India DPDP Act
DPDP SDF + DPO + Audit + DPIA (Sec 10-11)

India DPDP Act DPDP-SignificantDataFiduciary-SDF-Sec10-DPO-IndependentAuditor-DPIA-Algorithmic: DPDP Act Sections 10-11 + Significant Data Fiduciary (SDF) + Data Protection Officer + Independent Data Auditor + DPIA + Algorithmic Software Audit + Privacy by Design + Records of Processing Activities

Sections 10-11 of DPDP Act 2023 establish enhanced obligations on entities designated as Significant Data Fiduciaries (SDFs). Section 10 Significant Data Fiduciary: Central Government may notify Data Fiduciary or class of Data Fiduciaries as SDF having regard to such factors as may be relevant including (a) volume and sensitivity of personal data processed; (b) risk to rights of Data Principal; (c) potential impact on sovereignty + integrity of India; (d) risk to electoral democracy; (e) security of the State; (f) public order. SDF determination criteria operationalised through DPDP Rules 2025 quantitative thresholds. Enhanced SDF obligations: (a) appoint a Data Protection Officer (DPO) who shall be an individual responsible for representing the SDF + based in India + report directly to Board of Directors or similar governing body + be the point of contact for the grievance redressal mechanism + business contact info published; (b) appoint an independent Data Auditor to evaluate the compliance of the SDF with the provisions of the Act - independent + qualified + audit periodic per DPDP Rules 2025 cadence; (c) undertake periodic Data Protection Impact Assessment (DPIA) - process comprising a description of the rights of Data Principals and the purpose of processing of their personal data + assessment and management of the risk to the rights of Data Principals + such other matters regarding such process as may be prescribed; (d) undertake periodic audit; (e) other measures consistent with the provisions of the Act as may be prescribed. Section 11 Algorithmic Software Audit (per DPDP Rules 2025): for SDFs whose processing involves algorithmic decision-making or AI/ML systems + audit of algorithmic software for fairness + bias + discrimination + explainability + accuracy + impact on Data Principals. Privacy by Design and Default: built into business processes + system design + product development + data minimisation + purpose limitation + storage limitation + integrity + confidentiality. Records of Processing Activities (ROPA): comprehensive records of processing activities + categories + purpose + Data Principals + recipients + retention + TOMs + cross-border + DPIA outcomes + breach register. Coordinates with GDPR Arts 35 + 36 + 37 + 38 + 39 + ISO 27701 PIMS + Privacy Impact Assessment + India CERT-In + RBI Cyber Framework + ISMS 27001 alignment + AI Risk Management Frameworks (NIST AI RMF + ISO 42001) + EU AI Act + Algorithmic Accountability requirements. DPDP Sec 10-11 SDF + DPO + DPIA + Algorithmic Audit applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 158 controls across 64 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FTC-Safeguards-EffectiveDate-Small-Institution Effective Date, Small Institution Exemption and Sectoral Coordination (16 CFR 314.5, 314.6)
  • FTC-Safeguards-IR-Plan-BoardReporting-FTC-Notification Written Incident Response Plan + Board Reporting + FTC Breach Notification (16 CFR 314.4(h), (i), (j))
  • FTC-Safeguards-Risk-Assessment Written Risk Assessment (16 CFR 314.4(b))
  • FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g))

Bahrain PDPL · 4 controls

FDA 21 CFR Part 11 · 4 controls

  • Part11.30 Controls for open systems (21 CFR §11.30)
  • Part11.AuditTrail Audit trail requirements - secure computer-generated time-stamped (21 CFR §11.10(e))
  • Part11.CSV Computer system validation + risk-based approach (21 CFR §11.10(a) + 2003 FDA Scope and Application Guidance + 2023 CSA draft)
  • Part11.RecordRetention Record protection + retention + readiness for inspection (21 CFR §11.10(b) + (c))
  • AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction
  • AT-DSG-12 Section 62 - Administrative penalties
  • AT-DSG-7 Section 18 - Establishment of the Data Protection Authority

BSI IT-Grundschutz · 3 controls

  • BSI-13 Risk assessment procedures
  • BSI-15 Security categorization
  • BSI-17 Continuous monitoring strategy
  • BB-DPA-1 Section 1 - Short Title
  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • BB-DPA-4 Section 4 - Principles Relating to Processing

