Digital Personal Data Protection Act, 2023 · vAct No. 22 of 2023
Digital Personal Data Protection Act, 2023
Digital Personal Data Protection Act, 2023 — 100% of in-scope requirements covered.
8 requirements · 3 in scope (3 enforced) · 5 out-of-scope (outside KYE™’s authority layer). The 100% is weighted over the in-scope base.
Source: The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), Government of India
By category
| Category | Reqs | Enforced | Designed | Advisory | Deferred | Coverage |
|---|---|---|---|---|---|---|
| Digital Personal Data Protection Act, 2023 | 8 | 3 | 0 | 0 | 0 | 100% |
Every requirement → the KYE™ artefact that enforces it
| ID | Title | Status | KYE™ enforcement |
|---|---|---|---|
dpdp-act-2023.PURPOSE-LIMITATION |
Personal data processed only for the purpose for which consent was given | enforced | audit_events: kye.purpose.admissibility.v1, kye.evidence.decision_map.v1engines: internalconstitution_refs: constitution/12-PURPOSE-PERMISSION.md |
dpdp-act-2023.ACTION-EVIDENCE |
Every consequential action on personal data is evidenced and replayable | enforced | audit_events: kye.evidence.pack.v1, kye.replay.context_seal.v1, kye.compliance.attestation.v1engines: internalconstitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/30-AUDIT-WORM-RETENTION.md |
dpdp-act-2023.ERASURE-ROUTE |
Data Principal right to erasure is routed and evidenced | enforced | agents: internalaudit_events: kye.evidence.pack.v1, kye.replay.context_seal.v1, kye.compliance.attestation.v1constitution_refs: constitution/31-DATA-GOVERNANCE-PACK.md, constitution/61-RIGHTS-DISPUTES-DISCLOSURE-RAIL.md |
dpdp-act-2023.NOTICE-CONSENT |
Itemised notice and valid consent obtained from the Data Principal | out-of-scope | constitution_refs: constitution/12-PURPOSE-PERMISSION.md |
dpdp-act-2023.BREACH-INTIMATION |
Personal-data breach intimated to the Board and affected Data Principals | out-of-scope | constitution_refs: constitution/13-RESILIENCE-LOOP.md |
dpdp-act-2023.SDF-OBLIGATIONS |
Significant Data Fiduciary duties — DPO, independent audit, DPIA | out-of-scope | constitution_refs: constitution/31-DATA-GOVERNANCE-PACK.md |
dpdp-act-2023.CHILDREN-DATA |
Verifiable parental consent and no tracking or targeted advertising directed at children | out-of-scope | constitution_refs: constitution/12-PURPOSE-PERMISSION.md |
dpdp-act-2023.CROSS-BORDER |
Transfer of personal data outside India subject to Government restriction | out-of-scope | constitution_refs: constitution/30-AUDIT-WORM-RETENTION.md |