Beta. These concepts are summarised from the text of the Digital Personal Data Protection Act, 2023 (No. 22 of 2023) and the Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E), 13 November 2025), with AI assistance. The framework is still moving: MeitY continues to notify, and the rules 3, 5 to 16, 22 and 23 tranche commences later. Penalties are maximums the Board may impose, not automatic fines. Always check the Section or Rule cited on a node against the official gazette text before relying on it. This is an educational resource, not legal advice. Spotted an error? Tell me and I will fix it.
Knowledge graph built with Google's Open Knowledge Format (OKF) · sourced from the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025.
How to use it
Concept index
All 128 concepts in the graph, with their article references. Click any card to open it in the graph above.
Additional Obligations of a Significant Data Fiduciary
A Significant Data Fiduciary carries four additional obligations under rule 13: a periodic Data Protection Impact Assessment and audit, reporting significant observations to the Board, algorithmic due diligence, and a restriction on transferring specified personal data outside India.
Additional Obligations of a Significant Data Fiduciary (Act)
A Significant Data Fiduciary must appoint a Data Protection Officer and an independent data auditor, and must undertake a periodic Data Protection Impact Assessment, periodic audit, and such other measures as may be prescribed.
Adult Means Eighteen Years
For the purposes of verifiable parental consent, an adult means an individual who has completed the age of eighteen years.
Algorithmic Due Diligence by a Significant Data Fiduciary
A Significant Data Fiduciary must observe due diligence to verify that technical measures including algorithmic software adopted by it for hosting, display, uploading, modification, publishing, transmission, storage, updating or sharing of personal data are not likely to pose a risk to the rights of Data Principals.
Annual DPIA and Audit for a Significant Data Fiduciary
A Significant Data Fiduciary must, once in every period of twelve months from the date on which it is notified as such or included in a class notified as such, undertake a Data Protection Impact Assessment and an audit to ensure effective observance of the Act and the rules.
Appeal to the Appellate Tribunal
A person aggrieved by an order or direction of the Board may appeal to the Appellate Tribunal, filed in digital form as the Tribunal may decide, accompanied by a fee of like amount as applicable to an appeal under the Telecom Regulatory Authority of India Act, 1997.
Appeal to the Appellate Tribunal (Act)
Any person aggrieved by an order or direction made by the Board may prefer an appeal before the Appellate Tribunal, which may confirm, modify or set aside the order appealed against after giving the parties an opportunity of being heard.
Application of the Act
The Act applies to the processing of digital personal data within India where the data is collected in digital form, or in non-digital form and digitised subsequently, and to processing outside India where it is in connection with offering goods or services to Data Principals in India.
Authorised Entity (Defined)
An authorised entity means an entity entrusted by law or by the Central Government or a State Government with the issuance of details of identity and age or a virtual token mapped to such details, or a person appointed or permitted by such an entity for that issuance.
Board Approval for Transfer of Control of a Consent Manager
The control of the company registered as a Consent Manager must not be transferred by way of sale, merger or otherwise except with the previous approval of the Data Protection Board and subject to fulfilment of such conditions as the Board may specify.
Board Functions as a Digital Office
The Board functions as a digital office and may adopt techno-legal measures to conduct proceedings in a manner that does not require the physical presence of any individual.
Board Has the Powers of a Civil Court
For discharging its functions the Board has the same powers as are vested in a civil court under the Code of Civil Procedure, 1908 in respect of summoning and enforcing attendance and examining on oath, receiving evidence on affidavit requiring discovery and production of documents, and inspecting any data, book, document, register or books of account.
Breach Intimation to Affected Data Principal
On becoming aware of a personal data breach, the Data Fiduciary must intimate each affected Data Principal, to the best of its knowledge, in a concise, clear and plain manner and without delay, through her user account or any mode of communication registered with it.
Breach Intimation to the Data Protection Board
On becoming aware of a personal data breach, the Data Fiduciary must intimate the Board without delay with a description of the breach, and follow it with a detailed report within seventy-two hours.
Calling for Information from a Data Fiduciary or Intermediary
The Central Government may, for the purposes specified in the Seventh Schedule and acting through the corresponding authorised person, require any Data Fiduciary or intermediary to furnish such information as may be called for within the period specified.
