/ind-dpdpa-expert
India DPDPA expert for the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025. Covers Data Fiduciary obligations, Data Principal rights, Significant Data Fiduciary regime, Consent Manager, breach notification (72-hour), cross-border transfer regime, children's
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill ind-dpdpa-expert --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/ind-dpdpa-expert
Context preview
The summary Claude sees to decide when to auto-load this skill.
India DPDPA expert for the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025. Covers Data Fiduciary obligations, Data Principal rights, Significant Data Fiduciary regime, Consent Manager, breach notification (72-hour), cross-border transfer regime, children's
SKILL.md
ind-dpdpa-expert.SKILL.mdname: ind-dpdpa-expert
description: India DPDPA expert for the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025. Covers Data Fiduciary obligations, Data Principal rights, Significant Data Fiduciary regime, Consent Manager, breach notification (72-hour), cross-border transfer regime, children's data, sectoral overlap with RBI / SEBI / IRDAI / TRAI / CERT-In / ABDM, and Data Protection Board enforcement.
allowed-tools: Read, Glob, Grep, Write
India DPDPA Expert
Deep working knowledge of the **Digital Personal Data Protection Act, 2023** (DPDPA) and the **Digital Personal Data Protection Rules, 2025** (DPDP Rules), as enforced by the **Data Protection Board of India** (DPB) under the Ministry of Electronics and Information Technology (MeitY).
This skill is engineering and assessment guidance for CISOs, DPOs, GRC engineers, and platform teams. It is **not** legal advice. Binding interpretations come from DPB orders, MeitY notifications, and the courts.
When to invoke this skill
Invoke when the user is:
- Mapping a system, product, or third-party vendor to DPDPA obligations
- Determining whether DPDPA applies (territorial, material, role)
- Assessing Significant Data Fiduciary (SDF) exposure
- Drafting or auditing privacy notices, consent flows, or rights-fulfilment workflows
- Building or stress-testing a personal-data-breach playbook (with DPDPA's 72-hour clock and the parallel sectoral clocks)
- Preparing for a DPB enquiry or compiling penalty-mitigation evidence
- Deciding cross-border transfer postures or evaluating a Consent Manager partner
- Comparing DPDPA to GDPR / Singapore PDPA / other regimes for a multi-jurisdictional product
Framework identity
| Field | Value | |---|---| | Statute | Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) | | Operational rules | Digital Personal Data Protection Rules, 2025 (notified November 2025) | | Regulator | Data Protection Board of India (DPB) under MeitY | | Territorial scope | Processing within India; processing outside India in connection with offering goods or services to Data Principals located in India | | Material scope | Digital personal data — personal data in digital form, or in non-digital form digitised subsequently | | SCF framework ID | `apac-ind-dpdpa-2023` | | SCF coverage | 41 SCF controls map to 96 DPDPA control identifiers | | Status (as of 2026) | Act in force; Rules notified November 2025 with phased operational dates |
The Act and the Rules **must be read together**. The Act sets substantive obligations; the Rules set the operational detail — timelines, formats, registration mechanisms, and procedures. Gaps in either side are gaps in compliance.
Roles and definitions
| DPDPA term | Meaning | GDPR analogue | |---|---|---| | **Data Fiduciary** | Determines the purpose and means of processing personal data. The controller-equivalent. | Controller | | **Data Processor** | Processes personal data on behalf of a Fiduciary under contract. | Processor | | **Data Principal** | The natural person whose personal data is processed. For a child, the parent or lawful guardian; for a person with a disability, the lawful guardian. | Data Subject | | **Significant Data Fiduciary (SDF)** | A class of Data Fiduciary notified by the Central Government as having higher-risk processing. Carries additional obligations. | (Broader and stricter than GDPR's "large-scale" qualifier) | | **Consent Manager** | A registrable entity that manages consents on behalf of Data Principals — gives, manages, reviews, withdraws consent across multiple Fiduciaries. | (No direct GDPR analogue) | | **Personal data** | Any data about an individual who is identifiable by or in relation to such data. | Personal data (Article 4(1)) | | **Processing** | Wholly or partly automated operation/s on personal data — collection, storage, use, sharing, disclosure, erasure, destruction. | Processing | | **Personal data breach** | Any incident that compromises the confidentiality, integrity, or availability of personal data — covering unauthorised processing, accidental disclosure or sharing, alteration, destruction, and loss of access (see Section 2(u) of the Act for the authoritative wording). | Personal data breach |
DPDPA does **not** define "sensitive personal data" as a separate category (unlike GDPR Article 9 or India's earlier SPDI Rules 2011). All personal data is governed by the same baseline obligations, with intensified obligations for children's data (Section 9) and SDF processing (Section 10).
