DPDP control matrix
This is the decision-facing view. The complete machine-readable capability definitions live in
src/data/controls.yaml; the generated control index exposes
every record.
| Requirement | Source / status | Applies to | Product capability | Customer decision | Evidence | Responsible |
|---|---|---|---|---|---|---|
LEG-DPDP-003 | G.S.R. 843(E); 13 May 2027 | covered persons | applicability/control plan | entities, roles, processing | approved assessment | legal/privacy |
LEG-NOTICE-001 | s5–6, r3; 13 May 2027 | consent Fiduciaries | notice version and delivery | data, purpose, channel, language | hash, approval, delivery | privacy/content |
LEG-CONSENT-001 | s6–7; 13 May 2027 | Fiduciaries | purpose ground and consent proof | exact consent or s7 use | purpose decision, receipt | data owner |
LEG-WITHDRAW-001 | s6(4)–(7); 13 May 2027 | Fiduciaries/processors | comparable withdrawal and propagation | lawful continuation, systems | receipt, destination report | privacy/system |
LEG-DF-001 | s8; 13 May 2027 | Fiduciaries | processor, quality, security, retention, contact | contract and control config | control pack | Fiduciary |
LEG-SEC-001 | s8(5), r6; 13 May 2027 | Fiduciaries/processors | safeguard baseline | risk and compensating controls | tests/exceptions | CISO |
LEG-BREACH-001 | s8(6), r7; 13 May 2027 | Fiduciaries | breach case and notifications | awareness, impact, content | assessment/notices | commander/DPO |
LEG-RET-001 | s8(7)–(8), r8; 13 May 2027 | Fiduciaries/processors | retention/hold/deletion | authority and disposition | decision/certificate | records/legal |
LEG-RIGHTS-001 | s11–14, r13–14; 13 May 2027 | Fiduciaries/Principals | verified rights case | identity, exception, response | case package | DPO |
LEG-CHILD-001 | s9, r10–12; 13 May 2027 | child-data Fiduciaries | assurance and policy enforcement | method and exception | outcome/test | child safety |
LEG-SDF-001 | s10, r13; designation dependent | notified SDF | governance/DPIA/audit/algorithmic | notification and annual cycle | reports | board/DPO |
LEG-XBRD-001 | s16, r15; order dependent | relevant Fiduciaries | transfer/residency policy | destinations and overlays | assessment/policy test | legal/cloud |
LEG-DPDP-002 | s6(9), s27(1)(d); 13 Nov 2026 | registered CM | statutory separation/readiness | registration status | Board pack | CM governing body |
LEG-RULE-002 | r4, First Schedule; 13 Nov 2026 | prospective CM | interoperable no-read platform | standards and onboarded DF | certification/audit/export | CM compliance |
LEG-CERT-001 | CERT-In directions; in force | covered entities | separate six-hour clock/log control | incident test, log sources | report/NTP/log test | CISO |
Exceptions and uncertainty
Section titled “Exceptions and uncertainty”LEG-SDF-001does not activate without a designation source.LEG-XBRD-001supports future government orders; it does not manufacture a restricted-country or localisation list.- a software control can be configured incorrectly or bypassed; evidence proves an event or test, not overall legal compliance.
- sector packs may make a control mandatory earlier or impose a shorter clock/longer retention.
Traceability rule
Section titled “Traceability rule”Every mandatory requirement must map to:
source provision → legal status → control → configured workflow→ responsible person → system task → evidence → test → review dateA missing link is a programme risk. The UI shows it as unmapped, unconfigured,
implementation_pending, evidence_stale or exception_open; it never converts absence into a
green percentage.