Central Government Power to Call for Information
The Central Government may, for the purposes of the Act, require the Board and any Data Fiduciary or intermediary to furnish such information as it may call for.
Certain Legitimate Uses
A Data Fiduciary may process personal data without consent for the legitimate uses listed in section 7, which include voluntary provision by the Data Principal, State provision of a subsidy or benefit, medical emergencies, epidemics, disasters, and specified employment purposes.
Child Means Under Eighteen
A child means an individual who has not completed the age of eighteen years.
Composition and Qualifications of the Board
The Board consists of a Chairperson and such number of other Members as the Central Government may notify, appointed by the Central Government, who must be persons of ability, integrity and standing with special knowledge or practical experience in specified fields, and at least one among them must be an expert in the field of law.
Conditions for Registration of Consent Manager
Part A of the First Schedule sets nine conditions for registration as a Consent Manager, covering incorporation in India, capacity, financial soundness, net worth, reputation of management, constitutional documents, and independent certification of the platform.
Consent Manager
A Consent Manager is a company registered with the Data Protection Board that provides an interoperable platform through which a Data Principal gives, manages, reviews and withdraws her consent to processing by Data Fiduciaries onboarded onto that platform.
Consent Manager Accountable to the Data Principal
A Data Principal may give, manage, review or withdraw her consent through a Consent Manager, who is accountable to the Data Principal and acts on her behalf, and every Consent Manager must be registered with the Board.
Consent Manager Cannot Read the Personal Data It Routes
The Consent Manager must ensure that the manner of making available the personal data or its sharing is such that the contents are not readable by it.
Consent Manager Cannot Sub-Contract Its Obligations
The Consent Manager must not sub-contract or assign the performance of any of its obligations under the Act and these rules.
Consent Manager Conflict of Interest Controls
The Consent Manager must avoid conflict of interest with Data Fiduciaries, including in respect of their promoters and key managerial personnel, and must have measures in place to ensure no conflict arises from its own directors, key managerial personnel and senior management holding interests in Data Fiduciaries.
Consent Manager Net Worth Threshold
The net worth of an applicant for registration as a Consent Manager must not be less than two crore rupees.
Consent Manager Record Retention Period
A Consent Manager must maintain the record of consents, notices and data sharing for at least seven years, or for such longer period as the Data Principal and Consent Manager may agree upon or as may be required by law.
Consent Manager Registration Process
A person who fulfils the conditions in Part A of the First Schedule applies to the Data Protection Board for registration as a Consent Manager, and the Board either registers the applicant and publishes its particulars on its website or rejects the application and communicates the reasons.
Consent Manager Two Per Cent Shareholding Disclosure
The Consent Manager must publish on its website or app every person who holds shares in excess of two per cent of its shareholding, alongside its promoters, directors, key managerial personnel and senior management.
Contractual Safeguards with a Data Processor
A Data Fiduciary must make appropriate provision in the contract entered into with a Data Processor, wherever applicable, for taking reasonable security safeguards.
Criteria for Notifying a Significant Data Fiduciary
The Central Government may notify any Data Fiduciary or class of Data Fiduciaries as a Significant Data Fiduciary on the basis of an assessment of relevant factors including the volume and sensitivity of personal data processed, risk to the rights of Data Principals, potential impact on the sovereignty and integrity of India, risk to electoral democracy, security of the State, and public order.
Data Fiduciary (Defined)
A Data Fiduciary means any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data.
Data Principal (Defined)
A Data Principal means the individual to whom the personal data relates, and where that individual is a child it includes the parents or lawful guardian, and where she is a person with disability it includes her lawful guardian acting on her behalf.
Data Processor (Defined)
A Data Processor means any person who processes personal data on behalf of a Data Fiduciary.
Data Protection Board of India
The Data Protection Board is the body that registers and supervises Consent Managers, receives personal data breach intimations and Significant Data Fiduciary audit reports, and conducts inquiries, functioning as a digital office.
Data Protection Officer Requirements
The Data Protection Officer appointed by a Significant Data Fiduciary must represent it under the Act, be based in India, be an individual responsible to its Board of Directors or similar governing body, and be the point of contact for the grievance redressal mechanism.
