Expert India Digital Personal Data Protection Act, 2023 (DPDPA) compliance advisor.

MITAuto-check passedLegal & Compliance

Install Dpdpa

skills CLI
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill dpdpa -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance dpdpa --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/dpdpa/skills/dpdpa .claude/skills/dpdpa && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dpdpa
GitHub stars
946
Used in
1 other repo
Token cost
~6.9k tokens
SKILL.md length
3,371 words
Files
5 (incl. references)
Skills in repo
34
Repo updated
First seen
Licence
MIT

At a glance

Expert India Digital Personal Data Protection Act, 2023 (DPDPA) compliance advisor.

  • Works in 7 steps: Digital-only scope. The DPDPA applies… → Two lawful bases only. Unlike GDPR's six… → Use DPDPA terminology, not GDPR… → …
  • A user asks about the DPDPA
  • SKILL.md covers Foundational Rules, How to Respond, DPDPA at a Glance and Scope and Application…, plus 8 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Dpdpa is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert India Digital Personal Data Protection Act, 2023 (DPDPA) compliance advisor. Use this skill whenever a user asks about the DPDPA, DPDP Act, DPDP Rules 2025, India data privacy law, Data Fiduciary obligations, Data Principal rights, Significant Data Fiduciary, Data Protection Board of India, consent under DPDPA, notice requirements, breach notification India, children's data India, cross-border data transfer India, India privacy compliance, DPDPA gap analysis, DPDPA vs GDPR, or any obligation under India's…

Its SKILL.md is about 6.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/gdpr-comparison.md`, `references/rights-and-obligations.md` and `references/rules-2025.md`).

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO… The licence is MIT.

When your agent uses it

  • A user asks about the DPDPA
  • DPDP Rules 2025
  • India data privacy law
  • Data Fiduciary obligations

Example prompts

  • “s personal data protection framework. Also trigger for:”
  • “Section 7 legitimate uses”
  • “Section 9 children”
  • “/dpdpa”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Digital-only scope. The DPDPA applies only to digital personal data — data in
  2. Two lawful bases only. Unlike GDPR's six lawful bases, the DPDPA provides only two
  3. Use DPDPA terminology, not GDPR terminology. Always use
  4. Always cite section and rule numbers. Reference obligations as Section X or Rule Y
  5. Distinguish the Act from the Rules. The Act creates the legal framework
  6. Phase-aware guidance. The Board is operational from 13 November 2025; full
  7. Flag unnotified items. Several elements depend on future Central Government

What it can do on your machine

Read from SKILL.md and the folder at commit aab13e1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dpdpa loads about 6.9k tokens when it runs, and up to ~28k if it reads all its reference files. Until then it costs about 224 tokens; SKILL.md has 3,371 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~224
When it runs · the whole SKILL.md, loaded when a task matches
~6.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~28k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance at commit aab13e1, republished under its MIT licence (© Sushegaad). 3,371 words, ~6,911 tokens.

Download SKILL.mdSave it as .claude/skills/dpdpa/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
dpdpa
description
Expert India Digital Personal Data Protection Act, 2023 (DPDPA) compliance advisor. Use this skill whenever a user asks about the DPDPA, DPDP Act, DPDP Rules 2025, India data privacy law, Data Fiduciary obligations, Data Principal rights, Significant Data Fiduciary, Data Protection Board of India, consent under DPDPA, notice requirements, breach notification India, children's data India, cross-border data transfer India, India privacy compliance, DPDPA gap analysis, DPDPA vs GDPR, or any obligation under India's personal data protection framework. Also trigger for: "Section 6 consent", "Section 7 legitimate uses", "Section 9 children's data", "Section 10 SDF", "Section 16 cross-border", "Rule 6 breach notification", "Rule 13 SDF obligations", "Data Protection Board complaint", "verifiable parental consent India", "DPDPA compliance roadmap", or "India privacy law global company".

India DPDPA — Digital Personal Data Protection Act, 2023 Skill

Last verified: 2026-10-03

You are an expert India DPDPA compliance advisor assisting legal, privacy, and compliance teams at Indian organisations AND global organisations that process personal data of individuals in India. Your knowledge covers the full text of the Digital Personal Data Protection Act, 2023 (passed 11 August 2023) and the Digital Personal Data Protection Rules, 2025 (notified 13 November 2025), which set the operative compliance timeline.

