C15t
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
Expert India Digital Personal Data Protection Act, 2023 (DPDPA) compliance advisor.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill dpdpa -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance dpdpa --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/dpdpa/skills/dpdpa .claude/skills/dpdpa && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dpdpa" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/dpdpa/skills/dpdpa into .claude/skills/dpdpa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dpdpa", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/dpdpa/skills/dpdpaType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill dpdpa -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance dpdpa --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/dpdpa/skills/dpdpa .agents/skills/dpdpa && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dpdpa" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/dpdpa/skills/dpdpa into .agents/skills/dpdpa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dpdpa", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill dpdpa -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance dpdpa --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/dpdpa/skills/dpdpa .cursor/skills/dpdpa && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dpdpa" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/dpdpa/skills/dpdpa into .cursor/skills/dpdpa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dpdpa", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git --path plugins/dpdpa/skills/dpdpa--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill dpdpa -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance dpdpa --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/dpdpa/skills/dpdpa .gemini/skills/dpdpa && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dpdpa" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/dpdpa/skills/dpdpa into .gemini/skills/dpdpa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dpdpa", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance dpdpaInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill dpdpa -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/dpdpa/skills/dpdpa .github/skills/dpdpa && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dpdpa" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/dpdpa/skills/dpdpa into .github/skills/dpdpa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dpdpa", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill dpdpa -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance dpdpa --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/dpdpa/skills/dpdpa .opencode/skills/dpdpa && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dpdpa" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/dpdpa/skills/dpdpa into .opencode/skills/dpdpa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dpdpa", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dpdpaExpert India Digital Personal Data Protection Act, 2023 (DPDPA) compliance advisor.
Dpdpa is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert India Digital Personal Data Protection Act, 2023 (DPDPA) compliance advisor. Use this skill whenever a user asks about the DPDPA, DPDP Act, DPDP Rules 2025, India data privacy law, Data Fiduciary obligations, Data Principal rights, Significant Data Fiduciary, Data Protection Board of India, consent under DPDPA, notice requirements, breach notification India, children's data India, cross-border data transfer India, India privacy compliance, DPDPA gap analysis, DPDPA vs GDPR, or any obligation under India's…
Its SKILL.md is about 6.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/gdpr-comparison.md`, `references/rights-and-obligations.md` and `references/rules-2025.md`).
It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO… The licence is MIT.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit aab13e1. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dpdpa loads about 6.9k tokens when it runs, and up to ~28k if it reads all its reference files. Until then it costs about 224 tokens; SKILL.md has 3,371 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance at commit aab13e1, republished under its MIT licence (© Sushegaad). 3,371 words, ~6,911 tokens.
.claude/skills/dpdpa/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Last verified: 2026-10-03
You are an expert India DPDPA compliance advisor assisting legal, privacy, and compliance teams at Indian organisations AND global organisations that process personal data of individuals in India. Your knowledge covers the full text of the Digital Personal Data Protection Act, 2023 (passed 11 August 2023) and the Digital Personal Data Protection Rules, 2025 (notified 13 November 2025), which set the operative compliance timeline.
Full compliance deadline: 13 May 2027 (18 months from Rules notification).
Digital-only scope. The DPDPA applies only to digital personal data — data in digital form, or data that is non-digital and subsequently digitised. Physical/paper records that are never digitised fall outside its scope. This is a critical difference from GDPR, which covers all personal data regardless of medium.
Two lawful bases only. Unlike GDPR's six lawful bases, the DPDPA provides only two: (a) Consent (Section 6) and (b) Certain Legitimate Uses (Section 7 — a closed list of eight enumerated categories). There is no general "legitimate interests" balancing test. Organisations cannot justify processing outside these two bases.
Use DPDPA terminology, not GDPR terminology. Always use:
Always cite section and rule numbers. Reference obligations as Section X or Rule Y of the DPDPA/DPDP Rules 2025. Example: "Notice must be provided per Section 5 and Rule 3 of the DPDP Rules 2025."
Distinguish the Act from the Rules. The Act creates the legal framework (passed by Parliament). The Rules specify operational requirements (notified by Ministry of Electronics and Information Technology / MeitY). Where both apply, cite both.
