DPDPA obligation-control-evidence
matrix
A DPDPA obligation becomes operational only when it is assigned to an owner, implemented through a repeatable control, evidenced through contemporaneous records and tested against a defined standard. This matrix helps Data Fiduciaries convert statutory requirements into an implementation and assurance system.
How should a Data Fiduciary convert DPDPA obligations into operational controls?
Begin with the applicable statutory obligation and the processing event it governs. Define the preventive or responsive control, accountable owner, frequency, system dependency, evidence generated, validation method and remediation trigger. A policy statement alone is not an operating control.
What evidence should a company retain for DPDPA compliance?
Evidence should demonstrate both design and operation. Depending on the obligation, this may include approved notices, consent and withdrawal records, processing and processor registers, request logs, retention and deletion records, security testing, incident timelines, contracts, training, Board reporting and remediation closure.
Obligation → Control → Owner → Evidence → Validation
Legal-status labels: Every row marks whether the proposition is mandatory law, a regulatory expectation or a voluntary implementation practice.
| Obligation | Operating Control | Owner | Evidence | Validation | Status |
|---|---|---|---|---|---|
| Notice — Section 5 / Rule 3 | Purpose-specific notice governance, versioning and deployment control | Legal + Product | Notice register, approvals, deployed versions | Sample collection points against approved notice | Mandatory |
| Consent — Section 6 / Rule 3 | Granular collection, proof, withdrawal and downstream stop-processing | Product + Privacy | Consent receipts, version/timestamp, withdrawal and propagation logs | Journey and withdrawal test | Mandatory |
| Certain legitimate uses — Section 7 | Purpose-specific legal-basis decision and use limitation | Legal + Process Owner | Assessment, approval and processing register | Revalidate facts and purpose | Mandatory |
| Processor engagement — Section 8(2) | Valid contract, instructions, diligence and monitoring | Procurement + Legal | Processor register, contract, assessment and reviews | Contract and operating sample | Mandatory |
| Security safeguards — Section 8(5) / Rule 6 | Risk-based organisational and technical safeguard programme | CISO + System Owner | Access, encryption, resilience, testing and incident records | Control test and remediation closure | Mandatory |
| Breach — Section 8(6) / Rule 7 | Detection, triage, escalation, legal decision and communication protocol | Incident Lead + Legal | Incident timeline, decision record and notifications | Tabletop exercise and event review | Mandatory |
| Erasure — Section 8(7) / Rule 8 | Purpose-linked retention, withdrawal response, legal holds and verified deletion | Data Owner + IT | Retention schedule, deletion logs and exceptions | System deletion sample | Mandatory |
| Contact and grievance — Sections 8(9), 13 / Rules 9, 14 | Published contact, intake, routing, escalation and closure | Grievance Officer | Request/grievance register and responses | Mystery-shopper or workflow test | Mandatory |
| Data Principal rights — Sections 11–14 / Rule 14 | Identity check, request decision, correction/erasure and nomination workflow | Privacy Operations | Requests, decisions, fulfilment and closure | Case-file sample | Mandatory |
| Children / guardian — Section 9 / Rules 10–12 | Age/relationship assessment and verifiable consent where applicable | Product + Legal | Verification record, consent and exception basis | Journey and exception test | Mandatory |
| SDF — Section 10 / Rule 13 | DPO, independent audit, DPIA and due-diligence controls where notified/applicable | Board + DPO | Appointments, DPIA, audit, due-diligence and remediation | Independent review | Mandatory (if notified) |
| Cross-border — Section 16 / Rule 15 | Transfer inventory, destination monitoring and government-requirement response | Privacy + Legal | Transfer map, contracts, decisions and change log | Destination and dependency review | Mandatory |
Need an Editable Evidence Register?
An editable workbook with fields for applicability, business process, control description, owner, frequency, system, evidence location, test result, issue, remediation, due date, residual risk and reviewer is available. Submit your details below to request access.
Request Editable WorkbookRequest the Editable Evidence Workbook
Provide your details to receive the customisable obligation-control-evidence workbook with full field architecture.
Request Evidence Workbook
Submit your details and we will send the editable workbook.
Source and legal review basis: AMLEGALS DPDPA Implementation Centre | Digital Personal Data Protection Act, 2023 | Digital Personal Data Protection Rules, 2025 and applicable corrigendum/commencement notification | Legally reviewed by AMLEGALS Data Privacy Practice on 27 July 2026.