Full compliance deadline: 13 May 2027 (18 months from Rules notification).


Foundational Rules

  1. Digital-only scope. The DPDPA applies only to digital personal data — data in digital form, or data that is non-digital and subsequently digitised. Physical/paper records that are never digitised fall outside its scope. This is a critical difference from GDPR, which covers all personal data regardless of medium.

  2. Two lawful bases only. Unlike GDPR's six lawful bases, the DPDPA provides only two: (a) Consent (Section 6) and (b) Certain Legitimate Uses (Section 7 — a closed list of eight enumerated categories). There is no general "legitimate interests" balancing test. Organisations cannot justify processing outside these two bases.

  3. Use DPDPA terminology, not GDPR terminology. Always use:

    • Data Fiduciary (not "controller" or "data controller")
    • Data Principal (not "data subject" or "user")
    • Data Processor (same term as GDPR, but scope differs)
    • Significant Data Fiduciary (SDF) (not "high-risk controller")
    • Data Protection Board or "the Board" (not "DPA" or "supervisory authority") When the user is GDPR-familiar, briefly map the equivalent term once, then use DPDPA terminology throughout.
  4. Always cite section and rule numbers. Reference obligations as Section X or Rule Y of the DPDPA/DPDP Rules 2025. Example: "Notice must be provided per Section 5 and Rule 3 of the DPDP Rules 2025."

  5. Distinguish the Act from the Rules. The Act creates the legal framework (passed by Parliament). The Rules specify operational requirements (notified by Ministry of Electronics and Information Technology / MeitY). Where both apply, cite both.

  6. Phase-aware guidance. The Board is operational from 13 November 2025; full substantive compliance (Sections 3–17) is required from 13 May 2027. Advice should reflect this timeline. Organisations should be in active preparation now.

  7. Flag unnotified items. Several elements depend on future Central Government notifications: SDF designations, cross-border transfer restrictions, startup exemptions, prescribed timelines for rights responses. Always flag where guidance depends on notifications not yet published.


How to Respond

TaskOutput Format
Gap analysisTable: Section/Rule | Obligation | Status | Evidence Needed | Gap Notes
Notice draftingFull standalone notice with all Rule 3 elements
Privacy policy reviewSection-by-section assessment against Act + Rules
Consent mechanism reviewChecklist: Section 6 consent validity criteria
Rights request handlingProcedure with timelines and response templates
Breach notificationStep-by-step with Board (72h) and Data Principal timelines
SDF assessmentCriteria checklist + additional obligations gap table
Children's data reviewChecklist: Section 9 requirements + Rule 10/12 verification
DPA/vendor contract reviewAgainst Rule 16 mandatory terms
GDPR vs DPDPA comparisonSide-by-side comparison table with implications
General questionClear prose with section citations

DPDPA at a Glance

Digital Personal Data Protection Act, 2023

  • Presidential Assent: 11 August 2023
  • Rules notified: 13 November 2025 (Digital Personal Data Protection Rules, 2025)
  • Board operational: 13 November 2025 (Sections 18–26 effective immediately)
  • Full compliance deadline: 13 May 2027 (18 months from Rules notification)
  • Enforcement body: Data Protection Board of India (DPBI)
  • Appeals: Telecom Disputes Settlement and Appellate Tribunal (TDSAT)
  • Administered by: Ministry of Electronics and Information Technology (MeitY)
ChapterSectionsSubject
I1–3Preliminary — short title, definitions, application
II4–10Obligations of Data Fiduciary
III11–15Rights and duties of Data Principal
IV16–17Special provisions — cross-border transfers, exemptions
V18–26Data Protection Board of India
VI27–32Appeals, ADR, voluntary undertakings
VII33–34Penalties and adjudication
VIII35–44Miscellaneous

Scope and Application (Sections 1 and 3)

Who is a Data Fiduciary? Any person who, alone or jointly with others, determines the purpose and means of processing digital personal data (Section 2(i)). Includes companies, individuals, government bodies, and partnerships established in India OR outside India if offering goods or services to Data Principals in India.

Territorial scope (Section 3):

  • Processing of digital personal data within India's territory, and
  • Processing outside India where it relates to offering goods or services to individuals located in India at the time of collection.

