Free Interactive Tool · India DPDP

DPDP Brain Beta

An interactive knowledge graph of India's Digital Personal Data Protection Act 2023 and the DPDP Rules 2025 notified on 13 November 2025, mapped together. Every node is a cited concept, obligation, penalty, threshold or deadline; every line is a real connection. Search it, drag it, and click any node to read the provision and jump to the Rule that operationalises it or the penalty that backs it.

Read the free DPDP guide → Get DPDP updates

Hover a node to focus • drag • scroll to zoom • click for details
By type

Beta. These concepts are summarised from the text of the Digital Personal Data Protection Act, 2023 (No. 22 of 2023) and the Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E), 13 November 2025), with AI assistance. The framework is still moving: MeitY continues to notify, and the rules 3, 5 to 16, 22 and 23 tranche commences later. Penalties are maximums the Board may impose, not automatic fines. Always check the Section or Rule cited on a node against the official gazette text before relying on it. This is an educational resource, not legal advice. Spotted an error? Tell me and I will fix it.

Knowledge graph built with Google's Open Knowledge Format (OKF) · sourced from the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025.

How to use it

Filter by theme using the chips above the graph (Foundations, Consent & notice, Fiduciary duties, Consent Manager and more) to focus on one subsystem of the framework at a time.
Search a term like "provider", "biometric" or "penalty" to spotlight the matching nodes.
Hover a node to light up its direct connections and fade the rest, so a dense area reads clearly.
Click a node to read the article-cited rule, its tags, and its linked concepts in the Details tab, then click a related concept to travel the graph.
Browse the Concepts tab beside the graph for every concept in one scrollable list; filter it by name and click any row to light that node up.
Follow the arrows on a selected node: key links are labelled with a relationship (requires, triggers, comprises, penalizes), with the arrow pointing from cause to effect.
Filter by colour using the legend: concepts, processes, entities and facts. Toggle a type off to declutter.
Share a concept by copying the URL after you select a node; it deep-links straight back to that node.

Concept index

All 128 concepts in the graph, with their article references. Click any card to open it in the graph above.

conceptRule 13

Additional Obligations of a Significant Data Fiduciary

A Significant Data Fiduciary carries four additional obligations under rule 13: a periodic Data Protection Impact Assessment and audit, reporting significant observations to the Board, algorithmic due diligence, and a restriction on transferring specified personal data outside India.

conceptSection 10

Additional Obligations of a Significant Data Fiduciary (Act)

A Significant Data Fiduciary must appoint a Data Protection Officer and an independent data auditor, and must undertake a periodic Data Protection Impact Assessment, periodic audit, and such other measures as may be prescribed.

factRule 10

Adult Means Eighteen Years

For the purposes of verifiable parental consent, an adult means an individual who has completed the age of eighteen years.

factRule 13

Algorithmic Due Diligence by a Significant Data Fiduciary

A Significant Data Fiduciary must observe due diligence to verify that technical measures including algorithmic software adopted by it for hosting, display, uploading, modification, publishing, transmission, storage, updating or sharing of personal data are not likely to pose a risk to the rights of Data Principals.

factRule 13

Annual DPIA and Audit for a Significant Data Fiduciary

A Significant Data Fiduciary must, once in every period of twelve months from the date on which it is notified as such or included in a class notified as such, undertake a Data Protection Impact Assessment and an audit to ensure effective observance of the Act and the rules.

processRule 22

Appeal to the Appellate Tribunal

A person aggrieved by an order or direction of the Board may appeal to the Appellate Tribunal, filed in digital form as the Tribunal may decide, accompanied by a fee of like amount as applicable to an appeal under the Telecom Regulatory Authority of India Act, 1997.

processSection 29

Appeal to the Appellate Tribunal (Act)

Any person aggrieved by an order or direction made by the Board may prefer an appeal before the Appellate Tribunal, which may confirm, modify or set aside the order appealed against after giving the parties an opportunity of being heard.

conceptSection 3

Application of the Act

The Act applies to the processing of digital personal data within India where the data is collected in digital form, or in non-digital form and digitised subsequently, and to processing outside India where it is in connection with offering goods or services to Data Principals in India.

