| Data and purpose inventory | Before notice and consent design | System register, purpose map, processor list, retention rule and accountable owner. |
| Notices and consent | Operational by 13 May 2027 | Versioned notice, purpose IDs, affirmative-action log, withdrawal path and downstream propagation test. |
| Security and processor governance | Operational by 13 May 2027 | Safeguard standard, access controls, logging, backups, incident detection and appropriate processor contract terms. |
| Breach response | Operational by 13 May 2027 | Detection route, decision authority, Data Principal notice, Board intimation workflow and 72-hour information pack. |
| Rights and grievance handling | Operational by 13 May 2027 | Published channel, identity standard, system search list, response record, escalation and contact information. |
| Children and special cases | Operational by 13 May 2027 | Age and parental-consent method, tracking restrictions, exemption analysis and product-control tests. |