| Sec. 10(2)(c)(i) | A Significant Data Fiduciary must undertake periodic Data Protection Impact Assessments. | Assessments run on a defined schedule per processing activity, with completion, findings and residual risk tracked as a live posture rather than an annual artefact. |
|---|
| Sec. 10(2)(c)(ii) | A Significant Data Fiduciary must undertake periodic audit. | Assessment findings feed the audit workflow directly, so the auditor tests against the same record the business used to make the decision. |
|---|
| Sec. 10(2)(a) | Appoint a Data Protection Officer based in India, answerable to the board or its equivalent. | The DPO is a first-class role in the workflow with named approval gates, so accountability is recorded per decision rather than asserted in a policy. |
|---|
| Sec. 10(2)(c)(iii) | Undertake such other measures as prescribed, including due diligence of algorithmic software that may risk the rights of Data Principals. | Algorithmic due diligence is a dedicated assessment type covering model purpose, training data provenance, bias testing and human oversight. |
|---|
| Sec. 8(4) | Implement appropriate technical and organisational measures to ensure effective observance of the Act. | Every mitigation decision is recorded against the processing activity it protects, so “appropriate measures” is demonstrable rather than declarative. |
|---|