factRule 10

Authorised Entity (Defined)

An authorised entity means an entity entrusted by law or by the Central Government or a State Government with the issuance of details of identity and age or a virtual token mapped to such details, or a person appointed or permitted by such an entity for that issuance.

factFirst Schedule

Board Approval for Transfer of Control of a Consent Manager

The control of the company registered as a Consent Manager must not be transferred by way of sale, merger or otherwise except with the previous approval of the Data Protection Board and subject to fulfilment of such conditions as the Board may specify.

conceptRule 20

Board Functions as a Digital Office

The Board functions as a digital office and may adopt techno-legal measures to conduct proceedings in a manner that does not require the physical presence of any individual.

factSection 28

Board Has the Powers of a Civil Court

For discharging its functions the Board has the same powers as are vested in a civil court under the Code of Civil Procedure, 1908 in respect of summoning and enforcing attendance and examining on oath, receiving evidence on affidavit requiring discovery and production of documents, and inspecting any data, book, document, register or books of account.

processRule 7

Breach Intimation to Affected Data Principal

On becoming aware of a personal data breach, the Data Fiduciary must intimate each affected Data Principal, to the best of its knowledge, in a concise, clear and plain manner and without delay, through her user account or any mode of communication registered with it.

processRule 7

Breach Intimation to the Data Protection Board

On becoming aware of a personal data breach, the Data Fiduciary must intimate the Board without delay with a description of the breach, and follow it with a detailed report within seventy-two hours.

processRule 23, Seventh Schedule

Calling for Information from a Data Fiduciary or Intermediary

The Central Government may, for the purposes specified in the Seventh Schedule and acting through the corresponding authorised person, require any Data Fiduciary or intermediary to furnish such information as may be called for within the period specified.

factSection 36

Central Government Power to Call for Information

The Central Government may, for the purposes of the Act, require the Board and any Data Fiduciary or intermediary to furnish such information as it may call for.

conceptSection 7

Certain Legitimate Uses

A Data Fiduciary may process personal data without consent for the legitimate uses listed in section 7, which include voluntary provision by the Data Principal, State provision of a subsidy or benefit, medical emergencies, epidemics, disasters, and specified employment purposes.

factSection 2

Child Means Under Eighteen

A child means an individual who has not completed the age of eighteen years.

factSection 19, Section 20

Composition and Qualifications of the Board

The Board consists of a Chairperson and such number of other Members as the Central Government may notify, appointed by the Central Government, who must be persons of ability, integrity and standing with special knowledge or practical experience in specified fields, and at least one among them must be an expert in the field of law.

conceptFirst Schedule

Conditions for Registration of Consent Manager

Part A of the First Schedule sets nine conditions for registration as a Consent Manager, covering incorporation in India, capacity, financial soundness, net worth, reputation of management, constitutional documents, and independent certification of the platform.

entityRule 4

Consent Manager

A Consent Manager is a company registered with the Data Protection Board that provides an interoperable platform through which a Data Principal gives, manages, reviews and withdraws her consent to processing by Data Fiduciaries onboarded onto that platform.

factSection 6

Consent Manager Accountable to the Data Principal

A Data Principal may give, manage, review or withdraw her consent through a Consent Manager, who is accountable to the Data Principal and acts on her behalf, and every Consent Manager must be registered with the Board.

factFirst Schedule

Consent Manager Cannot Read the Personal Data It Routes

The Consent Manager must ensure that the manner of making available the personal data or its sharing is such that the contents are not readable by it.

factFirst Schedule

Consent Manager Cannot Sub-Contract Its Obligations

The Consent Manager must not sub-contract or assign the performance of any of its obligations under the Act and these rules.

factFirst Schedule

Consent Manager Conflict of Interest Controls

The Consent Manager must avoid conflict of interest with Data Fiduciaries, including in respect of their promoters and key managerial personnel, and must have measures in place to ensure no conflict arises from its own directors, key managerial personnel and senior management holding interests in Data Fiduciaries.

factFirst Schedule

Consent Manager Net Worth Threshold

The net worth of an applicant for registration as a Consent Manager must not be less than two crore rupees.

