Skip to main content

Taxmann's Digital Personal Data Protection – Law & Practice

Page 1

Sample Read


Contents PAGE

About the Author

I-5

Preface

I-7

Acknowledgements

I-9

Resume of the various sections of the DPDP Act

I-15

Resume of Digital Personal Data Protection Rules, 2025

I-27

Abbreviations

I-29

An Introduction

I-33

DIVISION 1 : LAW & PRACTICE RELATING TO DIGITAL PERSONAL DATA PROTECTION DIGITAL PERSONAL DATA PROTECTION ACT, 2023 CHAPTER I PRELIMINARY 1. Short title and commencement

4

2. Definitions

11

3. Application of Act

64 CHAPTER II

OBLIGATIONS OF DATA FIDUCIARY 4. Grounds for processing personal data

73

5. Notice

77

6. Consent

84

7. Certain legitimate uses

119

I-11


CONTENTS

I-12 PAGE

8. General obligations of Data Fiduciary

157

9. Processing of Personal Data of Children

202

10. Additional Obligations of Significant Data Fiduciary

227

CHAPTER III RIGHTS AND DUTIES OF DATA PRINCIPAL 11. Right to access information about personal data

240

12. Right to correction and erasure of personal data

247

13. Right of grievance redressal

249

14. Right to nominate

251

15. Duties of Data Principal

253

CHAPTER IV SPECIAL PROVISIONS 16. Processing of personal data outside India

258

17. Exemptions

264 CHAPTER V

DATA PROTECTION BOARD OF INDIA 18. Establishment of Board

276

19. Composition and qualifications for appointment of Chairperson and Members

278

20. Salary, allowances payable to and term of office

282

21. Disqualifications for appointment and continuation as Chairperson and Members of Board

285

22. Resignation by Members and filling of vacancy

287

23. Proceedings of Board

288

24. Officers and Employees of Board

292

25. Members and officers to be public servants

294

26. Powers of Chairperson

296

CHAPTER VI POWERS, FUNCTIONS AND PROCEDURE TO BE FOLLOWED BY BOARD 27. Powers and functions of Board

298


I-13

CONTENTS PAGE

28. Procedure to be followed the Board

302

CHAPTER VII APPEAL AND ALTERNATE DISPUTE RESOLUTION 29. Appeal to Appellate Tribunal

309

30. Orders passed by Appellate Tribunal to be executable as decree

314

31. Alternate dispute resolution

316

32. Voluntary undertaking

317

CHAPTER VIII PENALTIES AND ADJUDICATION 33. Penalties

320

34. Crediting sums realised by way of penalties to Consolidated Fund of India

324

CHAPTER IX MISCELLANEOUS 35. Protection of action taken in good faith

327

36. Power to call for information

331

37. Power of Central Government to issue directions

335

38. Consistency with other laws

338

39. Bar of jurisdiction

340

40. Power to make rules

341

41. Laying of rules and certain notifications

348

42. Power to amend Schedule

350

43. Power to remove difficulties

352

44. Amendments to certain Acts

354

DIVISION 2 : FAQs ON DIGITAL PERSONAL DATA PROTECTION ACT, 2023 FAQs on Digital Personal Data Protection Act, 2023

361


CONTENTS

I-14 PAGE

APPENDICES APPENDIX 1 : DIGITAL PERSONAL DATA PROTECTION ACT, 2023

433

APPENDIX 2 : DIGITAL PERSONAL DATA PROTECTION RULES, 2025

478

APPENDIX 3 : NOTIFICATIONS UNDER DIGITAL PERSONAL DATA PROTECTION ACT, 2023

500

APPENDIX 4 : INFORMATION TECHNOLOGY ACT, 2000

509

APPENDIX 5 : INFORMATION TECHNOLOGY (REASONABLE SECURITY PRACTICES AND PROCEDURES AND SENSITIVE PERSONAL DATA OR INFORMATION) RULES, 2011

569


S. 3

LAW & PRACTICE RELATING TO DPDP

72

The provisions of the DPDP Act apply to the processing of such sensitive personal data in digital form. Processing of Digital Data by Foreign Entities Offering Goods or Services to Indians — Covered under the Act These involve foreign data fiduciaries targeting Indian users. Foreign E-Commerce Platform

ShopEase, a US-based e-commerce platform, sells products to customers in India and collects their personal data during the purchase process. The provisions of the DPDP Act apply to ShopEase’s processing of this digital personal data, as it is connected to offering goods and services to individuals within India. Foreign University Admissions

