RULE 12 – Measures to be undertaken by the Significant Data Fiduciary.
u/s 10(2)(c)(i) and (iii)
| No | Description |
| (1) | A Significant Data Fiduciary shall in addition to the measures provided under the Act undertake the following measures , namely:- |
| (a)Ensure that its Data Protection Officer shall be the point of contact for answering on its behalf, the questions, if any, raised by the Data Principal about the processing of her personal data | |
| (b)Include in the business contact information to be published under rule 9 a toll-free telephone number issued in India and an e-mail address for Data Principals to contact its Data Protection Officer: and | |
| (c)Undertake the periodic Data Protection Impact assessment and the periodic audit under the provisions of the Act at least once in every year. | |
| 2 | In this rule, the expression “every year” in relation to a Data Fiduciary, shall mean every period of one year reckoned from the date on which these rules come into force or such data fiduciary becomes a significant data fiduciary, whichever is later. |
Compliance Checklist — Rule 12 (Significant Data Fiduciary)
- Data Protection Officer (DPO) is appointed and designated as point of contact
- DPO contact details (email and toll-free number) are publicly available
- Mechanism exists to address queries from Data Principals effectively
- Periodic Data Protection Impact Assessment (DPIA) is conducted
- Independent data audits are carried out at least once every year
- Compliance processes are documented and regularly reviewed
- Internal governance framework ensures accountability and risk management