academic-research-comp…
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing,…
India DPDPA expert for the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025. Covers Data Fiduciary obligations, Data Principal rights, Significant Data Fiduciary regime, Consent Manager, breach notification (72-hour), cross-border transfer regime, children's
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill ind-dpdpa-expert --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/ind-dpdpa-expertContext preview
The summary Claude sees to decide when to auto-load this skill.
India DPDPA expert for the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025. Covers Data Fiduciary obligations, Data Principal rights, Significant Data Fiduciary regime, Consent Manager, breach notification (72-hour), cross-border transfer regime, children's
name: ind-dpdpa-expert description: India DPDPA expert for the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025. Covers Data Fiduciary obligations, Data Principal rights, Significant Data Fiduciary regime, Consent Manager, breach notification (72-hour), cross-border transfer regime, children's data, sectoral overlap with RBI / SEBI / IRDAI / TRAI / CERT-In / ABDM, and Data Protection Board enforcement. allowed-tools: Read, Glob, Grep, Write
Deep working knowledge of the **Digital Personal Data Protection Act, 2023** (DPDPA) and the **Digital Personal Data Protection Rules, 2025** (DPDP Rules), as enforced by the **Data Protection Board of India** (DPB) under the Ministry of Electronics and Information Technology (MeitY).
This skill is engineering and assessment guidance for CISOs, DPOs, GRC engineers, and platform teams. It is **not** legal advice. Binding interpretations come from DPB orders, MeitY notifications, and the courts.
Invoke when the user is:
| Field | Value | |---|---| | Statute | Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) | | Operational rules | Digital Personal Data Protection Rules, 2025 (notified November 2025) | | Regulator | Data Protection Board of India (DPB) under MeitY | | Territorial scope | Processing within India; processing outside India in connection with offering goods or services to Data Principals located in India | | Material scope | Digital personal data — personal data in digital form, or in non-digital form digitised subsequently | | SCF framework ID | `apac-ind-dpdpa-2023` | | SCF coverage | 41 SCF controls map to 96 DPDPA control identifiers | | Status (as of 2026) | Act in force; Rules notified November 2025 with phased operational dates |
The Act and the Rules **must be read together**. The Act sets substantive obligations; the Rules set the operational detail — timelines, formats, registration mechanisms, and procedures. Gaps in either side are gaps in compliance.
| DPDPA term | Meaning | GDPR analogue | |---|---|---| | **Data Fiduciary** | Determines the purpose and means of processing personal data. The controller-equivalent. | Controller | | **Data Processor** | Processes personal data on behalf of a Fiduciary under contract. | Processor | | **Data Principal** | The natural person whose personal data is processed. For a child, the parent or lawful guardian; for a person with a disability, the lawful guardian. | Data Subject | | **Significant Data Fiduciary (SDF)** | A class of Data Fiduciary notified by the Central Government as having higher-risk processing. Carries additional obligations. | (Broader and stricter than GDPR's "large-scale" qualifier) | | **Consent Manager** | A registrable entity that manages consents on behalf of Data Principals — gives, manages, reviews, withdraws consent across multiple Fiduciaries. | (No direct GDPR analogue) | | **Personal data** | Any data about an individual who is identifiable by or in relation to such data. | Personal data (Article 4(1)) | | **Processing** | Wholly or partly automated operation/s on personal data — collection, storage, use, sharing, disclosure, erasure, destruction. | Processing | | **Personal data breach** | Any incident that compromises the confidentiality, integrity, or availability of personal data — covering unauthorised processing, accidental disclosure or sharing, alteration, destruction, and loss of access (see Section 2(u) of the Act for the authoritative wording). | Personal data breach |
DPDPA does **not** define "sensitive personal data" as a separate category (unlike GDPR Article 9 or India's earlier SPDI Rules 2011). All personal data is governed by the same baseline obligations, with intensified obligations for children's data (Section 9) and SDF processing (Section 10).
DPDPA applies to processing of **digital personal data**:
1. **Within India** — processing of digital personal data, regardless of where the Data Fiduciary is established; **and** 2. **Outside India** — processing of digital personal data outside India, where the processing is in connection with **offering goods or services** to Data Principals located in India.
Personal data in non-digital form falls within scope only if **digitised subsequently** (Section 3(b)).
DPDPA does **not** apply to:
When determining applicability, use `/ind-dpdpa:scope` — it walks the decision tree.
Every Data Fiduciary, whether SDF or not, owes the following baseline obligations:
| Obligation | Section | What it requires | |---|---|---| | Accuracy | 8(3) | Make reasonable efforts to ensure personal data is accurate and complete when used to make a de
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing,…
Expertise in evaluating AWS accounts for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret aws CLI output.
Use when interpreting AWS Secrets Manager connector output, deciding between inspector and retrieve modes, drafting SCF-mapped controls for rotation / KMS /…
Expertise in evaluating Azure subscription findings from azure-inspector and mapping them to SCF controls.
Interpret CrowdStrike Falcon findings for sensor coverage, policy visibility, and host group scoping.
Interpret datadog-inspector findings and translate Datadog monitoring, audit, log-retention, SSO, and RBAC results into GRC evidence and remediation.