Chapter 36 — Sustaining Compliance and the Next Regulatory Change
1. Close the programme without closing its obligations
Chapter 35 does not end with the gates universally green. It ends with a usable dossier that distinguishes local checks from supplier completion, a response from execution, and a stopped proposal from an approved launch. That is the right starting point for business-as-usual work. The Company can finish a bounded implementation project while retaining the people, funding and authority needed to operate its controls. It cannot convert unresolved copies into successful deletion by changing the dashboard owner.
Three living records cross the handover: the applicable-source register, the control/evidence map and the residual register. Each has a named owner and a backup. The project team supplies versioned inputs and reproducible checks; the receiving service owner accepts the duty to investigate failures, not merely custody of a folder. A fourth record, the change ticket, connects new facts to the specific decisions they invalidate. The dossier guide keeps those records together, with the manifest distinguishing authored scenarios from actual local execution output.
This avoids two familiar failures. In close-and-decay, the last successful test becomes a permanent green light, despite changed software, personnel or data. In change-blindness, the register is nominally maintained but nobody can show which sources were checked, when the check succeeded or what happened when it failed. Both failures can persist behind a current-looking date. A regenerated cover page is not a new legal reconciliation, and a recent test of the wrong policy is not current assurance.
Sustaining is not always cheap rerunning. A rule change may require interpretation, new processor terms, an architectural restriction or more operational capacity. Reusing identifiers and executable checks reduces avoidable effort; it does not guarantee that the remaining change fits the existing budget or deadline. The Company therefore maintains a reserve and an escalation route rather than promising to absorb every change within a week.
2. Keep the legal baseline narrower than institutional claims
The retained evidence distinguishes Board establishment, composition and actual appointments. GSR 844(E) establishes the Board and states its head-office location. GSR 845(E) specifies four members; it does not name appointed people. The retained recruitment notice is an invitation concerning a Chairperson and four other members, not evidence that the posts are filled. EST:51–57; MEMBERS:49–52; RECRUIT:19–24.[3][4][7]
That inconsistency remains visible alongside the Act’s definition of Member; it is not repaired by inventing an appointment notification or an operational portal. ACT:100.[1] The Company must verify actual complaint, reporting and contact channels before real use. A digital-office provision or working ministry webpage does not by itself prove that a particular statutory filing route is available. Its incident specimens remain locally prepared, never represented as filings accepted by the Board.
Commencement is also provision-specific. The retained Act notification separates immediate institutional provisions, the one-year Consent Manager tranche and the eighteen-month core tranche. Rules have a separate commencement provision, read with the corrigendum’s corrected publication wording. COMM:49–59; RULES:1005–1010; CORR:28–30.[2][5][6]
The sustaining owner records instrument date, Gazette publication date, retrieval date, effective date and applicability decision separately. This makes a temporal error visible. A document downloaded in September is not necessarily September law; an instrument effective later may require readiness work now; an institutional provision already operative does not accelerate deferred core powers. Where actual publication evidence or entity-specific application is disputed, the owner records the issue and its containment consequence instead of making every legal question a generic “pending” flag.
The base Company remains not_designated as an SDF. Notification is the trigger under Section 10(1); voluntary preparation does not create designation. For an actually designated entity, Rule 13 separately supplies the twelve-month assessment/audit cycle, significant-observations reporting, technical-measure diligence and conditional specified-data/traffic restrictions. Those are distinct performance obligations, not a general instruction to commission one annual certificate. ACT:404–438; RULES:1276–1293.[1][5]
3. Assign sources to risks, not to a monthly ritual
The recommended source register groups official Gazette and MeitY material, Board publications when available, applicable sector regulators, contracts and internal technical changes. It records the exact source URL, retained body/hash, checked time, responsible role, backup, comparison result and affected provision/flow IDs. Press coverage and vendor alerts are leads; a load-bearing legal change is validated against its operative source before the register is amended. A source-fetch failure is an event with a retry and escalation owner, not evidence that nothing changed.
