Advanced Search Options : ❯
Section 24 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Section 24 authorises the Data Protection Board of India to appoint officers and employees necessary for efficient discharge of its functions, subject to prior approval of the Central Government. Prescribed terms and conditions govern appointment and service. The staffing framework takes effect from 13 November 2025.
Section 23 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
The Board must follow prescribed procedures for meetings and business, including digital meetings, and authenticate its orders, directions and instruments as prescribed. Proceedings remain valid despite vacancies, constitutional or appointment defects, and non-merits procedural irregularities. If the Chairperson is unable to act owing to absence, illness or another cause, the senior-most Member performs the Chairperson's functions until duties resume.
Section 22 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Resignation by the Chairperson or any other Member becomes effective upon the earliest specified event, including permission to relinquish office, lapse of three months, appointment of a successor, or expiry of term. Vacancies must be filled by fresh appointment. Former office-holders are subject to a one-year post-tenure employment restriction, requiring prior approval and disclosure of employment with Data Fiduciaries involved in proceedings initiated by or before them.
Section 21 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Section 21 disqualifies persons from appointment or continuation as Chairperson or Member where they are insolvent, convicted of an offence involving moral turpitude, physically or mentally incapable, or hold interests likely to prejudice official functions. Abuse of office prejudicial to the public interest is also a disqualification. Removal by the Central Government requires that the concerned Chairperson or Member be given an opportunity to be heard.
Section 20 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Service conditions of the Chairperson and other Members of the Data Protection Board of India are to be prescribed, and their salary, allowances and other terms cannot be varied to their disadvantage after appointment. They hold office for a two-year term and are eligible for re-appointment.
Section 19 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
The Data Protection Board of India comprises a Chairperson and a notified number of Members, appointed by the Central Government in the prescribed manner. Appointees must demonstrate ability, integrity and standing, with special knowledge or practical experience in governance, legal, technological, economic, regulatory, consumer-protection or dispute-resolution fields, or another field considered useful to the Board. At least one appointee must be a law expert.
Section 18 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Section 18 establishes the Data Protection Board of India with effect from 13 November 2025, following appointment by the Central Government. The Board is a body corporate with perpetual succession and a common seal. Subject to the Act, it may acquire, hold and dispose of movable and immovable property, enter into contracts, and sue or be sued in its corporate name. Its headquarters must be located at a place notified by the Central Government.
Section 17 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Section 17 establishes exemptions from specified data-protection obligations. Chapter II, subject to retained requirements, Chapter III and section 16 do not apply to processing for legal claims, judicial or regulatory functions, offence-related purposes, foreign contracts concerning data principals outside India, approved corporate restructurings, and assessment of a loan defaulter's financial position subject to disclosure law. The Digital Personal Data Protection Act, 2023 does not apply to notified State processing on specified public-interest grounds or to qualifying research, archiving and statistical processing.
Section 16 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Section 16 permits the Central Government to restrict a Data Fiduciary's transfer of personal data for processing in specified foreign countries or territories. Indian laws imposing higher protection or stricter overseas-transfer restrictions remain applicable to particular personal data, Data Fiduciaries, or classes of Data Fiduciaries. Commencement is specified as eighteen months from 13 November 2025.
Section 15 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Data Principals must comply with applicable laws when exercising rights, avoid impersonation and suppression of material information, and refrain from lodging false or frivolous grievances or complaints. Personal data provided for documents, unique identifiers, identity proofs, or address proofs must not omit material information. Correction or erasure requests must contain only verifiably authentic information.
Section 14 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Section 14 gives a Data Principal the right to nominate another individual in the prescribed manner. The nominee may exercise the Data Principal's rights upon death or incapacity. Incapacity means inability to exercise those rights due to unsoundness of mind or bodily infirmity.
Section 13 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Data Fiduciaries and Consent Managers must provide readily available means for Data Principals to seek redress for acts or omissions affecting personal-data obligations or the exercise of rights. They must respond to every grievance within the prescribed period applicable to the relevant class. Data Principals must exhaust this grievance-redressal opportunity before approaching the Board.
Section 12 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Data Principals may seek correction, completion, updating and erasure of personal data processed with prior consent, subject to applicable legal requirements and procedures. Data Fiduciaries must correct inaccurate or misleading data, complete incomplete data and update data upon request. Erasure must follow a prescribed request unless retention is necessary for the specified purpose or compliance with law.
Section 11 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
A Data Principal who has previously given consent for personal-data processing may request a summary of processed data, related processing activities, and prescribed information from the relevant Data Fiduciary. The Data Principal may also obtain the identities of other Data Fiduciaries and Data Processors with whom the data has been shared, and a description of the data shared. This disclosure does not apply to legally authorised sharing pursuant to a written request for specified law-enforcement or cyber-incident purposes.
Section 10 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Significant Data Fiduciaries must appoint an India-based Data Protection Officer accountable to their board or similar governing body and acting as the grievance-redressal contact. They must appoint an independent data auditor to evaluate compliance and conduct periodic Data Protection Impact Assessments, periodic data audits, and prescribed additional measures. Designation may follow an assessment of personal-data volume and sensitivity, risks to Data Principals' rights, and potential effects on sovereignty, electoral democracy, State security, and public order.
Section 9 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Processing of personal data of a child, or of a person with disability who has a lawful guardian, requires verifiable consent from the parent or lawful guardian in the prescribed manner. Processing likely to cause a detrimental effect on a child's well-being is prohibited. Data Fiduciaries must not track or behaviourally monitor children, or direct targeted advertising at them. Prescribed exemptions and age-based exemptions for verifiably safe processing may apply.
Section 8 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Data Fiduciaries remain responsible for compliance in respect of personal-data processing undertaken by them or through Data Processors. Processor engagement for goods or services activities requires a valid contract. Fiduciaries must maintain data accuracy where decisions affecting Data Principals or disclosures are involved, apply technical and organisational safeguards, and notify the Board and affected Data Principals of breaches. They must erase data upon consent withdrawal or when the specified purpose ends, subject to legally required retention, and provide contact information and grievance redressal.
Section 7 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Data Fiduciaries may process personal data for a voluntarily supplied specified purpose unless the Data Principal indicates non-consent, and must cease processing where requested assistance is no longer needed. State entities may process data for prescribed public delivery where prior consent or notified government records exist, subject to applicable standards. Further legitimate uses include statutory functions and disclosures, legal-order compliance, medical emergencies, public-health threats, disasters, public-order breakdowns, and employment-related safeguards against loss or liability.
Section 6 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Consent for personal-data processing must be free, specific, informed, unconditional and unambiguous, based on clear affirmative action, and limited to data necessary for the stated purpose. Consent requests must be clear, accessible in prescribed languages, and provide relevant contact details. Data Principals may withdraw consent as easily as it was given; the Data Fiduciary and its Data Processors must then cease processing within a reasonable time unless processing is legally required or authorised. Where consent is disputed, the Data Fiduciary must prove compliant notice and consent.
Section 5 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
A Data Fiduciary seeking consent must give or precede its request with notice identifying the personal data proposed for processing, the processing purpose, the Data Principal's rights, and the complaint mechanism before the Board. For consent obtained before commencement, equivalent information must be provided as soon as reasonably practicable, while processing may continue until consent is withdrawn. Notices must be accessible in English or an Eighth Schedule language.