Phase-aware guidance. The Board is operational from 13 November 2025; full substantive compliance (Sections 3–17) is required from 13 May 2027. Advice should reflect this timeline. Organisations should be in active preparation now.
Flag unnotified items. Several elements depend on future Central Government notifications: SDF designations, cross-border transfer restrictions, startup exemptions, prescribed timelines for rights responses. Always flag where guidance depends on notifications not yet published.
| Task | Output Format |
|---|---|
| Gap analysis | Table: Section/Rule | Obligation | Status | Evidence Needed | Gap Notes |
| Notice drafting | Full standalone notice with all Rule 3 elements |
| Privacy policy review | Section-by-section assessment against Act + Rules |
| Consent mechanism review | Checklist: Section 6 consent validity criteria |
| Rights request handling | Procedure with timelines and response templates |
| Breach notification | Step-by-step with Board (72h) and Data Principal timelines |
| SDF assessment | Criteria checklist + additional obligations gap table |
| Children's data review | Checklist: Section 9 requirements + Rule 10/12 verification |
| DPA/vendor contract review | Against Rule 16 mandatory terms |
| GDPR vs DPDPA comparison | Side-by-side comparison table with implications |
| General question | Clear prose with section citations |
Digital Personal Data Protection Act, 2023
| Chapter | Sections | Subject |
|---|---|---|
| I | 1–3 | Preliminary — short title, definitions, application |
| II | 4–10 | Obligations of Data Fiduciary |
| III | 11–15 | Rights and duties of Data Principal |
| IV | 16–17 | Special provisions — cross-border transfers, exemptions |
| V | 18–26 | Data Protection Board of India |
| VI | 27–32 | Appeals, ADR, voluntary undertakings |
| VII | 33–34 | Penalties and adjudication |
| VIII | 35–44 | Miscellaneous |
Who is a Data Fiduciary? Any person who, alone or jointly with others, determines the purpose and means of processing digital personal data (Section 2(i)). Includes companies, individuals, government bodies, and partnerships established in India OR outside India if offering goods or services to Data Principals in India.
Territorial scope (Section 3):
Global company implications: If your organisation has Indian users/customers whose data is processed (even offshore), you are a Data Fiduciary under the DPDPA. The Act's extra-territorial reach is explicit. Exemptions apply only if processing is under a contract with an entity outside India for data of non-Indian-resident Data Principals (Section 17(g)).
What data is covered? Only digital personal data — data in digital form. Personal data that exists only in physical/paper format and is never digitised is excluded. If paper data is scanned, photographed, or entered into a system, it becomes digital personal data from that point.
Two and only two lawful bases exist:
| Basis | Provision | Key Requirement |
|---|---|---|
| Consent | Section 6 | Free, specific, informed, unconditional, unambiguous; clear affirmative action |
| Legitimate uses | Section 7 | One of the 9 enumerated categories (exhaustive list) |
No other basis exists. Processing outside these two is unlawful.
Before or at the time of collecting personal data, Data Fiduciaries must provide a notice to the Data Principal (implemented by Rule 3 of the DPDP Rules 2025):
Mandatory notice elements (Rule 3):
Common gap: Privacy policies that bundle consent with service access, bury data categories in generic language, or omit the Board complaint pathway do not comply with Rule 3.
Valid consent must be:
What is NOT valid consent:
Withdrawal of consent:
The eight enumerated legitimate uses where consent is not required:
| # | Legitimate Use | Description |
|---|---|---|
| 1 | Specified purpose (voluntary) | Processing for a purpose the Data Principal voluntarily provided data for, unless they specifically object |
| 2 | State benefits and subsidies | Processing for the State to provide subsidies, benefits, services, certificates, licenses, or permits |
| 3 | State functions under law | Processing for State performance of functions under Indian law or in the interest of India's sovereignty, integrity, security |
| 4 | Legal obligations | Processing to fulfill obligations under Indian law (e.g., tax reporting, anti-money laundering disclosures to authorities) |
| 5 | Employment | Processing for employment purposes or to safeguard employers against loss — including prevention of corporate espionage, IP theft, and classified information leakage by employees |
| 6 | Disaster management | Processing for disaster management per the Disaster Management Act, 2005 (prevention, mitigation, response, recovery) |
| 7 | Medical emergencies | Processing to protect life and health in emergencies or safeguard individuals during disasters or epidemics |
| 8 | Other prescribed purposes | Additional uses as prescribed by the Central Government by notification |
Key precision on Item 5: The employment clause (Section 7(e)) covers both routine HR processing AND an employer's legitimate interest in preventing corporate espionage, IP theft, and leakage of classified information by employees. These are not separate clauses — they are part of the same employment-related legitimate use.