factFirst Schedule

Consent Manager Record Retention Period

A Consent Manager must maintain the record of consents, notices and data sharing for at least seven years, or for such longer period as the Data Principal and Consent Manager may agree upon or as may be required by law.

processRule 4

Consent Manager Registration Process

A person who fulfils the conditions in Part A of the First Schedule applies to the Data Protection Board for registration as a Consent Manager, and the Board either registers the applicant and publishes its particulars on its website or rejects the application and communicates the reasons.

factFirst Schedule

Consent Manager Two Per Cent Shareholding Disclosure

The Consent Manager must publish on its website or app every person who holds shares in excess of two per cent of its shareholding, alongside its promoters, directors, key managerial personnel and senior management.

factRule 6

Contractual Safeguards with a Data Processor

A Data Fiduciary must make appropriate provision in the contract entered into with a Data Processor, wherever applicable, for taking reasonable security safeguards.

factSection 10

Criteria for Notifying a Significant Data Fiduciary

The Central Government may notify any Data Fiduciary or class of Data Fiduciaries as a Significant Data Fiduciary on the basis of an assessment of relevant factors including the volume and sensitivity of personal data processed, risk to the rights of Data Principals, potential impact on the sovereignty and integrity of India, risk to electoral democracy, security of the State, and public order.

entitySection 2

Data Fiduciary (Defined)

A Data Fiduciary means any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data.

entitySection 2

Data Principal (Defined)

A Data Principal means the individual to whom the personal data relates, and where that individual is a child it includes the parents or lawful guardian, and where she is a person with disability it includes her lawful guardian acting on her behalf.

entitySection 2

Data Processor (Defined)

A Data Processor means any person who processes personal data on behalf of a Data Fiduciary.

entityRule 17

Data Protection Board of India

The Data Protection Board is the body that registers and supervises Consent Managers, receives personal data breach intimations and Significant Data Fiduciary audit reports, and conducts inquiries, functioning as a digital office.

factSection 10

Data Protection Officer Requirements

The Data Protection Officer appointed by a Significant Data Fiduciary must represent it under the Act, be based in India, be an individual responsible to its Board of Directors or similar governing body, and be the point of contact for the grievance redressal mechanism.

entityRule 10

Digital Locker Service Provider

A Digital Locker service provider means an intermediary, including a body corporate or an agency of the appropriate Government, notified by the Central Government in accordance with the rules made in that regard under the Information Technology Act, 2000.

conceptSection 1

Digital Personal Data Protection Act, 2023

The Digital Personal Data Protection Act, 2023 (No. 22 of 2023) received the assent of the President on 11 August 2023 and provides for the processing of digital personal data in a manner that recognises both the right of individuals to protect their personal data and the need to process such data for lawful purposes.

conceptRule 1

Digital Personal Data Protection Rules, 2025

The Digital Personal Data Protection Rules, 2025 are the subordinate legislation made under section 40 of the Digital Personal Data Protection Act, 2023, notified by G.S.R. 846(E) on 13 November 2025.

factRule 23

Direction Not to Disclose a Government Information Request

Where disclosure of the furnishing of information is likely to prejudicially affect the sovereignty and integrity of India or the security of the State, the Central Government may require the Data Fiduciary or intermediary not to disclose it to the affected Data Principal or any other person except with the previous permission in writing of the authorised person.

factSection 21, Section 22

Disqualifications and Post-Office Restrictions for Board Members

A person is disqualified from being appointed and continued as Chairperson or Member if she is an undischarged insolvent, has been convicted of an offence involving moral turpitude in the opinion of the Central Government, has become physically or mentally incapable of acting, has acquired a prejudicial financial or other interest, or has so abused her position as to render her continuance prejudicial to the public interest.

factSection 15

Duties of a Data Principal

A Data Principal must comply with applicable laws while exercising her rights, must not impersonate another person or suppress material information when providing personal data, must not register a false or frivolous grievance or complaint, and must furnish only verifiably authentic information when exercising the right to correction or erasure.

