| Sec. 4 & 7 | Personal data may be processed only for a lawful purpose — with consent, or for one of the listed legitimate uses. | Lawful basis is recorded per processing activity and re-tested when the purpose changes, so “legitimate use” is a documented determination rather than a convenient assumption. |
|---|
| Sec. 8(1)–(2) | The Data Fiduciary is responsible for processing by a processor engaged under a valid contract, including on the Principal's behalf. | A processor register ties every vendor to the activities, purposes and consents they inherit, and to the contract that permits it — so liability is mapped, not discovered. |
|---|
| Sec. 10(1) | The Central Government may notify any Data Fiduciary or class as a Significant Data Fiduciary based on volume, sensitivity and risk factors. | SDF obligations are tracked as a live posture that can be switched on by class, so notification is a configuration change rather than a programme. |
|---|
| Sec. 16 | Transfer of personal data outside India is permitted except to countries restricted by the Central Government by notification. | Transfer controls are evaluated against the current restricted list at processing time, with the data flow map showing where each attribute physically resides. |
|---|
| Sec. 17 | Exemptions apply for certain purposes, including legal claims, State instrumentalities and research, subject to prescribed standards. | Exemptions are configured as explicit, evidenced exceptions with a named basis and owner — never as an undocumented gap in enforcement. |
|---|