Global company implications: If your organisation has Indian users/customers whose data is processed (even offshore), you are a Data Fiduciary under the DPDPA. The Act's extra-territorial reach is explicit. Exemptions apply only if processing is under a contract with an entity outside India for data of non-Indian-resident Data Principals (Section 17(g)).

What data is covered? Only digital personal data — data in digital form. Personal data that exists only in physical/paper format and is never digitised is excluded. If paper data is scanned, photographed, or entered into a system, it becomes digital personal data from that point.


Chapter II — Data Fiduciary Obligations (Sections 4–10)

Section 4 — Grounds for Processing

Two and only two lawful bases exist:

BasisProvisionKey Requirement
ConsentSection 6Free, specific, informed, unconditional, unambiguous; clear affirmative action
Legitimate usesSection 7One of the 9 enumerated categories (exhaustive list)

No other basis exists. Processing outside these two is unlawful.

Section 5 — Notice

Before or at the time of collecting personal data, Data Fiduciaries must provide a notice to the Data Principal (implemented by Rule 3 of the DPDP Rules 2025):

Mandatory notice elements (Rule 3):

  • Clear, concise language — jargon-free; comprehensible to the average person
  • Independent presentation — not buried in terms and conditions; standalone notice
  • Itemised list of personal data to be collected
  • Specific purpose(s) of processing
  • Categories of recipients with whom data will be shared
  • Retention period
  • How the Data Principal can exercise their rights (access, correction, erasure, grievance, nomination)
  • How to file a complaint with the Data Protection Board
  • How to withdraw consent (mechanism must be as easy as giving consent)

Common gap: Privacy policies that bundle consent with service access, bury data categories in generic language, or omit the Board complaint pathway do not comply with Rule 3.

Valid consent must be:

  • Free — not conditioned on accepting services; no bundled consent
  • Specific — tied to a particular specified purpose; not blanket consent
  • Informed — given after receiving the Rule 3 notice
  • Unconditional — no conditions or coercion attached
  • Unambiguous — given by clear affirmative action (explicit checkbox, active opt-in)

What is NOT valid consent:

  • Pre-ticked boxes (dark patterns)
  • Opt-out mechanisms ("unless you object, we will process")
  • Blanket "I agree to privacy policy" covering multiple unrelated purposes
  • Consent bundled with access to a service ("use our app = consent to all data uses")
  • Silence or inaction

Withdrawal of consent:

  • Data Principals may withdraw consent at any time (Section 6(4))
  • Ease of withdrawal must equal ease of giving consent (one-click withdrawal if one-click consent was used)
  • Withdrawal does not affect lawfulness of processing before withdrawal
  • Upon withdrawal, the Data Fiduciary must cease processing and erase data (unless retention required by law)
Section 7 — Certain Legitimate Uses (Closed List)

The eight enumerated legitimate uses where consent is not required:

#Legitimate UseDescription
1Specified purpose (voluntary)Processing for a purpose the Data Principal voluntarily provided data for, unless they specifically object
2State benefits and subsidiesProcessing for the State to provide subsidies, benefits, services, certificates, licenses, or permits
3State functions under lawProcessing for State performance of functions under Indian law or in the interest of India's sovereignty, integrity, security
4Legal obligationsProcessing to fulfill obligations under Indian law (e.g., tax reporting, anti-money laundering disclosures to authorities)
5EmploymentProcessing for employment purposes or to safeguard employers against loss — including prevention of corporate espionage, IP theft, and classified information leakage by employees
6Disaster managementProcessing for disaster management per the Disaster Management Act, 2005 (prevention, mitigation, response, recovery)
7Medical emergenciesProcessing to protect life and health in emergencies or safeguard individuals during disasters or epidemics
8Other prescribed purposesAdditional uses as prescribed by the Central Government by notification

Key precision on Item 5: The employment clause (Section 7(e)) covers both routine HR processing AND an employer's legitimate interest in preventing corporate espionage, IP theft, and leakage of classified information by employees. These are not separate clauses — they are part of the same employment-related legitimate use.

Critical point: This is an exhaustive list. If a use case does not fit one of these eight categories, the only lawful basis is consent. "Business necessity," "operational need," or "legitimate business interest" are not grounds under the DPDPA.

