India

Digital Personal Data Protection Rules, 2025: From Parents Consent To Cross Border Data Transfer, Check Here

The Ministry of Electronics and Information Technology (MeitY) released the draft rules today for the Digital Personal Data Protection (DPDP) Act, 2023, which was passed by Parliament last year. These draft rules, now open for public consultation until February 18, 2025, aim to provide a robust framework for data protection in India’s digital landscape.

Key Aspects of the Draft Rules

Applicability and Structure

The “Digital Personal Data Protection Rules, 2025” apply to all entities processing personal data within India and to those offering goods or services to individuals in India. The rules define the roles of data fiduciaries, data processors, and consent managers, laying out detailed accountability measures for each.

Responsibilities of Data Fiduciaries

Data fiduciaries must ensure transparency and accountability in their data processing activities. This includes providing individuals with clear notices about:

  • The types of personal data being processed.
  • The purposes for processing the data.
  • How individuals can withdraw consent or exercise their rights.

Fiduciaries are also required to implement security measures, such as encryption, and conduct regular audits to prevent data breaches.

Consent and Consent Managers

Consent is a central theme in the draft rules. Certified consent managers are tasked with managing user consent. These entities must ensure that individuals can provide, review, and withdraw consent easily. They are also required to maintain records of consent in machine-readable formats and ensure data processing methods prevent unauthorized access.

Rights of Data Principals

Data principals (individuals) are granted several rights, including the right to:

  • Access and correct their personal data.
  • Request the erasure of their data under certain conditions.
  • File grievances through specified channels.

The rules also mandate that individuals be informed of any data breaches within a set time frame.

Significant Data Fiduciaries

Entities classified as significant data fiduciaries face more stringent compliance requirements, such as conducting regular data protection impact assessments, audits, and algorithmic accountability checks. These entities must also ensure the hosting and transmission of sensitive data complies with Indian data sovereignty regulations.

Protection for Children and Disabled Persons

For processing children’s data, verifiable parental consent is required. The rules also include provisions for individuals with disabilities, allowing legal guardians to act on their behalf.

Cross-Border Data Transfers

The draft rules impose restrictions on the transfer of personal data outside India, allowing such transfers only to jurisdictions approved by the Central Government, in line with India’s push for data localization and sovereignty.

Grievance Redressal and Appeals

The draft outlines a clear framework for grievance redressal, with fiduciaries required to publicly list the contact details of their data protection officers. Individuals can file appeals with the Appellate Tribunal against decisions made by the Data Protection Board.

Sanctions and Compliance

Penalties for non-compliance include failure to implement security measures or mishandling data breaches. Data fiduciaries are also required to disclose details of their stakeholders, such as promoters and directors, on their websites.

Exemptions and Retention Period

Exemptions are provided for certain data processing activities, such as for research, archival, or statistical purposes, provided adequate safeguards are in place. The rules also define a retention period for personal data—three years from the last interaction with the data fiduciary or from the commencement of the DPDP rules.

Public Consultation Process

The draft rules are open for public consultation through the MyGov portal until February 18, 2025. MeitY has encouraged stakeholders to submit their suggestions publicly to ensure transparency. The final rules will be implemented in phases, with different sections taking effect at specified times.

 

Swastika Sruti

Recent Posts

What Is Gen Beta? India’s First Baby Of The New Generation Born In Aizawl

Frankie Remruatdika Zadeng, the first Gen Beta baby born in India, was born in Aizawl,…

16 mins ago

OYO New Rules Implemented In Meerut: Will Other Cities Follow?

OYO has introduced a new policy in Meerut, Uttar Pradesh, barring unmarried couples from checking…

17 mins ago

Instagrammer Kristen Fischer Struggles With India’s Delayed Dinner Party Tradition – But Why?

Kristen Fischer, an Instagrammer from the US, shared her struggles adapting to India's unique dinner…

31 mins ago

Delhi-NCR AQI Improves: Stage-III GRAP Measures Revoked, Stage-I And II Still Active

The Commission for Air Quality Management (CAQM) has de-notified Stage-III GRAP measures in the Delhi-NCR…

1 hour ago

What’s Behind OYO’s Decision To Restrict Unmarried Couples From Checking In At Hotels? Manager Explains

In a significant move aimed at reshaping its check-in protocols, OYO, the Indian hospitality giant,…

1 hour ago

For The First Time In 40 Years, India’s Best-Selling Car Is No Longer A Maruti

For the first time in 40 years, Tata Motors has finally dethroned Maruti Suzuki, with…

2 hours ago