A French university offers online courses to students in India and collects their names, email addresses, and payment information during enrollment. The provisions of the DPDP Act apply to the processing of such data, as it relates to offering services to individuals within India. CHAPTER II OBLIGATIONS OF DATA FIDUCIARY Introduction Imagine you are shopping online at a popular website. Before you complete your purchase, a pop-up informs you about the data they collect and why they need it. This simple step is part of a bigger framework under the Digital Personal Data Protection Law, which ensures your personal data is handled responsibly. This chapter covers the key responsibilities of data fiduciaries, such as obtaining your consent before processing your data (Section 4), informing you about the purpose and your rights (Section 5), and ensuring your consent is free, specific, and informed (Section 6). It also explains the difference between lawful and legal purposes, the comprehensive meaning of data processing, and the necessity for clear, easy-to-understand notices. Furthermore, it highlights your right to withdraw consent and the obligations of data fiduciaries to respect and act upon such withdrawals promptly, except where legal requirements dictate otherwise. Through detailed illustrations and


73

DIGITAL PERSONAL DATA PROTECTION ACT, 2023

S. 4

case law references, and effort has been made to provide a practical understanding of these obligations to ensure transparency and protect your privacy.

Grounds for processing personal data. 6

4. (1) A person may process the personal data of a Data Principal only in accordance with the provisions of this Act and for a lawful purpose,— (a) for which the Data Principal has given her consent; or (b) for certain legitimate uses. (2) For the purposes of this section, the expression “lawful purpose” means any purpose which is not expressly forbidden by law. COMMENTS

4.1 GENERAL RULE ON DATA PROCESSING Section 4 establishes a critical principle regarding the processing of personal data. It mandates that personal data can only be processed in compliance with the provisions set out in the Act. This means that any data processing must adhere to the rules, rights, and obligations defined within the Act, ensuring that personal data is handled in a lawful, transparent, and fair manner. The provision ensures that data is processed in a controlled environment and does not violate the rights of the Data Principal, the individual to whom the data pertains.

4.2 LAWFUL PURPOSE FOR PROCESSING PERSONAL DATA [SECTION 4(1)] The section clarifies that data processing can only occur for a “lawful purpose.” A lawful purpose is defined as one that is not prohibited by law, meaning any purpose for which the law does not impose a direct prohibition. The objective is to ensure that the data is processed in ways that are legally acceptable and not for unlawful or unauthorized activities. Section 4(1) of the DPDP Act further prescribes twin conditions for processing personal data firstly, the 6. Shall be enforced w.e.f. 13-5-2027.


S. 4

LAW & PRACTICE RELATING TO DPDP

74

consent of the Data Principal and second, that data processing must be for lawful uses:

Consent of the Data Principal: The first condition is when the Data Principal, meaning the individual whose data is being processed, has given explicit consent for the processing of their personal data. This consent must be informed, voluntary, and specific to the purpose for which the data is being collected and processed. The importance of this provision is that it empowers the Data Principal to have control over how their personal data is used.

Legitimate Uses: The second condition allows processing for certain legitimate purposes. While the section does not explicitly define what constitutes a legitimate use, these typically refer to situations where processing is necessary for purposes such as compliance with legal obligations, the performance of a contract, or other vital interests that are recognized by law. These purposes are considered justified even in the absence of explicit consent from the Data Principal, as long as they fall within the legal framework.

4.2-1 Meaning of Lawful purpose in Section 4(1) The term “lawful purpose” is crucial to understanding the scope of this provision. According to the section, a lawful purpose is one that is not expressly forbidden by law. This definition is intentionally broad, allowing for a wide range of permissible activities, as long as they are not prohibited by any legal provision. This provision ensures that processing activities are bound by the law and cannot


