Control Master Matrix & Ownership Crosswalk
Every statutory obligation mapped to recommended enterprise owners, target systems (SYS-001 to SYS-014), mechanism chapters, and test specimens.
| Control Obligation | Statutory Scope | Recommended Owner & Systems | Mechanism Chapter | Test Specimen | Details |
|---|---|---|---|---|---|
OBL-01 Processing Scope & Territorial Perimeter Verifies digital personal data processing within India and offshore goods/services nexus. | Section 3(a), (b), (c) | Legal / activity owner | Chapter 3 — Scope, Roles, Exemptions and Processing Grounds | SPEC-Q10-OBL-01 | |
OBL-02 Statutory Roles & Entity Classification Determines activity-specific roles: Data Fiduciary, Data Processor, or Data Principal. | Section 2 (Definitions) | Legal / activity owner | Chapter 3 — Scope, Roles, Exemptions and Processing Grounds | SPEC-Q10-OBL-02 | |
OBL-03 Lawful Grounds for Processing Asserts valid consent or statutory Section 7 legitimate use before processing. | Section 4 (Grounds) | Legal / activity owner | Chapter 3 — Scope, Roles, Exemptions and Processing Grounds | SPEC-Q10-OBL-03 | |
OBL-04 Itemised Notice & Legacy Consent Transition Issues transparent multilingual notice and manages pre-commencement consent transition. | Section 5 (noticeSection 5(2) legacy) | Product / privacy | Chapter 9 — Notice and Consent Experience Design | SPEC-Q10-OBL-04 | |
OBL-05 Consent Capture, Withdrawal & CM Registry Governs affirmative consent lifecycles, withdrawal requests, and Consent Manager registration. | Section 6(9) CM registration(10) fiduciary proof | Product / privacy engineering | Chapter 10 — Consent Withdrawal and Downstream Cessation | SPEC-Q10-OBL-05 | |
OBL-06 Legitimate Uses & Exemption Validation Validates employment, medical emergency, judicial, and statutory legitimate grounds. | Section 7 (legitimate uses) | Legal / activity owner | Chapter 3 — Scope, Roles, Exemptions and Processing Grounds | SPEC-Q10-OBL-06 | |
OBL-07 Notice Content & Language Presentation Mandates itemised data/purposes, DPO contacts, and Eighth Schedule language support (Rule 3). | Rule 3 (Notice Content) | Product / privacy | Chapter 9 — Notice and Consent Experience Design | SPEC-Q10-OBL-07 | |
OBL-08 Processor Engagement & Subprocessing Contracts Enforces valid data processing agreements and downstream propagation of statutory duties. | Section 8(1) to (2) | Vendor manager / Legal | Chapter 17 — Processors, Subprocessors and Third-Party Risk | SPEC-Q10-OBL-08 | |
OBL-09 Personal Data Accuracy & Decision Completeness Maintains accuracy and completeness of personal data used to make decisions affecting principals. | Section 8(3) | Data owner / rights operations | Chapter 12 — Rights, Grievances, Identity and Nomination | SPEC-Q10-OBL-09 | |
OBL-10 Technical & Organizational Safeguards Establishes baseline technical controls to prevent unauthorized access or processing. | Section 8(4) | Security / service owner | Chapter 15 — Security Safeguards and Access Control | SPEC-Q10-OBL-10 | |
OBL-11 Reasonable Security Safeguards Implementation Deploys end-to-end encryption, access controls, and boundary defenses against data breaches. | Section 8(5) | Security / service owner | Chapter 15 — Security Safeguards and Access Control | SPEC-Q10-OBL-11 | |
OBL-12 Personal Data Breach Detection & Intimation Mandates prompt notification to the Data Protection Board and affected principals upon breach. | Section 8(6) | Incident commander / Legal | Chapter 16 — Personal-Data Breach Detection and Response | SPEC-Q10-OBL-12 | |
OBL-13 Purpose-Completion Erasure & Retention Limits Automates deletion or de-identification when processing purpose is fulfilled or consent withdrawn. | Section 8(7)(a), (b) | Records / storage owner | Chapter 14 — Retention, Deletion, Backups and Legal Holds | SPEC-Q10-OBL-13 | |
OBL-14 Retention Schedule & Inactivity Review Maintains storage schedules and periodic reviews for inactive customer and employee data. | Section 8(8) | Records / storage owner | Chapter 14 — Retention, Deletion, Backups and Legal Holds | SPEC-Q10-OBL-14 | |
OBL-15 DPO & Grievance Contact Publication Publishes business contact details of the Data Protection Officer or grievance representative. | Section 8(9) | Rights operations / Legal Customer App & Web PortalSYS-001published contact surface | Chapter 12 — Rights, Grievances, Identity and Nomination | SPEC-Q10-OBL-15 | |
