Legal Register
Assurance & Controls

Control Master Matrix & Ownership Crosswalk

Every statutory obligation mapped to recommended enterprise owners, target systems (SYS-001 to SYS-014), mechanism chapters, and test specimens.

Showing 54 of 54 operational control obligationsAppendix B Control Master Matrix
Control ObligationStatutory ScopeRecommended Owner & SystemsMechanism ChapterTest SpecimenDetails
OBL-01
Processing Scope & Territorial Perimeter

Verifies digital personal data processing within India and offshore goods/services nexus.

Section 3(a), (b), (c)
Legal / activity owner
Chapter 3 — Scope, Roles, Exemptions and Processing GroundsSPEC-Q10-OBL-01
OBL-02
Statutory Roles & Entity Classification

Determines activity-specific roles: Data Fiduciary, Data Processor, or Data Principal.

Section 2 (Definitions)
Legal / activity owner
Chapter 3 — Scope, Roles, Exemptions and Processing GroundsSPEC-Q10-OBL-02
OBL-03
Lawful Grounds for Processing

Asserts valid consent or statutory Section 7 legitimate use before processing.

Section 4 (Grounds)
Legal / activity owner
Chapter 3 — Scope, Roles, Exemptions and Processing GroundsSPEC-Q10-OBL-03
OBL-04
Itemised Notice & Legacy Consent Transition

Issues transparent multilingual notice and manages pre-commencement consent transition.

Section 5 (noticeSection 5(2) legacy)
Product / privacy
Chapter 9 — Notice and Consent Experience DesignSPEC-Q10-OBL-04
OBL-05
Consent Capture, Withdrawal & CM Registry

Governs affirmative consent lifecycles, withdrawal requests, and Consent Manager registration.

Section 6(9) CM registration(10) fiduciary proof
Product / privacy engineering
Chapter 10 — Consent Withdrawal and Downstream CessationSPEC-Q10-OBL-05
OBL-06
Legitimate Uses & Exemption Validation

Validates employment, medical emergency, judicial, and statutory legitimate grounds.

Section 7 (legitimate uses)
Legal / activity owner
Chapter 3 — Scope, Roles, Exemptions and Processing GroundsSPEC-Q10-OBL-06
OBL-07
Notice Content & Language Presentation

Mandates itemised data/purposes, DPO contacts, and Eighth Schedule language support (Rule 3).

Rule 3 (Notice Content)
Product / privacy
Chapter 9 — Notice and Consent Experience DesignSPEC-Q10-OBL-07
OBL-08
Processor Engagement & Subprocessing Contracts

Enforces valid data processing agreements and downstream propagation of statutory duties.

Section 8(1) to (2)
Vendor manager / Legal
Chapter 17 — Processors, Subprocessors and Third-Party RiskSPEC-Q10-OBL-08
OBL-09
Personal Data Accuracy & Decision Completeness

Maintains accuracy and completeness of personal data used to make decisions affecting principals.

Section 8(3)
Data owner / rights operations
Chapter 12 — Rights, Grievances, Identity and NominationSPEC-Q10-OBL-09
OBL-10
Technical & Organizational Safeguards

Establishes baseline technical controls to prevent unauthorized access or processing.

Section 8(4)
Security / service owner
Chapter 15 — Security Safeguards and Access ControlSPEC-Q10-OBL-10
OBL-11
Reasonable Security Safeguards Implementation

Deploys end-to-end encryption, access controls, and boundary defenses against data breaches.

Section 8(5)
Security / service owner
Chapter 15 — Security Safeguards and Access ControlSPEC-Q10-OBL-11
OBL-12
Personal Data Breach Detection & Intimation

Mandates prompt notification to the Data Protection Board and affected principals upon breach.

Section 8(6)
Incident commander / Legal
Chapter 16 — Personal-Data Breach Detection and ResponseSPEC-Q10-OBL-12
OBL-13
Purpose-Completion Erasure & Retention Limits

Automates deletion or de-identification when processing purpose is fulfilled or consent withdrawn.

Section 8(7)(a), (b)
Records / storage owner
Chapter 14 — Retention, Deletion, Backups and Legal HoldsSPEC-Q10-OBL-13
OBL-14
Retention Schedule & Inactivity Review

Maintains storage schedules and periodic reviews for inactive customer and employee data.

