← ClaudeAtlas

dpdp-analyzelisted

Analyse anything against India's Digital Personal Data Protection Act, 2023 (Act 22 of 2023) and the DPDP Rules, 2025. Use whenever the question touches Indian data protection or privacy law, whether or not "DPDP" is named. Triggers include - is this DPDP compliant, what consent do we need in India, Indian privacy notice review, data breach notification India, is my company a Significant Data Fiduciary, do we need a DPO in India, children's data and age gating for Indian users, can we transfer Indian user data abroad, data localisation India, RTI section 8(1)(j) after DPDP, IT Act section 43A repeal, SPDI Rules status, DPDP penalties and the Data Protection Board, DPDP vs GDPR, and any Indian privacy policy, consent flow, DPA or vendor contract review. Also reach for it when auditing a product or store that collects personal data from users in India.
mksd0398/dpdp-act-skill · ★ 0 · AI & Automation · score 60
Install: claude install-skill mksd0398/dpdp-act-skill
# DPDP analysis Analyse anything against the **Digital Personal Data Protection Act, 2023** and the **DPDP Rules, 2025**, from a one-line question to a full compliance audit. ## Hard rules 1. **Never state a DPDP proposition without a section or rule anchor.** If you cannot point to `s.X` or `Rule Y`, you do not know it. Say so. 2. **Quote from `references/act-full-text.md` only.** That file is verbatim Gazette text. Do not quote the Act from memory, and do not paraphrase a quotation into quotation marks. 3. **Rules are secondary.** `references/rules-2025.md` was assembled from PIB and cross-checked secondary sources, not from the Gazette. Every output that relies on a Rule must carry the line: *verify against the notified Gazette text before external use.* 4. **Penalties are ceilings.** Every Schedule figure is "may extend to", gated on the Board finding the breach "significant" under s.33(1). Never present one as a fine that will be levied. 5. **Check commencement before saying anything is binding.** s.1(2) permits staggered commencement. Substantive Rules commence **14 May 2027**; Rule 4 Consent Managers **14 November 2026**; Board machinery has been live since **14 November 2025**. 6. **Do not import GDPR.** No sensitive-data category, no legitimate interests, no portability, no right against automated decisions, no compensation to individuals. Asserting any of these is the most common way to get DPDP wrong. See `references/doctrine.md` secti