factThird Schedule

E-Commerce Entity Retention Threshold

A Data Fiduciary that is an e-commerce entity having not less than two crore registered users in India must erase personal data three years from the date the Data Principal last approached it for the specified purpose or exercised her rights, or from the commencement of these Rules, whichever is latest.

factRule 6

Encryption, Obfuscation, Masking or Virtual Tokens

Appropriate data security measures required of a Data Fiduciary include securing personal data through encryption, obfuscation, masking or the use of virtual tokens mapped to that personal data.

conceptRule 8, Third Schedule

Erasure When the Specified Purpose Is Deemed No Longer Served

A Data Fiduciary of a class specified in the Third Schedule must erase personal data once the corresponding time period has elapsed without the Data Principal approaching it for the specified purpose or exercising her rights, unless retention is necessary for compliance with any law in force.

factSection 18

Establishment of the Data Protection Board of India

With effect from such date as the Central Government may notify, there shall be established a Board called the Data Protection Board of India, which is a body corporate with perpetual succession and a common seal, able to acquire, hold and dispose of property and to contract, sue and be sued.

factSection 17

Exemption for Notified Startups

The Central Government may, having regard to the volume and nature of personal data processed, notify certain Data Fiduciaries or classes of Data Fiduciaries, including startups, to whom section 5, sub-sections (3) and (7) of section 8, and sections 10 and 11 do not apply.

factSection 17

Exemption for Notified State Instrumentalities

The Act does not apply to the processing of personal data by such instrumentality of the State as the Central Government may notify, in the interests of sovereignty and integrity of India, security of the State, friendly relations with foreign States, maintenance of public order or preventing incitement to any cognizable offence relating to any of these, nor to the processing by the Central Government of personal data such an instrumentality may furnish to it.

factSection 17

Exemption for Research, Archiving or Statistical Purposes

The Act does not apply to processing necessary for research, archiving or statistical purposes if the personal data is not to be used to take any decision specific to a Data Principal and the processing is carried on in accordance with such standards as may be prescribed.

factRule 16, Second Schedule

Exemption for Research, Archiving or Statistical Purposes

The provisions of the Act do not apply to the processing of personal data necessary for research, archiving or statistical purposes if that processing is carried on in accordance with the standards specified in the Second Schedule.

conceptRule 12, Fourth Schedule

Exemptions from Certain Obligations for Children’s Personal Data

The provisions of sub-sections (1) and (3) of section 9 of the Act do not apply to the processing of a child’s personal data by the classes of Data Fiduciaries in Part A of the Fourth Schedule, or for the purposes in Part B, subject to the conditions specified in the relevant Part.

conceptSection 17

Exemptions from Chapter II, Chapter III and Section 16

The provisions of Chapter II, except sub-sections (1) and (5) of section 8, and those of Chapter III and section 16 do not apply where processing is necessary for enforcing a legal right or claim, for judicial or regulatory functions, for the prevention or investigation of offences, for certain contracts with persons outside India, for corporate restructuring approved by a court or authority, or for ascertaining the financial information of a loan defaulter.

factSection 33

Factors in Determining the Amount of a Penalty

In determining the amount of a monetary penalty the Board must have regard to the nature, gravity and duration of the breach, the type and nature of the personal data affected, whether the breach is repetitive, whether the person realised a gain or avoided a loss, what mitigating action was taken and how timely and effective it was, whether the penalty is proportionate and effective, and the likely impact of the penalty on the person.

factRule 8

Forty-Eight Hour Notice Before Erasure

At least forty-eight hours before completion of the time period for erasure, the Data Fiduciary must inform the Data Principal that her personal data will be erased on completion of that period.

conceptFourth Schedule

Fourth Schedule Part A: Exempt Classes of Data Fiduciaries

Part A of the Fourth Schedule exempts five classes of Data Fiduciaries from sections 9(1) and 9(3) for children’s data: clinical, mental health and healthcare establishments and professionals, allied healthcare professionals, educational institutions, individuals entrusted with children in a creche or day care centre, and persons engaged for the transport of children.

conceptFourth Schedule

Fourth Schedule Part B: Exempt Purposes

Part B of the Fourth Schedule exempts six purposes from sections 9(1) and 9(3) for children’s data, each restricted to the extent necessary for that purpose.

