Advanced Search Options : ❯
Section 26 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
The Chairperson exercises general superintendence over the Board's administrative matters and may issue directions. Board officers may be authorised to scrutinise intimations, complaints, references and correspondence. The Chairperson may also authorise individual Members or groups of Members to perform Board functions and conduct proceedings, and may allocate proceedings among them.
Section 25 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Public-servant status is conferred on the Chairperson, Members, officers and employees of the Data Protection Board of India when acting, or purporting to act, under the Digital Personal Data Protection Act, 2023. They are deemed to be public servants for the purposes of the Indian Penal Code.
Section 24 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Section 24 authorises the Data Protection Board of India to appoint officers and employees necessary for efficient discharge of its functions, subject to prior approval of the Central Government. Prescribed terms and conditions govern appointment and service. The staffing framework takes effect from 13 November 2025.
Section 23 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
The Board must follow prescribed procedures for meetings and business, including digital meetings, and authenticate its orders, directions and instruments as prescribed. Proceedings remain valid despite vacancies, constitutional or appointment defects, and non-merits procedural irregularities. If the Chairperson is unable to act owing to absence, illness or another cause, the senior-most Member performs the Chairperson's functions until duties resume.
Section 22 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Resignation by the Chairperson or any other Member becomes effective upon the earliest specified event, including permission to relinquish office, lapse of three months, appointment of a successor, or expiry of term. Vacancies must be filled by fresh appointment. Former office-holders are subject to a one-year post-tenure employment restriction, requiring prior approval and disclosure of employment with Data Fiduciaries involved in proceedings initiated by or before them.
Section 21 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Section 21 disqualifies persons from appointment or continuation as Chairperson or Member where they are insolvent, convicted of an offence involving moral turpitude, physically or mentally incapable, or hold interests likely to prejudice official functions. Abuse of office prejudicial to the public interest is also a disqualification. Removal by the Central Government requires that the concerned Chairperson or Member be given an opportunity to be heard.
Section 20 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Service conditions of the Chairperson and other Members of the Data Protection Board of India are to be prescribed, and their salary, allowances and other terms cannot be varied to their disadvantage after appointment. They hold office for a two-year term and are eligible for re-appointment.
Section 19 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
The Data Protection Board of India comprises a Chairperson and a notified number of Members, appointed by the Central Government in the prescribed manner. Appointees must demonstrate ability, integrity and standing, with special knowledge or practical experience in governance, legal, technological, economic, regulatory, consumer-protection or dispute-resolution fields, or another field considered useful to the Board. At least one appointee must be a law expert.
Section 18 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Section 18 establishes the Data Protection Board of India with effect from 13 November 2025, following appointment by the Central Government. The Board is a body corporate with perpetual succession and a common seal. Subject to the Act, it may acquire, hold and dispose of movable and immovable property, enter into contracts, and sue or be sued in its corporate name. Its headquarters must be located at a place notified by the Central Government.
Section 17 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Section 17 disapplies Chapter II requirements, except section 8(1) and (5), Chapter III, and section 16 for defined processing, including legal claims, judicial or regulatory functions, law enforcement, foreign-data contracts, approved corporate restructuring, and assessment of loan defaulters' financial information. It allows broader exclusions for notified State processing on specified public-interest grounds and for research, archiving, or statistical purposes where no decision is made about a Data Principal and prescribed standards are followed.
Section 16 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Cross-border processing of personal data may be restricted through notification for transfers by a Data Fiduciary to specified countries or territories outside India. The provision preserves the operation of Indian laws imposing higher protection standards or stricter restrictions on transfers of personal data outside India, whether concerning particular personal data, Data Fiduciaries, or classes thereof.
Section 15 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Section 15 requires Data Principals to exercise personal-data rights in compliance with applicable laws. They must not impersonate another person, suppress material information when furnishing personal data for State-issued identity or address documentation, or lodge false or frivolous grievances or complaints. Information furnished while exercising correction or erasure rights must be verifiably authentic.
Section 14 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Section 14 gives a Data Principal the right to nominate another individual in the prescribed manner. The nominee may exercise the Data Principal's rights upon death or incapacity. Incapacity means inability to exercise those rights due to unsoundness of mind or bodily infirmity.
Section 13 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Data Fiduciaries and Consent Managers must provide readily available means for Data Principals to seek redress for acts or omissions affecting personal-data obligations or the exercise of rights. They must respond to every grievance within the prescribed period applicable to the relevant class. Data Principals must exhaust this grievance-redressal opportunity before approaching the Board.
Section 12 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Data Principals may seek correction, completion, updating and erasure of personal data processed with prior consent, subject to applicable legal requirements and procedures. Data Fiduciaries must correct inaccurate or misleading data, complete incomplete data and update data upon request. Erasure must follow a prescribed request unless retention is necessary for the specified purpose or compliance with law.
Section 11 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
A Data Principal who has previously given consent for personal-data processing may request a summary of processed data, related processing activities, and prescribed information from the relevant Data Fiduciary. The Data Principal may also obtain the identities of other Data Fiduciaries and Data Processors with whom the data has been shared, and a description of the data shared. This disclosure does not apply to legally authorised sharing pursuant to a written request for specified law-enforcement or cyber-incident purposes.
Section 10 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Significant Data Fiduciaries must appoint an India-based Data Protection Officer accountable to their board or similar governing body and acting as the grievance-redressal contact. They must appoint an independent data auditor to evaluate compliance and conduct periodic Data Protection Impact Assessments, periodic data audits, and prescribed additional measures. Designation may follow an assessment of personal-data volume and sensitivity, risks to Data Principals' rights, and potential effects on sovereignty, electoral democracy, State security, and public order.
Section 9 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Processing of personal data of a child, or of a person with disability who has a lawful guardian, requires verifiable consent from the parent or lawful guardian in the prescribed manner. Processing likely to cause a detrimental effect on a child's well-being is prohibited. Data Fiduciaries must not track or behaviourally monitor children, or direct targeted advertising at them. Prescribed exemptions and age-based exemptions for verifiably safe processing may apply.
Section 8 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Data Fiduciaries remain responsible for compliance in respect of personal-data processing undertaken by them or through Data Processors. Processor engagement for goods or services activities requires a valid contract. Fiduciaries must maintain data accuracy where decisions affecting Data Principals or disclosures are involved, apply technical and organisational safeguards, and notify the Board and affected Data Principals of breaches. They must erase data upon consent withdrawal or when the specified purpose ends, subject to legally required retention, and provide contact information and grievance redressal.
Section 7 of the Digital Personal Data Protection Act, 2023 - Indian Laws - Acts
Data Fiduciaries may process personal data for a voluntarily supplied specified purpose unless the Data Principal indicates non-consent, and must cease processing where requested assistance is no longer needed. State entities may process data for prescribed public delivery where prior consent or notified government records exist, subject to applicable standards. Further legitimate uses include statutory functions and disclosures, legal-order compliance, medical emergencies, public-health threats, disasters, public-order breakdowns, and employment-related safeguards against loss or liability.