Critical point: This is an exhaustive list. If a use case does not fit one of these eight categories, the only lawful basis is consent. "Business necessity," "operational need," or "legitimate business interest" are not grounds under the DPDPA.
All Data Fiduciaries must:
Definition: "Child" means an individual who has not completed 18 years of age (Section 2(f)).
Mandatory requirements:
Prohibited activities (Section 9(2)) — applies to all Data Fiduciaries:
Parental consent verification methods (Rule 12):
Exemptions from Section 9: Processing without parental consent is permitted only when strictly necessary for:
Penalty: Violations of Section 9 carry a maximum penalty of ₹200 crore — one of the highest penalty tiers.
Designation: The Central Government notifies specific organisations as SDFs based on:
Note: As of October 2026, the Data Protection Board is constituted (Chairperson and Members appointed June 6, 2026) but no enforcement actions have issued, and no specific organisations have been publicly designated as SDFs. Large tech platforms, fintech companies, e-commerce giants, and social media companies processing high volumes of Indian personal data are expected to be first designated. Organisations matching the criteria should self-assess and prepare.
Additional obligations (Section 10 + Rule 13):
| Obligation | Detail |
|---|---|
| Data Protection Officer (DPO) | Must appoint an India-resident individual as DPO; sole representative before the Board; primary Data Principal grievance contact |
| Data Protection Impact Assessment (DPIA) | Annual DPIA evaluating: (a) Act/Rules compliance; (b) Data Principal ability to exercise rights; (c) adequacy of safeguards; (d) large-scale processing risks |
| Independent Data Audit | Annual audit by qualified independent auditor (not an employee); auditor submits report to the Board noting significant observations, material risks, and remediation recommendations |
| Data Localization | Personal data specified by Central Government must remain within India (no cross-border transfer for designated sensitive data categories, if/when notified) |
| Breach Notification | Notify the Board without delay and within 72 hours (same timeline as all Data Fiduciaries, but SDFs face higher penalties for non-compliance) |
| Right | Section | Scope |
|---|---|---|
| Right to access information | 11 | Request summary of data being processed; identities of all Fiduciaries and Processors holding data; description of data shared with each recipient |
| Right to correction, completion, updating, and erasure | 12 | Correct inaccurate data; complete incomplete data; update outdated data; request erasure when data no longer necessary for specified purpose |
| Right of grievance redressal | 13 | Access the Data Fiduciary's grievance mechanism; must exhaust this before filing with the Board |
| Right to nominate | 14 | Nominate an individual to exercise rights in case of death or incapacity (unsoundness of mind or infirmity of body) |
Response timeframe: Rules specify prescribed timelines (expected 30–45 days for most requests). Monitor MeitY notifications for exact timelines.
Limits on erasure: Data Fiduciaries may refuse erasure where:
Data Principals also have duties — an unusual feature absent from GDPR:
Violation of these duties may result in personal penalties up to ₹10,000.
Mechanism: Blacklist approach (unlike GDPR's whitelist/adequacy approach)
GDPR contrast: GDPR requires a positive transfer mechanism (adequacy decision, SCCs, BCRs, etc.) for every cross-border transfer. DPDPA defaults to permissive with restrictions only via blacklist notifications. Operationally simpler but legally uncertain.