conceptSection 8

General Obligations of a Data Fiduciary

A Data Fiduciary is responsible for complying with the Act and the rules made under it in respect of any processing undertaken by it or on its behalf by a Data Processor, irrespective of any agreement to the contrary or any failure by the Data Principal to carry out her duties.

conceptSection 4

Grounds for Processing Personal Data

A person may process the personal data of a Data Principal only in accordance with the Act and for a lawful purpose, either for which the Data Principal has given her consent or for certain legitimate uses.

factRule 14

Identifier (Defined)

An identifier means any sequence of characters issued by the Data Fiduciary to identify the Data Principal, and includes a customer identification file number, customer acquisition form number, application reference number, enrolment ID, email address, mobile number or licence number that enables such identification.

entitySection 10

Independent Data Auditor

A Significant Data Fiduciary must appoint an independent data auditor to carry out data audit, who evaluates its compliance in accordance with the provisions of the Act.

factRule 3

Itemised Description Requirement in Notice

The notice must state, at the minimum, an itemised description of the personal data and the specified purpose or purposes together with a specific description of the goods or services to be provided or uses to be enabled by the processing.

factRule 13

Localisation Restriction on Specified Personal Data

A Significant Data Fiduciary must ensure that personal data specified by the Central Government, on the recommendations of a committee constituted by it, is processed subject to the restriction that the personal data and the traffic data pertaining to its flow are not transferred outside the territory of India.

factSection 31

Mediation of Complaints

If the Board is of the opinion that any complaint may be resolved by mediation, it may direct the parties concerned to attempt resolution of the dispute through such mediator as the parties may mutually agree upon, or as provided for under any law in force in India.

factRule 14

Ninety-Day Grievance Redressal Period

Every Data Fiduciary and Consent Manager must publish the period, not exceeding ninety days, within which it will respond to grievances of Data Principals under its grievance redressal system.

factSection 5

Notice Accompanying a Request for Consent

Every request for consent must be accompanied or preceded by a notice informing the Data Principal of the personal data and the purpose of processing, the manner in which she may exercise her rights under section 6(4) and section 13, and the manner of making a complaint to the Board.

conceptRule 3

Notice Given by Data Fiduciary to Data Principal

The notice given by a Data Fiduciary to a Data Principal must give a fair account, in clear and plain language, of the details necessary to enable her to give specific and informed consent to the processing of her personal data.

factRule 3

Notice Must Be Understandable Independently

The notice must be presented and be understandable independently of any other information that has been, is or may be made available by the Data Fiduciary.

factSection 8

Obligation to Erase Personal Data

Unless retention is necessary for compliance with any law in force, a Data Fiduciary must erase personal data upon the Data Principal withdrawing her consent or as soon as it is reasonable to assume that the specified purpose is no longer being served, whichever is earlier, and must cause its Data Processor to erase any personal data made available to it.

factSection 8

Obligation to Establish a Grievance Redressal Mechanism

A Data Fiduciary must establish an effective mechanism to redress the grievances of Data Principals.

factSection 8

Obligation to Intimate a Personal Data Breach

In the event of a personal data breach, the Data Fiduciary must give the Board and each affected Data Principal intimation of the breach, in such form and manner as may be prescribed.

factSection 8

Obligation to Publish Contact Information

A Data Fiduciary must publish, in such manner as may be prescribed, the business contact information of a Data Protection Officer if applicable, or of a person who is able to answer on its behalf the questions raised by a Data Principal about the processing of her personal data.

factSection 8

Obligation to Take Reasonable Security Safeguards

A Data Fiduciary must protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach.

conceptFirst Schedule

Obligations of Consent Manager

Part B of the First Schedule imposes thirteen obligations on a Consent Manager, covering consent routing, record keeping, platform maintenance, security, fiduciary conduct, conflict of interest, transparency and audit.

factRule 19

One-Third Quorum for Board Meetings

One-third of the membership of the Board is the quorum for its meetings.

