Headline: MeitY Notifies Digital Personal Data Protection Rules, 2025, Begins Phased Rollout
Bullet Points:
- MeitY notifies digital personal data protection Rules, 2025, beginning a phased rollout of the Digital Personal Data Protection Act, 2023.
- The framework sets clear rules for how companies, digital platforms, and government bodies must collect, store, process, and manage the personal data of individuals (“Data Principals”).
- The operational rules specify a phased rollout: general duties, grievance redressal provisions, and other foundational obligations under Rules 1, 2, and 17‑21 are effective immediately; the registration and governance of Consent Managers under Rule 4 will be applicable one year from notification; and the detailed notice formats, security measures, processing conditions, data retention norms, and remaining operational rules under Rules 3, 5‑16, 22‑23 will apply in full after 18 months.
- A significant addition through the new rules is the establishment of a formal framework for Consent Managers, who must be registered with the Data Protection Board and comply with governance, transparency, and security requirements.
- The Rules also lay down standards for encryption, masking, tokenisation, access controls, activity logging, backup systems, and business-continuity planning, making these safeguards mandatory for all fiduciaries.
- In the event of a data breach, fiduciaries must provide immediate intimation to the Board and deliver a fuller report within 72 hours while simultaneously informing affected users about the nature of the breach, potential harm, and mitigation steps.
- The Digital Personal Data Protection (DPDP) Act is India’s first full-scale privacy law, introducing explicit and affirmative consent for data processing and codifying a clear set of rights for individuals, including withdrawing consent, correcting or erasing data, and seeking timely grievance redressal.
- The Act also requires mandatory breach notifications to both regulators and affected users and imposes steep penalties up to Rs 250 crore for violations.
Digital Personal Data Protection (DPDP) Rules Ready for Publication (End of September)
The Digital Personal Data Protection (DPDP) rules are ready and will be published in the next 10 days IT Minister Ashwini Vaishnaw confirmed the rules will be released by September 28
Draft IT Rules Amendments: Mandatory Labelling & Metadata for AI-Generated Content (End of October)
Proposed by: Ministry of Electronics and Information Technology (MeitY) through draft amendments to the IT Rules, 2021 Objective: 'to curb user harm from AI-generated deepfakes and synthetically produced content' and…
IPPB Partners with EPFO to Offer Digital Life Certificates to Pensioners (Start of November)
India Post Payments Bank (IPPB), a 100% government-owned entity under the Department of Posts, has signed an MoU with the Employees' Provident Fund Organisation (EPFO). The partnership aims to provide doorstep digital…
India-U.K. CETA Chapter 12: Digital Trade Gains and Sovereignty Concerns (Mid of August)
The Commerce Ministry estimates India’s software export pipeline at $30 billion a year. Close to 99% of Indian merchandise exports are expected to enter the U.K. duty-free once the agreement is implemented.