Resources

DPDPA & AI governance, sourced and dated

Every guide cites the primary statutory text and carries a "last verified" date. If the Act or Rules change, the guides change.

The TRACE Score: A Five-Dimension Framework for AI Tool Risk

Training behaviour, Residency, Audit certification, Compliance standard, Engagement terms — the five verifiable dimensions to document before approving any AI vendor.

The AI Governance RADAR: Five Questions That Test Your Actual Exposure

Registry, Awareness, Documentation, Access audit, Recency — a diagnostic you answer from documentation, not assumption. Most organisations cannot answer one.

The Permission Plane Model: Data Plane vs Control Plane Permissions

Mail.Read hands over every email; Application.Read.All only reveals which apps exist. Why a governance tool should never need data plane access.

The Ghost Token Problem: Why Offboarding Misses AI Tool Access

Deactivating a departing employee's account doesn't revoke the OAuth grants they created. Those tokens stay live until someone manually revokes them.

AI Access Governance: The Missing Layer Beneath Every AI Governance Programme

Data Governance and AI Governance both assume an accurate inventory of connected AI tools. Establishing that inventory is a discipline of its own — and it comes first.

DPDPA Compliance Deadlines: What's Due in Nov 2026 vs May 2027

Full enforcement lands 13 May 2027, with a separate 12-month milestone on 13 November 2026 — and a proposed earlier deadline for Significant Data Fiduciaries. What each date actually requires.

DPDPA Penalties: Every Fine in the Act, Explained

The full DPDPA 2023 penalty Schedule — all seven ceilings, how the Data Protection Board decides amounts, the misconceptions to avoid, and where AI tool usage fits.