factRule 8, Seventh Schedule

One-Year Minimum Retention of Processing Logs

For processing undertaken by a Data Fiduciary or on its behalf by a Data Processor, personal data, associated traffic data and other logs of the processing must be retained for a minimum of one year from the date of that processing, for the purposes specified in the Seventh Schedule.

factRule 6

One-Year Retention of Logs for Breach Detection

To enable detection of unauthorised access, its investigation and remediation, a Data Fiduciary must retain logs and personal data for a period of one year unless compliance with any law in force requires otherwise.

factThird Schedule

Online Gaming Intermediary Retention Threshold

A Data Fiduciary that is an online gaming intermediary having not less than fifty lakh registered users in India must erase personal data three years from the date the Data Principal last approached it for the specified purpose or exercised her rights, or from the commencement of these Rules, whichever is latest.

conceptSection 33, Schedule to the Act

Penalties and Adjudication

If the Board determines on conclusion of an inquiry that a breach of the Act or the rules by a person is significant, it may, after giving that person an opportunity of being heard, impose the monetary penalty specified in the Schedule.

factSection 34

Penalties Credited to the Consolidated Fund of India

All sums realised by way of penalties imposed by the Board under the Act are credited to the Consolidated Fund of India.

factSchedule to the Act

Penalty for Breach of a Voluntary Undertaking

Breach of any term of a voluntary undertaking accepted by the Board under section 32 carries a penalty up to the extent applicable for the breach in respect of which the proceedings under section 28 were instituted.

factSchedule to the Act

Penalty for Breach of Data Principal Duties

Breach in observance of the duties under section 15 may extend to ten thousand rupees.

factSchedule to the Act

Penalty for Breach of Obligations Relating to Children

Breach in observance of additional obligations in relation to children under section 9 may extend to two hundred crore rupees.

factSchedule to the Act

Penalty for Breach of Significant Data Fiduciary Obligations

Breach in observance of the additional obligations of a Significant Data Fiduciary under section 10 may extend to one hundred and fifty crore rupees.

factSchedule to the Act

Penalty for Failing to Notify a Personal Data Breach

Breach in observing the obligation to give the Board or affected Data Principals notice of a personal data breach under section 8(6) may extend to two hundred crore rupees.

factSchedule to the Act

Penalty for Failing to Take Reasonable Security Safeguards

Breach in observing the obligation of a Data Fiduciary to take reasonable security safeguards to prevent personal data breach under section 8(5) may extend to two hundred and fifty crore rupees.

factSection 2

Personal Data (Defined)

Personal data means any data about an individual who is identifiable by or in relation to such data.

factSection 2

Personal Data Breach (Defined)

A personal data breach means any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data.

factSection 42, Schedule to the Act

Power to Amend the Schedule, Capped at Double

The Central Government may by notification amend the Schedule, subject to the restriction that no such notification may increase any penalty specified in it to more than twice what was specified when the Act was originally enacted.

factSection 37

Power to Block Access After Repeated Penalties

On a written reference from the Board that a monetary penalty has been imposed on a Data Fiduciary in two or more instances, and that blocking is advised in the interests of the general public, the Central Government may, after giving that Data Fiduciary an opportunity of being heard and for reasons recorded in writing, direct any agency or intermediary to block public access to the information enabling it to offer goods or services in India.

factSection 40

Power to Make Rules

The Central Government may, by notification and subject to the condition of previous publication, make rules not inconsistent with the Act to carry out its purposes, and section 40(2) lists twenty-six specific matters for which rules may provide.

factSection 16

Power to Restrict Cross-Border Transfer

The Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified.

conceptSection 27

Powers and Functions of the Board

The Board inquires into personal data breaches and breaches of obligations and imposes penalties, acting on an intimation of breach under section 8(6), on a complaint by a Data Principal, on a reference by the Central or a State Government, in compliance with court directions, on an intimation of breach of a Consent Manager’s registration conditions, or on a reference regarding an intermediary under section 37(2).

factSection 9

Prohibition on Tracking and Targeted Advertising to Children

A Data Fiduciary must not undertake processing of personal data that is likely to cause any detrimental effect on the well-being of a child, and must not undertake tracking or behavioural monitoring of children or targeted advertising directed at children.

