Role guide
Legal and privacy counsel
Legal usually interprets the framework for the organisation and drafts what users see. The obligations still bind the organisation as a whole, and much of the delivery sits with other functions.
How to read this page. The obligations belong to your organisation, not to a role or a sector. Everything here is practical emphasis: which official duties this audience usually leads or feeds into, with links to the official text. Finishing one function's work never makes the company compliant by itself.
Work your function usually leads
Notice contentRule 3, official text →
The notice must stand alone, itemise the personal data and purposes, and point to withdrawal, rights and the complaint channel.
Verifiable consent design for children and guardiansRule 10, official text →
Choosing a lawful verification approach for parents and guardians is a legal design decision before it is a technical one.
Child data exemption analysisRule 12, official text →
Whether a Fourth Schedule child data exemption applies is conditional and needs legal judgment.
Research and statistics exemptionRule 16, official text →
Processing necessary for research, archiving or statistics can sit outside the Act when the Second Schedule standards are followed; deciding that is a legal call.
Work your function usually feeds into
Breach communicationsRule 7, official text →
The intimation to affected individuals must be plain and complete; legal usually reviews what security drafts.
Cross border transfer requirementsRule 15, official text →
Transfer restrictions depend on government orders that legal tracks.
Tools for this role
Tool
Privacy Notice Checker
Check whether your notice covers the elements the DPDP sources require.
Open
Tool
Children's Data Checker
See whether child data obligations or exemptions are triggered and what they require.
Open
Tool
DPDP vs GDPR Gap Checker
If you have a GDPR program, find the DPDP specific areas that need separate review.
Open