Skip to content

Current legal status ledger

This page is the human-readable companion to src/data/legal-status.yaml. The YAML record is the canonical structured ledger; validation rejects unknown control mappings and incomplete fields.

Ledger IDProvision cohortEffective dateStatus
LEG-DPDP-001Act sections 1(2), 2, 18–26, 35, 38–43, 44(1), 44(3)13 Nov 2025DPDP — in force
LEG-DPDP-002Act 6(9), 27(1)(d)13 Nov 2026DPDP — not yet effective
LEG-DPDP-003Main Act cohort13 May 2027DPDP — not yet effective
LEG-RULE-001Rules 1, 2, 17–2113 Nov 2025DPDP — in force
LEG-RULE-002Rule 4 and First Schedule13 Nov 2026DPDP — not yet effective
LEG-RULE-003Rules 3, 5–16, 22, 23 and remaining Schedules13 May 2027DPDP — not yet effective
IDRequirementApplies toProduct controlsEvidence
LEG-NOTICE-001standalone itemised notice and service routesconsent-based Data Fiduciary processingCTRL-NOTICE-001, 002approved version, delivery
LEG-CONSENT-001valid consent or a specific section 7 useData FiduciariesCTRL-CONSENT-001, CTRL-PURPOSE-001receipt, approved ground
LEG-WITHDRAW-001comparable-ease withdrawal and downstream stopFiduciaries and processors through instructionCTRL-CONSENT-002, CTRL-PROPAGATION-001receipt, destination results
LEG-DF-001accountability, contracts, quality, security, erasure, contactData Fiduciariesprocessor, quality, security, retention controlscontract and control evidence
LEG-BREACH-001principal/Board notices and 72-hour detailData FiduciariesCTRL-BREACH-001, 002assessment and receipts
LEG-RET-001purpose/withdrawal erasure subject to lawFiduciaries and processorsretention, hold, deletion controlsdecision and certificate
LEG-RIGHTS-001access information, correction, erasure, grievance, nominationFiduciaries and Principalsrights, identity, grievance, nominationcase file
LEG-CHILD-001verifiable parent/guardian consent and restrictionsrelevant Fiduciarieschild assurance and policy enforcementoutcome and tests
LEG-SDF-001DPO, auditor, DPIA, audit, algorithms, notified localitydesignated SDFsSDF, DPIA, algorithmic, residency controlsgovernance pack
LEG-XBRD-001notified transfer and foreign-State access restrictionsrelevant Fiduciariestransfer and residency controlsapproved assessment
Adjacent law — in force

The CERT-In Directions can require a listed cyber incident to be reported within six hours and ICT logs to be retained securely in India for 180 days. A DPDP personal data breach and a CERT-In listed cyber incident are different legal tests. One event may satisfy neither, one or both.

The incident model therefore stores a clock as:

clock_id
regime # DPDP | CERT_IN | RBI | SEBI | IRDAI | contract
trigger_facts
triggered_at
deadline_at
authority_source_id
decision # applies | does_not_apply | uncertain
decision_owner
approved_at
submission_receipt
FactProvenNot proven
Board existence and NCR head officeG.S.R. 844(E), effective 13 Nov 2025full operational staffing
Recruitmentapplications invited 6 May 2026appointments completed
Aadhaar use casevoluntary portal use approved 20 Jul 2026mandatory Aadhaar or live portal
Rules corrigendumG.S.R. 892(E), Gazette dated 11 Dec 2025no consolidated official Rules text located

The implementation baseline reads G.S.R. 846(E) with G.S.R. 892(E). The corrigendum makes these published-text corrections:

Rules PDF locationEarlier textCorrected text
page 24, line 22“of this Gazette”“in the Official Gazette”
page 24, line 24“of this Gazette”“in the Official Gazette”
page 29, line 44“Department”“Departments”
page 32, line 4“given in such”“given in such order”
page 34, line 1“everybody”“every body”
page 34, line 26“(18 or 2013)”“(18 of 2013)”
page 38“.” and “(a) to (f)”“;” and “(a) to (g)”

This is a transcription of the corrigendum for implementation traceability, not a substitute for the signed Gazette PDF. No official consolidated Rules text was located in this research pass.

Every product control references one or more ledger IDs. The legal reviewer changes status only after comparing a new primary source, recording the effective date, assessing impacted controls and approving the diff. Product teams consume the signed configuration version; they do not scrape the web or silently change a customer’s obligations.