Generated control index
This index is generated from src/data/controls.yaml. Classification matters: a recommended
control is not presented as a statutory obligation.
| Control ID | Control | Classification | Accountable role | Requirement IDs |
|---|---|---|---|---|
| CTRL-GOV-001 | Applicability and role registry | recommended control supporting DPDP | Privacy admin | LEG-DPDP-001, LEG-DPDP-003 |
| CTRL-REG-001 | Regulatory change ledger | recommended control | Legal reviewer | LEG-DPDP-001, LEG-BOARD-001, LEG-BOARD-002, LEG-BOARD-003 |
| CTRL-PURPOSE-001 | DPDP processing-ground and purpose register | DPDP — not yet effective | Data owner | LEG-CONSENT-001 |
| CTRL-NOTICE-001 | Standalone itemised notice | DPDP — not yet effective | Privacy admin | LEG-NOTICE-001 |
| CTRL-NOTICE-002 | Notice language and assisted delivery | DPDP — not yet effective | Content reviewer | LEG-NOTICE-001 |
| CTRL-CONSENT-001 | Consent capture and proof | DPDP — not yet effective | Product system owner | LEG-CONSENT-001 |
| CTRL-CONSENT-002 | Comparable-ease withdrawal | DPDP — not yet effective | Privacy admin | LEG-WITHDRAW-001 |
| CTRL-PROPAGATION-001 | Downstream stop-processing propagation | DPDP — not yet effective | System owner | LEG-WITHDRAW-001 |
| CTRL-PROCESSOR-001 | Processor instruction and contract register | DPDP — not yet effective | Processor manager | LEG-DF-001, LEG-SEC-001, LEG-RBI-001 |
| CTRL-DATA-QUALITY-001 | Decision and disclosure data-quality checkpoint | DPDP — not yet effective | Data owner | LEG-DF-001 |
| CTRL-SEC-001 | Reasonable security safeguard baseline | DPDP — not yet effective | CISO | LEG-SEC-001 |
| CTRL-AUDIT-001 | Tamper-evident audit and evidence log | recommended control supporting DPDP and CERT-In | Auditor | LEG-SEC-001, LEG-CERT-001 |
| CTRL-BREACH-001 | Multi-regime incident clock | DPDP — not yet effective; adjacent law in force | Incident commander | LEG-BREACH-001, LEG-CERT-001, LEG-RBI-001, LEG-SEBI-001 |
| CTRL-BREACH-002 | Data Principal and Board notification pack | DPDP — not yet effective | DPO | LEG-BREACH-001 |
| CTRL-RET-001 | Source-linked retention rules | DPDP — not yet effective | Records manager | LEG-DF-001, LEG-RET-001 |
| CTRL-HOLD-001 | Legal hold | recommended control | Legal reviewer | LEG-RET-001 |
| CTRL-DELETE-001 | Deletion orchestration and certificate | DPDP — not yet effective | System owner | LEG-RET-001 |
| CTRL-CONTACT-001 | Published privacy contact | DPDP — not yet effective | Privacy admin | LEG-DF-001 |
| CTRL-RIGHTS-IDENTITY-001 | Proportionate identity assurance | DPDP — not yet effective | Support agent | LEG-RIGHTS-001, LEG-BOARD-003 |
| CTRL-RIGHTS-001 | Data Principal rights case | DPDP — not yet effective | DPO | LEG-RIGHTS-001 |
| CTRL-GRIEVANCE-001 | Grievance redressal | DPDP — not yet effective | Grievance officer | LEG-RIGHTS-001 |
| CTRL-NOMINATION-001 | Nomination record and activation | DPDP — not yet effective | Privacy admin | LEG-RIGHTS-001 |
| CTRL-CHILD-001 | Child and guardian assurance | DPDP — not yet effective | Privacy admin | LEG-CHILD-001 |
| CTRL-CHILD-002 | Child processing policy enforcement | DPDP — not yet effective | Product owner | LEG-CHILD-001 |
| CTRL-SDF-001 | Significant Data Fiduciary governance | designation-dependent DPDP control | Board / DPO | LEG-SDF-001 |
| CTRL-DPIA-001 | Data protection impact assessment | designation-dependent DPDP control; recommended more broadly | DPO | LEG-SDF-001 |
| CTRL-ALGO-001 | Algorithmic due-diligence assessment | designation-dependent DPDP control | Model risk owner | LEG-SDF-001 |
| CTRL-XBRD-001 | Transfer and foreign-access register | DPDP — not yet effective | Legal reviewer | LEG-XBRD-001 |
| CTRL-XBRD-002 | Residency policy enforcement | order- or sector-dependent | Cloud platform owner | LEG-SDF-001, LEG-XBRD-001 |
| CTRL-CM-001 | Statutory Consent Manager separation | DPDP — not yet effective | Governing body | LEG-DPDP-002, LEG-RULE-002 |
| CTRL-CM-002 | Consent Manager registration readiness | DPDP — not yet effective | Compliance officer | LEG-DPDP-002, LEG-RULE-002 |
| CTRL-CM-003 | Consent Manager interoperable platform boundary | DPDP — not yet effective; government interface open | Consent Manager CTO | LEG-RULE-002 |
| CTRL-CERT-001 | CERT-In report and 180-day India log control | adjacent India law — in force | CISO | LEG-CERT-001 |
| CTRL-VENDOR-001 | Vendor and subprocessor assurance | recommended control; sector requirements may bind | Processor manager | LEG-RBI-001 |
| CTRL-EXIT-001 | Processor and platform exit | contractual; sector requirements may bind | Vendor owner | LEG-RBI-001 |
| CTRL-SECTOR-SEBI-001 | SEBI CSCRF entity profile | sector regulation | CISO | LEG-SEBI-001 |