factRule 9

Publication of Contact Information for Processing Queries

Every Data Fiduciary must prominently publish on its website or app, and mention in every response to a communication for the exercise of a Data Principal’s rights, the business contact information of the Data Protection Officer if applicable, or of a person able to answer questions about the processing on its behalf.

conceptRule 14

Publication of the Means to Exercise Data Principal Rights

To enable Data Principals to exercise their rights, the Data Fiduciary and, where applicable, the Consent Manager must prominently publish on its website or app the details of the means of making a request and the particulars required to identify the Data Principal.

conceptRule 6

Reasonable Security Safeguards

A Data Fiduciary must protect personal data in its possession or under its control, including any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach.

factSchedule to the Act

Residual Penalty for Any Other Breach

Breach of any other provision of the Act or the rules made thereunder may extend to fifty crore rupees.

factSection 13

Right of Grievance Redressal

A Data Principal has the right to readily available means of grievance redressal provided by a Data Fiduciary or Consent Manager, and must exhaust the opportunity of redressing her grievance under this section before approaching the Board.

factSection 11

Right to Access Information About Personal Data

A Data Principal has the right to obtain from the Data Fiduciary a summary of the personal data being processed and the processing activities undertaken, the identities of all other Data Fiduciaries and Data Processors with whom the data has been shared along with a description of what was shared, and any other prescribed information.

factSection 12

Right to Correction, Completion, Updating and Erasure

A Data Principal has the right to correction, completion, updating and erasure of her personal data for processing to which she has previously consented, and on receiving a request the Data Fiduciary must correct inaccurate or misleading data, complete incomplete data, and update the data.

factSection 14

Right to Nominate

A Data Principal has the right to nominate any other individual who shall, in the event of her death or incapacity, exercise her rights under the Act and the rules in accordance with the prescribed manner.

factRule 14

Right to Nominate an Individual

To exercise her right to nominate under the Act, a Data Principal may nominate one or more individuals in accordance with the terms of service of the Data Fiduciary and such law as may be applicable, using the means and furnishing the particulars required by that Data Fiduciary.

factSection 6

Right to Withdraw Consent

Where consent is the basis of processing, the Data Principal has the right to withdraw her consent at any time, with the ease of doing so being comparable to the ease with which the consent was given.

factFifth Schedule

Salary of the Chairperson and Members

The Chairperson receives a consolidated salary of four lakh fifty thousand rupees per month and every other Member four lakh rupees per month, in both cases without the facility of house and car.

processRule 17

Search-cum-Selection Committee for Board Appointments

Two separate Search-cum-Selection Committees recommend individuals for appointment: one chaired by the Cabinet Secretary for the Chairperson, and one chaired by the Secretary of the Ministry of Electronics and Information Technology for other Members.

conceptSecond Schedule

Second Schedule Standards for Lawful Processing

The Second Schedule requires implementation of appropriate technical and organisational measures ensuring eight standards: lawful processing, purpose limitation, data minimisation, accuracy, retention limitation, security safeguards, intimation to the Data Principal, and accountability.

factRule 19

Seven-Day Communication of Emergent Board Action

Where an emergent situation warrants immediate action by the Board and it is not feasible to call a meeting, the Chairperson may take such action as may be necessary while recording the reasons in writing, and it must be communicated within seven days to all Members and laid before the Board for ratification at its next meeting.

factRule 7

Seventy-Two Hour Breach Report to the Board

The detailed breach report must reach the Board within seventy-two hours of the Data Fiduciary becoming aware of the breach, or within such longer period as the Board may allow on a request made in writing.

factSection 2

Significant Data Fiduciary (Defined)

A Significant Data Fiduciary means any Data Fiduciary or class of Data Fiduciaries as may be notified by the Central Government under section 10.

factSection 29

Six-Month Endeavour to Dispose of an Appeal

An appeal must be dealt with as expeditiously as possible and endeavour must be made to dispose of it finally within six months from the date on which it is presented, and where it is not, the Appellate Tribunal must record its reasons in writing.

factRule 19

Six-Month Period for Completing a Board Inquiry

An inquiry by the Board must be completed within six months from the date of receipt of the intimation, complaint, reference or direction under section 27 of the Act, unless the period is extended by the Board for reasons recorded in writing for a further period not exceeding three months at a time.

