Intent on paper
Policies establish principles, roles, and expectations. They do not by themselves show the current location or treatment of sensitive data in a working estate.
PRIVACY CONTROL OUTCOMES
Policies and assessments describe intent. Operational confidence comes from showing where sensitive data exists, how it was classified, what control was applied, what evidence was produced, who reviewed it, and what approved remediation occurred. PDI turns that chain into a reviewable operating record across structured systems and source materials.
FIND · CLASSIFY · PROVE · REMEDIATE · EVIDENCE-LED PRIVACY OPERATIONS
Technical outcomes support customer and counsel review. Legal applicability and remediation approval remain with the customer and counsel.
The privacy control gap
A policy can define intent. A stated control can describe a planned process. Privacy control maturity requires a reviewable record of the data, the finding, the decision, and the bounded action taken—if an action is approved.
Policies establish principles, roles, and expectations. They do not by themselves show the current location or treatment of sensitive data in a working estate.
Assessments and control statements can describe a process. Reviewers still need the source, classification, decision, and approval context behind the result.
Evidence records, traceability, and review history make the technical outcome visible without turning it into a claim of legal sufficiency or universal compliance.
Four privacy control outcomes
The service framework is deliberately connected: a finding informs classification; classification carries context into evidence; evidence supports review; and only an approved decision can lead to bounded remediation.
Inventory PII across structured systems, attachments, PDFs, scans, images, and shared drives so the estate can be discussed from observed sources rather than assumptions.
Identify PII and sensitive categories with location and context, including the record or source material in which the finding appears.
Provide evidence records, traceability, and review chains that connect the technical finding to the decision made about it.
Mask, Vault, or Strip only approved supported structured data after the customer’s remediation decision and any applicable review.
Know what you actually hold
Privacy exposure is rarely limited to a database table. The service starts by establishing an inspection boundary that includes operational records and the source materials that travel with them.
Find, classify, and evidence PII in supported structured systems, with the location and context reviewers need to understand the control outcome.
Discover and classify PII in ERP and CRM attachments, PDFs, scans, images, and shared drives. These materials may be evidenced, but they are not represented as altered.
Inspection boundary
Aadhaar OCR remains detection, inventory, and review support only. It does not represent source-document alteration or a legal determination.
Turn findings into evidence
PDI connects the finding to its source and location, then carries the classification, review, decision, and approved action into one technical evidence chain. That supports customer and counsel review; it does not claim every statutory obligation has been addressed.
Record the PII category, source location, relevant context, and technical result produced by the discovery and classification workflow.
Keep the relationship between source finding, classification, review decision, and approved supported-structured-data remediation available for inspection.
Carry review and approval history with the evidence so the customer and counsel can decide legal applicability, holds, exceptions, and remediation scope.
From evidence to approved action
The service separates what is observed from what is decided. That distinction keeps the operational record useful while leaving legal applicability, holds, exceptions, and remediation approval with the customer and counsel.
Privacy control evidence in practice
PDI’s source-grounded evidence library helps put observable control outcomes in regulatory and enforcement context. These summaries are supporting reference points, not a substitute for legal analysis or a required step in understanding this service.
Evidence reference boundary
Library case records are scoped evidence references, not all-time government enforcement totals. Pending matters are excluded where the library says so, monetary figures remain in original currency, and shared multistate totals appear once nationally rather than being attributed in full to every state. A zero direct attribution does not mean zero enforcement. No reference establishes legal sufficiency or a compliance guarantee.
Jurisdiction control mappings
The service story does not require a buyer to read every case record. These concise mappings show how the evidence chain relates to the important control questions, while legal interpretation, applicability, and reporting decisions remain with the customer and counsel.
Articles 5(1)(c), 25. Inventory candidate PII and produce scoped evidence to support review of what is adequate, relevant, and limited.
Article 5(1)(e). Identify retained data and produce evidence for policy-led retention decisions; PDI does not set lawful retention periods.
Article 17. Locate candidate records and support approved structured-data actions, subject to legal holds and applicable exceptions.
Articles 5(2), 24, 30. Audit rows and evidence packs can support internal accountability work; they are not statutory records by themselves.
Article 32. Discovery and inventory can inform risk review. Security compliance requires wider technical and organizational measures.
Article 33. Evidence may support breach investigation; PDI does not decide reportability or whether notification is required.
These are service-level evidence mappings, not a complete legal checklist. The Evidence Library retains the selected enforcement examples, official-source links, and full jurisdiction notes.
The Act and Rules use staged commencement. The supplied research keeps the Gazette-date ambiguity and future Tranche 3 timing explicit; within the supplied library, completed monetary DPDP enforcement is 0 cases / ₹0.
