Legal Register
Control Workpaper
OBL-10 Section 8(4) ACT-8

OBL-10: Technical & Organizational Safeguards

Establishes baseline technical controls to prevent unauthorized access or processing.

Statutory scope: Section 8(4) · Assigned to Security / service owner · Systems: Consent Ledger & Policy Decision Point (SYS-010); SIEM & Security Telemetry Store (SYS-012)

Operational Interface Requirement

Recommended interface: Supply forged purpose or stale authority; expected outcome is deny. Deployment identity, key and direct-store controls still require actual integration tests.

Expected Audit Assertion / Test Result

Supply forged purpose or stale authority; expected outcome is deny. Deployment identity, key and direct-store controls still require actual integration tests.

Governance & Architecture

Recommended Activity Owner
Security / service owner
Target Systems & Interfaces

Verification Specification & Workpaper

Proposed Test Specimen ID
SPEC-Q10-OBL-10

proposed per-row review/acceptance specification; not a claim of executed statutory coverage

Populated Teaching Workpaper
out/dossier/CASE-001/security-decisions.json

populated hypothetical decision/specimen; not actual enterprise execution

Local Execution Reference
out/dossier/CASE-001/tests/results.json

Canonical Statutory Grounding

Source references verified against the official Gazette of India publication baseline.

ACT-8 Lines 330–385
Commencement: 2027-05-13 (scheduled, not yet operative)
Obligated Actor

Data Fiduciary

Trigger Context

Processing by it or its processor

Statutory Conditions

Responsibility despite agreements/principal default; valid processor contract; conditional data accuracy; safeguards; breach intimation; erasure; contact and grievance mechanism.

Statutory Exceptions

s8(7) lawful-retention exception; s17 preserves s8(1),(5) under subsection (1).