75

DIGITAL PERSONAL DATA PROTECTION ACT, 2023

S. 4

be carried out arbitrarily. The law acts as a safeguard, ensuring that personal data is not used for unlawful or unethical purposes. 4.2.1-1 Principal of “Lawful Purpose” under DPDP Act and GDPR: Emphasis on Consent and Legitimacy in Data Processing - The principal of Lawful purpose as given in Section 4 of the DPDP Act are enshrined in the Article 5 of the GDPR7, which outlines key principles for processing personal data, specifically focusing on the lawful basis for data processing. Both provisions emphasize that data processing must be for a lawful purpose, either with the explicit consent of the Data Principal or based on legitimate grounds. Like the GDPR, Section 4 requires that data processing activities must align with legal standards and not be undertaken for unlawful or prohibited purposes, ensuring consistency with broader international data protection norms. Both Section 4 of the DPDP Act and Article 5 of the GDPR emphasize that personal data can only be processed for a lawful purpose. They require that processing be done with the explicit consent of the Data Principal or based on legitimate grounds. Both frameworks ensure 7. See Art. 5 of GDPR (EU)- “Principles relating to processing of personal data”. 1. Personal data shall be: (a) processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness and transparency’); (b) collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 89(1), not be considered to be incompatible with the initial purposes (‘purpose limitation’); (c) adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimisation’); (d) accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (‘accuracy’); (e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) subject to implementation of the appropriate technical and organisational measures required by this Regulation in order to safeguard the rights and freedoms of the data subject (‘storage limitation’); (f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’). 2. The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1 (‘accountability’).


S. 4

LAW & PRACTICE RELATING TO DPDP

76

that data processing must align with legal provisions, prohibiting any unlawful or unauthorized use of personal data. This aligns the principles of data protection with a focus on transparency, consent, and legality. 4.2.1-2 Distinction between Lawful and Legal - The principal distinction between “lawful” and “legal” is that the former contemplates the substance of law and the latter form of law. To say of an act that it is lawful implies that it is authorised, sanctioned or at any rate not forbidden by law. Lawful possession means a legal possession which is also rightful ors at least excusable. Thus, that which is not stricto legalo may yet be lawful. It should not be forbidden by law. In fact legal is associated with provisions in the Act, rules, etc., whereas lawful visualises all that is not illegal against law or even permissible. Lawful is wider in connotation than legal. What is legal is lawful. But what is lawful may be so without being formally legal.(Krishna Kishore Firm v. Government of Andhra Pradesh AIR 1990 SC 2292) 4.2.1-3 Implications for Data Processors - Organizations or individuals who process personal data (referred to as data processors), must to ensure that data processing activity complies with the requirements of the Act. Data processors must ensure that they have either the Data Principal’s consent or a valid, legitimate reason for processing the data, as defined under the Act. In practice, this means that organizations must create processes for obtaining clear consent from individuals or justify the processing through other legal grounds, such as compliance with contractual obligations or legal requirements. Failure to do so could lead to violations of the Act and potential legal consequences. 4.2.1-4 Ensuring Compliance and Accountability - In order to comply with this provision, organizations that handle personal data must implement robust mechanisms to manage consent and demonstrate that they are processing data for lawful purposes. This involves informing Data Principals about the specific purposes for which their data is being processed and ensuring transparency throughout the data processing lifecycle. Data processors must also maintain proper records and documentation to show that the data processing activities are in line with the Act’s provisions. This requirement enhances accountability and


77

DIGITAL PERSONAL DATA PROTECTION ACT, 2023

S. 5

ensures that personal data is always handled in a manner consistent with the rights of the Data Principal and the legal framework established by the Act.

Notice. 8

5. (1) Every request made to a Data Principal under section 6 for consent shall be accompanied or preceded by a notice given by the Data Fiduciary to the Data Principal, informing her,— (i) the personal data and the purpose for which the same is proposed to be processed; (ii) the manner in which she may exercise her rights under sub-section (4) of section 6 and section 13; and (iii) the manner in which the Data Principal may make a complaint to the Board, in such manner and as may be prescribed. Illustration

X, an individual, opens a bank account using the mobile app or website of Y, a bank. To complete the Know-Your-Customer requirements under law for opening of bank account, X opts for processing of her personal data by Y in a live, video-based customer identification process. Y shall accompany or precede the request for the personal data with notice to X, describing the personal data and the purpose of its processing.

(2) Where a Data Principal has given her consent for the processing of her personal data before the date of commencement of this Act,— (a) the Data Fiduciary shall, as soon as it is reasonably practicable, give to the Data Principal a notice informing her,–– (i) the personal data and the purpose for which the same has been processed;

8. Shall be enforced w.e.f. 13-5-2027.


S. 5

LAW & PRACTICE RELATING TO DPDP

78

(ii) the manner in which she may exercise her rights under sub-section (4) of section 6 and section 13; and (iii) the manner in which the Data Principal may make a complaint to the Board, in such manner and as may be prescribed. (b) the Data Fiduciary may continue to process the personal data until and unless the Data Principal withdraws her consent. Illustration X, an individual, gave her consent to the processing of her personal data for an online shopping app or website operated by Y, an e-commerce service provider, before the commencement of this Act. Upon commencement of the Act, Y shall, as soon as practicable, give through email, in-app notification or other effective method information to X, describing the personal data and the purpose of its processing.