FISMA · 3 controls

  • FISMA-3554-Agency-Responsibilities Federal Agency Responsibilities (44 USC 3554) - CIO + CISO + Program + Reporting
  • FISMA-CIRCIA-ZTA-EO14028 CIRCIA, Zero Trust Architecture, EO 14028 + 14110 + OMB Memoranda
  • FISMA-NIST-800-53-RMF-800-171-FIPS Operationalisation via NIST 800-53 + 800-37 RMF + 800-171 + FIPS 199 + FIPS 200
  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-FreeZones Coordination with DIFC, ADGM and sectoral data protection regimes

IEEE 7000 · 3 controls

  • IEEE7000-EthicalRisk-Identification-Analysis-Treatment-ValidationOutcomes IEEE 7000 Clauses 8 + 8.1 + 8.2 - Ethical Risk Identification + Analysis + Treatment + Validation of Ethical Outcomes + AI Safety + Robustness + Adversarial Protection
  • IEEE7000-Operations-Lifecycle-OngoingMonitoring-Incident-Decommissioning IEEE 7000 - Operations + Lifecycle + Ongoing AI Risk Monitoring + Data Provenance + Retention + Privacy + Safe Deployment + Decommissioning + Disposal
  • IEEE7000-Values-Elicitation-Prioritisation-IEEE7000Family-Bias-Privacy-Transparency IEEE 7000 Clauses 6 + 6.1 - Ethical Values Elicitation + Prioritisation + IEEE 7000 Family Integration (Bias + Privacy + Transparency + Wellbeing)

ISO/IEC 27011:2024 · 3 controls

  • 27011-5.2 Information Security Roles in Telecoms
  • 27011-6.3 Awareness and Training
  • 27011-8.6 Data protection and backup

ISO/IEC 29134:2023 · 3 controls

  • 29134-1 Scope
  • 29134-3 Terms and definitions
  • 29134-9.1 PIA report structure
  • AUPRV-1 APP 1 Open and Transparent Management + Privacy Management Framework
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement

API 1164 · 2 controls

  • API1164-07 Remote Access
  • API1164-24 Vulnerability assessment for critical systems
  • AWWA-1.2 Risk Assessment
  • AWWA-3.4 Encryption and Data Protection
  • AL-DPA-14 Direct Marketing
  • AL-DPA-7 Right of Access
  • AZ-DPA-15 Article 17 - Dispute resolution
  • AZ-DPA-6 Article 6 - State regulation in personal data protection
  • DIQ-2 Data Quality Management
  • DIQ-3 Metadata Management
  • Sapin2-Pillar3-Risk-Mapping Pillar 3 - Corruption Risk Mapping (Cartographie des Risques)
  • Sapin2-Pillar4-ThirdParty-DueDiligence Pillar 4 - Third-Party Due Diligence (Clients, Suppliers, Intermediaries, M&A)
  • GhCSA-CII-Designation-Plan-Audit-Risk CII Designation, Registration, Cybersecurity Plan, Audit and Risk Assessment
  • GhCSA-Implementation-Roadmap Implementation Roadmap - Organizational Roles, Tooling and Metrics
  • IATF16949-Clause6-Planning-Risk-Contingency-Objectives-Change IATF 16949 Clause 6 - Planning + Risks and Opportunities + Contingency Plans + Quality Objectives + Change
  • IATF16949-Clause8-Operation-APQP-Design-Production-ControlPlan-SpecialChars IATF 16949 Clause 8 - Operation Planning + APQP + Design + Special Characteristics + Production + Control Plan + Set-Up Verification
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • ICAO-ANX17-Chap4-Cargo-Mail-Catering-Stores-Supplies-RegulatedAgent-KnownConsignor ICAO Annex 17 Chapter 4 - Cargo + Mail + Catering + Stores + Supplies Security + Regulated Agent + Known Consignor + Supply Chain

IEEE 1686 · 2 controls

  • IEEE1686-IR-Recovery-Reporting-Exercises-Drills-RECOV IEEE 1686 - Incident Response + Recovery from Failed Update + Reporting to Authorities + Coordination with Sector-Specific Agencies + Exercises and Drills
  • IEEE1686-Section5.1-AccessControl-Accounts-Roles-Password-Session-Remote IEEE 1686 Section 5.1 - Electronic Access Account Management + Roles + Password + Failed Login + Session + Remote Access + Personnel

