India's personal data law, and the Rules that make it operable. It is consent-first, it applies to digital personal data wherever it is processed if the processing relates to offering goods or services in India, and the Board can impose penalties running to hundreds of crores.
The library does not carry this regime yet. The obligations are enumerated and the mapping to our common controls is known, but nothing is authored into ControlRegistry and no crosswalk is published. This page describes the law. It does not claim we cover it, and we are not offering an assessment against it today.
Any organisation that determines the purpose and means of processing digital personal data in India, and any organisation outside India processing such data in connection with offering goods or services to people in India. The Act calls that organisation a fiduciary rather than a controller, and the duty is not delegable: it remains accountable for what its processors do. A subset are designated as significant, which adds independent audit, impact assessment and algorithmic due diligence on top of everything else. Whether an organisation falls in that subset is a determination it makes against the criteria, not one this page can make for it.
Most of the security half is work an organisation has usually started. Encryption, access control and logging are the same controls ISO 27001 and SOC 2 ask for, and evidence gathered for those carries over. What is genuinely new is the privacy-procedural half, and it is procedural rather than technical: knowing every point at which personal data is collected and what notice was in force there, being able to answer a person within the response period, and being able to run a breach as a sequence with two clocks rather than a single notification. The work that catches organisations out is not a control they lack but a record they cannot produce: which version of the notice a given consent was given against.
There is no certificate. DPDP is supervised rather than certified: the Board acts on complaints and breaches, and what protects an organisation is the record it can produce at that moment. That makes preparation a matter of evidence and operational routine rather than of achieving a status, and it is why we treat it as an obligations register with clocks attached rather than as a checklist.
SecureEdge Advisory prepares you and facilitates the process. The affirmation is made by an external auditor, a certification body or the regulator, never by us.
Control mappings for this framework are not yet published in the library. It is carried in full for assessment and preparation, and cross-framework reuse will follow as the mapping matures. We would rather state that plainly than imply reuse that does not exist.