Legal Register
Control Workpaper
OBL-36 Rule 13 RULE-13

OBL-36: SDF Algorithmic & Assessment Safeguards (Rule 13)

Conducts algorithmic transparency reviews and periodic risk assessments under Rule 13.

Statutory scope: Rule 13 · Assigned to Privacy / accountable sponsor · Systems: SIEM & Security Telemetry Store (SYS-012); conditional SDF controls

Operational Interface Requirement

Recommended interface: Vary notification date, cycle evidence, significant-observation report, algorithmic diligence and applicable specified-data restriction separately; each missing applicable component remains a gap.

Expected Audit Assertion / Test Result

Vary notification date, cycle evidence, significant-observation report, algorithmic diligence and applicable specified-data restriction separately; each missing applicable component remains a gap.

Governance & Architecture

Recommended Activity Owner
Privacy / accountable sponsor
Target Systems & Interfaces

Verification Specification & Workpaper

Proposed Test Specimen ID
SPEC-Q10-OBL-36

proposed per-row review/acceptance specification; not a claim of executed statutory coverage

Populated Teaching Workpaper
out/remediation/Q05/sdf-readiness.json

populated hypothetical decision/specimen; not actual enterprise execution

Local Execution Reference
out/dossier/CASE-001/tests/results.json

Canonical Statutory Grounding

Source references verified against the official Gazette of India publication baseline.

RULE-13 Lines 1276–1293
Commencement: 2027-05-13 (scheduled, not yet operative)
Obligated Actor

Notified SDF; assessment/audit person; Central Government

Trigger Context

Designation; algorithms; Government data specification

Statutory Conditions

DPIA and audit once each twelve-month period from notification; significant observations report by assessor/auditor; algorithmic technical-measure diligence; specified data/traffic not abroad.

Statutory Exceptions

Data restriction requires specification on committee recommendation; no general all-data localisation.