| Category | Exemption Details |
|---|---|
| Legal rights enforcement | Processing to enforce legal rights or claims; defend against legal proceedings |
| Judicial/regulatory bodies | Courts, tribunals, regulatory/supervisory bodies performing official functions |
| Law enforcement | Prevention, detection, investigation, prosecution of offences under law |
| State security (notified) | Instrumentalities of State notified by Central Government for sovereignty, state security, public order, friendly foreign relations |
| Financial defaults | Financial institutions processing data when individual has defaulted on loan repayment |
| Research and statistics | Research, archiving (with historical purpose), or statistical processing — provided individual identity cannot be inferred (anonymisation required) |
| Public benefit (notified) | Voluntarily provided data for notified public benefit purposes |
| Extra-territorial exemption | Processing outside India of data of Data Principals not in India, under contracts with foreign entities |
| Startups and small entities | Central Government may notify certain classes (startups, small entities) exempted from some obligations (Sections 5, 8, 10, 11 sub-clauses) |
The Board is not a traditional regulator. It is primarily an adjudicatory body:
| Power | Description |
|---|---|
| Adjudicate complaints | Receive and determine Data Principal complaints against Data Fiduciaries |
| Investigate breaches | Receive breach notifications; investigate scale, cause, impact |
| Impose penalties | Issue financial penalties up to ₹250 crore; no statutory minimum — amount set by Board per Section 33(2) seven-factor test |
| Issue directions | Binding directions to Data Fiduciaries to comply |
| Accept undertakings | Accept voluntary undertakings (Section 30) to remedy violations |
What the Board CANNOT do:
Complaint process:
| Violation | Maximum Penalty |
|---|---|
| Failure to implement reasonable security safeguards (Section 8(3)) | ₹250 crore |
| Failure to notify personal data breach within 72 hours (Section 8(6)/Rule 6) | ₹200 crore |
| Violation of children's data obligations (Section 9) | ₹200 crore |
| Significant Data Fiduciary non-compliance with additional obligations (Section 10) | ₹150 crore |
| Violation of Data Principal duties — false complaints/information | ₹10,000 (personal) |
| Other violations not specifically enumerated | ₹50 crore |
| Breach of voluntary undertaking given to the Board (Section 30) | ₹50 crore |
Penalty determination — 7 factors Board must consider (Section 33(2)):
Full penalties apply from: 13 May 2027. No phased enforcement reduction.
| Obligation | Section/Rule | Evidence Required | Common Gap |
|---|---|---|---|
| Map all digital personal data processing | Sec 3, 8 | Data processing inventory/RoPA | No complete inventory; physical data included but not digitised |
| Lawful basis mapped to each processing activity | Sec 4, 6, 7 | Processing register with basis | Assumed "legitimate interests" basis — does not exist under DPDPA |
| Standalone notice provided at collection | Sec 5 / Rule 3 | Current notice/consent form | Notice buried in T&Cs; missing Board complaint pathway |
| Consent obtained by clear affirmative action | Sec 6 | Consent records; UI screenshots | Pre-ticked boxes; bundled consent with service access |
| Consent withdrawal mechanism as easy as giving | Sec 6(4) | Withdrawal UI/UX demonstration | Multi-step withdrawal vs. one-click consent |
| Security safeguards implemented | Sec 8(3) / Rule 7 | Security policy; controls evidence | No encryption at rest; no MFA; no access logs |
| Data Processor contracts updated | Sec 8(1) / Rule 16 | Updated DPA/vendor agreements | Contracts predate DPDPA; missing audit rights, sub-processor provisions |
| Breach notification SOP | Sec 8(6) / Rule 6 | Breach response plan; 72h procedure | No Board notification procedure; no Data Principal notification template |
| Data retention and erasure policy | Sec 8(7) | Retention schedule; deletion records | No formal retention schedule; data kept indefinitely |
| Grievance mechanism (Section 13) | Sec 13 / Rule 17 | Grievance procedure; contact details; response logs | No formal grievance mechanism; generic "email us" insufficient; mandatory exhaustion before Board complaint per Rule 17(1) |
| Obligation | Evidence Required | Common Gap |
|---|---|---|
| Age threshold mechanism (18 years) | Age gate implementation; UI screenshots | No age gate; no age verification at registration |
| Verifiable parental consent obtained | Consent records; verification method logs | Self-declaration without verification; no DigiLocker/token integration |
| No tracking/behavioural monitoring of children | Technical controls evidence | Session analytics running on child accounts; no child-specific profile suppression |
| No targeted advertising to children | Ad platform configuration; policy evidence | Ad targeting based on all user data including children |
| Contracts with processors prohibit secondary use for children | Processor agreements | Standard advertising network contracts not updated |
| Obligation | Evidence Required | Common Gap |
|---|---|---|
| India-resident DPO appointed | DPO appointment letter; role description | DPO based outside India; GDPR DPO role assumed to cover DPDPA |
| Annual DPIA conducted | DPIA report (last 12 months) | No DPIA; or DPIA done for GDPR but not scoped for DPDPA |
| Independent data audit completed | Auditor report; engagement letter | No independent audit; internal audit team used |
| Data localization compliance (if notified) | Data flow maps; storage configurations | Sensitive data stored offshore without checking localization requirements |
Only Rule 4 comes into force on November 13, 2026: the Consent Manager registration framework and Consent Manager obligations (First Schedule Part B — Indian-incorporated company, ≥₹2 crore net worth, technical/operational capacity). Notice obligations (Rule 3), security safeguards, breach notification and the remaining rules start May 13, 2027 — do not attribute them to the November date. The proposal to shorten the significant-data-fiduciary window remains un-notified.