ISO/IEC 27400:2022 · 2 controls

  • 27400-7.1 Network Security for IoT
  • 27400-7.4 Data retention and deletion
  • 27557-4.3 Individual impact consideration
  • 27557-6.3 Privacy risk assessment
  • ItalyCodice-Garante-Enforcement-AdministrativeSanctions-Criminal-Art166-167-170-20MEUR-Coord-EDPB Italy Codice Garante Authority + Article 140-bis + Article 144 Complaints + Article 166 Administrative Sanctions up to EUR 20M/4% + Article 167 Criminal Offences + Article 170 Failure to Comply with Garante Orders + EDPB Coordination
  • ItalyCodice-ePrivacy-Cookies-ElectronicCommunications-Telemarketing-PublicOpposition-TrafficDataRetention-Art121-122-130-132 Italy Codice ePrivacy - Article 121 Electronic Communications + Article 122 Cookies and Tracking + Article 130 Unsolicited Direct Marketing + Article 132 Traffic Data Retention + Italian Public Opposition Register (Registro delle Opposizioni)
  • ASTWO-1 Audit Planning, Scaling, Risk Assessment, and Integration
  • ASTWO-3 Entity-Level Controls and Period-End Financial Reporting Process
  • PAKPDPB-6 Cross-Border Transfer and Data Localization
  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO
  • 2.4.4 Hazard Analysis and Risk Assessment
  • 2.7.2 Food Fraud Plan
  • CRM-1 AML/CFT Compliance
  • CRM-4 Business Risk Assessment
  • D.1 Incident Response Planning
  • UKDEFSTD-1 Cyber Defence Cyber Risk Profile (CRP)
  • CPSC-CS.3 Data Protection for Safety Systems
  • CPSC-RA.3 Lifecycle Risk Assessment
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency
  • VERMONTAICDA-4 Vermont AG Enforcement and Cure
  • AMLCTF-PartA-RiskAssess ML/TF Risk Assessment
  • CPS230-11 Identification, Assessment and Management of Operational Risk
  • ASD37-27 Outbound data loss prevention (Very Good)
  • 4.3.1 Risk Assessment and Impact Analysis
  • R.16-VATR.Unhosted Unhosted (self-hosted / non-custodial) wallet transfers - 2024 Targeted Update
  • CJIS-17 Risk Assessment
  • FSSC-Additional-Requirements-v6 FSSC 22000 Additional Requirements v6 (Food Defense + Food Fraud + Allergen + Environmental + Culture)

FedRAMP Rev 5 · 1 control

  • FedRAMP-Boundary Authorization Boundary, SSP, SAR, POA&M documentation
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • GGAP-IFA-AllFarmBase-Mgmt-Workers-Env-Trace GLOBALG.A.P. IFA v6 All Farm Base (AF): Management, Workers, Environment, Traceability and Food Safety
  • IACS-UR-E26-Identify-Plan-Risk-Survey-Documentation IACS UR E26 Identify Goal - Ship Cyber Resilience Plan + CBS Risk Assessment + Survey + Documentation
  • IMO-MSC-FAL-Identify-AssetInventory-ThreatsVulnerabilities-CyberRiskAssessment-RolesResponsibilities IMO MSC-FAL Identify Function - OT/IT Asset Inventory + Threats + Vulnerabilities + Cyber Risk Assessment + Roles and Responsibilities + Crew + CSO + DPA

ISO/IEC 27031:2011 · 1 control

  • 27031-7.2 Resource Requirements

ISO/IEC 29147:2018 · 1 control

  • 29147-5.11 Researcher Safe Harbour and Legal Posture
  • DOM172-Supervisory-Authority-Cooperation-Sanctions-Penalties-Articles-77-79-Awareness-Training-Retention-DPO-Designation Dominican Republic Law 172-13 Supervisory Authority + Sanctions + Articles 77-79 + DPO + Awareness
  • RUSPD-4 Special Categories, Biometric Data
  • AIGF-1.3 Data Management

South Korea PIPA · 1 control

  • PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33
  • VIETNAMCYBER-4 Incident Reporting and Cooperation

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 158 it maps to, and the evidence behind each claim, over MCP and REST.