Advanced Search Options : ❯
Section 21 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Disqualification from appointment or continuation as Chairperson or Member arises from insolvency, a conviction involving moral turpitude, physical or mental incapacity, prejudicial financial or other interests, or abuse of office prejudicial to public interest. Removal by the Central Government requires that the Chairperson or Member first receive an opportunity to be heard.
Section 20 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Service conditions, including salary and allowances, of the Chairperson and other Members are to be prescribed and cannot be varied to their disadvantage after appointment. Each holds office for a two-year term and is eligible for re-appointment, combining protection against adverse service-condition changes with eligibility for successive appointments.
Section 19 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
The Data Protection Board of India comprises a Chairperson and such additional Members as may be notified by the Central Government, with appointments made through the prescribed manner. Appointees must have ability, integrity and standing, together with special knowledge or practical experience in data governance, administration, social or consumer protection laws, dispute resolution, information and communication technology, the digital economy, law, regulation or techno-regulation. At least one appointee must be a legal expert.
Section 18 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Section 18 establishes the Data Protection Board of India from a date appointed by Central Government notification. The Board is a body corporate with perpetual succession and a common seal. Subject to the Act, it may acquire, hold and dispose of movable or immovable property, contract, and sue or be sued. Its headquarters shall be at a place notified by the Central Government.
Section 17 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Section 17 disapplies specified data-protection obligations for processing necessary to enforce legal claims, perform judicial or regulatory functions, support law enforcement, fulfil certain foreign contracts, implement approved corporate transactions, or assess a loan defaulter's financial position. Full exemptions may apply to notified State instrumentalities on specified public-interest grounds and to qualifying research, archiving or statistical processing. The Central Government may also grant targeted exemptions to notified Data Fiduciaries, including recognised startups, and may temporarily disapply any provision to specified Data Fiduciaries or classes.
Section 16 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Cross-border processing of personal data may be restricted through notification for transfers by a Data Fiduciary to specified countries or territories outside India. The provision preserves the operation of Indian laws imposing higher protection standards or stricter restrictions on transfers of personal data outside India, whether concerning particular personal data, Data Fiduciaries, or classes thereof.
Section 15 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Section 15 requires Data Principals to exercise personal-data rights in compliance with applicable laws. They must not impersonate another person, suppress material information when furnishing personal data for State-issued identity or address documentation, or lodge false or frivolous grievances or complaints. Information furnished while exercising correction or erasure rights must be verifiably authentic.
Section 14 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Right to nominate enables a Data Principal to designate another individual, in the manner prescribed by law, to exercise the Data Principal's rights upon death or incapacity. The nominee acts in accordance with the applicable statutory framework and governing rules. Incapacity means inability to exercise Data Principal rights because of unsoundness of mind or infirmity of body.
Section 13 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Section 13 grants a Data Principal the right to readily available grievance redressal against acts or omissions of a Data Fiduciary or Consent Manager concerning personal-data obligations or the exercise of rights. Data Fiduciaries and Consent Managers must respond within the prescribed period. The Data Principal must exhaust the available grievance-redressal process before approaching the Board.
Section 12 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
A Data Principal may seek correction, completion, updating and erasure of personal data for which consent to processing was previously given, subject to applicable legal requirements and procedures. A Data Fiduciary must correct inaccurate or misleading data, complete incomplete data, and update data upon request. Personal data must be erased following a prescribed request unless retention is necessary for the specified purpose or compliance with applicable law.
Section 11 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Section 11 enables a Data Principal who has previously consented to processing to request from the relevant Data Fiduciary a summary of personal data and processing activities, identities of recipients and the data shared, and prescribed related information. Disclosure of recipient identities and prescribed related information is excluded for sharing with a legally authorised Data Fiduciary on a written request connected with preventing, detecting or investigating offences or cyber incidents, or prosecuting or punishing offences.
Section 10 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Significant Data Fiduciary status may be notified after considering the scale and sensitivity of personal data processing and related risks to Data Principal rights, national interests, electoral democracy, State security, and public order. Such fiduciaries must appoint an India-based Data Protection Officer and an independent data auditor, conduct periodic Data Protection Impact Assessments and audits, and comply with further prescribed measures.
Section 9 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Data Fiduciaries must obtain verifiable consent from a child's parent or lawful guardian before processing a child's personal data and must not undertake processing likely to harm the child's well-being. Tracking, behavioural monitoring and targeted advertising directed at children are prohibited. Prescribed exemptions may apply to specified Data Fiduciaries, purposes and conditions. Where processing is verifiably safe, an age-based exemption may apply to specified consent and child-protection obligations.
Section 8 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Data Fiduciaries remain responsible for compliant personal-data processing undertaken by them or by Data Processors, who may be engaged only under valid contracts. They must maintain data quality for consequential decisions or disclosures, implement technical and organisational compliance measures, maintain reasonable security safeguards, and notify the Board and affected Data Principals of breaches. Personal data must be erased on consent withdrawal or when its purpose ends, unless legal retention is required, including erasure by Data Processors. They must also publish appropriate contact information and provide effective grievance redressal.
Section 7 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
A Data Fiduciary may process personal data for the specified purpose for which a Data Principal voluntarily supplies it, provided the Data Principal has not indicated non-consent, and must cease processing when requested assistance is no longer required. Processing is also permitted for prescribed State benefits and functions, legally required disclosures, compliance with judgments or orders, medical emergencies, public-health threats, disasters, public-order breakdowns, and employment purposes. Employment-related processing includes protection against loss or liability, prevention of corporate espionage, confidentiality of trade secrets, intellectual property or classified information, and provision of employee-requested services or benefits.
Section 6 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Consent-based personal data processing requires free, specific, informed, unconditional and unambiguous affirmative consent, limited to data necessary for a specified purpose. Consent requests must use clear language, permit access in English or a listed constitutional language, and provide rights-related contact details. Consent may be withdrawn as easily as it is given; the Data Fiduciary and its Data Processors must then cease processing within a reasonable time unless otherwise authorised by law. The Data Fiduciary must prove compliant notice and consent where disputed.
Section 5 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Data Fiduciaries must provide notice before or with a consent request, identifying the personal data proposed for processing, its purpose, the means to exercise statutory rights, and the complaint mechanism. For consent obtained before commencement, notice must be provided as soon as reasonably practicable, and processing may continue until consent is withdrawn. Notices must be accessible in English or an Eighth Schedule language.
Section 4 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Personal data processing is permitted only in accordance with the Act and for a lawful purpose. Processing a Data Principal's personal data may proceed where the Data Principal has given consent or where it falls within certain legitimate uses. A lawful purpose is one not expressly forbidden by law.
Section 3 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Digital Personal Data Protection Act, 2023 applies to processing of digital personal data within India when collected digitally or subsequently digitised, and to certain processing outside India connected with offering goods or services to Data Principals in India. Coverage excludes personal data processed for personal or domestic purposes and data publicly made available by the Data Principal or by a person legally obliged to disclose it.
Section 2 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Processing comprises wholly or partly automated operations on digital personal data, including collection, storage, use, sharing, restriction, erasure and destruction. A personal data breach includes unauthorised processing or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access that compromises confidentiality, integrity or availability. A Data Fiduciary determines the purpose and means of processing, while a Data Processor acts on its behalf. Consent Managers enable Data Principals to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform.