Short answer: One line per duty, with owner and evidence
Turn each duty into a risk line with an owner, a control, evidence and a review date. Map controls you already run for your regulator, auditors or certifications, so the same evidence serves several purposes. Track vendor risk separately.
What the law says
The Act sets duties in Sections 5 to 12. A risk register shows management where each duty stands.
Section 8(1)–(2): The organisation that decides why and how data is used (the Data Fiduciary) stays responsible, even when a vendor (Data Processor) does the work. A processor may be engaged only under a valid contract.
Section 8(5) · Rule 6: Protect personal data with reasonable security safeguards. Rule 6 lists the minimum: encryption, masking or tokenisation; access control; logs and monitoring; backups for continuity; keeping logs for at least one year; and security terms in contracts with processors.
Section 8(6) · Rule 7: On becoming aware of a personal data breach, tell each affected person and the Data Protection Board without delay. Send the Board a detailed report within 72 hours, or a longer period if the Board allows on request.
Section 10 · Rule 13: The government may notify organisations as Significant Data Fiduciaries based on the volume and sensitivity of data and the risk involved. They need a DPO based in India, an independent data auditor, and a yearly impact assessment and audit. None had been notified when this page was last reviewed.
Steps
List the duties that apply to you.
For each, write the risk in plain words, the control and the owner.
Chief risk officer: Split DPDP into separate duties. One line called 'DPDP compliance' hides where the risk actually is.
What a good answer from management sounds like
“DPDP sits in our risk register as separate duties, each with an owner, a control and evidence, reviewed every quarter.” Effort and time: Light · 2 to 4 weeks.