OBL-35: DPIA & Periodic Security Risk Audit (Section 10(2)(c))
Executes periodic Data Protection Impact Assessments (DPIAs) and periodic security audits.
Statutory scope: Section 10(2)(c) · Assigned to Privacy / accountable sponsor · Systems: SIEM & Security Telemetry Store (SYS-012); assessment/audit evidence
Recommended interface: In a stipulated applicable SDF branch, omit a periodic assessment or audit workpaper; expected outcome is a tracked gap, not acceptance from a risk score.
In a stipulated applicable SDF branch, omit a periodic assessment or audit workpaper; expected outcome is a tracked gap, not acceptance from a risk score.
Governance & Architecture
Verification Specification & Workpaper
proposed per-row review/acceptance specification; not a claim of executed statutory coverage
populated hypothetical decision/specimen; not actual enterprise execution
Canonical Statutory Grounding
Source references verified against the official Gazette of India publication baseline.
Central Government; notified SDF
Notification of fiduciary or class following relevant-factor assessment
India-based individual DPO responsible to governing body; independent auditor; periodic DPIA/audit and prescribed measures.
Not automatic from scale/sensitivity; designation and effective timing matter.