OBL-10: Technical & Organizational Safeguards
Establishes baseline technical controls to prevent unauthorized access or processing.
Statutory scope: Section 8(4) · Assigned to Security / service owner · Systems: Consent Ledger & Policy Decision Point (SYS-010); SIEM & Security Telemetry Store (SYS-012)
Recommended interface: Supply forged purpose or stale authority; expected outcome is deny. Deployment identity, key and direct-store controls still require actual integration tests.
Supply forged purpose or stale authority; expected outcome is deny. Deployment identity, key and direct-store controls still require actual integration tests.
Governance & Architecture
Verification Specification & Workpaper
proposed per-row review/acceptance specification; not a claim of executed statutory coverage
populated hypothetical decision/specimen; not actual enterprise execution
Canonical Statutory Grounding
Source references verified against the official Gazette of India publication baseline.
Data Fiduciary
Processing by it or its processor
Responsibility despite agreements/principal default; valid processor contract; conditional data accuracy; safeguards; breach intimation; erasure; contact and grievance mechanism.
s8(7) lawful-retention exception; s17 preserves s8(1),(5) under subsection (1).