dpdpa

Solid

Expert India Digital Personal Data Protection Act, 2023 (DPDPA) compliance advisor. Use this skill whenever a user asks about the DPDPA, DPDP Act, DPDP Rules 2025, India data privacy law, Data Fiduciary obligations, Data Principal rights, Significant Data Fiduciary, Data Protection Board of India, consent under DPDPA, notice requirements, breach notification India, children's data India, cross-border data transfer India, India privacy compliance, DPDPA gap analysis, DPDPA vs GDPR, or any obligation under India's personal data protection framework. Also trigger for: "Section 6 consent", "Section 7 legitimate uses", "Section 9 children's data", "Section 10 SDF", "Section 16 cross-border", "Rule 6 breach notification", "Rule 13 SDF obligations", "Data Protection Board complaint", "verifiable parental consent India", "DPDPA compliance roadmap", or "India privacy law global company".

Data & Documents 780 stars 162 forks Updated 1 weeks ago MIT

Install

View on GitHub

Quality Score: 90/100

Stars 20%
96
Recency 20%
90
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# India DPDPA — Digital Personal Data Protection Act, 2023 Skill > **Last verified:** 2026-07-03 You are an expert **India DPDPA compliance advisor** assisting **legal, privacy, and compliance teams** at Indian organisations AND global organisations that process personal data of individuals in India. Your knowledge covers the full text of the **Digital Personal Data Protection Act, 2023** (passed 11 August 2023) and the **Digital Personal Data Protection Rules, 2025** (notified 13 November 2025), which set the operative compliance timeline. **Full compliance deadline: 13 May 2027** (18 months from Rules notification). --- ## Foundational Rules 1. **Digital-only scope.** The DPDPA applies only to **digital personal data** — data in digital form, or data that is non-digital and subsequently digitised. Physical/paper records that are never digitised fall outside its scope. This is a critical difference from GDPR, which covers all personal data regardless of medium. 2. **Two lawful bases only.** Unlike GDPR's six lawful bases, the DPDPA provides only two: **(a) Consent** (Section 6) and **(b) Certain Legitimate Uses** (Section 7 — a closed list of eight enumerated categories). There is **no general "legitimate interests" balancing test.** Organisations cannot justify processing outside these two bases. 3. **Use DPDPA terminology, not GDPR terminology.** Always use: - **Data Fiduciary** (not "controller" or "data controller") - **Data Principal** (n...

Details

Author
Sushegaad
Repository
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Created
4 months ago
Last Updated
1 weeks ago
Language
HTML
License
MIT

Similar Skills

Semantically similar based on skill content — not just same category

Data & Documents Listed

data-protection-check

Focused Personal Data Protection Act 2026 compliance review — processing inventory, lawful basis, data classification, localisation, cross-border transfers, breach and registration duties. Use for "PDPA check", "can we send this data abroad", "privacy review", "data protection compliance", DPA/data-clause reviews, or breach response.

0 Updated 1 weeks ago
Zerif007
AI & Automation Solid

vn-pdpl

Expert Vietnam Personal Data Protection Law (PDPL) compliance advisor for Law No. 91/2025/QH15 and implementing Decree 356/2025/ND-CP (effective January 1, 2026). Use this skill for gap analysis against the Vietnam PDPL, data subject rights fulfilment workflows, cross-border data transfer impact assessments, privacy notices and internal policies, breach notification procedures, sector-specific obligations (finance, AI, cloud, blockchain), and DPO qualification reviews. Trigger whenever a user mentions Vietnam data privacy, VN-PDPL, Nghị định 356, Vietnamese personal data, or cross-border transfers involving Vietnamese citizens' data.

780 Updated 1 weeks ago
Sushegaad
Data & Documents Solid

lgpd

Expert LGPD compliance advisor for Brazil's Lei Geral de Proteção de Dados (Law 13,709/2018). Use this skill whenever a user asks about LGPD, Brazilian data protection, ANPD, personal data processing in Brazil, data subject rights under Brazilian law, legal bases for processing, sensitive data handling, DPO appointment in Brazil, data breach notification to ANPD, LGPD penalties (fines up to 2% of revenue / R$50M), international data transfers from Brazil, Brazil-EU mutual adequacy (January 2026 — SCCs/BCRs no longer needed for Brazil-EU transfers), LGPD gap assessments, privacy policy drafting for Brazilian operations, DPIA under LGPD, consent management, or comparing LGPD with GDPR. Trigger for any Brazil privacy or data protection question even if LGPD is not named explicitly.

780 Updated 1 weeks ago
Sushegaad