OBL-16 Data Principal Grievance Redressal Mechanism Provides an easily accessible channel for principal complaints with timely resolution workflows. | Section 8(10) | Rights operations / Legal Principal Rights & Grievance ServiceSYS-011grievance service | Chapter 12 — Rights, Grievances, Identity and Nomination | SPEC-Q10-OBL-16 | |
OBL-17 Prescribed Security Safeguard Controls (Rule 6) Implements continuous security monitoring, encryption, and audit log safeguards under Rule 6. | Rule 6 (safeguard detail) | Security / service owner | Chapter 15 — Security Safeguards and Access Control | SPEC-Q10-OBL-17 | |
OBL-18 Dual-Clock Breach Incident Workflow (Rule 7) Executes dual reporting clocks: CERT-In 6-hour intimation and DPDP Rule 7 Board breach dossiers. | Rule 7 — breach content/clocks | Incident commander / Legal | Chapter 16 — Personal-Data Breach Detection and Response | SPEC-Q10-OBL-18 | |
OBL-19 Account Inactivity Deletion & De-identification (Rule 8) Enforces automated data erasure after prolonged account inactivity under Rule 8. | Rule 8 — inactivity AND separate retention | Records / storage owner | Chapter 14 — Retention, Deletion, Backups and Legal Holds | SPEC-Q10-OBL-19 | |
OBL-20 Contact Publication & Notice Surfaces (Rule 9) Prominently displays DPO contact details across web, mobile, and communication surfaces (Rule 9). | Rule 9 (contact publication) | Rights operations / Legal Customer App & Web PortalSYS-001contact publication surface | Chapter 12 — Rights, Grievances, Identity and Nomination | SPEC-Q10-OBL-20 | |
OBL-21 State Processing Exemption Review (Rule 5) Evaluates statutory criteria and Second Schedule exemptions for state instrumentality processing. | Rule 5 + Second Schedule (State processing) | Legal / activity owner Not a base Company State-processing activityapplicability review only | Chapter 3 — Scope, Roles, Exemptions and Processing Grounds | SPEC-Q10-OBL-21 | |
OBL-22 Cross-Border Data Transfer Governance (Rule 15) Enforces cross-border transfer blacklists, adequacy checks, and contractual transfer terms. | Rule 15 (transfer) | Architecture / sector Legal | Chapter 18 — Transfers, Cloud and Enterprise Reference Architecture | SPEC-Q10-OBL-22 | |
OBL-23 Research, Archival & Statistical Exemptions (Rule 16) Applies research and statistical exemptions without using personal data for individual decisions. | Rule 16 (research exemption) | Legal / activity owner | Chapter 3 — Scope, Roles, Exemptions and Processing Grounds | SPEC-Q10-OBL-23 | |
OBL-24 Verifiable Parental Consent (Section 9(1)) Requires verifiable consent from parents or lawful guardians before processing child data. | Section 9(1) | Product / guardian assurance Separate CASE-101 fixturenot Company child lending | Chapter 13 — Children, Parents and Lawful Guardians | SPEC-Q10-OBL-24 | |
OBL-25 Child Detrimental Processing Prohibition (Section 9(2)) Prohibits any processing of child personal data that is likely to cause harm to child well-being. | Section 9(2) | Product / guardian assurance Separate CASE-101 fixturenot Company child lending | Chapter 13 — Children, Parents and Lawful Guardians | SPEC-Q10-OBL-25 | |
OBL-26 Child Tracking & Targeted Advertising Ban (Section 9(3)) Prohibits tracking, behavioral monitoring, and targeted advertising directed at children. | Section 9(3) | Product / guardian assurance Separate CASE-101 fixturenot Company child lending | Chapter 13 — Children, Parents and Lawful Guardians | SPEC-Q10-OBL-26 | |
OBL-27 Prescribed Relief for Child Data Processing (Section 9(4)) Applies government notified conditional exemptions for specialized educational/child entities. | Section 9(4) — prescribed conditional relief | Product / guardian assurance Separate CASE-101 fixturenot Company child lending | Chapter 13 — Children, Parents and Lawful Guardians | SPEC-Q10-OBL-27 | |
OBL-28 Notification-Dependent Child Exemptions (Section 9(5)) Applies statutory exemptions where verifiable age assurance mechanisms are deployed. | Section 9(5) — notification-dependent relief | Product / guardian assurance Separate CASE-101 fixturenot Company child lending | Chapter 13 — Children, Parents and Lawful Guardians | SPEC-Q10-OBL-28 | |