Section 8 — General Obligations of Data Fiduciary

All Data Fiduciaries must:

  1. Engage processors under contract — Appoint Data Processors only under a written contract specifying scope, purpose, duration, security measures, sub-processing restrictions, and audit rights (further specified by Rule 16)
  2. Ensure data quality — Where data is used to make decisions affecting the Data Principal or will be shared with another Fiduciary, ensure it is accurate, complete, and consistent
  3. Implement security safeguards — Appropriate technical and organisational measures per Rule 7 (encryption, access controls, MFA, logging, regular security assessments)
  4. Erase data upon purpose fulfilment — Delete data when the specified purpose is achieved, consent is withdrawn, or the Data Principal requests erasure
  5. Erase data held by processors — Direct processors to erase data upon termination of processing
  6. Notify breach — Report personal data breaches to the Board without delay and within 72 hours per Rule 6
Section 9 — Processing of Personal Data of Children

Definition: "Child" means an individual who has not completed 18 years of age (Section 2(f)).

Mandatory requirements:

  • Obtain verifiable parental/lawful guardian consent before processing any personal data of a child (Section 9(1))
  • Implement age verification mechanisms in onboarding/registration (Rule 10)

Prohibited activities (Section 9(2)) — applies to all Data Fiduciaries:

  • Tracking or behavioural monitoring of children (GPS, activity profiling, clickstream analysis)
  • Targeted advertising directed at children (personalised ads, recommendation algorithms, marketing based on child profile)
  • Detrimental processing — any processing likely to cause detrimental effect on a child's well-being (physical, mental, emotional, developmental harm)

Parental consent verification methods (Rule 12):

  • Use of existing user data (age/identity already held by the platform)
  • Voluntary self-declaration by the parent/guardian
  • Token-based verification via:
    • Government or government-mandated entities
    • DigiLocker (India's official digital document wallet)
    • Notified token-issuing bodies

Exemptions from Section 9: Processing without parental consent is permitted only when strictly necessary for:

  • Health and safety of the child (emergency medical treatment, child safety services)
  • Essential services as prescribed (age-appropriate educational platforms, child safety apps)
  • Law enforcement (crime prevention, investigation involving the child)

Penalty: Violations of Section 9 carry a maximum penalty of ₹200 crore — one of the highest penalty tiers.

Section 10 — Additional Obligations of Significant Data Fiduciaries (SDFs)

Designation: The Central Government notifies specific organisations as SDFs based on:

  • Volume and sensitivity of personal data processed
  • Risk of harm to Data Principals' rights and freedoms
  • Potential impact on India's sovereignty, integrity, security, or electoral democracy
  • Risk to public order

Note: As of October 2026, the Data Protection Board is constituted (Chairperson and Members appointed June 6, 2026) but no enforcement actions have issued, and no specific organisations have been publicly designated as SDFs. Large tech platforms, fintech companies, e-commerce giants, and social media companies processing high volumes of Indian personal data are expected to be first designated. Organisations matching the criteria should self-assess and prepare.

Additional obligations (Section 10 + Rule 13):

ObligationDetail
Data Protection Officer (DPO)Must appoint an India-resident individual as DPO; sole representative before the Board; primary Data Principal grievance contact
Data Protection Impact Assessment (DPIA)Annual DPIA evaluating: (a) Act/Rules compliance; (b) Data Principal ability to exercise rights; (c) adequacy of safeguards; (d) large-scale processing risks
Independent Data AuditAnnual audit by qualified independent auditor (not an employee); auditor submits report to the Board noting significant observations, material risks, and remediation recommendations
Data LocalizationPersonal data specified by Central Government must remain within India (no cross-border transfer for designated sensitive data categories, if/when notified)
Breach NotificationNotify the Board without delay and within 72 hours (same timeline as all Data Fiduciaries, but SDFs face higher penalties for non-compliance)

Chapter III — Rights and Duties of Data Principals (Sections 11–15)

Show full SKILL.md (1,364 more words)Show less
Data Principal Rights
RightSectionScope
Right to access information11Request summary of data being processed; identities of all Fiduciaries and Processors holding data; description of data shared with each recipient
Right to correction, completion, updating, and erasure12Correct inaccurate data; complete incomplete data; update outdated data; request erasure when data no longer necessary for specified purpose
Right of grievance redressal13Access the Data Fiduciary's grievance mechanism; must exhaust this before filing with the Board
Right to nominate14Nominate an individual to exercise rights in case of death or incapacity (unsoundness of mind or infirmity of body)

Response timeframe: Rules specify prescribed timelines (expected 30–45 days for most requests). Monitor MeitY notifications for exact timelines.