Territorial and material applicability (Section 3)
DPDPA applies to processing of **digital personal data**:
1. **Within India** — processing of digital personal data, regardless of where the Data Fiduciary is established; **and** 2. **Outside India** — processing of digital personal data outside India, where the processing is in connection with **offering goods or services** to Data Principals located in India.
Personal data in non-digital form falls within scope only if **digitised subsequently** (Section 3(b)).
DPDPA does **not** apply to:
- Personal data processed by an individual for **personal or domestic purposes**.
- Personal data **made publicly available** by the Data Principal themselves, or by another person under a legal obligation.
- Specific exemptions notified under **Section 17** — including processing necessary for research, archival, statistical purposes (subject to safeguards), processing by the State for sovereign functions, prevention/detection/investigation of offences, and certain other notified contexts.
When determining applicability, use `/ind-dpdpa:scope` — it walks the decision tree.
Data Fiduciary obligations (Section 8)
Every Data Fiduciary, whether SDF or not, owes the following baseline obligations:
| Obligation | Section | What it requires | |---|---|---| | Accuracy | 8(3) | Make reasonable efforts to ensure personal data is accurate and complete when used to make a de
Read more
name: ind-dpdpa-expert description: India DPDPA expert for the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025. Covers Data Fiduciary obligations, Data Principal rights, Significant Data Fiduciary regime, Consent Manager, breach notification (72-hour), cross-border transfer regime, children's data, sectoral overlap with RBI / SEBI / IRDAI / TRAI / CERT-In / ABDM, and Data Protection Board enforcement. allowed-tools: Read, Glob, Grep, Write
India DPDPA Expert
Deep working knowledge of the **Digital Personal Data Protection Act, 2023** (DPDPA) and the **Digital Personal Data Protection Rules, 2025** (DPDP Rules), as enforced by the **Data Protection Board of India** (DPB) under the Ministry of Electronics and Information Technology (MeitY).
This skill is engineering and assessment guidance for CISOs, DPOs, GRC engineers, and platform teams. It is **not** legal advice. Binding interpretations come from DPB orders, MeitY notifications, and the courts.
When to invoke this skill
Invoke when the user is:
- Mapping a system, product, or third-party vendor to DPDPA obligations
- Determining whether DPDPA applies (territorial, material, role)
- Assessing Significant Data Fiduciary (SDF) exposure
- Drafting or auditing privacy notices, consent flows, or rights-fulfilment workflows
- Building or stress-testing a personal-data-breach playbook (with DPDPA's 72-hour clock and the parallel sectoral clocks)
- Preparing for a DPB enquiry or compiling penalty-mitigation evidence
- Deciding cross-border transfer postures or evaluating a Consent Manager partner
- Comparing DPDPA to GDPR / Singapore PDPA / other regimes for a multi-jurisdictional product
Framework identity
| Field | Value | |---|---| | Statute | Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) | | Operational rules | Digital Personal Data Protection Rules, 2025 (notified November 2025) | | Regulator | Data Protection Board of India (DPB) under MeitY | | Territorial scope | Processing within India; processing outside India in connection with offering goods or services to Data Principals located in India | | Material scope | Digital personal data — personal data in digital form, or in non-digital form digitised subsequently | | SCF framework ID | `apac-ind-dpdpa-2023` | | SCF coverage | 41 SCF controls map to 96 DPDPA control identifiers | | Status (as of 2026) | Act in force; Rules notified November 2025 with phased operational dates |
The Act and the Rules **must be read together**. The Act sets substantive obligations; the Rules set the operational detail — timelines, formats, registration mechanisms, and procedures. Gaps in either side are gaps in compliance.
