Legal Register
Control Workpaper
OBL-33 Section 10(2)(a) ACT-10

OBL-33: India-Resident Statutory DPO Appointment (Section 10(2)(a))

Appoints an India-resident Data Protection Officer reporting directly to the Board of Directors.

Statutory scope: Section 10(2)(a) · Assigned to Privacy / accountable sponsor · Systems: Governance appointment evidence; no actual appointment claimed

Operational Interface Requirement

Recommended interface: In a stipulated applicable SDF branch, omit the India-based individual DPO or governing-body responsibility evidence; expected outcome is readiness gap.

Expected Audit Assertion / Test Result

In a stipulated applicable SDF branch, omit the India-based individual DPO or governing-body responsibility evidence; expected outcome is readiness gap.

Governance & Architecture

Recommended Activity Owner
Privacy / accountable sponsor
Target Systems & Interfaces
Governance appointment evidenceno actual appointment claimed

Verification Specification & Workpaper

Proposed Test Specimen ID
SPEC-Q10-OBL-33

proposed per-row review/acceptance specification; not a claim of executed statutory coverage

Populated Teaching Workpaper
out/remediation/Q05/sdf-readiness.json

populated hypothetical decision/specimen; not actual enterprise execution

Local Execution Reference
out/dossier/CASE-001/tests/results.json

Canonical Statutory Grounding

Source references verified against the official Gazette of India publication baseline.

ACT-10 Lines 404–438
Commencement: 2027-05-13 (scheduled, not yet operative)
Obligated Actor

Central Government; notified SDF

Trigger Context

Notification of fiduciary or class following relevant-factor assessment

Statutory Conditions

India-based individual DPO responsible to governing body; independent auditor; periodic DPIA/audit and prescribed measures.

Statutory Exceptions

Not automatic from scale/sensitivity; designation and effective timing matter.