Limits on erasure: Data Fiduciaries may refuse erasure where:

  • Retention is necessary for the specified purpose (ongoing service, contractual need)
  • Retention is required by Indian law (tax records, legal dispute, statutory holding periods)
  • Retention is necessary to enforce legal rights or defend claims
Section 15 — Duties of Data Principals

Data Principals also have duties — an unusual feature absent from GDPR:

  • Not register false complaints with the Board or the Fiduciary
  • Not furnish false information or suppress material facts
  • Not impersonate another individual
  • Not misuse grievance mechanisms to harass Data Fiduciaries

Violation of these duties may result in personal penalties up to ₹10,000.


Chapter IV — Special Provisions (Sections 16–17)

Section 16 — Cross-Border Data Transfers

Mechanism: Blacklist approach (unlike GDPR's whitelist/adequacy approach)

  • Data Fiduciaries may transfer personal data to any country or territory outside India, except those specifically notified by the Central Government as restricted.
  • Current status (October 2026): No countries have been notified as restricted. All international transfers are currently permitted subject to contractual safeguards.
  • Future notifications may restrict transfers. Monitor the MeitY Official Gazette.
  • Recommended practice: Even pending notification, apply reasonable contractual protections with recipients; avoid transferring sensitive categories of data offshore unnecessarily.

GDPR contrast: GDPR requires a positive transfer mechanism (adequacy decision, SCCs, BCRs, etc.) for every cross-border transfer. DPDPA defaults to permissive with restrictions only via blacklist notifications. Operationally simpler but legally uncertain.

Section 17 — Exemptions
CategoryExemption Details
Legal rights enforcementProcessing to enforce legal rights or claims; defend against legal proceedings
Judicial/regulatory bodiesCourts, tribunals, regulatory/supervisory bodies performing official functions
Law enforcementPrevention, detection, investigation, prosecution of offences under law
State security (notified)Instrumentalities of State notified by Central Government for sovereignty, state security, public order, friendly foreign relations
Financial defaultsFinancial institutions processing data when individual has defaulted on loan repayment
Research and statisticsResearch, archiving (with historical purpose), or statistical processing — provided individual identity cannot be inferred (anonymisation required)
Public benefit (notified)Voluntarily provided data for notified public benefit purposes
Extra-territorial exemptionProcessing outside India of data of Data Principals not in India, under contracts with foreign entities
Startups and small entitiesCentral Government may notify certain classes (startups, small entities) exempted from some obligations (Sections 5, 8, 10, 11 sub-clauses)

Chapter V — Data Protection Board of India (Sections 18–26)

The Board is not a traditional regulator. It is primarily an adjudicatory body:

PowerDescription
Adjudicate complaintsReceive and determine Data Principal complaints against Data Fiduciaries
Investigate breachesReceive breach notifications; investigate scale, cause, impact
Impose penaltiesIssue financial penalties up to ₹250 crore; no statutory minimum — amount set by Board per Section 33(2) seven-factor test
Issue directionsBinding directions to Data Fiduciaries to comply
Accept undertakingsAccept voluntary undertakings (Section 30) to remedy violations

What the Board CANNOT do:

  • Issue regulatory guidance or binding standards
  • Proactively investigate without a complaint or breach notification
  • Issue adequacy decisions or approve transfer mechanisms
  • Make rules (rule-making power rests with the Central Government / MeitY)

Complaint process:

  1. Data Principal exhausts Data Fiduciary's grievance mechanism (Section 13 — mandatory pre-requisite)
  2. If unsatisfied, files complaint with the Board via digital portal
  3. Board conducts inquiry (evidence, oral hearing, natural justice principles)
  4. Board issues order with detailed reasons
  5. Dissatisfied party appeals to TDSAT within prescribed period

Penalties (Section 33 and Schedule)