Cadence follows potential urgency. The hypothetical Company uses a daily business-day check for commencement, designation, transfer and incident-reporting sources, plus event-driven supplier and service-change alerts. It performs a monthly full inventory reconciliation to discover missing sources and stale ownership. These are author recommendations, not statutory frequencies. An immediately effective restriction can outrun any periodic review, so the system also accepts urgent direct alerts and can restrict affected dispatch pending verification. A month-end review alone cannot justify a promise of same-week publication-to-remediation performance.
The change record assigns the privacy change owner and Compliance deputy. If the scheduled daily check lacks a recorded result, the deputy takes over at the next stated checkpoint and escalates an unacknowledged handover to the COO and Legal. If time to effectiveness is shorter than the estimated investigation and implementation window, the team starts an urgent response. It restricts the affected route where necessary rather than silently extending the effective date or waiting for the regular board meeting.
Internal changes deserve the same discipline. A new analytics purpose, foreign support session, processor subservice, backup region, model input or identity integration can invalidate a decision without any Gazette publication. The product owner must register those changes before release; emergency containment can proceed under its separate incident authority. The control owner then asks what was actually changed: permission, data population, destination, execution mechanism, evidence or operational capacity. A content-only notice correction and a new processing purpose do not take the same approval path.
Recommended ownership is deliberately redundant but not ambiguous. Legal decides the applicable source interpretation; the business sponsor owns scope and resources; engineering owns implementation evidence; operations owns ongoing execution; the independent reviewer challenges the package within a defined remit. Two roles may inspect the same fact without either assuming the other approved it. A named backup must have sufficient access and competence to act, not merely appear in a RACI cell.
4. Measure the clocks that the team can actually influence
Publication, detection, validation, decision, restriction, implementation and verified closure are different timestamps. The Company measures publication-to-detection separately from detection-to-restriction and restriction-to-verified-release. Otherwise an impressive remediation interval can conceal weeks of unnoticed exposure. A source retrieval timestamp also cannot be substituted for when the decision owner became aware of the change.
The specimen CHANGE-001 assumes an internal exercise bulletin published at 18:00 on 30 June 2027, detected at 09:00 on 1 July and effective at 09:00 on 2 July. Thus detection lag is fifteen hours and detection-to-effectiveness leaves twenty-four hours. A 10:00 restriction checkpoint leaves twenty-three hours before the hypothetical policy becomes effective. Those intervals are calculated by the local checks, not observed operational response times. The scene’s 16:00 retest entry is a scenario timestamp; actual program execution time is stored separately in test results.
This policy bulletin is invented for the tabletop. It is not a country designation under Section 16, contains no fabricated Gazette number and does not claim that DPDP generally requires all data to stay in India. If a real transfer restriction arrives, its country, data, actor, effective time, exceptions and interaction with other requirements must be established from the actual instrument. Section 16 preserves the specified other-law transfer protections, while Rule 15 concerns Government requirements for the stated foreign-State/control circumstances. ACT:515–522; RULES:1319–1323.[1][5]
The dashboard does not treat “within target” as legal compliance. An internal response target can be missed without conclusively establishing a statutory breach, or met while a different mandatory duty fails. For incidents, Rule 7’s initial without-delay requirement and detailed-update clock are separate from the change-management service targets. A prepared notification is not sent; an attempted delivery is not a receipt; an assumed longer period is not a Board-allowed extension. RULES:1112–1139.[5]
5. Execute two design reroutes and preserve one purpose stop
CHANGE-001 links to actual dossier identifiers rather than narrating anonymous migrations. The first design reroute replaces new FLOW-004 dispatch to foreign SYS-008 with proposed India backup SYS-Q09-015. The old cohort remains inventoried and isolated. Its retention, export and disposal evidence are still required; creating a destination does not remove a source copy. SYS-008 keeps its identity, and the change does not retrospectively approve how the copy got there.
The second design reroute concerns FLOW-Q04-011, the offshore support path identified in ARCH-001. Raw foreign support access to SYS-002 stays denied. Proposed SYS-Q09-016 is an India-controlled masked support queue with its own operator, access and minimisation conditions. Calling a queue masked is not sufficient: actual field review, masking behavior and absence of backend bypass credentials are acceptance evidence. The route does not borrow permission from a backup decision simply because both targets are local.