OBL-29 Parental Consent Verification Standards (Rule 10) Implements verifiable age-token and parent relationship checks in compliance with Rule 10. | Rule 10 | Product / guardian assurance Separate CASE-101 fixturenot Company child lending | Chapter 13 — Children, Parents and Lawful Guardians | SPEC-Q10-OBL-29 | |
OBL-30 Child-Safe Data Processing Defaults (Rule 11) Enforces child-safe processing architecture and strict safeguard defaults under Rule 11. | Rule 11 | Product / guardian assurance Separate CASE-101 fixturenot Company child lending | Chapter 13 — Children, Parents and Lawful Guardians | SPEC-Q10-OBL-30 | |
OBL-31 Fourth Schedule Child Processing Relief (Rule 12) Applies Fourth Schedule conditional compliance relaxations for qualifying health/education fiduciaries. | Rule 12 | Product / guardian assurance Separate CASE-101 fixturenot Company child lending | Chapter 13 — Children, Parents and Lawful Guardians | SPEC-Q10-OBL-31 | |
OBL-32 Significant Data Fiduciary Assessment (Section 10(1)) Assesses processing volume, sensitivity, and national security factors against SDF designation. | Section 10(1) — designation-dependent SDF status | Privacy / accountable sponsor Governance source register | Chapter 19 — Significant Data Fiduciary Readiness | SPEC-Q10-OBL-32 | |
OBL-33 India-Resident Statutory DPO Appointment (Section 10(2)(a)) Appoints an India-resident Data Protection Officer reporting directly to the Board of Directors. | Section 10(2)(a) | Privacy / accountable sponsor Governance appointment evidenceno actual appointment claimed | Chapter 19 — Significant Data Fiduciary Readiness | SPEC-Q10-OBL-33 | |
OBL-34 Independent Data Auditor Engagement (Section 10(2)(b)) Appoints an independent external auditor to conduct periodic compliance evaluations. | Section 10(2)(b) | Privacy / accountable sponsor Governance audit relationshipno actual appointment claimed | Chapter 19 — Significant Data Fiduciary Readiness | SPEC-Q10-OBL-34 | |
OBL-35 DPIA & Periodic Security Risk Audit (Section 10(2)(c)) Executes periodic Data Protection Impact Assessments (DPIAs) and periodic security audits. | Section 10(2)(c) | Privacy / accountable sponsor SIEM & Security Telemetry StoreSYS-012assessment/audit evidence | Chapter 19 — Significant Data Fiduciary Readiness | SPEC-Q10-OBL-35 | |
OBL-36 SDF Algorithmic & Assessment Safeguards (Rule 13) Conducts algorithmic transparency reviews and periodic risk assessments under Rule 13. | Rule 13 | Privacy / accountable sponsor SIEM & Security Telemetry StoreSYS-012conditional SDF controls | Chapter 19 — Significant Data Fiduciary Readiness | SPEC-Q10-OBL-36 | |
OBL-37 Right to Information & Processing Summary (Section 11) Furnishes Data Principals a summary of processed personal data and shared third-party identities. | Section 11 | Rights operations / Legal Principal Rights & Grievance ServiceSYS-011rights access work item | Chapter 12 — Rights, Grievances, Identity and Nomination | SPEC-Q10-OBL-37 | |
OBL-38 Right to Correction, Completion & Erasure (Section 12) Processes principal requests to correct inaccurate data, complete records, or erase obsolete data. | Section 12 | Rights operations / Legal | Chapter 12 — Rights, Grievances, Identity and Nomination | SPEC-Q10-OBL-38 | |
OBL-39 Right to Grievance Redressal (Section 13) Provides timely, documented internal grievance resolution before regulatory escalation. | Section 13 | Rights operations / Legal Principal Rights & Grievance ServiceSYS-011grievance workflow | Chapter 12 — Rights, Grievances, Identity and Nomination | SPEC-Q10-OBL-39 | |
OBL-40 Right to Nominate Representative (Section 14) Enables Data Principals to nominate a representative to exercise rights upon death or incapacity. | Section 14 | Rights operations / Legal Principal Rights & Grievance ServiceSYS-011nominee authority record | Chapter 12 — Rights, Grievances, Identity and Nomination | SPEC-Q10-OBL-40 | |
OBL-41 Data Principal Statutory Duties (Section 15) Validates authentic principal claims and prevents false, frivolous, or impersonated requests. | Section 15 | Rights operations / Legal Rights/Legal reviewData Principal duty is not a Company software guarantee | Chapter 12 — Rights, Grievances, Identity and Nomination | SPEC-Q10-OBL-41 | |