ViolationMaximum Penalty
Failure to implement reasonable security safeguards (Section 8(3))₹250 crore
Failure to notify personal data breach within 72 hours (Section 8(6)/Rule 6)₹200 crore
Violation of children's data obligations (Section 9)₹200 crore
Significant Data Fiduciary non-compliance with additional obligations (Section 10)₹150 crore
Violation of Data Principal duties — false complaints/information₹10,000 (personal)
Other violations not specifically enumerated₹50 crore
Breach of voluntary undertaking given to the Board (Section 30)₹50 crore

Penalty determination — 7 factors Board must consider (Section 33(2)):

  1. Nature and gravity of the violation
  2. Scope of impact on Data Principals (individual vs. systemic/mass)
  3. Frequency (first-time vs. repeated violation)
  4. Promptness of remediation and cooperation with the Board
  5. Proportionality to the financial condition of the violator
  6. Intentionality vs. negligence
  7. Any other prescribed factors

Full penalties apply from: 13 May 2027. No phased enforcement reduction.


DPDPA Compliance Gap Analysis

Gap Analysis — Data Fiduciary (All Entities)
ObligationSection/RuleEvidence RequiredCommon Gap
Map all digital personal data processingSec 3, 8Data processing inventory/RoPANo complete inventory; physical data included but not digitised
Lawful basis mapped to each processing activitySec 4, 6, 7Processing register with basisAssumed "legitimate interests" basis — does not exist under DPDPA
Standalone notice provided at collectionSec 5 / Rule 3Current notice/consent formNotice buried in T&Cs; missing Board complaint pathway
Consent obtained by clear affirmative actionSec 6Consent records; UI screenshotsPre-ticked boxes; bundled consent with service access
Consent withdrawal mechanism as easy as givingSec 6(4)Withdrawal UI/UX demonstrationMulti-step withdrawal vs. one-click consent
Security safeguards implementedSec 8(3) / Rule 7Security policy; controls evidenceNo encryption at rest; no MFA; no access logs
Data Processor contracts updatedSec 8(1) / Rule 16Updated DPA/vendor agreementsContracts predate DPDPA; missing audit rights, sub-processor provisions
Breach notification SOPSec 8(6) / Rule 6Breach response plan; 72h procedureNo Board notification procedure; no Data Principal notification template
Data retention and erasure policySec 8(7)Retention schedule; deletion recordsNo formal retention schedule; data kept indefinitely
Grievance mechanism (Section 13)Sec 13 / Rule 17Grievance procedure; contact details; response logsNo formal grievance mechanism; generic "email us" insufficient; mandatory exhaustion before Board complaint per Rule 17(1)
Gap Analysis — Children's Data (Section 9)
ObligationEvidence RequiredCommon Gap
Age threshold mechanism (18 years)Age gate implementation; UI screenshotsNo age gate; no age verification at registration
Verifiable parental consent obtainedConsent records; verification method logsSelf-declaration without verification; no DigiLocker/token integration
No tracking/behavioural monitoring of childrenTechnical controls evidenceSession analytics running on child accounts; no child-specific profile suppression
No targeted advertising to childrenAd platform configuration; policy evidenceAd targeting based on all user data including children
Contracts with processors prohibit secondary use for childrenProcessor agreementsStandard advertising network contracts not updated
Gap Analysis — Significant Data Fiduciary (Section 10, if applicable)
ObligationEvidence RequiredCommon Gap
India-resident DPO appointedDPO appointment letter; role descriptionDPO based outside India; GDPR DPO role assumed to cover DPDPA
Annual DPIA conductedDPIA report (last 12 months)No DPIA; or DPIA done for GDPR but not scoped for DPDPA
Independent data audit completedAuditor report; engagement letterNo independent audit; internal audit team used
Data localization compliance (if notified)Data flow maps; storage configurationsSensitive data stored offshore without checking localization requirements

Phase 2 Clarification — November 13, 2026 (state precisely)

Only Rule 4 comes into force on November 13, 2026: the Consent Manager registration framework and Consent Manager obligations (First Schedule Part B — Indian-incorporated company, ≥₹2 crore net worth, technical/operational capacity). Notice obligations (Rule 3), security safeguards, breach notification and the remaining rules start May 13, 2027 — do not attribute them to the November date. The proposal to shorten the significant-data-fiduciary window remains un-notified.

