← Files Rohas Legal AI: PrivacyARCHIVED FILE

skills/dpdp-compliance-checker/SKILL.md

3.29 KB · Oct 4, 2026 · 12:29 UTC

↓ Download file

---
name: dpdp-compliance-checker
description: >-
  Assess a processing activity against India's Digital Personal Data Protection
  Act, 2023, Digital Personal Data Protection Rules, 2025, commencement
  notifications, corrigenda, exemptions, and sector rules. Use for India-facing
  notices, consent, rights, children, security, breaches, retention, or transfers.
---

# India DPDP Compliance Checker

Apply only provisions in force on the assessment date. The Act and Rules use
staggered commencement, so distinguish current duties from future readiness work.

## Intake

Obtain the assessment date, entities and roles, India nexus, data principals,
digital personal data and sources, purposes, systems, processors, consent and
notice flows, legitimate-use reliance, children or persons with disabilities,
security, breaches, retention, rights channels, grievances, transfers,
Significant Data Fiduciary status, exemptions, and sector obligations.

## Checking method

1. Build a commencement table from official notifications and state which Act
   sections, Rules, schedules, corrigenda, and Board functions are operative.
2. Confirm territorial and material scope, digital form, India offering nexus,
   exclusions, state or private roles, and any statutory exemption.
3. Map data flows by Data Fiduciary, Data Processor, Data Principal, Consent
   Manager, recipient, purpose, source, system, location, and retention.
4. Test each purpose for consent or an applicable legitimate use. Check free,
   specific, informed, unconditional, unambiguous affirmative action, withdrawal,
   burden, and verifiable records where consent is used.
5. Review notices for required items, clear language, standalone accessibility,
   rights and grievance routes, contact details, and consistency with operations.
6. Test accuracy where decisions or disclosures depend on data, data minimisation,
   purpose limitation, processor oversight, reasonable security safeguards,
   breach response, erasure, retention, and record evidence.
7. Assess rights workflows for access information, correction, completion,
   updating, erasure, grievance redressal, nomination, identity verification,
   response tracking, and appeal or escalation.
8. Apply current child and lawful-guardian requirements, prohibited processing,
   exemptions, and age or verification rules without guessing future obligations.
9. Determine whether Significant Data Fiduciary duties, DPO, auditor, DPIA,
   periodic audit, algorithmic due diligence, or other notified measures apply.
10. Review cross-border restrictions and sector localisation against current
    government notifications, not assumptions.
11. Rank current violations, implementation gaps, future commencement work,
    evidence needs, owners, and deadlines separately.

## Output

Provide the commencement table, scope and exemption analysis, data-flow register,
obligation-and-evidence matrix, notice and consent review, rights and grievance
assessment, security and breach gaps, transfer analysis, and remediation roadmap.

## Guardrails

Do not state that every Act or Rule provision is already effective, import GDPR
concepts as if they were DPDP text, or treat consent as universally required.
Verify official Gazette materials, corrigenda, Board notices, and sector rules
as of the assessment date with qualified Indian privacy counsel.

SHA-256: 823d1e2784ad421ac34bf31b8e3a632b8296c4db0d6518cb39869edf8d4f1d44