The one purpose stop is PUR-003 across FLOW-003 and FLOW-005. This maintains the original absence-of-training-authority decision. FLOW-005 remains restricted, as EVT-024 requires; it is not reported as a successful analytics relocation. The phrase “two reroutes and one stop” therefore counts two design decisions and one stopped purpose, not three observed migrated data flows. The original Q01 IDs remain intact and the additive targets are defined in the ID register.
A useful counterfactual exposes the policy boundary. Suppose the backup target becomes unavailable before its acceptance test. Falling back to the old prohibited route restores availability at the expense of the restriction. The recommended rollback is to retain the stop/quarantine and invoke the separately authorised continuity plan. Conversely, stopping optional analytics should not disable the incident evidence store or prevent an authenticated principal from obtaining the status of an unresolved request. A global kill switch without action scope can harm the very service the programme is protecting.
The change record deliberately remains not_deployment_closed. Local route-decision tests can check that an unapproved target is not selected; they cannot establish a cloud configuration, supplier export, physical replica disposal or masked-data correctness. Only the actual deployment packet could close those checks. In this book the missing evidence is the boundary of the teaching case, not an invitation to generate plausible-looking migration telemetry.
6. Handle a correction without inventing a new regulatory event
The second populated correction exercise, CHANGE-Q09-002, uses the retained corrigendum as a known historical source. It does not pretend that a new July 2027 Gazette correction was discovered. Instead, the scenario deliberately introduces a stale internal reference that places the corrected definition lettering in the wrong schedule. The owner detects the stale citation, compares the retained original and corrigendum, and records the affected reference and decision surfaces.
GSR 892(E) corrects publication wording, “Departments”, order wording, First Schedule text and Fourth Schedule definition punctuation/lettering. The page-38 lettering correction is not a breach-clock amendment or a nomination schedule. CORR:24–38; RULES:1751–1765.[5][6]
That distinction is useful precisely because a legal-text change does not always require changing a runtime number. The author-designed review asks whether meaning, scope, labels, evidence or behavior changed. For this exercise the corrected reference is repaired, the exception mapping is re-read, and the incident timer is retained. A deliberately wrong seventy-one-hour update deadline must still fail its independent clock check. A “no runtime change” disposition includes that reasoning and traceability; it is not permission to skip reading the correction.
The record separates the historical source date from the hypothetical detection and repair scenes. Its completion is only the authored tabletop correction, supported by local source/range and calculation checks. There is no claim that two production fixtures turned green or that a live compliance issue was closed within a week. Where an actual correction changes a condition encoded in a service, the owner must update the decision, implementation and relevant tests together, retaining the previous version for explanation of earlier decisions.
7. Make supplier exit and evidence ageing first-class work
The unresolved marketing acknowledgement ACK-001 is not just a project defect. It is a continuing supplier-management issue with an owner, review date and release condition in the residual register. A successful local RETEST-001 does not close it. The vendor manager asks what operation the acknowledgement covers, which subject/purpose and dataset it concerns, whether it demonstrates cessation or eligible erasure, and what remains in replicas, backups or downstream subprocessors. An undifferentiated “completed” message is insufficient for this recommended evidence design.
Supplier exit uses the same discipline. The proposed exit package includes a neutral export, counts reconciled to the agreed scope, retained restrictions, failed-copy exceptions, revoked service/operator access and separately reviewed disposal. Legal retention may survive the commercial relationship. Deleting all evidence to produce a clean exit certificate would confuse contract closure with data lifecycle obligations. A successor service must preserve withdrawn authority and open rights cases, not recreate every imported contact as newly consented.
Evidence ageing is assessed by dependency, not one arbitrary expiry for every test. Changing SYS-010’s policy schema invalidates the adapters and replay tests that consume it. A new supplier location reopens the transfer decision even if last month’s access test passed. A payroll staffing change may alter coverage and escalation capacity without changing the software. The owner records the version actually exercised and the precise condition that would require retest. Old evidence remains useful historical evidence; it is not automatically current assurance.