Roles and definitions
| DPDPA term | Meaning | GDPR analogue | |---|---|---| | **Data Fiduciary** | Determines the purpose and means of processing personal data. The controller-equivalent. | Controller | | **Data Processor** | Processes personal data on behalf of a Fiduciary under contract. | Processor | | **Data Principal** | The natural person whose personal data is processed. For a child, the parent or lawful guardian; for a person with a disability, the lawful guardian. | Data Subject | | **Significant Data Fiduciary (SDF)** | A class of Data Fiduciary notified by the Central Government as having higher-risk processing. Carries additional obligations. | (Broader and stricter than GDPR's "large-scale" qualifier) | | **Consent Manager** | A registrable entity that manages consents on behalf of Data Principals — gives, manages, reviews, withdraws consent across multiple Fiduciaries. | (No direct GDPR analogue) | | **Personal data** | Any data about an individual who is identifiable by or in relation to such data. | Personal data (Article 4(1)) | | **Processing** | Wholly or partly automated operation/s on personal data — collection, storage, use, sharing, disclosure, erasure, destruction. | Processing | | **Personal data breach** | Any incident that compromises the confidentiality, integrity, or availability of personal data — covering unauthorised processing, accidental disclosure or sharing, alteration, destruction, and loss of access (see Section 2(u) of the Act for the authoritative wording). | Personal data breach |
DPDPA does **not** define "sensitive personal data" as a separate category (unlike GDPR Article 9 or India's earlier SPDI Rules 2011). All personal data is governed by the same baseline obligations, with intensified obligations for children's data (Section 9) and SDF processing (Section 10).
Territorial and material applicability (Section 3)
DPDPA applies to processing of **digital personal data**:
1. **Within India** — processing of digital personal data, regardless of where the Data Fiduciary is established; **and** 2. **Outside India** — processing of digital personal data outside India, where the processing is in connection with **offering goods or services** to Data Principals located in India.
Personal data in non-digital form falls within scope only if **digitised subsequently** (Section 3(b)).
DPDPA does **not** apply to:
- Personal data processed by an individual for **personal or domestic purposes**.
- Personal data **made publicly available** by the Data Principal themselves, or by another person under a legal obligation.
- Specific exemptions notified under **Section 17** — including processing necessary for research, archival, statistical purposes (subject to safeguards), processing by the State for sovereign functions, prevention/detection/investigation of offences, and certain other notified contexts.
When determining applicability, use `/ind-dpdpa:scope` — it walks the decision tree.
Data Fiduciary obligations (Section 8)
Every Data Fiduciary, whether SDF or not, owes the following baseline obligations:
| Obligation | Section | What it requires | |---|---|---| | Accuracy | 8(3) | Make reasonable efforts to ensure personal data is accurate and complete when used to make a de
Showing the first part of this file.
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Other skills on trust-center.
- /academic-research-companion
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing, feedback, and publication. Use this skill whenever the user shares a research idea, asks to "flesh out" a topic, wants sources
Open skill - /aws-inspector-expert
Expertise in evaluating AWS accounts for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret aws CLI output.
Open skill - /azure-inspector-expert
Expertise in evaluating Azure subscription findings from azure-inspector and mapping them to SCF controls.
Open skill - /crowdstrike-inspector-expert
Interpret CrowdStrike Falcon findings for sensor coverage, policy visibility, and host group scoping.
Open skill - /datadog-inspector-expert
Interpret datadog-inspector findings and translate Datadog monitoring, audit, log-retention, SSO, and RBAC results into GRC evidence and remediation.
Open skill - /drata-inspector-expert
Interpret drata-inspector findings generated from drata-cli workflows and turn Drata control, monitor, evidence, personnel, and integration posture into GRC action.
Open skill

