Operational Lifecycle Hub
Operational Lifecycle Hub
Section 8(1) Section 8(2) Section 16 Rule 15
Processors, Subprocessors & Cloud Transfers
Fiduciary liability irrespective of contract (s.8(1)), valid processor agreements (s.8(2)), subprocessor changes, cross-border transfers (s.16/r.15).
Mapped Controls & Evidence Obligations
Appendix B Control Master Matrix rows governing this lifecycle.
OBL-08 Section 8(1) to (2)
SPEC-Q10-OBL-08 Processor Engagement & Subprocessing Contracts
Enforces valid data processing agreements and downstream propagation of statutory duties.
Owner: Vendor manager / Legal Open Workpaper →
Systems: Marketing Automation Engine (SYS-003); Processor Orchestration Gateway & Queue (SYS-013)
OBL-22 Rule 15 (transfer)
SPEC-Q10-OBL-22 Cross-Border Data Transfer Governance (Rule 15)
Enforces cross-border transfer blacklists, adequacy checks, and contractual transfer terms.
Owner: Architecture / sector Legal Open Workpaper →
Systems: Foreign-Region Secondary Backup Replica (SYS-008); Overseas Analytics Cluster (SYS-009)
OBL-43 Section 16(1) — notified restrictions
SPEC-Q10-OBL-43 Notified Cross-Border Transfer Restrictions (Section 16(1))
Blocks personal data transfers to countries blacklisted or restricted by the Central Government.
Owner: Architecture / sector Legal Open Workpaper →
Systems: Foreign-Region Secondary Backup Replica (SYS-008); Overseas Analytics Cluster (SYS-009)
OBL-44 Section 16(2) — transfer-specific saving
SPEC-Q10-OBL-44 Sectoral Higher Transfer Standards Saving (Section 16(2))
Preserves stricter sectoral data localization and transfer mandates (RBI, SEBI, IRDAI).
Owner: Architecture / sector Legal Open Workpaper →
Systems: Foreign-Region Secondary Backup Replica (SYS-008); Overseas Analytics Cluster (SYS-009)
Mechanism Chapters
Detailed architecture, implementation patterns, and case studies.
Ch.17
Chapter 17 — Processors, Subprocessors and Third-Party Risk
Part III — Privacy Engineering & Technical Implementation · 17 min read
Read Chapter →
Ch.18
Chapter 18 — Transfers, Cloud and Enterprise Reference Architecture
Part III — Privacy Engineering & Technical Implementation · 19 min read
Read Chapter →