Section 8(8)
Records / storage owner
Chapter 14 — Retention, Deletion, Backups and Legal HoldsSPEC-Q10-OBL-14
OBL-15
DPO & Grievance Contact Publication

Publishes business contact details of the Data Protection Officer or grievance representative.

Section 8(9)
Rights operations / Legal
Customer App & Web PortalSYS-001published contact surface
Chapter 12 — Rights, Grievances, Identity and NominationSPEC-Q10-OBL-15
OBL-16
Data Principal Grievance Redressal Mechanism

Provides an easily accessible channel for principal complaints with timely resolution workflows.

Section 8(10)
Rights operations / Legal
Chapter 12 — Rights, Grievances, Identity and NominationSPEC-Q10-OBL-16
OBL-17
Prescribed Security Safeguard Controls (Rule 6)

Implements continuous security monitoring, encryption, and audit log safeguards under Rule 6.

Rule 6 (safeguard detail)
Security / service owner
Chapter 15 — Security Safeguards and Access ControlSPEC-Q10-OBL-17
OBL-18
Dual-Clock Breach Incident Workflow (Rule 7)

Executes dual reporting clocks: CERT-In 6-hour intimation and DPDP Rule 7 Board breach dossiers.

Rule 7 — breach content/clocks
Incident commander / Legal
Chapter 16 — Personal-Data Breach Detection and ResponseSPEC-Q10-OBL-18
OBL-19
Account Inactivity Deletion & De-identification (Rule 8)

Enforces automated data erasure after prolonged account inactivity under Rule 8.

Rule 8 — inactivity AND separate retention
Records / storage owner
Chapter 14 — Retention, Deletion, Backups and Legal HoldsSPEC-Q10-OBL-19
OBL-20
Contact Publication & Notice Surfaces (Rule 9)

Prominently displays DPO contact details across web, mobile, and communication surfaces (Rule 9).

Rule 9 (contact publication)
Rights operations / Legal
Customer App & Web PortalSYS-001contact publication surface
Chapter 12 — Rights, Grievances, Identity and NominationSPEC-Q10-OBL-20
OBL-21
State Processing Exemption Review (Rule 5)

Evaluates statutory criteria and Second Schedule exemptions for state instrumentality processing.

Rule 5 + Second Schedule (State processing)
Legal / activity owner
Not a base Company State-processing activityapplicability review only
Chapter 3 — Scope, Roles, Exemptions and Processing GroundsSPEC-Q10-OBL-21
OBL-22
Cross-Border Data Transfer Governance (Rule 15)

Enforces cross-border transfer blacklists, adequacy checks, and contractual transfer terms.

Rule 15 (transfer)
Architecture / sector Legal
Chapter 18 — Transfers, Cloud and Enterprise Reference ArchitectureSPEC-Q10-OBL-22
OBL-23
Research, Archival & Statistical Exemptions (Rule 16)

Applies research and statistical exemptions without using personal data for individual decisions.

Rule 16 (research exemption)
Legal / activity owner
Chapter 3 — Scope, Roles, Exemptions and Processing GroundsSPEC-Q10-OBL-23
OBL-24
Verifiable Parental Consent (Section 9(1))

Requires verifiable consent from parents or lawful guardians before processing child data.

Section 9(1)
Product / guardian assurance
Separate CASE-101 fixturenot Company child lending
Chapter 13 — Children, Parents and Lawful GuardiansSPEC-Q10-OBL-24
OBL-25
Child Detrimental Processing Prohibition (Section 9(2))

Prohibits any processing of child personal data that is likely to cause harm to child well-being.

Section 9(2)
Product / guardian assurance
Separate CASE-101 fixturenot Company child lending
Chapter 13 — Children, Parents and Lawful GuardiansSPEC-Q10-OBL-25
OBL-26
Child Tracking & Targeted Advertising Ban (Section 9(3))

Prohibits tracking, behavioral monitoring, and targeted advertising directed at children.

Section 9(3)
Product / guardian assurance
Separate CASE-101 fixturenot Company child lending
Chapter 13 — Children, Parents and Lawful GuardiansSPEC-Q10-OBL-26
OBL-27
Prescribed Relief for Child Data Processing (Section 9(4))

Applies government notified conditional exemptions for specialized educational/child entities.

Section 9(4) — prescribed conditional relief
Product / guardian assurance
Separate CASE-101 fixturenot Company child lending
Chapter 13 — Children, Parents and Lawful GuardiansSPEC-Q10-OBL-27
OBL-28
Notification-Dependent Child Exemptions (Section 9(5))

Applies statutory exemptions where verifiable age assurance mechanisms are deployed.

