights. Mandatory gates, not that unsupported claim, prevent a low-evidence legal floor from being traded away.

Evidence is considered twice for different reasons. The row multiplier discounts the support for a capability claim. C10 evaluates the system’s ability to preserve and export usable evidence as an operational capability. That is deliberate, not accidental double counting, but the weights are a buyer policy choice and should be sensitivity-tested. A high-quality export function does not prove that another row’s processing behavior works.

A reference in column G is not an authentication mechanism. The workbook checks completeness and arithmetic, not the truth of a document. The evaluator must resolve the reference, inspect its content and scope, and retain a review record. All references in the example resolve to clearly synthetic workpapers; their Tested labels are stipulated teaching inputs, not claims that a vendor was tested by this book.

4. Mandatory gates override the average

The workbook contains eight buyer-designed gates at rows 23–30. Each requires a reviewed PASS and supporting reference. FAIL disqualifies; blanks, unknown values or a missing reference leave the result incomplete. A declared failure takes priority over missing scoring data. These gates translate applicable requirements and minimum operating conditions into procurement decisions; they are not statutory form fields.

GateMinimum decision required before acceptance
G01 — Legal mappingReviewed activity, grounds, conditions, exceptions and commencement; unresolved permission is not approval.
G02 — Withdrawal/child restrictionsThe required scope rejects stale grants and prohibited targeting; a parent token cannot override an applicable prohibition.
G03 — Rights/actor scopeVerified actor, truthful partial response and correct rights semantics; no invented general portability right or response clock.
G04 — Retention/restoreRestricted lawful retention and eligible disposal coexist; restore cannot reactivate withdrawn use.
G05 — Processor evidenceMissing acknowledgement or an unresolved eligible copy cannot be called completed execution.
G06 — Security/locationApproved processing/access boundaries with no unresolved critical bypass or unapproved movement.
G07 — Evidence/exit minimumReconstructable export and meaningful neutral import; retained exceptions are preserved.
G08 — Operations/retestA named operator and completed critical-defect retest support acceptance.

Each gate must be evaluated against the relevant legal scope. Withdrawal is accepted under Section 6(4); cessation follows Section 6(6), including reasonable time and the exception for processing required or authorised without consent.[1] Lines 232–249. The Company’s immediate new-marketing gate and five-minute processor target are stricter illustrative engineering/service choices, not statutory deadlines. Sections 8(7) and 12(3) require scoped erasure/retention analysis; Rule 8(3) adds restricted retention for its specified purposes.[1] Lines 351–359, 473–476.[40] Lines 1153–1166.

For breach workflows, awareness starts Rule 7’s notification logic: initial intimation without delay and the Board’s detailed information within seventy-two hours, or a longer period the Board allows on written request.[40] Lines 1112–1139. Merely discovering personal data in an authorised log does not establish a breach. An alert, classified breach, prepared notification and successful delivery are different events. The supplied PoV specification keeps them separate.

SDF criteria remain conditional. Section 10 requires designation; the individual DPO, independent auditor and additional measures cannot be assumed merely from business size.[1] Lines 404–438. Rule 13 specifies the cycle and further duties.[40] Lines 1276–1293. All post-commencement CASE-001 examples assume the retained scheduled provisions commence unchanged; the notification, Rule 1 and corrigendum—not a sales timeline—support that planning assumption.[39] Lines 49–59.[40] Lines 1005–1010.[41] Lines 25–38.

5. The complete hypothetical comparison

BID-001 is a fictional integrated proposal. It scores four on each criterion, with stipulated Tested evidence and all eight hypothetical gates passing. Its diagnostic and eligible scores are both 80.00. This is an illustration of the model, not an assertion that an unnamed real vendor produced these results.

BID-002 is a fictional high-feature proposal with an unresolved processor defect. It scores five on most rows, two on processor execution and three on evidence/auditability. Its TCO row has Report evidence; the other rows use stipulated Tested inputs. Its diagnostic score is 88.20, but G05 is FAIL, so its status is DISQUALIFIED and its eligible score is blank. The model refuses to award on a high average. That is the principal worked decision, not a disguised ranking of the firms discussed earlier.

Hypothetical caseDiagnostic scoreStatusEligible score
BID-001 base80.00ELIGIBLE80.00
BID-002 base88.20DISQUALIFIED — G05
Unfilled reusable template0.00INCOMPLETE
BID-001 without first-row evidence70.40INCOMPLETE
BID-001 with first-row Report tier77.12ELIGIBLE77.12
BID-001 with every row’s evidence absent0.00INCOMPLETE

The hypothetical eligibility threshold is 70, stored at B16. Equality passes: a score of 80 with threshold 80 is eligible, while threshold 80.01 places the same otherwise-complete proposal below threshold. Blank or invalid scores do not cause automatic reweighting over the remaining criteria. They block eligibility. A missing gate reference also blocks eligibility even if someone has typed PASS.

A sensitivity shifts four weight points from consent to TCO: C01 becomes 8 and C11 becomes 10, with all other weights unchanged. BID-001 stays at 80.00; BID-002 changes to 87.00 but remains disqualified. This does not prove the weights are universally right. It shows that the refusal survives this commercial emphasis. Sensitivity analysis should challenge rankings among eligible bidders, never weaken the legal floor to obtain a preferred winner.