Digital Locker Service Provider
A Digital Locker service provider means an intermediary, including a body corporate or an agency of the appropriate Government, notified by the Central Government in accordance with the rules made in that regard under the Information Technology Act, 2000.
Digital Personal Data Protection Act, 2023
The Digital Personal Data Protection Act, 2023 (No. 22 of 2023) received the assent of the President on 11 August 2023 and provides for the processing of digital personal data in a manner that recognises both the right of individuals to protect their personal data and the need to process such data for lawful purposes.
Digital Personal Data Protection Rules, 2025
The Digital Personal Data Protection Rules, 2025 are the subordinate legislation made under section 40 of the Digital Personal Data Protection Act, 2023, notified by G.S.R. 846(E) on 13 November 2025.
Direction Not to Disclose a Government Information Request
Where disclosure of the furnishing of information is likely to prejudicially affect the sovereignty and integrity of India or the security of the State, the Central Government may require the Data Fiduciary or intermediary not to disclose it to the affected Data Principal or any other person except with the previous permission in writing of the authorised person.
Disqualifications and Post-Office Restrictions for Board Members
A person is disqualified from being appointed and continued as Chairperson or Member if she is an undischarged insolvent, has been convicted of an offence involving moral turpitude in the opinion of the Central Government, has become physically or mentally incapable of acting, has acquired a prejudicial financial or other interest, or has so abused her position as to render her continuance prejudicial to the public interest.
Duties of a Data Principal
A Data Principal must comply with applicable laws while exercising her rights, must not impersonate another person or suppress material information when providing personal data, must not register a false or frivolous grievance or complaint, and must furnish only verifiably authentic information when exercising the right to correction or erasure.
E-Commerce Entity Retention Threshold
A Data Fiduciary that is an e-commerce entity having not less than two crore registered users in India must erase personal data three years from the date the Data Principal last approached it for the specified purpose or exercised her rights, or from the commencement of these Rules, whichever is latest.
Encryption, Obfuscation, Masking or Virtual Tokens
Appropriate data security measures required of a Data Fiduciary include securing personal data through encryption, obfuscation, masking or the use of virtual tokens mapped to that personal data.
Erasure When the Specified Purpose Is Deemed No Longer Served
A Data Fiduciary of a class specified in the Third Schedule must erase personal data once the corresponding time period has elapsed without the Data Principal approaching it for the specified purpose or exercising her rights, unless retention is necessary for compliance with any law in force.
Establishment of the Data Protection Board of India
With effect from such date as the Central Government may notify, there shall be established a Board called the Data Protection Board of India, which is a body corporate with perpetual succession and a common seal, able to acquire, hold and dispose of property and to contract, sue and be sued.
Exemption for Notified Startups
The Central Government may, having regard to the volume and nature of personal data processed, notify certain Data Fiduciaries or classes of Data Fiduciaries, including startups, to whom section 5, sub-sections (3) and (7) of section 8, and sections 10 and 11 do not apply.
Exemption for Notified State Instrumentalities
The Act does not apply to the processing of personal data by such instrumentality of the State as the Central Government may notify, in the interests of sovereignty and integrity of India, security of the State, friendly relations with foreign States, maintenance of public order or preventing incitement to any cognizable offence relating to any of these, nor to the processing by the Central Government of personal data such an instrumentality may furnish to it.
Exemption for Research, Archiving or Statistical Purposes
The Act does not apply to processing necessary for research, archiving or statistical purposes if the personal data is not to be used to take any decision specific to a Data Principal and the processing is carried on in accordance with such standards as may be prescribed.
Exemption for Research, Archiving or Statistical Purposes
The provisions of the Act do not apply to the processing of personal data necessary for research, archiving or statistical purposes if that processing is carried on in accordance with the standards specified in the Second Schedule.
Exemptions from Certain Obligations for Children’s Personal Data
The provisions of sub-sections (1) and (3) of section 9 of the Act do not apply to the processing of a child’s personal data by the classes of Data Fiduciaries in Part A of the Fourth Schedule, or for the purposes in Part B, subject to the conditions specified in the relevant Part.
