DPDP Obligation Register
Automated Statutory Applicability & Compliance Decision Engine
Product Overview & Key Capabilities
An intelligent statutory decision engine that automates the classification of digital personal data processing activities, determines applicability across primary Act and subordinate Rules, establishes enforcement milestones across all 3 commencement tranches, and assigns operational control ownership with full audit traceability.
Versioned enterprise applicability decision register: canonical provision references, entity facts, effective-date basis, source locators, legal interpretations, control owners, and review sign-off history.
Target Roles & Operational Impact
| Target Persona & Role | Decision Authority | Operational Value & Impact |
|---|---|---|
| Data Protection Officer & Compliance Lead | Operational Sign-Off | Record deterministic APPLICABLE, NOT_APPLICABLE, or UNRESOLVED decisions with automated evidence requirement checks. |
| General Counsel & Legal Advisor | Legal Interpretation Veto | Validate entity facts against statutory thresholds, exemptions under Section 17, and subordinate rule notifications. |
| Programme Sponsor & CISO | Budget & Resource Allocation | Identify unassigned control obligations and track compliance countdowns across all 3 statutory commencement tranches. |
Data Schema & Architecture Interface Contracts
The following data schemas and interface contracts define the structured payloads and integration endpoints of this product:
Operational Workflow & Product Invariants
Execution Workflow Procedure
- Catalog business activities, data categories, and processing purposes across business units.
- Evaluate against all 102 canonical Act sections and subordinate Rules using deterministic fact gates.
- Assign statutory applicability states (APPLICABLE, NOT_APPLICABLE, UNRESOLVED) with rationale.
- Calculate effective commencement tranches (Tranche 1 Nov 2025, Tranche 2 Nov 2026, Tranche 3 May 2027).
- Map applicable provisions to operational controls (OBL-01 to OBL-54) and assign accountable internal owners.
- Export immutable, digest-bound decision packages in JSON, CSV, or executive PDF audit reports.
Mandatory Product Invariants
- P01-R01: Preserve canonical statutory provision IDs exactly without simplifying into generic advice labels.
- P01-R02: Require explicit tri-state classification (APPLICABLE, NOT_APPLICABLE, UNRESOLVED) with reviewer attribution.
- P01-R03: Automatically track Gazette amendments and trigger freshness re-evaluation upon statutory changes.
- P01-R04: Generate portable, tamper-evident audit dossiers with SHA-256 integrity digests.
Operational Boundaries & Architecture Assumptions
- • Does not constitute binding legal representation before the Data Protection Board of India.
- • Does not automate real-time network traffic filtering without integration with enforcement engines.
Built-in Quality Verification & Compliance Test Harness
Verify that mapping activity facts to statutory provisions correctly generates traceable applicability proposals.
Validate that absence of required entity facts forces an UNRESOLVED state and blocks compliance sign-off.
Confirm that updating a statutory source digest automatically marks affected historical reviews for re-evaluation.
Statutory Grounding & Regulatory Crosswalk
10 Enforced ProvisionsThe following primary Act sections and subordinate Rule provisions establish the direct legal grounding, mandatory statutory constraints, and operational compliance duties enforced by this product:
Section 1
Different provisions may have different dates; reference to commencement follows the provision.
Section 2
Child: below 18; fiduciary: alone or jointly determines purpose and means; processor: acts on behalf; breach: CIA-compromising unauthorised processing or specified accidental events.
Section 3
Includes later-digitised collection; offshore nexus is principals within India, not Indian citizenship.
Section 4
Lawful purpose plus consent or a section 7 use.
Section 7
Complete (a)-(i) subrows govern; there is no s7(1)(h).
Section 8
Responsibility despite agreements/principal default; valid processor contract; conditional data accuracy; safeguards; breach intimation; erasure; contact and grievance mechanism.
Section 10
India-based individual DPO responsible to governing body; independent auditor; periodic DPIA/audit and prescribed measures.
Section 17
Differently scoped disapplications in (1)-(5); see complete subrows.
Section 33
May impose scheduled penalty; seven statutory factors.
Rule 1
rr1,2,17-21 publication; r4 one year; rr3,5-16,22,23 eighteen months.
Target Systems Topology (SYS-001..014)
View Complete Architecture Topology →Public client boundary & untrusted intake surface for notices and consent capture
Model training and algorithm development node gated against unconsented data
Internal employer database holding employee payroll and candidate records
Immutable consent event store and Policy Decision Point issuing authority tokens