Section 9(5) — notification-dependent relief
Product / guardian assurance
Separate CASE-101 fixturenot Company child lending
Chapter 13 — Children, Parents and Lawful GuardiansSPEC-Q10-OBL-28
OBL-29
Parental Consent Verification Standards (Rule 10)

Implements verifiable age-token and parent relationship checks in compliance with Rule 10.

Rule 10
Product / guardian assurance
Separate CASE-101 fixturenot Company child lending
Chapter 13 — Children, Parents and Lawful GuardiansSPEC-Q10-OBL-29
OBL-30
Child-Safe Data Processing Defaults (Rule 11)

Enforces child-safe processing architecture and strict safeguard defaults under Rule 11.

Rule 11
Product / guardian assurance
Separate CASE-101 fixturenot Company child lending
Chapter 13 — Children, Parents and Lawful GuardiansSPEC-Q10-OBL-30
OBL-31
Fourth Schedule Child Processing Relief (Rule 12)

Applies Fourth Schedule conditional compliance relaxations for qualifying health/education fiduciaries.

Rule 12
Product / guardian assurance
Separate CASE-101 fixturenot Company child lending
Chapter 13 — Children, Parents and Lawful GuardiansSPEC-Q10-OBL-31
OBL-32
Significant Data Fiduciary Assessment (Section 10(1))

Assesses processing volume, sensitivity, and national security factors against SDF designation.

Section 10(1) — designation-dependent SDF status
Privacy / accountable sponsor
Governance source register
Chapter 19 — Significant Data Fiduciary ReadinessSPEC-Q10-OBL-32
OBL-33
India-Resident Statutory DPO Appointment (Section 10(2)(a))

Appoints an India-resident Data Protection Officer reporting directly to the Board of Directors.

Section 10(2)(a)
Privacy / accountable sponsor
Governance appointment evidenceno actual appointment claimed
Chapter 19 — Significant Data Fiduciary ReadinessSPEC-Q10-OBL-33
OBL-34
Independent Data Auditor Engagement (Section 10(2)(b))

Appoints an independent external auditor to conduct periodic compliance evaluations.

Section 10(2)(b)
Privacy / accountable sponsor
Governance audit relationshipno actual appointment claimed
Chapter 19 — Significant Data Fiduciary ReadinessSPEC-Q10-OBL-34
OBL-35
DPIA & Periodic Security Risk Audit (Section 10(2)(c))

Executes periodic Data Protection Impact Assessments (DPIAs) and periodic security audits.

Section 10(2)(c)
Privacy / accountable sponsor
Chapter 19 — Significant Data Fiduciary ReadinessSPEC-Q10-OBL-35
OBL-36
SDF Algorithmic & Assessment Safeguards (Rule 13)

Conducts algorithmic transparency reviews and periodic risk assessments under Rule 13.

Rule 13
Privacy / accountable sponsor
Chapter 19 — Significant Data Fiduciary ReadinessSPEC-Q10-OBL-36
OBL-37
Right to Information & Processing Summary (Section 11)

Furnishes Data Principals a summary of processed personal data and shared third-party identities.

Section 11
Rights operations / Legal
Chapter 12 — Rights, Grievances, Identity and NominationSPEC-Q10-OBL-37
OBL-38
Right to Correction, Completion & Erasure (Section 12)

Processes principal requests to correct inaccurate data, complete records, or erase obsolete data.

Section 12
Rights operations / Legal
Chapter 12 — Rights, Grievances, Identity and NominationSPEC-Q10-OBL-38
OBL-39
Right to Grievance Redressal (Section 13)

Provides timely, documented internal grievance resolution before regulatory escalation.

Section 13
Rights operations / Legal
Chapter 12 — Rights, Grievances, Identity and NominationSPEC-Q10-OBL-39
OBL-40
Right to Nominate Representative (Section 14)

Enables Data Principals to nominate a representative to exercise rights upon death or incapacity.

Section 14
Rights operations / Legal
Chapter 12 — Rights, Grievances, Identity and NominationSPEC-Q10-OBL-40
OBL-41
Data Principal Statutory Duties (Section 15)

Validates authentic principal claims and prevents false, frivolous, or impersonated requests.

Section 15
Rights operations / Legal
Rights/Legal reviewData Principal duty is not a Company software guarantee
Chapter 12 — Rights, Grievances, Identity and NominationSPEC-Q10-OBL-41
OBL-42
Rights & Grievance Service Channels (Rule 14)

Operates self-service rights fulfillment portals adhering to prescribed timelines under Rule 14.