Timing: Future Tranche 3 — 13/14 May 2027; plan to 12 May 2027 due to Gazette-date ambiguity.
Requirement: Encryption, obfuscation, masking or virtual tokens as reasonable security safeguards.
Control outcome: Mask / Vault / Strip for supported structured data, subject to policy and legal hold.
Boundary: Structured-data remediation only; it does not establish that the full safeguard duty is legally sufficient.
Timing: Future Tranche 3 — 13/14 May 2027; plan to 12 May 2027.
Requirement: Logs, monitoring and review enabling detection, investigation and remediation.
Control outcome: Kestryl audit row product capability supports review evidence.
Boundary: Audit rows support the control; they do not by themselves satisfy all monitoring, detection, investigation or remediation duties.
Timing: Future Tranche 3 — 13/14 May 2027; plan to 12 May 2027. The three-year dormancy and 48-hour notice mechanics are future.
Requirement: Erase on withdrawal or when the specified purpose is no longer served, whichever is earlier, unless legal retention is necessary. Rule 8/Third Schedule adds a three-year inactivity trigger only for specified classes and thresholds: e-commerce entities with at least 2 crore registered users, online gaming intermediaries with at least 50 lakh users, and social-media intermediaries with at least 2 crore users, subject to stated exclusions; give at least 48 hours’ pre-erasure notice.
Control outcome: Strip for supported structured data plus erasure evidence.
Boundary: Subject to policy, legal hold, applicable retention law, class/threshold scoping and downstream processor duties. Documents and attachments are inventoried, not altered.
Timing: Future Tranche 3 — 13/14 May 2027; plan to 12 May 2027.
Requirement: Inventory the nature, extent, timing and location of the breach; notify affected Data Principals without delay; notify the Board without delay and provide the detailed report within 72 hours of awareness, unless the Board allows longer on written request.
Control outcome: Discovery and inventory can support breach scoping and evidence preparation.
Boundary: Documents and attachments are scanned and inventoried, not altered. PDI does not send notices or determine legal reportability.
Timing: Future Tranche 3 — 13/14 May 2027; plan to 12 May 2027.
Requirement: The burden is on the Data Fiduciary to prove notice and consent only where consent is relied upon.
Control outcome: Evidence packs support review of notice/consent artefacts and related data locations.
Boundary: Evidence packs do not prove legal sufficiency, validity of consent, or that consent is the correct lawful basis.
Timing: Future Tranche 3 — 13/14 May 2027; plan to 12 May 2027.
Requirement: The Board must consider whether mitigation occurred and the timeliness and effectiveness of that action when determining a monetary penalty.
Control outcome: The discovery-to-review-to-remediation chain supports evidence of mitigation activity and timing.
Boundary: Technical evidence supports review; it does not determine the Board’s penalty or prove effectiveness.
Timing: Live now in the board paper; amended 25 January 2024 and 21 August 2025.
Requirement: Core biometric information may not be shared; core biometrics captured for authentication by a requesting entity may not be stored or shared; identity information is purpose- and consent-constrained.
Control outcome: OCR identifies Aadhaar text in scans, images and shared drives for inventory and review.
Boundary: PDI does not mask, redact or otherwise alter source documents or attachments.
The full DPDP mapping retains the official source links, commencement ledger, and educational-not-legal-advice qualification in the Evidence Library.
Evidence / control mapping
The evidence library groups its reference material through a ten-use-case key. It is a methodology for organizing a privacy-control discussion—not a legal checklist, representation that every obligation is covered, or a claim that a technical finding proves compliance.
The library retains its August 23, 2026 evidence snapshot, August 25, 2026 research verification/cutoff, and August 26, 2026 metadata modification markers as distinct dates with distinct meanings.
Delivery approach
Important control boundaries
Replace identified PII with a protected representation when the approved structured-data workflow requires the record to remain usable without exposing the original value.
Place an original value in a controlled, tokenized, key-recoverable vault only when that action is approved for supported structured data.
Remove identified PII from supported structured-data output when the approved remediation decision is permanent removal.
Non-negotiable boundary
Documents, PDFs, scans, images, and attachments may be discovered, classified, and evidenced, but must not be represented as source-document remediation. Aadhaar OCR remains detection, inventory, and review support only. Kestryl is enabling PDI product technology, not this service’s identity.
Why PDI / service outcome
Privacy Control Outcomes brings the technical estate, review context, evidence chain, and approved action into one PDI service posture. The objective is an observable privacy-control result—not a product feature pitch or a blanket compliance promise.
Next step
Tell us which systems and source materials need to be understood. We will define the evidence path, supported scope, and customer approval points in writing.
PACIFIC DATA INTEGRATORS · SERVICES · PRIVACY CONTROL OUTCOMES