Exemptions from Chapter II, Chapter III and Section 16
The provisions of Chapter II, except sub-sections (1) and (5) of section 8, and those of Chapter III and section 16 do not apply where processing is necessary for enforcing a legal right or claim, for judicial or regulatory functions, for the prevention or investigation of offences, for certain contracts with persons outside India, for corporate restructuring approved by a court or authority, or for ascertaining the financial information of a loan defaulter.
Factors in Determining the Amount of a Penalty
In determining the amount of a monetary penalty the Board must have regard to the nature, gravity and duration of the breach, the type and nature of the personal data affected, whether the breach is repetitive, whether the person realised a gain or avoided a loss, what mitigating action was taken and how timely and effective it was, whether the penalty is proportionate and effective, and the likely impact of the penalty on the person.
Forty-Eight Hour Notice Before Erasure
At least forty-eight hours before completion of the time period for erasure, the Data Fiduciary must inform the Data Principal that her personal data will be erased on completion of that period.
Fourth Schedule Part A: Exempt Classes of Data Fiduciaries
Part A of the Fourth Schedule exempts five classes of Data Fiduciaries from sections 9(1) and 9(3) for children’s data: clinical, mental health and healthcare establishments and professionals, allied healthcare professionals, educational institutions, individuals entrusted with children in a creche or day care centre, and persons engaged for the transport of children.
Fourth Schedule Part B: Exempt Purposes
Part B of the Fourth Schedule exempts six purposes from sections 9(1) and 9(3) for children’s data, each restricted to the extent necessary for that purpose.
General Obligations of a Data Fiduciary
A Data Fiduciary is responsible for complying with the Act and the rules made under it in respect of any processing undertaken by it or on its behalf by a Data Processor, irrespective of any agreement to the contrary or any failure by the Data Principal to carry out her duties.
Grounds for Processing Personal Data
A person may process the personal data of a Data Principal only in accordance with the Act and for a lawful purpose, either for which the Data Principal has given her consent or for certain legitimate uses.
Identifier (Defined)
An identifier means any sequence of characters issued by the Data Fiduciary to identify the Data Principal, and includes a customer identification file number, customer acquisition form number, application reference number, enrolment ID, email address, mobile number or licence number that enables such identification.
Independent Data Auditor
A Significant Data Fiduciary must appoint an independent data auditor to carry out data audit, who evaluates its compliance in accordance with the provisions of the Act.
Itemised Description Requirement in Notice
The notice must state, at the minimum, an itemised description of the personal data and the specified purpose or purposes together with a specific description of the goods or services to be provided or uses to be enabled by the processing.
Localisation Restriction on Specified Personal Data
A Significant Data Fiduciary must ensure that personal data specified by the Central Government, on the recommendations of a committee constituted by it, is processed subject to the restriction that the personal data and the traffic data pertaining to its flow are not transferred outside the territory of India.
Mediation of Complaints
If the Board is of the opinion that any complaint may be resolved by mediation, it may direct the parties concerned to attempt resolution of the dispute through such mediator as the parties may mutually agree upon, or as provided for under any law in force in India.
Ninety-Day Grievance Redressal Period
Every Data Fiduciary and Consent Manager must publish the period, not exceeding ninety days, within which it will respond to grievances of Data Principals under its grievance redressal system.
Notice Accompanying a Request for Consent
Every request for consent must be accompanied or preceded by a notice informing the Data Principal of the personal data and the purpose of processing, the manner in which she may exercise her rights under section 6(4) and section 13, and the manner of making a complaint to the Board.
Notice Given by Data Fiduciary to Data Principal
The notice given by a Data Fiduciary to a Data Principal must give a fair account, in clear and plain language, of the details necessary to enable her to give specific and informed consent to the processing of her personal data.
Notice Must Be Understandable Independently
The notice must be presented and be understandable independently of any other information that has been, is or may be made available by the Data Fiduciary.
Obligation to Erase Personal Data
Unless retention is necessary for compliance with any law in force, a Data Fiduciary must erase personal data upon the Data Principal withdrawing her consent or as soon as it is reasonable to assume that the specified purpose is no longer being served, whichever is earlier, and must cause its Data Processor to erase any personal data made available to it.