Rule 14
Rights operations / Legal
Chapter 12 — Rights, Grievances, Identity and NominationSPEC-Q10-OBL-42
OBL-43
Notified Cross-Border Transfer Restrictions (Section 16(1))

Blocks personal data transfers to countries blacklisted or restricted by the Central Government.

Section 16(1) — notified restrictions
Architecture / sector Legal
Chapter 18 — Transfers, Cloud and Enterprise Reference ArchitectureSPEC-Q10-OBL-43
OBL-44
Sectoral Higher Transfer Standards Saving (Section 16(2))

Preserves stricter sectoral data localization and transfer mandates (RBI, SEBI, IRDAI).

Section 16(2) — transfer-specific saving
Architecture / sector Legal
Chapter 18 — Transfers, Cloud and Enterprise Reference ArchitectureSPEC-Q10-OBL-44
OBL-45
Statutory Exemptions Governance (Section 17)

Evaluates legal process, law enforcement, debt recovery, and court order exemption perimeters.

Section 17
Legal / activity owner
Chapter 3 — Scope, Roles, Exemptions and Processing GroundsSPEC-Q10-OBL-45
OBL-46
Consent Manager Interoperability (Section 2(g))

Interoperates with Board-registered Consent Managers acting as trusted intermediaries.

Section 2(g)
Legal / CM integration owner
Chapter 11 — Consent Managers and Consent-Management SoftwareSPEC-Q10-OBL-46
OBL-47
Consent Manager Interface & Security Standards (Rule 4)

Implements secure APIs, cryptographic logs, and technical specifications for Consent Managers.

Rule 4
Legal / CM integration owner
Chapter 11 — Consent Managers and Consent-Management SoftwareSPEC-Q10-OBL-47
OBL-48
Statutory Penalty Exposure & Liability Controls (Section 33)

Governs financial penalty exposure up to ₹250 Crore per significant statutory non-compliance.

Section 33(1) to (2)
Legal / board secretariat
Governance registerno live Board system asserted
Chapter 6 — Exposure, Enforcement and Board OversightSPEC-Q10-OBL-48
OBL-49
Schedule 1–7 Penalty Tier Risk Mitigation (Schedule)

Monitors statutory penalty tiers across security safeguards, breach, children, and SDF duties.

Schedule items 1–7
Legal / board secretariat
Governance registerno live Board system asserted
Chapter 6 — Exposure, Enforcement and Board OversightSPEC-Q10-OBL-49
OBL-50
Data Protection Board Inquiry Governance (Sections 18–26)

Maintains operational readiness for regulatory summons, inquiries, and institutional proceedings.

Sections 18 to 26 — institutional provisions, not appointment evidence
Legal / board secretariat
Governance registerno live Board system asserted
Chapter 6 — Exposure, Enforcement and Board OversightSPEC-Q10-OBL-50
OBL-51
Board Proceedings, Directions & Mediation (Sections 28–34, 36–37)

Handles Board investigations, binding compliance directions, and alternate dispute resolution.

Sections 28 to 34,36–37 — staged functions with separate actors
Legal / board secretariat
Governance registerno live Board system asserted
Chapter 6 — Exposure, Enforcement and Board OversightSPEC-Q10-OBL-51
OBL-52
Board Digital-by-Design Proceedings (Rules 17–21)

Interfaces with the Board's digital portal for electronic filing, service, and virtual hearings.

Rules 17 to 21 — institutional Rules, not proof of operation
Legal / board secretariat
Governance registerno live Board system asserted
Chapter 6 — Exposure, Enforcement and Board OversightSPEC-Q10-OBL-52
OBL-53
Appellate Tribunal Appeal Procedure (Rule 22)

Governs appeals before TDSAT, statutory deposit requirements, and limitation periods (Rule 22).

Rule 22
Legal / board secretariat
Governance registerno live Board system asserted
Chapter 6 — Exposure, Enforcement and Board OversightSPEC-Q10-OBL-53
OBL-54
Government Information Requisitions & Inquiries (Rule 23)

Responds to Central Government statutory information calls for Seventh Schedule purposes.

Rule 23
Legal / board secretariat
Governance registerno live Board system asserted
Chapter 6 — Exposure, Enforcement and Board OversightSPEC-Q10-OBL-54