DECISION
DISCOVER / IMPLEMENTATION ARCHITECTURE
Discovery and ownership
Make systems, data categories, purposes, owners and processors visible before deciding what should change.
Engineering layer
not a legal conclusion
DEFAULT OWNER MODEL
Privacy operations with named product, system and business owners
LEGAL / STATUS BOUNDARY
This layer is an implementation foundation. Its control records are engineering patterns, not standalone legal duties or proof of compliance.
Open status console →SOURCE / STATUS BOUNDARY
Verify the legal status before implementation.
These IDs are verification pointers to the primary-source ledger. They are not provision mappings, applicability findings or legal conclusions.
GOOD SYSTEM PATTERN
Build the path, then test the path.
A versioned processing inventory links each purpose to systems, collection surfaces, data categories, processors, owners and a review trigger.
EVIDENCE THAT SHOULD EXIST
- Approved inventory snapshot with a version and review date
- System-to-purpose relationship map
- Named business and technical owners
- Change record for new or materially altered processing
HOW THIS LAYER FAILS
- A spreadsheet exists but nobody owns its accuracy
- Processors and shadow collection surfaces are omitted
- Purpose labels are too broad to guide downstream controls
ARCHITECTURE → EVIDENCE DECISION JOURNEY
Follow the dependency, then inspect the proof.
Each connection uses existing catalogue records. Source IDs remain verification pointers—not provision mappings.
Add to a review route- Layer pathwayDiscovery and ownership
- 01 · PrerequisiteProcessing inventory ownership
Establish processing inventory ownership before expanding the architecture boundary.
Engineering indicator · not a legal requirement · Verification pointers: dpdp-act-2023 - 02 · Implementation patternProcessor and sub-processor register
Link approved providers to instructions, data flows, locations, assurance and exit work.
Engineering indicator · not a legal requirement · Verification pointers: dpdp-act-2023, dpdp-rules-2025, act-commencement-2025 - 03 · Validation / testTest DISC-01
Trace the sample from its trigger and owner through the implemented system to the retained evidence.
Engineering indicator · not a legal requirement · Verification pointers: dpdp-act-2023 - 04 · Evidence artefactApproved inventory snapshot with a version and review date
Primary retrievable output for discover; inspect the full layer evidence set before drawing a conclusion.
Engineering indicator · not a legal requirement · Verification pointers: dpdp-act-2023, act-commencement-2025 - 05 · Failure modeA spreadsheet exists but nobody owns its accuracy
A visible failure case keeps a completion label from hiding an evidence gap.
Engineering indicator · not a legal requirement · Verification pointers: dpdp-act-2023, act-commencement-2025 - 06 · Research noteFrom obligation to evidence: the DPDP implementation stack
Implementation teams benefit from separating legal interpretation from the engineering artefacts used to execute and test a decision. Radar context: Software and data-flow inventories is Adopt.
Editorial analysis · reviewed 2026-08-30 · sources act-commencement-2025, pib-status-2026 - 07 · Specialist propertyImplementation pathways
Explore implementation planning when the inventory is ready to drive work. This route remains optional if the destination is unavailable.
Contextual external property · no affiliation or availability implied
- 01 · PrerequisiteProcessing inventory ownership
Open semantic relationship table (1pathway)
| Record | Phase | Relationship | Status / boundary | Source pointers |
|---|---|---|---|---|
| Discovery and ownership | 01 · Prerequisite | Processing inventory ownership Establish processing inventory ownership before expanding the architecture boundary. | Engineering indicator · not a legal requirement · Verification pointers: dpdp-act-2023 | dpdp-act-2023 |
| Discovery and ownership | 02 · Implementation pattern | Processor and sub-processor register Link approved providers to instructions, data flows, locations, assurance and exit work. | Engineering indicator · not a legal requirement · Verification pointers: dpdp-act-2023, dpdp-rules-2025, act-commencement-2025 | dpdp-act-2023 · dpdp-rules-2025 · act-commencement-2025 |
| Discovery and ownership | 03 · Validation / test | Test DISC-01 Trace the sample from its trigger and owner through the implemented system to the retained evidence. | Engineering indicator · not a legal requirement · Verification pointers: dpdp-act-2023 | dpdp-act-2023 |
| Discovery and ownership | 04 · Evidence artefact | Approved inventory snapshot with a version and review date Primary retrievable output for discover; inspect the full layer evidence set before drawing a conclusion. | Engineering indicator · not a legal requirement · Verification pointers: dpdp-act-2023, act-commencement-2025 | dpdp-act-2023 · act-commencement-2025 |
| Discovery and ownership | 05 · Failure mode | A spreadsheet exists but nobody owns its accuracy A visible failure case keeps a completion label from hiding an evidence gap. | Engineering indicator · not a legal requirement · Verification pointers: dpdp-act-2023, act-commencement-2025 | dpdp-act-2023 · act-commencement-2025 |
| Discovery and ownership | 06 · Research note | From obligation to evidence: the DPDP implementation stack Implementation teams benefit from separating legal interpretation from the engineering artefacts used to execute and test a decision. Radar context: Software and data-flow inventories is Adopt. | Editorial analysis · reviewed 2026-08-30 · sources act-commencement-2025, pib-status-2026 | act-commencement-2025 · pib-status-2026 |
| Discovery and ownership | 07 · Specialist property | Implementation pathways Explore implementation planning when the inventory is ready to drive work. This route remains optional if the destination is unavailable. | Contextual external property · no affiliation or availability implied | None · contextual external route |
LOCAL WORKSPACE NOTE
Give this work a next owner.
Nothing is sent anywhere. Avoid names, personal data or confidential incident details.