Obligation to Establish a Grievance Redressal Mechanism
A Data Fiduciary must establish an effective mechanism to redress the grievances of Data Principals.
Obligation to Intimate a Personal Data Breach
In the event of a personal data breach, the Data Fiduciary must give the Board and each affected Data Principal intimation of the breach, in such form and manner as may be prescribed.
Obligation to Publish Contact Information
A Data Fiduciary must publish, in such manner as may be prescribed, the business contact information of a Data Protection Officer if applicable, or of a person who is able to answer on its behalf the questions raised by a Data Principal about the processing of her personal data.
Obligation to Take Reasonable Security Safeguards
A Data Fiduciary must protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach.
Obligations of Consent Manager
Part B of the First Schedule imposes thirteen obligations on a Consent Manager, covering consent routing, record keeping, platform maintenance, security, fiduciary conduct, conflict of interest, transparency and audit.
One-Third Quorum for Board Meetings
One-third of the membership of the Board is the quorum for its meetings.
One-Year Minimum Retention of Processing Logs
For processing undertaken by a Data Fiduciary or on its behalf by a Data Processor, personal data, associated traffic data and other logs of the processing must be retained for a minimum of one year from the date of that processing, for the purposes specified in the Seventh Schedule.
One-Year Retention of Logs for Breach Detection
To enable detection of unauthorised access, its investigation and remediation, a Data Fiduciary must retain logs and personal data for a period of one year unless compliance with any law in force requires otherwise.
Online Gaming Intermediary Retention Threshold
A Data Fiduciary that is an online gaming intermediary having not less than fifty lakh registered users in India must erase personal data three years from the date the Data Principal last approached it for the specified purpose or exercised her rights, or from the commencement of these Rules, whichever is latest.
Penalties and Adjudication
If the Board determines on conclusion of an inquiry that a breach of the Act or the rules by a person is significant, it may, after giving that person an opportunity of being heard, impose the monetary penalty specified in the Schedule.
Penalties Credited to the Consolidated Fund of India
All sums realised by way of penalties imposed by the Board under the Act are credited to the Consolidated Fund of India.
Penalty for Breach of a Voluntary Undertaking
Breach of any term of a voluntary undertaking accepted by the Board under section 32 carries a penalty up to the extent applicable for the breach in respect of which the proceedings under section 28 were instituted.
Penalty for Breach of Data Principal Duties
Breach in observance of the duties under section 15 may extend to ten thousand rupees.
Penalty for Breach of Obligations Relating to Children
Breach in observance of additional obligations in relation to children under section 9 may extend to two hundred crore rupees.
Penalty for Breach of Significant Data Fiduciary Obligations
Breach in observance of the additional obligations of a Significant Data Fiduciary under section 10 may extend to one hundred and fifty crore rupees.
Penalty for Failing to Notify a Personal Data Breach
Breach in observing the obligation to give the Board or affected Data Principals notice of a personal data breach under section 8(6) may extend to two hundred crore rupees.
Penalty for Failing to Take Reasonable Security Safeguards
Breach in observing the obligation of a Data Fiduciary to take reasonable security safeguards to prevent personal data breach under section 8(5) may extend to two hundred and fifty crore rupees.
Personal Data (Defined)
Personal data means any data about an individual who is identifiable by or in relation to such data.
Personal Data Breach (Defined)
A personal data breach means any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data.
Power to Amend the Schedule, Capped at Double
The Central Government may by notification amend the Schedule, subject to the restriction that no such notification may increase any penalty specified in it to more than twice what was specified when the Act was originally enacted.
Power to Block Access After Repeated Penalties
On a written reference from the Board that a monetary penalty has been imposed on a Data Fiduciary in two or more instances, and that blocking is advised in the interests of the general public, the Central Government may, after giving that Data Fiduciary an opportunity of being heard and for reasons recorded in writing, direct any agency or intermediary to block public access to the information enabling it to offer goods or services in India.
Power to Make Rules
The Central Government may, by notification and subject to the condition of previous publication, make rules not inconsistent with the Act to carry out its purposes, and section 40(2) lists twenty-six specific matters for which rules may provide.