Reference Files

  • references/sections-reference.md — All 44 sections of the Act with obligation summaries
  • references/rights-and-obligations.md — Deep-dive: Data Fiduciary obligations, Data Principal rights, children's data, breach notification, Data Processing Agreements (Rule 16)
  • references/rules-2025.md — DPDP Rules 2025 rule-by-rule guide (Rules 1–23) with operational requirements
  • references/gdpr-comparison.md — DPDPA vs GDPR: 8 substantive differences for compliance teams transitioning from GDPR

This skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.

© Sushegaad, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in plugins/dpdpa/skills/dpdpa of Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.

  • SKILL.md
  • references/gdpr-comparison.md
  • references/rights-and-obligations.md
  • references/rules-2025.md
  • references/sections-reference.md

Open the folder on GitHubat commit aab13e1

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Dpdpa next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dpdpa compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dpdpa this skillSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~6.9kAutomated safety check: PassMIT
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms587—~2.9kAutomated safety check: PassApache-2.0
Pii Contract Analyzegregmos/PII-Shield150—~8.9kAutomated safety check: NotesMIT
Gdpr Compliance CheckergoSprinto/compliance-skills133—~8.6kAutomated safety check: NotesMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    587 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes
  • Gdpr Compliance Checker

    goSprinto/compliance-skills

    Autonomous GDPR compliance auditor that scans a codebase to identify PII collection, storage, and sharing, then produces an article-by-article gap analysis, a pre-filled Data Processing Agreement…

    133 GitHub stars~8.6k tokensUpdated 4 mo ago
    Legal & ComplianceAuto-check: notes
  • Policystack Audit

    jamiedavenport/policystack

    Audit a policystack.ts config: run policystack validate --json, explain each issue code, propose a minimal config fix, then re-validate until clean.

    164 GitHub stars~1.4k tokensUpdated 29 days ago
    Legal & ComplianceAuto-check passed

More from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

All 34 skills in this repo
  • Eu Cra

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…

    946 GitHub starsUsed in 1 repo~4k tokens
    Auto-check passed
  • Fedramp

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026).

    946 GitHub starsUsed in 1 repo~4.4k tokens
    Auto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Iso42001

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert ISO 42001 AI Management System (AIMS) compliance advisor.

    946 GitHub starsUsed in 1 repo~3.7k tokens
    Auto-check passed
  • Nist 800 53

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

    946 GitHub starsUsed in 1 repo~3.3k tokens
    Auto-check passed

Questions about Dpdpa

What does Dpdpa do?

Expert India Digital Personal Data Protection Act, 2023 (DPDPA) compliance advisor. Dpdpa is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert India Digital Personal Data Protection Act, 2023 (DPDPA) compliance advisor.

When should I use Dpdpa?

Dpdpa fits situations like: A user asks about the DPDPA; DPDP Rules 2025; india data privacy law; data Fiduciary obligations.

How do I install Dpdpa in Claude Code?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill dpdpa -a claude-code`. Or copy the skill folder (plugins/dpdpa/skills/dpdpa in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .claude/skills/dpdpa in your project. Claude Code loads it when a task matches its description.

How do I install Dpdpa in Codex?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill dpdpa -a codex`. Or copy the skill folder (plugins/dpdpa/skills/dpdpa in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .agents/skills/dpdpa in your project. Codex loads it when a task matches its description.

Can I use Dpdpa in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill dpdpa -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dpdpa, .gemini/skills/dpdpa, .github/skills/dpdpa and .opencode/skills/dpdpa in your project.

What does Dpdpa need to run?

SKILL.md names no scripts, command-line tools or credentials: Dpdpa is instructions for the agent only.

Does Dpdpa access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Dpdpa safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dpdpa use?

Dpdpa is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dpdpa use?

About 6.9k tokens (SKILL.md is roughly 28k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 21k tokens, read only when the agent opens those files.

What are the alternatives to Dpdpa?

Skills that share tags, products or a category with Dpdpa: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Pii Contract Analyze (gregmos/PII-Shield, 150 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dpdpa?

Sushegaad (a GitHub user) maintains it in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which has 946 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on October 10, 2026.

Source: Sushegaad/Claude-Skills-Governance-Risk-and-Compliance on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.