factSection 29

Sixty-Day Window to File an Appeal

An appeal must be filed within sixty days from the date of receipt of the order or direction appealed against, in such form and manner and accompanied by such fee as may be prescribed.

factThird Schedule

Social Media Intermediary Retention Threshold

A Data Fiduciary that is a social media intermediary having not less than two crore registered users in India must erase personal data three years from the date the Data Principal last approached it for the specified purpose or exercised her rights, or from the commencement of these Rules, whichever is latest.

factRule 1

Staggered Commencement of the Rules

The Rules commence in three tranches: rules 1, 2 and 17 to 21 on publication, rule 4 one year after publication, and rules 3, 5 to 16, 22 and 23 eighteen months after publication.

conceptRule 5, Second Schedule

State Processing for Subsidy, Benefit, Service, Certificate, Licence or Permit

Processing of personal data by the State and its instrumentalities for the provision or issue of a subsidy, benefit, service, certificate, licence or permit must be done following the standards specified in the Second Schedule.

processRule 4

Suspension or Cancellation of Consent Manager Registration

Where the Board is satisfied that it is necessary in the interests of Data Principals, it may, after giving the Consent Manager an opportunity of being heard and by order recording reasons in writing, suspend or cancel the registration and give such directions as it deems fit.

factRule 2

Techno-Legal Measures (Defined)

Techno-legal measures means the measures referred to under rules 20 and 22.

factSection 38, Section 39

The Act Prevails in the Event of Conflict

The Act is in addition to and not in derogation of any other law in force, and in the event of conflict between a provision of the Act and a provision of any other law, the Act prevails to the extent of the conflict.

factSection 6

The Standard of Valid Consent

Consent must be free, specific, informed, unconditional and unambiguous with a clear affirmative action, and must signify agreement to the processing of personal data for the specified purpose, limited to such personal data as is necessary for that purpose.

conceptRule 15

Transfer of Personal Data Outside India

Personal data processed by a Data Fiduciary may be transferred outside the territory of India subject to the restriction that the Data Fiduciary meets such requirements as the Central Government may specify by general or special order in respect of making that personal data available to any foreign State, or to any person or entity under the control of or any agency of such a State.

factSection 30

Tribunal Orders Executable as a Civil Court Decree

An order passed by the Appellate Tribunal under the Act is executable by it as a decree of civil court, and for that purpose the Tribunal has all the powers of a civil court.

factRule 2

User Account (Defined)

A user account is the online account registered by the Data Principal with the Data Fiduciary, including any profiles, pages, handles, email address, mobile number and other similar presences through which the Data Principal accesses that Data Fiduciary’s services.

factRule 2

Verifiable Consent (Defined)

Verifiable consent means a consent as specified in rule 10 or rule 11.

processRule 11

Verifiable Consent from a Lawful Guardian

A Data Fiduciary obtaining verifiable consent from an individual identifying herself as the lawful guardian of a person with disability must observe due diligence to verify that the guardian is appointed by a court of law, or by a designated authority or a local level committee, under the law applicable to guardianship.

processRule 10

Verifiable Parental Consent for a Child

A Data Fiduciary must adopt appropriate technical and organisational measures to ensure that verifiable consent of the parent is obtained before processing any personal data of a child, and must observe due diligence to check that the individual identifying herself as the parent is an adult who is identifiable if required under any law in force in India.

factSection 9

Verifiable Parental Consent Obligation

Before processing any personal data of a child or of a person with disability who has a lawful guardian, the Data Fiduciary must obtain verifiable consent of the parent or the lawful guardian, in such manner as may be prescribed.

processSection 32

Voluntary Undertaking

The Board may accept a voluntary undertaking in respect of any matter related to observance of the Act from any person at any stage of a proceeding, and acceptance bars proceedings as regards the contents of that undertaking.

factRule 3

Withdrawal of Consent Comparable in Ease to Giving It

The notice must describe the means by which the Data Principal may withdraw her consent, with the ease of doing so being comparable to that with which such consent was given.