Power to Restrict Cross-Border Transfer
The Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified.
Powers and Functions of the Board
The Board inquires into personal data breaches and breaches of obligations and imposes penalties, acting on an intimation of breach under section 8(6), on a complaint by a Data Principal, on a reference by the Central or a State Government, in compliance with court directions, on an intimation of breach of a Consent Manager’s registration conditions, or on a reference regarding an intermediary under section 37(2).
Prohibition on Tracking and Targeted Advertising to Children
A Data Fiduciary must not undertake processing of personal data that is likely to cause any detrimental effect on the well-being of a child, and must not undertake tracking or behavioural monitoring of children or targeted advertising directed at children.
Publication of Contact Information for Processing Queries
Every Data Fiduciary must prominently publish on its website or app, and mention in every response to a communication for the exercise of a Data Principal’s rights, the business contact information of the Data Protection Officer if applicable, or of a person able to answer questions about the processing on its behalf.
Publication of the Means to Exercise Data Principal Rights
To enable Data Principals to exercise their rights, the Data Fiduciary and, where applicable, the Consent Manager must prominently publish on its website or app the details of the means of making a request and the particulars required to identify the Data Principal.
Reasonable Security Safeguards
A Data Fiduciary must protect personal data in its possession or under its control, including any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach.
Residual Penalty for Any Other Breach
Breach of any other provision of the Act or the rules made thereunder may extend to fifty crore rupees.
Right of Grievance Redressal
A Data Principal has the right to readily available means of grievance redressal provided by a Data Fiduciary or Consent Manager, and must exhaust the opportunity of redressing her grievance under this section before approaching the Board.
Right to Access Information About Personal Data
A Data Principal has the right to obtain from the Data Fiduciary a summary of the personal data being processed and the processing activities undertaken, the identities of all other Data Fiduciaries and Data Processors with whom the data has been shared along with a description of what was shared, and any other prescribed information.
Right to Correction, Completion, Updating and Erasure
A Data Principal has the right to correction, completion, updating and erasure of her personal data for processing to which she has previously consented, and on receiving a request the Data Fiduciary must correct inaccurate or misleading data, complete incomplete data, and update the data.
Right to Nominate
A Data Principal has the right to nominate any other individual who shall, in the event of her death or incapacity, exercise her rights under the Act and the rules in accordance with the prescribed manner.
Right to Nominate an Individual
To exercise her right to nominate under the Act, a Data Principal may nominate one or more individuals in accordance with the terms of service of the Data Fiduciary and such law as may be applicable, using the means and furnishing the particulars required by that Data Fiduciary.
Right to Withdraw Consent
Where consent is the basis of processing, the Data Principal has the right to withdraw her consent at any time, with the ease of doing so being comparable to the ease with which the consent was given.
Salary of the Chairperson and Members
The Chairperson receives a consolidated salary of four lakh fifty thousand rupees per month and every other Member four lakh rupees per month, in both cases without the facility of house and car.
Search-cum-Selection Committee for Board Appointments
Two separate Search-cum-Selection Committees recommend individuals for appointment: one chaired by the Cabinet Secretary for the Chairperson, and one chaired by the Secretary of the Ministry of Electronics and Information Technology for other Members.
Second Schedule Standards for Lawful Processing
The Second Schedule requires implementation of appropriate technical and organisational measures ensuring eight standards: lawful processing, purpose limitation, data minimisation, accuracy, retention limitation, security safeguards, intimation to the Data Principal, and accountability.
Seven-Day Communication of Emergent Board Action
Where an emergent situation warrants immediate action by the Board and it is not feasible to call a meeting, the Chairperson may take such action as may be necessary while recording the reasons in writing, and it must be communicated within seven days to all Members and laid before the Board for ratification at its next meeting.
Seventy-Two Hour Breach Report to the Board
The detailed breach report must reach the Board within seventy-two hours of the Data Fiduciary becoming aware of the breach, or within such longer period as the Board may allow on a request made in writing.
Significant Data Fiduciary (Defined)
A Significant Data Fiduciary means any Data Fiduciary or class of Data Fiduciaries as may be notified by the Central Government under section 10.
