Agent skill · Data & Analytics

dpdpa

Expert India Digital Personal Data Protection Act, 2023 (DPDPA) compliance advisor. Use this skill whenever a user asks about the DPDPA, DPDP Act, DPDP Rules 2025, India data privacy law, Data Fiduciary obligations, Data Principal rights, Significant Data Fiduciary, Data Protection Board of India, consent under DPDPA, notice requirements, breach notification India, children's data India, cross-border data transfer India, India privacy compliance, DPDPA gap analysis, DPDPA vs GDPR, or any obligation under India's personal data protection framework. Also trigger for: "Section 6 consent", "Sectio

Sushegaadgithub.com/SushegaadGitHub ↗
claude-codeMIT
Install
npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill dpdpa --agent claude-code

Same command for any agent — swap --agent for codex, cursor, copilot.

Facts
Files in the skill folder: 5
SKILL.md size: 26 KB
Bundled scripts: none
Path: plugins/dpdpa/skills/dpdpa/SKILL.md
Open the folder on GitHub →
Where it comes from
Stars: 801
Language: HTML

Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.

Review
written from the skill's own SKILL.md · Aug 5, 2026

What it does

The skill guides an AI agent to function as an India DPDPA compliance advisor. It covers the scope of digital personal data, two lawful bases for processing (Consent and Certain Legitimate Uses), and requires using DPDPA terminology (Data Fiduciary, Data Principal, Data Processor, Signficant Data Fiduciary, Data Protection Board). It instructs to cite obligations with section or rule numbers (e.g., Section X or Rule Y of the DPDP Rules 2025). It emphasizes phase-aware guidance with timelines, and to flag items dependent on future notifications.

How it works

It provides concrete, section-based guidance across core topics:

  • Data Fiduciary obligations (Sections 4–10): grounds for processing (Section 4), notice obligations (Section 5, Rule 3), consent (Section 6), legitimate uses (Section 7), general duties (Section 8), and children processing (Section 9).
  • Notice drafting requires Rule 3 elements: standalone notice, itemised data categories, purposes, recipients, retention, rights, Board complaint pathway, and withdrawal mechanism.
  • Consent criteria (Section 6): must be free, specific, informed, unconditional, unambiguous; details invalid forms of consent and withdrawal (Section 6(4)).
  • Certain Legitimate Uses (Section 7): eight enumerated purposes; emphasizes exhaustivity and non-derivation from “business necessity” concepts.
  • General obligations (Section 8): processor contracts (Rule 16), data quality, security safeguards (Rule 7), erasure on purpose fulfilment/withdrawal, breach notification timelines.
  • Children processing (Section 9) with parental consent (Section 9(1)) and verification methods (Rule 12), plus prohibited activities (Section 9(2)) and penalties.
  • SDF obligations (Section 10, Rule 13): DPO appointment, DPIA, independent data audits, data localization, and future-notified designations.

When to use it

Use when addressing specific DPDPA topics or conducting gap analyses, breach response planning, privacy policy reviews, consent mechanism reviews, rights request handling, SDF assessments, and children’s data controls. The skill frames guidance with explicit section/rule references and requires alignment to the Act and Rules timelines (e.g., full compliance deadline 13 May 2027). It also notes when guidance depends on unnotified items and to flag those accordingly.

What it can touch

  • Mentions and references to: Section 4–10, Section 6, Section 7, Section 8, Section 9, Section 10, Rule 3, Rule 6, Rule 7, Rule 12, Rule 13, Rule 16.
  • Discusses roles and terms: Data Fiduciary, Data Principal, Data Processor, Significant Data Fiduciary, Data Protection Board.
  • Advises on documentation outputs like gap analyses, notices, DPIAs, audits, and compliance roadmaps.

Caveats

  • Licenses under MIT.
  • Notes that as of April 2026, no SDF designations publicly exist yet; guidance may depend on future notifications.
  • Emphasizes digital-only scope and the absence of a general legitimate interests basis (only Consent or Certain Legitimate Uses).
  • Penalty details for children’s data violations (₹200 crore) are specified.
  • Requires referencing both Act and Rules where applicable; does not extrapolate beyond stated sections/rules.
From the SKILL.md

# India DPDPA — Digital Personal Data Protection Act, 2023 Skill > **Last verified:** 2026-07-03 You are an expert **India DPDPA compliance advisor** assisting **legal, privacy, and compliance teams** at Indian organisations AND global organisations that process personal data of individuals in India. Your knowledge covers the full text of the **Digital Personal Data Protection Act, 2023** (passed 11 August 2023) and the **Digital Personal Data Protection Rules, 2025** (notified 13 November 2025), which set the operative compliance timeline. **Full compliance deadline: 13 May 2027** (18 months from Rules notification). --- ## Foundational Rules 1. **Digital-only scope.** The DPDPA applies only to **digital personal data** — data in digital form, or data that is non-digital and subsequently digitised. Physical/paper records that are never digitised fall outside its scope. This is a critical difference from GDPR, which covers all personal data regardless of medium. 2. **Two lawful bases only.** Unlike GDPR's six lawful bases, the DPDPA provides only two: **(a) Consent** (Section 6) and **(b) Certain Legitimate Uses** (Section 7 — a closed list of eight enumerated categories). There is

What's inside
Steps it walks through
  1. Foundational Rules
  2. How to Respond
  3. DPDPA at a Glance
  4. Scope and Application (Sections 1 and 3)
  5. Chapter II — Data Fiduciary Obligations (Sections 4–10)
  6. Section 4 — Grounds for Processing
  7. Section 5 — Notice
  8. Section 6 — Consent
  9. Section 7 — Certain Legitimate Uses (Closed List)
  10. Section 8 — General Obligations of Data Fiduciary
  11. Section 9 — Processing of Personal Data of Children
  12. Section 10 — Additional Obligations of Significant Data Fiduciaries (SDFs)
  13. Chapter III — Rights and Duties of Data Principals (Sections 11–15)
  14. Data Principal Rights
Ships with 4 files
  • references/gdpr-comparison.md
  • references/rights-and-obligations.md
  • references/rules-2025.md
  • references/sections-reference.md
More from Claude-Skills-Governance-Risk-and-Compliance
All skills →
About this skill
What does the dpdpa skill do?

Expert India Digital Personal Data Protection Act, 2023 (DPDPA) compliance advisor. Use this skill whenever a user asks about the DPDPA, DPDP Act, DPDP Rules 2025, India data privacy law, Data Fiduciary obligations, Data Principal rights, Significant Data Fiduciary, Data Protection Board of India, consent under DPDPA, notice requirements, breach notification India, children's data India, cross-border data transfer India, India privacy compliance, DPDPA gap analysis, DPDPA vs GDPR, or any obligation under India's personal data protection framework. Also trigger for: "Section 6 consent", "Sectio

How do I install it?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill dpdpa --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.

Where does this skill come from?

From Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, a repository with 801 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.

Is a popular skill a good skill?

Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.

Keep going