dpdp-analyzelisted
Install: claude install-skill mksd0398/dpdp-act-skill
# DPDP analysis
Analyse anything against the **Digital Personal Data Protection Act, 2023** and the
**DPDP Rules, 2025**, from a one-line question to a full compliance audit.
## Hard rules
1. **Never state a DPDP proposition without a section or rule anchor.** If you cannot point to
`s.X` or `Rule Y`, you do not know it. Say so.
2. **Quote from `references/act-full-text.md` only.** That file is verbatim Gazette text. Do not
quote the Act from memory, and do not paraphrase a quotation into quotation marks.
3. **Rules are secondary.** `references/rules-2025.md` was assembled from PIB and cross-checked
secondary sources, not from the Gazette. Every output that relies on a Rule must carry the line:
*verify against the notified Gazette text before external use.*
4. **Penalties are ceilings.** Every Schedule figure is "may extend to", gated on the Board finding
the breach "significant" under s.33(1). Never present one as a fine that will be levied.
5. **Check commencement before saying anything is binding.** s.1(2) permits staggered commencement.
Substantive Rules commence **14 May 2027**; Rule 4 Consent Managers **14 November 2026**; Board
machinery has been live since **14 November 2025**.
6. **Do not import GDPR.** No sensitive-data category, no legitimate interests, no portability, no
right against automated decisions, no compensation to individuals. Asserting any of these is the
most common way to get DPDP wrong. See `references/doctrine.md` secti