{"id":17375,"plugin_id":"plugins_6a762d36049481919d7b0751c31dc01c","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T23:14:08.296Z","digest":"89a9d9d589acee2f4e3854c7d2150111ecc5f4704f784a8676229c2cf8052d46","against":null,"payload":{"description":"Assess a processing activity against India's Digital Personal Data Protection Act, 2023, Digital Personal Data Protection Rules, 2025, commencement notifications, corrigenda, exemptions, and sector rules. Use for India-facing notices, consent, rights, children, security, breaches, retention, or transfers.","included_files":[{"relative_path":"agents/openai.yaml","size_in_bytes":330}],"name":"dpdp-compliance-checker","skill_md_contents":"---\nname: dpdp-compliance-checker\ndescription: >-\n  Assess a processing activity against India's Digital Personal Data Protection\n  Act, 2023, Digital Personal Data Protection Rules, 2025, commencement\n  notifications, corrigenda, exemptions, and sector rules. Use for India-facing\n  notices, consent, rights, children, security, breaches, retention, or transfers.\n---\n\n# India DPDP Compliance Checker\n\nApply only provisions in force on the assessment date. The Act and Rules use\nstaggered commencement, so distinguish current duties from future readiness work.\n\n## Intake\n\nObtain the assessment date, entities and roles, India nexus, data principals,\ndigital personal data and sources, purposes, systems, processors, consent and\nnotice flows, legitimate-use reliance, children or persons with disabilities,\nsecurity, breaches, retention, rights channels, grievances, transfers,\nSignificant Data Fiduciary status, exemptions, and sector obligations.\n\n## Checking method\n\n1. Build a commencement table from official notifications and state which Act\n   sections, Rules, schedules, corrigenda, and Board functions are operative.\n2. Confirm territorial and material scope, digital form, India offering nexus,\n   exclusions, state or private roles, and any statutory exemption.\n3. Map data flows by Data Fiduciary, Data Processor, Data Principal, Consent\n   Manager, recipient, purpose, source, system, location, and retention.\n4. Test each purpose for consent or an applicable legitimate use. Check free,\n   specific, informed, unconditional, unambiguous affirmative action, withdrawal,\n   burden, and verifiable records where consent is used.\n5. Review notices for required items, clear language, standalone accessibility,\n   rights and grievance routes, contact details, and consistency with operations.\n6. Test accuracy where decisions or disclosures depend on data, data minimisation,\n   purpose limitation, processor oversight, reasonable security safeguards,\n   breach response, erasure, retention, and record evidence.\n7. Assess rights workflows for access information, correction, completion,\n   updating, erasure, grievance redressal, nomination, identity verification,\n   response tracking, and appeal or escalation.\n8. Apply current child and lawful-guardian requirements, prohibited processing,\n   exemptions, and age or verification rules without guessing future obligations.\n9. Determine whether Significant Data Fiduciary duties, DPO, auditor, DPIA,\n   periodic audit, algorithmic due diligence, or other notified measures apply.\n10. Review cross-border restrictions and sector localisation against current\n    government notifications, not assumptions.\n11. Rank current violations, implementation gaps, future commencement work,\n    evidence needs, owners, and deadlines separately.\n\n## Output\n\nProvide the commencement table, scope and exemption analysis, data-flow register,\nobligation-and-evidence matrix, notice and consent review, rights and grievance\nassessment, security and breach gaps, transfer analysis, and remediation roadmap.\n\n## Guardrails\n\nDo not state that every Act or Rule provision is already effective, import GDPR\nconcepts as if they were DPDP text, or treat consent as universally required.\nVerify official Gazette materials, corrigenda, Board notices, and sector rules\nas of the assessment date with qualified Indian privacy counsel.\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}