Independent DPDP educationBrowser-only workspace · no accounts, analytics or submissions

01 Evidence operations

The seven evidence artefacts every Data Fiduciary should be able to retrieve

A policy says what an organisation intends. An evidence artefact shows whether a person, system and review process can carry that intention into a real request or incident.

The evidence retrieval loop

A collection event should lead to an owned record, a tested workflow and a review decision—not to a disconnected folder of screenshots.

The evidence retrieval loopA collection event should lead to an owned record, a tested workflow and a review decision—not to a disconnected folder of screenshots.01Eventcollect · change · request02Decisionpurpose · role · exception03Systemfield · access · lifecycle04Evidenceversion · log · test05Reviewowner · finding · next date
  1. 01
    Eventcollect · change · request
  2. 02
    Decisionpurpose · role · exception
  3. 03
    Systemfield · access · lifecycle
  4. 04
    Evidenceversion · log · test
  5. 05
    Reviewowner · finding · next date
Editorial operating model. Replace it with your evidenced systems, owners and decisions.

02 Provision-aware reading

Three states that must not be flattened.

01Operative

What is operative now

· in force

Selected definitions, institutional machinery and rule-making provisions are in force. That does not make every substantive operating duty discussed in this article currently operative.

Check the phased ledger
02Scheduled · 18 months

What is notified for later

· notified future commencement

Most day-to-day Data Fiduciary duties discussed here sit in the notified eighteen-month cohort. The displayed date is derived from the status ledger and must be rechecked against later instruments.

Check the phased ledger

A useful readiness review starts with retrieval. Can the operating team produce the notice shown at collection, the purpose-and-data map behind the form, any choice record relied on, the service register, the rights workflow, the retention decision and the security or breach record? If the answer depends on one person remembering where a file lives, the control is fragile even when the policy text sounds polished.

These seven artefacts are not an official government pack and their presence does not prove legal compliance. They are an editorial operating model for connecting the DPDP Act and final Rules to people, systems and tests. Each artefact should be versioned, owned, proportionate and linked to controlled evidence rather than filled with unnecessary personal data.

1. The notice version that was actually shown

Do not begin with the current privacy policy. Begin with the collection surface: a lead form, checkout, support channel, employee workflow or mobile screen. Save the exact notice version, language, fields, purpose statement, available choices and deployment period. The point is to answer what a particular person could reasonably have seen at that moment, not what the organisation publishes today.

A durable notice record also names the product owner and links to the system destination. That lets a later review detect when the form changed but the CRM fields, automation or downstream disclosure did not. Store a redacted rendering or version identifier; avoid copying a real submission into the evidence file.

2. The purpose-and-data map behind the interface

A data inventory becomes useful when it connects a collection point to fields, purpose, owner, destination, access and an end event. “Customer data in CRM” is too broad to test. A better row says that a phone number enters through a demo request, supports scheduling and follow-up, is visible to a defined sales group, is copied to a named mail tool and is reviewed when the opportunity closes.

Map derived fields, free-text notes, attachments, exports and shadow spreadsheets as well as the neat fields in the schema. Those less visible copies are often where minimisation, correction and deletion fail. Unknown destinations should remain visibly unknown until someone verifies them; uncertainty is a finding, not a reason to invent completeness.

3–4. Choice evidence and the service register

Where consent is relied on, evidence should connect the notice version, affirmative action, time, person or identifier, purpose and withdrawal route. A generic database flag called “consent = true” cannot explain what was chosen. Where another lawful route is assessed, record that analysis separately rather than manufacturing consent. Preference evidence must also travel: withdrawal in one screen is incomplete if campaigns or connected senders continue.

The service register then shows who else can process or access the data. Record the service, purpose, data categories, fact-specific role assessment, contract reference, privileged access, locations, sub-processors or connected services, deletion event and exit owner. Reconcile it with accounts payable, single sign-on, integration settings and team spreadsheets. A missing service is a discovery question, not an automatic legal conclusion.