The independent-workpaper specimen explicitly withholds actual acceptance. A real reviewer would need independence facts, scope, samples, source/configuration versions, procedures, exceptions and a defensible conclusion. Section 10’s independent-auditor requirement is conditional on actual SDF status and the applicable framework; the book’s stricter separation between builder and reviewer is a recommended safeguard rather than an invented categorical firm-wide statutory ban. ACT:418–438.[1]
8. Report decisions the board can act on
The sustaining dashboard should show the applicable-law snapshot, restricted flows, failed mandatory controls, incomplete execution, source-review health and funding/capacity pressure. It should also name what cannot be counted. Missing supplier evidence is not a successful denominator exclusion; prepared responses are not completed rights execution; hypothetical bid scores are not vendor validation; a fixture pass rate is not an expected fine calculation.
For CASE-001 the immediate board choices are concrete. Maintain the training stop, fund restricted backup/support redesign, keep the processor escalation open, complete the correction follow-up and preserve incident population/delivery uncertainty. The programme’s cost model distinguishes funded existing allocation from incremental capacity. Its annualised peak case is a sensitivity scenario, not a promise that three base case workers meet every queue-time objective. A burst, disputed identity or legal exception can consume more work than an average handling-time estimate predicts.
Recommended reporting cadence combines periodic review with material-event escalation. Quarterly board reporting can summarize stable work; it cannot delay an urgent effective-date, incident or unsafe-route decision. The operations owner also checks overdue residuals and failed source reviews between meetings. Repeatedly moving a review date without new evidence is reported as unresolved exposure, not progress. Budget reduction can change an optional launch or architecture scope but cannot make an applicable legal requirement optional.
Before accepting BAU handover, the receiving owner should be able to reproduce a failed check, locate its input and actual output, explain the response, and say which evidence still has to come from outside the book. The independent-workpaper specimen and pilot record provide that exercise without pretending to be a real acceptance certificate. The native independent book-review gates remain separate from all fictional governance roles.
A final exercise is to remove the primary source owner for a week and make the proposed backup destination fail its release check. Does the deputy receive a concrete unacknowledged task? Does the old route remain stopped? Does the board see the deadline risk and capacity consequence? If the answer is merely that the next monthly register will be updated, the sustaining design has not transferred operational responsibility.
The book ends with this narrower, testable standard: preserve the original decision, notice what invalidates it, restrict what is no longer justified, and obtain evidence before claiming restoration or closure. That standard does not promise uninterrupted compliance. It makes uncertainty, failure and correction visible enough for accountable people to act.
Source locations
ACT, COMM, EST, MEMBERS, RULES, CORR and RECRUIT are retained primary texts mapped by physical newline in source-passages.json, with dates and hashes in source-manifest.json. The historical source set is not a comprehensive fresh search for later or entity-specific instruments.
Sources
[1] https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf — Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) [2] https://www.meity.gov.in/static/uploads/2025/11/c56ceae6c383460ca69577428d36828b.pdf — G.S.R. 843(E), DPDP Act commencement notification [3] https://www.meity.gov.in/static/uploads/2025/11/cc217843dc3bcb37b2b05bcc3b4e031f.pdf — G.S.R. 844(E), establishment of Data Protection Board of India [4] https://www.meity.gov.in/static/uploads/2025/11/f6c0837972422cf79d890bfe84cc04d6.pdf — G.S.R. 845(E), number of members of Data Protection Board of India [5] https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf — Digital Personal Data Protection Rules, 2025, G.S.R. 846(E) [6] https://www.meity.gov.in/static/uploads/2025/12/3c7ebbae0e5456f493f486e6845df86b.pdf — Corrigenda to G.S.R. 846(E), G.S.R. 892(E) [7] https://www.meity.gov.in/static/uploads/2026/05/53b1bcf01cab9a0adde463e73fbc3417.pdf — Filling up the post of Chairman & Members in the Data Protection Board of India
Contents · Reader guide and citation conventions · Artifact index