The actual local calculation run exercised 29 cases, including blank sheets, missing gate/evidence inputs, invalid/fractional/out-of-range scores, wrong weight totals, zero evidence weight, each evidence discount and threshold boundaries. Results are retained in out/remediation/q08/verification-results.json. These are real formula-execution results on synthetic inputs. They do not establish that the hypothetical workpapers are real observations.

6. Contract the proof of value and acceptance schedule

Use buyer-controlled synthetic data in an isolated environment. Version the proposed configuration, seed data, expected decisions and evidence format before the supplier demonstrates it. Include stale replay, failed acknowledgement, partial rights response, lawful-retention exception, restore quarantine, child-targeting refusal and an incident-notification failure branch. The PoV Test-data sheet is a specification for such work; it is marked NOT RUN against a supplier.

The following schedule is an author-recommended contractual example, not an observed engagement or legally prescribed calendar.

StageDeliverable and accountable acceptance ownerDefect/payment treatment
Scope freezeProcurement and client legal/control owners agree systems, edition, actors, legal mapping, mandatory gates and quoted exclusions.No main deployment approval while scope or legal permission is unresolved. A bounded PoV may be separately contracted.
Isolated PoVEngineering retains setup, configuration, seeded inputs, expected/actual outputs and supplier explanations.Critical boundary failures block acceptance regardless of score; record lower-severity defects with owner and due date.
Defect correction/retestSupplier supplies change identity and cause analysis; client test owner reruns failed and affected regression cases.Do not overwrite the failed run. Retest cost responsibility and repeat-failure remedies are agreed in the contract, not assumed free.
HandoverOperations reconstructs a failed case, runs the procedure and imports an evidence export without supplier-only access.Final acceptance/payment milestone remains withheld under the agreed schedule until mandatory conditions pass; a project manager cannot waive an applicable legal floor.
Post-award reviewClient control owners review scoped operation at illustrative 30/60/90-day checkpoints and after material changes.Use approved non-destructive checks or isolated replays; live destructive testing needs separate authorisation. New critical defects trigger restriction, remediation and retest.
ExitClient and supplier reconcile export/import, unresolved work, legal retention, access revocation and eligible deletion.Closure needs scoped evidence; a generic deletion certificate or a count-only export is insufficient.

The contract should identify the owner and custodian of each evidence class, permitted access, delivery format and survival after termination. Obtain rights to configuration and custom artifacts needed for operation, without pretending a proprietary platform’s entire source code is automatically included. Define subprocessor visibility, change notices, incident assistance, rights cooperation and audit access for the relevant role. Remedies, liability and warranties require negotiation and legal review; no formula in the workbook supplies them.

Exit is not “export everything, then delete everything.” Records still subject to a valid retention requirement remain restricted under the agreed disposition, while eligible working copies are erased and access is revoked. Test both content and relationships: notice versions, purpose identifiers, subject/representative distinction, sequence order, incomplete processor tasks and retest history. Hashes and counts support reconciliation but do not alone prove semantic completeness or deletion.

7. What the delivered instrument establishes

The workbook contains working formulas rather than empty weighted-score cells. The local formulas 1.3.4 engine evaluated them; Excel and LibreOffice were not available, so UI layout, native-application recalculation and cached values remain unverified. Calc-on-open is enabled. This is an explicit tooling limit, not a claim that openpyxl calculated the workbook. The script and retained output make the actual verification reproducible.

The decision artifact to preserve is SCORE-001 with its exact weights, raw scores, tiers, gate decisions, evidence references and scope/version. The integrated dossier workbook preserves the same two fictional bidder sheets without renaming bidders as real suppliers. The source landscape remains a source inventory, the public comparisons remain bounded hypotheses, and the scorecard demonstrates how a procurement committee can refuse a high-scoring but ineligible proposal.

Chapter 31 moves into sector-specific applicability. It can change the questions and conditions, but not the distinction between a source claim, a hypothetical assumption, an observed test and authority to proceed.

Source notes and reproducibility

From the book root, run python3 -B out/remediation/q08_verify_calculations.py. Inputs are out/remediation/q08/score-model.json, synthetic-workpapers.json and the shipped workbook. The reproducibility README records local dependency installation and limitations. Source URL/date/hash identities are in out/remediation/q08/source-manifest.json.

Retained file map

The line ranges cited above refer to these exact local captures:

Sources

[1] https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdfhttps://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf [39] https://www.meity.gov.in/static/uploads/2025/11/c56ceae6c383460ca69577428d36828b.pdf — G.S.R. 843(E), DPDP Act commencement notification [40] https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf — Digital Personal Data Protection Rules, 2025, G.S.R. 846(E) [41] https://www.meity.gov.in/static/uploads/2025/12/3c7ebbae0e5456f493f486e6845df86b.pdf — Corrigenda to G.S.R. 846(E), G.S.R. 892(E)


Contents · Reader guide and citation conventions · Artifact index