Current legal status ledger
This page is the human-readable companion to src/data/legal-status.yaml. The YAML record is the
canonical structured ledger; validation rejects unknown control mappings and incomplete fields.
Commencement cohorts
Section titled “Commencement cohorts”| Ledger ID | Provision cohort | Effective date | Status |
|---|---|---|---|
LEG-DPDP-001 | Act sections 1(2), 2, 18–26, 35, 38–43, 44(1), 44(3) | 13 Nov 2025 | DPDP — in force |
LEG-DPDP-002 | Act 6(9), 27(1)(d) | 13 Nov 2026 | DPDP — not yet effective |
LEG-DPDP-003 | Main Act cohort | 13 May 2027 | DPDP — not yet effective |
LEG-RULE-001 | Rules 1, 2, 17–21 | 13 Nov 2025 | DPDP — in force |
LEG-RULE-002 | Rule 4 and First Schedule | 13 Nov 2026 | DPDP — not yet effective |
LEG-RULE-003 | Rules 3, 5–16, 22, 23 and remaining Schedules | 13 May 2027 | DPDP — not yet effective |
Main operational obligations
Section titled “Main operational obligations”| ID | Requirement | Applies to | Product controls | Evidence |
|---|---|---|---|---|
LEG-NOTICE-001 | standalone itemised notice and service routes | consent-based Data Fiduciary processing | CTRL-NOTICE-001, 002 | approved version, delivery |
LEG-CONSENT-001 | valid consent or a specific section 7 use | Data Fiduciaries | CTRL-CONSENT-001, CTRL-PURPOSE-001 | receipt, approved ground |
LEG-WITHDRAW-001 | comparable-ease withdrawal and downstream stop | Fiduciaries and processors through instruction | CTRL-CONSENT-002, CTRL-PROPAGATION-001 | receipt, destination results |
LEG-DF-001 | accountability, contracts, quality, security, erasure, contact | Data Fiduciaries | processor, quality, security, retention controls | contract and control evidence |
LEG-BREACH-001 | principal/Board notices and 72-hour detail | Data Fiduciaries | CTRL-BREACH-001, 002 | assessment and receipts |
LEG-RET-001 | purpose/withdrawal erasure subject to law | Fiduciaries and processors | retention, hold, deletion controls | decision and certificate |
LEG-RIGHTS-001 | access information, correction, erasure, grievance, nomination | Fiduciaries and Principals | rights, identity, grievance, nomination | case file |
LEG-CHILD-001 | verifiable parent/guardian consent and restrictions | relevant Fiduciaries | child assurance and policy enforcement | outcome and tests |
LEG-SDF-001 | DPO, auditor, DPIA, audit, algorithms, notified locality | designated SDFs | SDF, DPIA, algorithmic, residency controls | governance pack |
LEG-XBRD-001 | notified transfer and foreign-State access restrictions | relevant Fiduciaries | transfer and residency controls | approved assessment |
Adjacent clocks are independent
Section titled “Adjacent clocks are independent”The CERT-In Directions can require a listed cyber incident to be reported within six hours and ICT logs to be retained securely in India for 180 days. A DPDP personal data breach and a CERT-In listed cyber incident are different legal tests. One event may satisfy neither, one or both.
The incident model therefore stores a clock as:
clock_idregime # DPDP | CERT_IN | RBI | SEBI | IRDAI | contracttrigger_factstriggered_atdeadline_atauthority_source_iddecision # applies | does_not_apply | uncertaindecision_ownerapproved_atsubmission_receiptInstitutional status
Section titled “Institutional status”| Fact | Proven | Not proven |
|---|---|---|
| Board existence and NCR head office | G.S.R. 844(E), effective 13 Nov 2025 | full operational staffing |
| Recruitment | applications invited 6 May 2026 | appointments completed |
| Aadhaar use case | voluntary portal use approved 20 Jul 2026 | mandatory Aadhaar or live portal |
| Rules corrigendum | G.S.R. 892(E), Gazette dated 11 Dec 2025 | no consolidated official Rules text located |
Incorporated Rules corrigendum
Section titled “Incorporated Rules corrigendum”The implementation baseline reads G.S.R. 846(E) with G.S.R. 892(E). The corrigendum makes these published-text corrections:
| Rules PDF location | Earlier text | Corrected text |
|---|---|---|
| page 24, line 22 | “of this Gazette” | “in the Official Gazette” |
| page 24, line 24 | “of this Gazette” | “in the Official Gazette” |
| page 29, line 44 | “Department” | “Departments” |
| page 32, line 4 | “given in such” | “given in such order” |
| page 34, line 1 | “everybody” | “every body” |
| page 34, line 26 | “(18 or 2013)” | “(18 of 2013)” |
| page 38 | “.” and “(a) to (f)” | “;” and “(a) to (g)” |
This is a transcription of the corrigendum for implementation traceability, not a substitute for the signed Gazette PDF. No official consolidated Rules text was located in this research pass.
Use of the ledger
Section titled “Use of the ledger”Every product control references one or more ledger IDs. The legal reviewer changes status only after comparing a new primary source, recording the effective date, assessing impacted controls and approving the diff. Product teams consume the signed configuration version; they do not scrape the web or silently change a customer’s obligations.