Operational Lifecycle Hub
Operational Lifecycle Hub
Section 8(6) Rule 7 Section 33
Personal Data Breach & Dual Clocks
Parallel reporting clocks: CERT-In 6-hour incident report vs DPDP Rule 7 without-delay / 72-hour notification to Board and affected Data Principals.
Mapped Controls & Evidence Obligations
Appendix B Control Master Matrix rows governing this lifecycle.
OBL-12 Section 8(6)
SPEC-Q10-OBL-12 Personal Data Breach Detection & Intimation
Mandates prompt notification to the Data Protection Board and affected principals upon breach.
Owner: Incident commander / Legal Open Workpaper →
Systems: SIEM & Security Telemetry Store (SYS-012)
OBL-18 Rule 7 — breach content/clocks
SPEC-Q10-OBL-18 Dual-Clock Breach Incident Workflow (Rule 7)
Executes dual reporting clocks: CERT-In 6-hour intimation and DPDP Rule 7 Board breach dossiers.
Owner: Incident commander / Legal Open Workpaper →
Systems: SIEM & Security Telemetry Store (SYS-012)
OBL-48 Section 33(1) to (2)
SPEC-Q10-OBL-48 Statutory Penalty Exposure & Liability Controls (Section 33)
Governs financial penalty exposure up to ₹250 Crore per significant statutory non-compliance.
Owner: Legal / board secretariat Open Workpaper →
Systems: Governance register; no live Board system asserted
OBL-49 Schedule items 1–7
SPEC-Q10-OBL-49 Schedule 1–7 Penalty Tier Risk Mitigation (Schedule)
Monitors statutory penalty tiers across security safeguards, breach, children, and SDF duties.
Owner: Legal / board secretariat Open Workpaper →
Systems: Governance register; no live Board system asserted
Mechanism Chapters
Detailed architecture, implementation patterns, and case studies.