dpdpa

Solid

Expert India Digital Personal Data Protection Act, 2023 (DPDPA) compliance advisor. Use this skill whenever a user asks about the DPDPA, DPDP Act, DPDP Rules 2025, India data privacy law, Data Fiduciary obligations, Data Principal rights, Significant Data Fiduciary, Data Protection Board of India, consent under DPDPA, notice requirements, breach notification India, children's data India, cross-border data transfer India, India privacy compliance, DPDPA gap analysis, DPDPA vs GDPR, or any obligation under India's personal data protection framework. Also trigger for: "Section 6 consent", "Section 7 legitimate uses", "Section 9 children's data", "Section 10 SDF", "Section 16 cross-border", "Rule 6 breach notification", "Rule 13 SDF obligations", "Data Protection Board complaint", "verifiable parental consent India", "DPDPA compliance roadmap", or "India privacy law global company".

Data & Documents 488 stars 103 forks Updated today MIT

Install

View on GitHub

Quality Score: 91/100

Stars 20%
90
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# India DPDPA — Digital Personal Data Protection Act, 2023 Skill You are an expert **India DPDPA compliance advisor** assisting **legal, privacy, and compliance teams** at Indian organisations AND global organisations that process personal data of individuals in India. Your knowledge covers the full text of the **Digital Personal Data Protection Act, 2023** (passed 11 August 2023) and the **Digital Personal Data Protection Rules, 2025** (notified 13 November 2025), which set the operative compliance timeline. **Full compliance deadline: 13 May 2027** (18 months from Rules notification). --- ## Foundational Rules 1. **Digital-only scope.** The DPDPA applies only to **digital personal data** — data in digital form, or data that is non-digital and subsequently digitised. Physical/paper records that are never digitised fall outside its scope. This is a critical difference from GDPR, which covers all personal data regardless of medium. 2. **Two lawful bases only.** Unlike GDPR's six lawful bases, the DPDPA provides only two: **(a) Consent** (Section 6) and **(b) Certain Legitimate Uses** (Section 7 — a closed list of eight enumerated categories). There is **no general "legitimate interests" balancing test.** Organisations cannot justify processing outside these two bases. 3. **Use DPDPA terminology, not GDPR terminology.** Always use: - **Data Fiduciary** (not "controller" or "data controller") - **Data Principal** (not "data subject" or "user") -...

Details

Author
Sushegaad
Repository
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Created
2 months ago
Last Updated
today
Language
HTML
License
MIT

Similar Skills

Semantically similar based on skill content — not just same category

AI & Automation Solid

vn-pdpl

Expert Vietnam Personal Data Protection Law (PDPL) compliance advisor for Law No. 91/2025/QH15 and implementing Decree 356/2025/ND-CP (effective January 1, 2026). Use this skill for gap analysis against the Vietnam PDPL, data subject rights fulfilment workflows, cross-border data transfer impact assessments, privacy notices and internal policies, breach notification procedures, sector-specific obligations (finance, AI, cloud, blockchain), and DPO qualification reviews. Trigger whenever a user mentions Vietnam data privacy, VN-PDPL, Nghị định 356, Vietnamese personal data, or cross-border transfers involving Vietnamese citizens' data.

488 Updated today
Sushegaad
Data & Documents Listed

data-protection-law

Swiss data protection law analysis — applies the nDSG/FADP framework (in force 1.9.2023), assesses GDPR adequacy interplay, maps cantonal data protection laws (IDG/KDSG/LIPAD), conducts DSFAs/DPIAs, and evaluates cross-border transfer mechanisms (adequacy, SCCs, BCRs, TIA). Trigger when: a user asks 'are we nDSG/GDPR compliant', 'do we need a data processing agreement', 'can we transfer data to [country]', 'do we need a DPIA/DSFA', 'what data protection obligations apply to us', 'is our privacy policy compliant', 'what rights do data subjects have under Swiss law', or references FDPIC, nDSG, DSG, FADP, or cantonal DP laws. Also triggered when the data-protection agent is invoked. Do NOT trigger for: financial regulatory data processing in fintech (use compliance-frameworks alongside this skill); document analysis tasks (use swiss-document-analysis); attorney-client privilege routing (use privacy-routing skill first); general corporate compliance not involving personal data (use corporate-law-agent).

19 Updated today
fedec65
AI & Automation Solid

gdpr-data-handling

Implement GDPR-compliant data handling with consent management, data subject rights, and privacy by design. Use when building systems that process EU personal data, implementing privacy controls, or conducting GDPR compliance reviews.

36,166 Updated yesterday
wshobson
DevOps & Infrastructure Solid

gdpr-compliant

Apply GDPR-compliant engineering practices across your codebase. Use this skill whenever you are designing APIs, writing data models, building authentication flows, implementing logging, handling user data, writing retention/deletion jobs, designing cloud infrastructure, or reviewing pull requests for privacy compliance. Trigger this skill for any task involving personal data, user accounts, cookies, analytics, emails, audit logs, encryption, pseudonymization, anonymization, data exports, breach response, CI/CD pipelines that process real data, or any question framed as "is this GDPR-compliant?". Inspired by CNIL developer guidance and GDPR Articles 5, 25, 32, 33, 35.

34,158 Updated yesterday
github
Data & Documents Solid

lgpd

Expert LGPD compliance advisor for Brazil's Lei Geral de Proteção de Dados (Law 13,709/2018). Use this skill whenever a user asks about LGPD, Brazilian data protection, ANPD, personal data processing in Brazil, data subject rights under Brazilian law, legal bases for processing, sensitive data handling, DPO appointment in Brazil, data breach notification to ANPD, LGPD penalties (fines up to 2% of revenue / R$50M), international data transfers from Brazil, LGPD gap assessments, privacy policy drafting for Brazilian operations, DPIA under LGPD, consent management, or comparing LGPD with GDPR. Trigger for any Brazil privacy or data protection question even if LGPD is not named explicitly.

488 Updated today
Sushegaad