Legal Register
Control Workpaper
OBL-12 Section 8(6) ACT-8

OBL-12: Personal Data Breach Detection & Intimation

Mandates prompt notification to the Data Protection Board and affected principals upon breach.

Statutory scope: Section 8(6) · Assigned to Incident commander / Legal · Systems: SIEM & Security Telemetry Store (SYS-012)

Operational Interface Requirement

Recommended interface: Remove required notice content or assume an unallowed extension; expected outcome is validation failure and the original detailed deadline preserved.

Expected Audit Assertion / Test Result

Remove required notice content or assume an unallowed extension; expected outcome is validation failure and the original detailed deadline preserved.

Governance & Architecture

Recommended Activity Owner
Incident commander / Legal
Target Systems & Interfaces

Verification Specification & Workpaper

Proposed Test Specimen ID
SPEC-Q10-OBL-12

proposed per-row review/acceptance specification; not a claim of executed statutory coverage

Populated Teaching Workpaper
out/dossier/CASE-001/incident.json

populated hypothetical decision/specimen; not actual enterprise execution

Local Execution Reference
out/dossier/CASE-001/tests/results.json

Canonical Statutory Grounding

Source references verified against the official Gazette of India publication baseline.

ACT-8 Lines 330–385
Commencement: 2027-05-13 (scheduled, not yet operative)
Obligated Actor

Data Fiduciary

Trigger Context

Processing by it or its processor

Statutory Conditions

Responsibility despite agreements/principal default; valid processor contract; conditional data accuracy; safeguards; breach intimation; erasure; contact and grievance mechanism.

Statutory Exceptions

s8(7) lawful-retention exception; s17 preserves s8(1),(5) under subsection (1).