(3) The Data Fiduciary shall give the Data Principal the option to access the contents of the notice referred to in sub-sections (1) and (2) in English or any language specified in the Eighth Schedule to the Constitution. COMMENTS

5.1 MEANING OF NOTICE As per [Mozley and Whiteley’s Law Dictionary, Second edition, 1904, page 212], the meaning of the term ‘Notice’ is where one party in an action calls on another to admit a document, saving all just exceptions, or to admit certain facts. If the party so called on should neglect or refuse to give the admission, he will bear the cost of proving the same, unless the judge certifies that such refusal was reasonable. 3 Steph. Com; R.S.C. 1883, Ord. XXXII. rr. 2 and 4.

5.1-1 Notice must be issued to the data principal at the time of obtaining consent Section 5(1) puts an obligation on the part of the data fiduciary to send a notice to the data principal before or at the time of obtain-


79

DIGITAL PERSONAL DATA PROTECTION ACT, 2023

S. 5

ing his/her consent, the notice shall clearly inform him/her about the personal details that are being obtained and specific purpose for which the personal data would be processed. The notice should inform the data principal about the following three things: Personal Data and Purpose: The notice must clearly state the personal data that is being collected and processed, along with the purpose for which the data will be used. This ensures that the Data Principal is aware of what specific data will be processed and for what objective, allowing them to make an informed decision.

Rights of the Data Principal: The notice must inform the Data Principal about how they can exercise their rights under Section 6(4) and Section 13. These sections pertain to the rights of the Data Principal, such as the right to withdraw consent, access personal data, and seek rectification or erasure. Providing this information is crucial for enabling the Data Principal to exercise control over their data.

Complaint Mechanism: The notice must also explain how the Data Principal can file a complaint with the Board (likely the Data Protection Authority) if they feel their rights have been violated. It should outline the prescribed process and manner in which complaints can be made, ensuring that the Data Principal has a clear and accessible avenue for addressing grievances.

Essentials of a valid notice

Personal data and purpose Right to withdraw consent Manner in which Data principal may exercise his/her rights Manner of making complaint to Board

Right to have means of Grievance redressal


S. 5

LAW & PRACTICE RELATING TO DPDP

80

5.1-2 Notice should inform data principal about the right to withdraw consent Section 6(4) gives the Data Principal the right to withdraw her/his consent at any time, with the ease of doing so being comparable to the ease with which such consent was given. 5.1.2-1 CJEU: Data Subjects Have Right to Know Specific Data Recipients - In case of J.M. v. Apulaistietosuojavaltuutettu, Pankki S - C-579/21 (June 22, 2023), the CJEU clarified that under Article 15(1)(c) of the GDPR, data subjects have the right to be informed of the specific recipients of their personal data, not just general categories, unless it is genuinely impossible to do so. This ruling reinforces the principle of transparency in data processing.

5.1-3 Notice must inform about the right to have means of Grievance redressal Section 13 gives the Data Principal the right to have readily available means of grievance redressal in respect of any act or omission of the Data Fiduciary or consent manager regarding the performance of its obligation in relation to the personal data of the Data Principal.

5.1-4 Implications for Data Fiduciaries This section imposes an obligation on Data Fiduciaries to ensure that all requests for consent are accompanied by the necessary notice and that the notice is clear, accurate, and complete. Failure to provide the notice as required may result in the invalidation of the consent and potential legal consequences for non-compliance. Thus, Data Fiduciaries must establish procedures to comply with these requirements, demonstrating their commitment to transparency and data protection principles.

5.1-5 Manner of giving Notice to Data Principal by Data Fiduciary [Rule 3] Rule 3 of the DPDP Rules, 2025 prescribes the conditions with regard to the issuing of notice by the Data Fiduciary to the Data Principal, the notice must:


81

DIGITAL PERSONAL DATA PROTECTION ACT, 2023

S. 5

(a) Be Clear and Independent: The notice must be presented in a way that is understandable on its own, without reliance on any other information provided by the Data Fiduciary. (b) Enable Informed Consent: The notice must use clear and simple language to give a fair explanation of essential details for the Data Principal to provide specific and informed consent for processing personal data. This includes:

Description of the personal data to be processed.

