Compliance Rule Builder
No-code IF/THEN engine. Every rule maps to a framework clause for end-to-end traceability.
When
Clause text contains "breach notification"
And
Notification window > 72 hours
Then flag
Critical · mapped to DPDP Sec. 8(6)
Rule triggered on 3 of 6 sample contracts
Avg match confidence: 94%
Breach notification ≤ 72 hours (DPDP Sec. 8(6))
R-101 · maps to Sec. 8(6) · Personal data breach notification
Sub-processor change consent (DPDP Sec. 8(2))
R-102 · maps to Sec. 8(2) · Accountability for sub-processors
Children's data parental consent (DPDP Sec. 9)
R-103 · maps to Sec. 9 · Processing of children's data
Cross-border transfer to notified country only (DPDP Sec. 16)
R-104 · maps to Sec. 16 · Cross-border transfer of personal data
Reasonable security safeguards (DPDP Sec. 8(5))
R-105 · maps to Sec. 8(5) · Reasonable security safeguards
Annual audit right for Significant Data Fiduciary (DPDP Sec. 10)
R-106 · maps to Sec. 10 · Significant Data Fiduciary obligations
Liability cap ≥ 24 months (internal)
R-107 · maps to INT-1 · Liability cap ≥ 24 months fees
Right to erasure + deletion certificate (DPDP Sec. 8(7))
R-108 · maps to Sec. 8(7) · Erasure on withdrawal / purpose completion