5–6. Rights workflow and retention-by-event schedule

A rights workflow should be executable by someone other than its author. It needs intake, safe verification, search locations, accountable decisions, authorised action, downstream confirmation and response evidence. Run an exercise with a synthetic identifier across the CRM, support tool, mailbox, export folder and backup process. Record what could not be searched or corrected instead of calling the exercise complete.

The retention schedule should describe events and actions, not only durations. Name when the clock starts, what marks the end of purpose, which exception can pause deletion, how the system acts, what happens to backups and how the decision is approved. Separate legal or operational retention from indefinite convenience. The final Rules contain specific future-cohort retention provisions, so a blanket rule must not replace a fact-specific schedule.

7. Security and breach evidence that supports a timeline

A security artefact is more than a control list. It links access reviews, protective measures, logs, monitoring, backups, tests and exceptions to the systems that hold the mapped data. Evidence should show what was reviewed, by whom, when, with what result and how an unresolved finding is owned. Redact secrets, raw logs and personal data from the review record.

For an incident, preserve awareness time, scope changes, containment, impact analysis, affected-person communication, Board intimation decisions, remedial work and recurrence prevention. The record must be capable of evolving as facts improve. A polished retrospective assembled weeks later cannot replace a disciplined contemporaneous timeline.

Make retrieval a recurring operating test

Assign one accountable owner and at least one operational participant to each artefact. Test a small sample quarterly or after a material system, purpose, contract or product change. The useful question is not “Do we have a register?” but “Can the current owner retrieve a current row, the linked configuration and the last test result without exposing unrelated personal data?”

Version the structure, not every sensitive payload. Keep links to approved evidence repositories, apply access controls and retain the review record for an explicit period. When the test fails, capture a bounded gap with an owner and target event. That turns the artefact pack into a management system rather than an annual theatre exercise.

Put the next review into somebody's working queue.

A role label is a starting point. Assign named internal owners, evidence locations and review dates in an approved system; this site stores none of them.

01

Founder

  • Name an accountable owner for each artefact.
  • Ask for one live retrieval demonstration, not a slide.
02

Legal / Privacy

  • Map each legal statement to a current source and status.
  • Review exceptions and role assessments without turning the pack into a certificate.
03

IT / Security

  • Link systems, access reviews, logs, backups and tests.
  • Redact credentials and raw personal data from evidence packs.
04

Product / Engineering

  • Connect form versions and fields to purpose and lifecycle.
  • Fix gaps revealed by synthetic rights and deletion exercises.
05

Operations

  • Maintain service, request and retention records at real events.
  • Escalate unknowns instead of completing fields by assumption.

Confidence should follow retrieval

The seven artefacts are valuable because they force policy, system and ownership to meet. Start with one real collection journey and build only the records needed to explain and test it. A smaller pack that an operating team can retrieve is more useful than a comprehensive-looking archive nobody trusts.

Treat the result as readiness evidence. Recheck the official instruments, record phased status and obtain qualified advice before making a legal conclusion.

Sources and change log

Gazette instruments govern the text and commencement. Government explainers are contextual; this field note remains editorial analysis.

  1. Act No. 22 of 2023Digital Personal Data Protection Act, 2023

    Sections 5–13: notice, consent, general obligations, children, SDF duties and Data Principal rights

  2. G.S.R. 846(E)Digital Personal Data Protection Rules, 2025

    Rules 3 and 5–15: notices, safeguards, breach, retention, contact, children, SDF, rights and transfer

  3. G.S.R. 843(E)DPDP Act commencement notification

    Paragraphs (a)–(c): phased commencement cohorts

  4. G.S.R. 892(E)Corrigendum to the Digital Personal Data Protection Rules, 2025

    Items (i)–(v): corrections to the final Rules

Change log

Initial private-preview article created against the final Rules, commencement notification and published corrigendum.

Human-review gate: pinpoints, status and fact-specific interpretations must be rechecked before public reliance.

12 Continue with evidence

Turn the reading into a bounded operating record.

Use a template, inspect the mapped controls or answer the readiness assessment with only what your team can retrieve.

Operating templates32-control catalogueReadiness assessment