Legal Register
Control Workpaper
OBL-35 Section 10(2)(c) ACT-10

OBL-35: DPIA & Periodic Security Risk Audit (Section 10(2)(c))

Executes periodic Data Protection Impact Assessments (DPIAs) and periodic security audits.

Statutory scope: Section 10(2)(c) · Assigned to Privacy / accountable sponsor · Systems: SIEM & Security Telemetry Store (SYS-012); assessment/audit evidence

Operational Interface Requirement

Recommended interface: In a stipulated applicable SDF branch, omit a periodic assessment or audit workpaper; expected outcome is a tracked gap, not acceptance from a risk score.

Expected Audit Assertion / Test Result

In a stipulated applicable SDF branch, omit a periodic assessment or audit workpaper; expected outcome is a tracked gap, not acceptance from a risk score.

Governance & Architecture

Recommended Activity Owner
Privacy / accountable sponsor
Target Systems & Interfaces

Verification Specification & Workpaper

Proposed Test Specimen ID
SPEC-Q10-OBL-35

proposed per-row review/acceptance specification; not a claim of executed statutory coverage

Populated Teaching Workpaper
out/remediation/Q05/sdf-readiness.json

populated hypothetical decision/specimen; not actual enterprise execution

Local Execution Reference
out/dossier/CASE-001/tests/results.json

Canonical Statutory Grounding

Source references verified against the official Gazette of India publication baseline.

ACT-10 Lines 404–438
Commencement: 2027-05-13 (scheduled, not yet operative)
Obligated Actor

Central Government; notified SDF

Trigger Context

Notification of fiduciary or class following relevant-factor assessment

Statutory Conditions

India-based individual DPO responsible to governing body; independent auditor; periodic DPIA/audit and prescribed measures.

Statutory Exceptions

Not automatic from scale/sensitivity; designation and effective timing matter.