DPDP rules implementation | Current Affairs | Vision IAS
MENU
Home

Periodically curated articles and updates on national and international developments relevant for UPSC Civil Services Examination.

Quick Links

High-quality MCQs and Mains Answer Writing to sharpen skills and reinforce learning every day.

Watch explainer and thematic concept-building videos under initiatives like Deep Dive, Master Classes, etc., on important UPSC topics.

ESC

Daily News Summary

Get concise and efficient summaries of key articles from prominent newspapers. Our daily news digest ensures quick reading and easy understanding, helping you stay informed about important events and developments without spending hours going through full articles. Perfect for focused and timely updates.

News Summary

Sun Mon Tue Wed Thu Fri Sat

DPDP rules implementation

15 Nov 2025
2 min

Digital Personal Data Protection (DPDP) Act: New Rules and Implications

The newly notified administrative rules under the Digital Personal Data Protection (DPDP) Act are set to significantly impact the demand and functionality of consent managers, who act on behalf of users.

Consent Managers and Compliance

  • India-incorporated companies with a minimum net worth of ~20 million must apply to be consent managers within 12 months.
  • Such companies need to register with the Data Protection Board (DPB) and adhere to its obligations.
  • Consent managers must maintain a log of consents given, denied, or withdrawn and track notices related to data processing.
  • User data records should be kept for at least seven years, or longer if required.

Business Operations and Technological Overhaul

  • Businesses will require dedicated consent management platforms to handle consents across all user interactions.
  • Platforms must support one-click consent withdrawal, periodic audits, and re-consent mechanisms.
  • Firms face a choice: pursue transformative business redesign for compliance or risk penalties by incremental adjustments.

Role of Consent Managers and Data Protection Officers

  • Consent managers must not subcontract or assign any obligations under the DPDP Act.
  • The role of Chief Information Security Officer (CISO) now integrates with consent and governance, not just security.
  • Training staff and redesigning processes for compliance will be crucial.
  • Each company entity requires a Data Protection Officer (DPO) for consent and data governance.

Data Governance and Management

  • Entities collecting personal identifiable information (PII) must specify retention duration explicitly.

Verifiable Parental Consent for Children's Data

  • Users below 18 are considered children, requiring parental consent for data processing.
  • Identity of the parent must be verified through a voluntarily provided ID or via Digital Locker.

Explore Related Content

Discover more articles, videos, and terms related to this topic

Title is required. Maximum 500 characters.

Search Notes

Filter Notes

Loading your notes...
Searching your notes...
Loading more notes...
You've reached the end of your notes

No notes yet

Create your first note to get started.

No notes found

Try adjusting your search criteria or clear the search.

Saving...
Saved

Please select a subject.

Referenced Articles

linked

No references added yet

Subscribe for Premium Features