OBL-42 Rights & Grievance Service Channels (Rule 14) Operates self-service rights fulfillment portals adhering to prescribed timelines under Rule 14. | Rule 14 | Rights operations / Legal | Chapter 12 — Rights, Grievances, Identity and Nomination | SPEC-Q10-OBL-42 | |
OBL-43 Notified Cross-Border Transfer Restrictions (Section 16(1)) Blocks personal data transfers to countries blacklisted or restricted by the Central Government. | Section 16(1) — notified restrictions | Architecture / sector Legal | Chapter 18 — Transfers, Cloud and Enterprise Reference Architecture | SPEC-Q10-OBL-43 | |
OBL-44 Sectoral Higher Transfer Standards Saving (Section 16(2)) Preserves stricter sectoral data localization and transfer mandates (RBI, SEBI, IRDAI). | Section 16(2) — transfer-specific saving | Architecture / sector Legal | Chapter 18 — Transfers, Cloud and Enterprise Reference Architecture | SPEC-Q10-OBL-44 | |
OBL-45 Statutory Exemptions Governance (Section 17) Evaluates legal process, law enforcement, debt recovery, and court order exemption perimeters. | Section 17 | Legal / activity owner | Chapter 3 — Scope, Roles, Exemptions and Processing Grounds | SPEC-Q10-OBL-45 | |
OBL-46 Consent Manager Interoperability (Section 2(g)) Interoperates with Board-registered Consent Managers acting as trusted intermediaries. | Section 2(g) | Legal / CM integration owner Consent Ledger & Policy Decision PointSYS-010synthetic external CM adapter | Chapter 11 — Consent Managers and Consent-Management Software | SPEC-Q10-OBL-46 | |
OBL-47 Consent Manager Interface & Security Standards (Rule 4) Implements secure APIs, cryptographic logs, and technical specifications for Consent Managers. | Rule 4 | Legal / CM integration owner Consent Ledger & Policy Decision PointSYS-010synthetic external CM adapter | Chapter 11 — Consent Managers and Consent-Management Software | SPEC-Q10-OBL-47 | |
OBL-48 Statutory Penalty Exposure & Liability Controls (Section 33) Governs financial penalty exposure up to ₹250 Crore per significant statutory non-compliance. | Section 33(1) to (2) | Legal / board secretariat Governance registerno live Board system asserted | Chapter 6 — Exposure, Enforcement and Board Oversight | SPEC-Q10-OBL-48 | |
OBL-49 Schedule 1–7 Penalty Tier Risk Mitigation (Schedule) Monitors statutory penalty tiers across security safeguards, breach, children, and SDF duties. | Schedule items 1–7 | Legal / board secretariat Governance registerno live Board system asserted | Chapter 6 — Exposure, Enforcement and Board Oversight | SPEC-Q10-OBL-49 | |
OBL-50 Data Protection Board Inquiry Governance (Sections 18–26) Maintains operational readiness for regulatory summons, inquiries, and institutional proceedings. | Sections 18 to 26 — institutional provisions, not appointment evidence | Legal / board secretariat Governance registerno live Board system asserted | Chapter 6 — Exposure, Enforcement and Board Oversight | SPEC-Q10-OBL-50 | |
OBL-51 Board Proceedings, Directions & Mediation (Sections 28–34, 36–37) Handles Board investigations, binding compliance directions, and alternate dispute resolution. | Sections 28 to 34,36–37 — staged functions with separate actors | Legal / board secretariat Governance registerno live Board system asserted | Chapter 6 — Exposure, Enforcement and Board Oversight | SPEC-Q10-OBL-51 | |
OBL-52 Board Digital-by-Design Proceedings (Rules 17–21) Interfaces with the Board's digital portal for electronic filing, service, and virtual hearings. | Rules 17 to 21 — institutional Rules, not proof of operation | Legal / board secretariat Governance registerno live Board system asserted | Chapter 6 — Exposure, Enforcement and Board Oversight | SPEC-Q10-OBL-52 | |
OBL-53 Appellate Tribunal Appeal Procedure (Rule 22) Governs appeals before TDSAT, statutory deposit requirements, and limitation periods (Rule 22). | Rule 22 | Legal / board secretariat Governance registerno live Board system asserted | Chapter 6 — Exposure, Enforcement and Board Oversight | SPEC-Q10-OBL-53 | |
OBL-54 Government Information Requisitions & Inquiries (Rule 23) Responds to Central Government statutory information calls for Seventh Schedule purposes. | Rule 23 | Legal / board secretariat Governance registerno live Board system asserted | Chapter 6 — Exposure, Enforcement and Board Oversight | SPEC-Q10-OBL-54 |