Skip to content

/ind-dpdpa-expert

India DPDPA expert for the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025. Covers Data Fiduciary obligations, Data Principal rights, Significant Data Fiduciary regime, Consent Manager, breach notification (72-hour), cross-border transfer regime, children's

shell
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill ind-dpdpa-expert --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
  • You can call itInvoke it directly when you want it.
  • Slash command/ind-dpdpa-expert
How auto-invocation works

Context preview

The summary Claude sees to decide when to auto-load this skill.

India DPDPA expert for the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025. Covers Data Fiduciary obligations, Data Principal rights, Significant Data Fiduciary regime, Consent Manager, breach notification (72-hour), cross-border transfer regime, children's

SKILL.md

ind-dpdpa-expert.SKILL.md
name: ind-dpdpa-expert
description: India DPDPA expert for the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025. Covers Data Fiduciary obligations, Data Principal rights, Significant Data Fiduciary regime, Consent Manager, breach notification (72-hour), cross-border transfer regime, children's data, sectoral overlap with RBI / SEBI / IRDAI / TRAI / CERT-In / ABDM, and Data Protection Board enforcement.
allowed-tools: Read, Glob, Grep, Write

India DPDPA Expert

Deep working knowledge of the **Digital Personal Data Protection Act, 2023** (DPDPA) and the **Digital Personal Data Protection Rules, 2025** (DPDP Rules), as enforced by the **Data Protection Board of India** (DPB) under the Ministry of Electronics and Information Technology (MeitY).

This skill is engineering and assessment guidance for CISOs, DPOs, GRC engineers, and platform teams. It is **not** legal advice. Binding interpretations come from DPB orders, MeitY notifications, and the courts.

When to invoke this skill

Invoke when the user is:

  • Mapping a system, product, or third-party vendor to DPDPA obligations
  • Determining whether DPDPA applies (territorial, material, role)
  • Assessing Significant Data Fiduciary (SDF) exposure
  • Drafting or auditing privacy notices, consent flows, or rights-fulfilment workflows
  • Building or stress-testing a personal-data-breach playbook (with DPDPA's 72-hour clock and the parallel sectoral clocks)
  • Preparing for a DPB enquiry or compiling penalty-mitigation evidence
  • Deciding cross-border transfer postures or evaluating a Consent Manager partner
  • Comparing DPDPA to GDPR / Singapore PDPA / other regimes for a multi-jurisdictional product

Framework identity

| Field | Value | |---|---| | Statute | Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) | | Operational rules | Digital Personal Data Protection Rules, 2025 (notified November 2025) | | Regulator | Data Protection Board of India (DPB) under MeitY | | Territorial scope | Processing within India; processing outside India in connection with offering goods or services to Data Principals located in India | | Material scope | Digital personal data — personal data in digital form, or in non-digital form digitised subsequently | | SCF framework ID | `apac-ind-dpdpa-2023` | | SCF coverage | 41 SCF controls map to 96 DPDPA control identifiers | | Status (as of 2026) | Act in force; Rules notified November 2025 with phased operational dates |

The Act and the Rules **must be read together**. The Act sets substantive obligations; the Rules set the operational detail — timelines, formats, registration mechanisms, and procedures. Gaps in either side are gaps in compliance.

Roles and definitions

| DPDPA term | Meaning | GDPR analogue | |---|---|---| | **Data Fiduciary** | Determines the purpose and means of processing personal data. The controller-equivalent. | Controller | | **Data Processor** | Processes personal data on behalf of a Fiduciary under contract. | Processor | | **Data Principal** | The natural person whose personal data is processed. For a child, the parent or lawful guardian; for a person with a disability, the lawful guardian. | Data Subject | | **Significant Data Fiduciary (SDF)** | A class of Data Fiduciary notified by the Central Government as having higher-risk processing. Carries additional obligations. | (Broader and stricter than GDPR's "large-scale" qualifier) | | **Consent Manager** | A registrable entity that manages consents on behalf of Data Principals — gives, manages, reviews, withdraws consent across multiple Fiduciaries. | (No direct GDPR analogue) | | **Personal data** | Any data about an individual who is identifiable by or in relation to such data. | Personal data (Article 4(1)) | | **Processing** | Wholly or partly automated operation/s on personal data — collection, storage, use, sharing, disclosure, erasure, destruction. | Processing | | **Personal data breach** | Any incident that compromises the confidentiality, integrity, or availability of personal data — covering unauthorised processing, accidental disclosure or sharing, alteration, destruction, and loss of access (see Section 2(u) of the Act for the authoritative wording). | Personal data breach |

DPDPA does **not** define "sensitive personal data" as a separate category (unlike GDPR Article 9 or India's earlier SPDI Rules 2011). All personal data is governed by the same baseline obligations, with intensified obligations for children's data (Section 9) and SDF processing (Section 10).

Territorial and material applicability (Section 3)

DPDPA applies to processing of **digital personal data**:

1. **Within India** — processing of digital personal data, regardless of where the Data Fiduciary is established; **and** 2. **Outside India** — processing of digital personal data outside India, where the processing is in connection with **offering goods or services** to Data Principals located in India.

Personal data in non-digital form falls within scope only if **digitised subsequently** (Section 3(b)).

DPDPA does **not** apply to:

  • Personal data processed by an individual for **personal or domestic purposes**.
  • Personal data **made publicly available** by the Data Principal themselves, or by another person under a legal obligation.
  • Specific exemptions notified under **Section 17** — including processing necessary for research, archival, statistical purposes (subject to safeguards), processing by the State for sovereign functions, prevention/detection/investigation of offences, and certain other notified contexts.

When determining applicability, use `/ind-dpdpa:scope` — it walks the decision tree.

Data Fiduciary obligations (Section 8)

Every Data Fiduciary, whether SDF or not, owes the following baseline obligations:

| Obligation | Section | What it requires | |---|---|---| | Accuracy | 8(3) | Make reasonable efforts to ensure personal data is accurate and complete when used to make a de

Read more
Read it on GitHub ↗

Showing the first part of this file.

Ships withtrust-center

Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.

Get the whole plugin, auto-invoked