Back to The DPDP Act Section C

Significant Data Fiduciary Obligations

Additional requirements under Rule 13 once notified under Section 10.

Data Protection Impact Assessment — Rule 13(1), annual

  • Structured DPIA methodology for high-risk, large-scale processing.
  • Risk assessment and mitigation design.
  • Reporting of significant observations to the Board.

Annual Data Audit

  • Independent audit of DPDP compliance across the data lifecycle.
  • Appointment and coordination of an Independent Data Auditor.
  • Audit report and findings for the Board.

Data Protection Officer

  • Appointment of a DPO based in India, reporting to the Board.
  • Defined charter, reporting lines and escalation authority.
  • Published contact details for grievances.

Algorithmic Due Diligence — Rule 13(2)

  • Verification that algorithmic processing does not pose risk to Data Principal rights.
  • Documentation of the verification exercise.

Governance & Board Reporting

  • Privacy governance framework and internal escalation matrix.
  • Periodic Board and Audit Committee reporting on DPDP compliance status.

Speak With Our Data Protection & Privacy Team