A clear explanation of the purpose of processing, including a description of the goods or services to be provided or the specific uses enabled by the processing.

(c) Provide Accessibility and Rights Information - The notice must include: A direct link to the website or app of the Data Fiduciary. Information about other available methods, if any, through which the Data Principal can:

Withdraw her consent, with the withdrawal process being as simple as the process of giving consent.

Exercise her rights under the Act.

File a complaint with the Board. Illustrations

Mr. Verma, a customer, visits a popular online shopping platform, ShoppeSmart, to make a purchase. As per Section 5(1) of the Act, ShoppeSmart is obligated to provide Mr. Verma with a notice before or at the time of obtaining his consent for processing personal data. Purpose of data As Mr. Verma navigates to the checkout page to complete his purchase, before proceeding, a pop-up notification should appear, informing him that ShoppeSmart would collect his personal data, including name, address, contact details, and purchase history. The notice should clearly state that the purpose of collecting this data is to facilitate the processing of his order, delivery of products, and personalized recommendations based on his shopping preferences.


Digital Personal Data Protection – Law & Practice AUTHOR : PUBLISHER : DATE OF PUBLICATION : EDITION : ISBN NO : No. of Pages : BINDING TYPE :

Rachit Sharma Taxmann December 2025 2026 Edition 9789371260909 652 Hardbound

Rs. 1,195 DESCRIPTION Digital Personal Data Protection – Law & Practice is a concise, authoritative, and practice-oriented commentary on the Digital Personal Data Protection Act 2023 (DPDP Act) and the DPDP Rules—India’s first dedicated legal framework governing the lifecycle of digital personal data. Conceived as a proper Law & Practice work, the book goes beyond statutory explanation to translate the data protection regime into an operational, enforceable, and compliance-ready framework for India’s digital economy. The DPDP Act represents a decisive shift from the fragmented IT Act–based regime to a rights-based, fiduciarycentric, and enforcement-driven approach. This book captures that transition by treating the Act as a governance architecture that reshapes how personal data is collected, processed, secured, shared, retained, and erased across public and private sectors. Balancing doctrinal clarity with institutional realism, the commentary recognises data protection as a constitutional mandate, a regulatory obligation, a technology-driven process, and a governance discipline. It adopts a focused analytical approach combining statutory interpretation, operational guidance, compliance design, and enforcement preparedness—making it a reliable and enduring reference on India’s data protection law. This book is meticulously designed for all stakeholders who must interpret, implement, oversee, audit, or adjudicate data protection compliance in India, including: • Data Protection Officers (DPOs), Privacy Heads & Compliance Teams • Corporate Legal Teams & In-house Counsels • Legal Practitioners & Advocates • Technology, IT & Digital Governance Professionals • Government Officials, Policymakers & Regulators • Students, Academicians & Researchers The Present Publication is the Latest Edition, updated till 10th December 2025. This book is authored by CS Rachit Sharma, with the following noteworthy features: • [Law & Practice Orientation] Each provision is analysed for both legal interpretation and practical compliance impact • [Section-wise Commentary] Exhaustive coverage of the DPDP Act, addressing statutory scope, legislative intent, interpretative issues, and application • [Phased Commencement Mapping] Clear linkage between Act provisions, enforcement dates, and the DPDP Rules 2025, enabling structured compliance planning • [Embedded Compliance Toolkit] Includes checklists, tables, charts, illustrations, and step-by-step operational guidance for day-to-day compliance • [Consent Manager Framework] Detailed explanation of the role, eligibility, governance, and obligations of Consent Managers • [Security & Data Breach Governance] Practical guidance on security safeguards, organisational measures, and breach reporting requirements • [Institutional Enforcement Framework] In-depth analysis of the Data Protection Board of India, penalties, adjudication, appeals, and dispute resolution • [Dedicated FAQs Section] Addresses common Act- and Rule-specific implementation queries • [Comparative Perspective] Select references to GDPR and global privacy principles for contextual understanding

Buy Now


Turn static files into dynamic content formats.

Create a flipbook
Taxmann's Digital Personal Data Protection – Law & Practice by Taxmann - Issuu