The Centre Notifies Long-Awaited Rules for the Digital Personal Data Protection Act
By Squirrels·
The government notified the rules that operationalise the country's digital personal data protection law, giving companies a clearer picture of how they must collect, store and process the information of hundreds of millions of users. The rules had been awaited since the law itself was passed, and their absence had left businesses in limbo.
They spell out how organisations must obtain consent, respond to requests from users to access or delete their data, and report breaches to the authorities and to affected individuals. Businesses handling large volumes of sensitive information will face additional obligations, including appointing officers responsible for compliance and conducting periodic audits.
What changes for companies
At the heart of the framework is the principle of consent: organisations must tell people, in clear language, what data they are collecting and why, and must obtain agreement before doing so. Users gain the right to see the data held about them, to correct it and to have it erased, rights that companies must build systems to honour rather than treat as exceptions.
The rules also introduce stricter handling requirements for the data of children and for organisations designated as significant processors on the basis of the volume and sensitivity of the information they hold. Breach notification — long a grey area — is now formalised, with timelines for informing both the regulator and affected users.
A phased runway for compliance
Recognising that smaller firms need time to adapt, the rules set out a staggered timeline, with the most demanding requirements phased in over the coming months rather than taking effect overnight. A new data protection board will handle complaints, investigate lapses and can levy financial penalties for serious violations.
Compliance officers at large companies said the phased approach was a relief, giving them room to build consent-management systems, retrain staff and rework contracts with vendors who process data on their behalf. Smaller businesses, many of which have never had formal data-handling practices, face a steeper climb.
Praise and unease
Privacy advocates gave the framework a cautious welcome, calling it an overdue codification of rights that citizens have lacked, but flagged the breadth of exemptions available to government agencies as an area to watch closely. Where the state can exempt itself from rules that bind private companies, they argued, the protection is only as strong as the safeguards around those exemptions.
Industry groups said clarity was overdue and that the phased approach would help avoid disruption, while urging the government to issue further guidance on thorny questions such as cross-border data transfers and the treatment of data already collected. The real test, everyone agreed, will be enforcement: whether the new board has the resources and the independence to make the rules bite.
