Sign in REQUIRED
This API only accepts requests from an authorized DPDP-Ready account. Sign in with your Supabase Auth email/password to get a session — every request below then carries it automatically.
Consent & Notice Engine R3 · R10 · R11
Capture consent for the seeded "Treatment" purpose. The child principal has no guardian verification yet — try capturing consent for them first.
Breach Response Workflow Rule 7
Report an incident, then dispatch the patient notice, the initial Board notice, and the detailed Board report — each is idempotency-guarded.
Retention Reconciliation Engine Rule 8
Set a DPDP-default vs. sector-law period for the Treatment purpose, then evaluate a principal's erasure timeline.
Vendor Contract Register Rule 6(f)
Register a processor contract. A missing security-safeguards clause is flagged regardless of renewal timing — review it to clear the flag, and pull a starter clause from the library below.
Rights-Request Portal Rule 14
Submit an access/correction/erasure/nomination request, then move it through the 90-day SLA workflow.
Compliance Dashboard CROSS-MODULE
Single-glance snapshot aggregating consent, breach, retention, vendor, rights, and audit status for this tenant — computed from each module's own overdue/risk logic, not re-derived here.
Audit Trail HASH-CHAINED
Every mutation across all five modules is written here, hash-chained so tampering is detectable — the evidence trail a Data Protection Board inquiry (Rule 19(9)) or a DPO's periodic review would need.