Six-Month Endeavour to Dispose of an Appeal
An appeal must be dealt with as expeditiously as possible and endeavour must be made to dispose of it finally within six months from the date on which it is presented, and where it is not, the Appellate Tribunal must record its reasons in writing.
Six-Month Period for Completing a Board Inquiry
An inquiry by the Board must be completed within six months from the date of receipt of the intimation, complaint, reference or direction under section 27 of the Act, unless the period is extended by the Board for reasons recorded in writing for a further period not exceeding three months at a time.
Sixty-Day Window to File an Appeal
An appeal must be filed within sixty days from the date of receipt of the order or direction appealed against, in such form and manner and accompanied by such fee as may be prescribed.
Social Media Intermediary Retention Threshold
A Data Fiduciary that is a social media intermediary having not less than two crore registered users in India must erase personal data three years from the date the Data Principal last approached it for the specified purpose or exercised her rights, or from the commencement of these Rules, whichever is latest.
Staggered Commencement of the Rules
The Rules commence in three tranches: rules 1, 2 and 17 to 21 on publication, rule 4 one year after publication, and rules 3, 5 to 16, 22 and 23 eighteen months after publication.
State Processing for Subsidy, Benefit, Service, Certificate, Licence or Permit
Processing of personal data by the State and its instrumentalities for the provision or issue of a subsidy, benefit, service, certificate, licence or permit must be done following the standards specified in the Second Schedule.
Suspension or Cancellation of Consent Manager Registration
Where the Board is satisfied that it is necessary in the interests of Data Principals, it may, after giving the Consent Manager an opportunity of being heard and by order recording reasons in writing, suspend or cancel the registration and give such directions as it deems fit.
Techno-Legal Measures (Defined)
Techno-legal measures means the measures referred to under rules 20 and 22.
The Act Prevails in the Event of Conflict
The Act is in addition to and not in derogation of any other law in force, and in the event of conflict between a provision of the Act and a provision of any other law, the Act prevails to the extent of the conflict.
The Standard of Valid Consent
Consent must be free, specific, informed, unconditional and unambiguous with a clear affirmative action, and must signify agreement to the processing of personal data for the specified purpose, limited to such personal data as is necessary for that purpose.
Transfer of Personal Data Outside India
Personal data processed by a Data Fiduciary may be transferred outside the territory of India subject to the restriction that the Data Fiduciary meets such requirements as the Central Government may specify by general or special order in respect of making that personal data available to any foreign State, or to any person or entity under the control of or any agency of such a State.
Tribunal Orders Executable as a Civil Court Decree
An order passed by the Appellate Tribunal under the Act is executable by it as a decree of civil court, and for that purpose the Tribunal has all the powers of a civil court.
User Account (Defined)
A user account is the online account registered by the Data Principal with the Data Fiduciary, including any profiles, pages, handles, email address, mobile number and other similar presences through which the Data Principal accesses that Data Fiduciary’s services.
Verifiable Consent (Defined)
Verifiable consent means a consent as specified in rule 10 or rule 11.
Verifiable Consent from a Lawful Guardian
A Data Fiduciary obtaining verifiable consent from an individual identifying herself as the lawful guardian of a person with disability must observe due diligence to verify that the guardian is appointed by a court of law, or by a designated authority or a local level committee, under the law applicable to guardianship.
Verifiable Parental Consent for a Child
A Data Fiduciary must adopt appropriate technical and organisational measures to ensure that verifiable consent of the parent is obtained before processing any personal data of a child, and must observe due diligence to check that the individual identifying herself as the parent is an adult who is identifiable if required under any law in force in India.
Verifiable Parental Consent Obligation
Before processing any personal data of a child or of a person with disability who has a lawful guardian, the Data Fiduciary must obtain verifiable consent of the parent or the lawful guardian, in such manner as may be prescribed.
Voluntary Undertaking
The Board may accept a voluntary undertaking in respect of any matter related to observance of the Act from any person at any stage of a proceeding, and acceptance bars proceedings as regards the contents of that undertaking.
Withdrawal of Consent Comparable in Ease to Giving It
The notice must describe the means by which the Data Principal may withdraw her consent, with the ease of doing so being comparable to that with which such consent was given.