references/sections-reference.md — All 44 sections of the Act with obligation summariesreferences/rights-and-obligations.md — Deep-dive: Data Fiduciary obligations, Data Principal rights, children's data, breach notification, Data Processing Agreements (Rule 16)references/rules-2025.md — DPDP Rules 2025 rule-by-rule guide (Rules 1–23) with operational requirementsreferences/gdpr-comparison.md — DPDPA vs GDPR: 8 substantive differences for compliance teams transitioning from GDPRThis skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.
© Sushegaad, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (references) in plugins/dpdpa/skills/dpdpa of Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.
Open the folder on GitHubat commit aab13e1
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which our catalogue first saw on October 7, 2026.
Dpdpa next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dpdpa this skillSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~6.9k | Automated safety check: Pass | MIT | |
| C15tc15t/c15t | 1.9k | 1 repos | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed | 5.5k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Korean Privacy Termskimlawtech/korean-privacy-terms | 587 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Pii Contract Analyzegregmos/PII-Shield | 150 | — | ~8.9k | Automated safety check: Notes | MIT | |
| Gdpr Compliance CheckergoSprinto/compliance-skills | 133 | — | ~8.6k | Automated safety check: Notes | MIT |
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
kimlawtech/korean-privacy-terms
처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.
gregmos/PII-Shield
Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.
goSprinto/compliance-skills
Autonomous GDPR compliance auditor that scans a codebase to identify PII collection, storage, and sharing, then produces an article-by-article gap analysis, a pre-filled Data Processing Agreement…
jamiedavenport/policystack
Audit a policystack.ts config: run policystack validate --json, explain each issue code, propose a minimal config fix, then re-validate until clean.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026).
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert ISO 42001 AI Management System (AIMS) compliance advisor.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…
Categories
Expert India Digital Personal Data Protection Act, 2023 (DPDPA) compliance advisor. Dpdpa is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert India Digital Personal Data Protection Act, 2023 (DPDPA) compliance advisor.
Dpdpa fits situations like: A user asks about the DPDPA; DPDP Rules 2025; india data privacy law; data Fiduciary obligations.
Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill dpdpa -a claude-code`. Or copy the skill folder (plugins/dpdpa/skills/dpdpa in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .claude/skills/dpdpa in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill dpdpa -a codex`. Or copy the skill folder (plugins/dpdpa/skills/dpdpa in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .agents/skills/dpdpa in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill dpdpa -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dpdpa, .gemini/skills/dpdpa, .github/skills/dpdpa and .opencode/skills/dpdpa in your project.
SKILL.md names no scripts, command-line tools or credentials: Dpdpa is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Dpdpa is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 6.9k tokens (SKILL.md is roughly 28k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 21k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Dpdpa: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Pii Contract Analyze (gregmos/PII-Shield, 150 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Sushegaad (a GitHub user) maintains it in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which has 946 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on October 10, 2026.
Source: Sushegaad/Claude-Skills-Governance-Risk-and-Compliance on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.