THE RULES

Rule 11 - Verifiable consent for processing of personal data of person with disability

Official text

(1)A Data Fiduciary, while obtaining verifiable consent from an individual identifying herself as the lawful guardian of a person with disability, shall observe due diligence to verify that such guardian is appointed by a court of law, or by a designated authority or by a local level committee, under the law applicable to guardianship.

(2)In this rule, the expression—

(a)“designated authority” shall mean an authority designated under section 15 of the Rights of Persons with Disabilities Act, 2016 (49 of 2016) to support persons with disabilities in exercise of their legal capacity;

(b)“law applicable to guardianship” shall mean, —

(i)in relation to an individual who has long term physical, mental, intellectual or sensory impairment which, in interaction with barriers, hinders her full and effective participation in society equally with others and who despite being provided adequate and appropriate support is unable to take legally binding decisions, the provisions of law contained in Rights of Persons with Disabilities Act, 2016 (49 of 2016) and the rules made thereunder; and

(ii)in relation to a person who is suffering from any of the conditions relating to autism, cerebral palsy, mental retardation or a combination of such conditions and includes a person suffering from severe multiple disability, the provisions of law of the National Trust for the Welfare of Persons with Autism, Cerebral Palsy, Mental Retardation and Multiple Disabilities Act, 1999 (44 of 1999) and the rules made thereunder;

(c)“local level committee” shall mean a local level committee constituted under section 13 of the National Trust for the Welfare of Persons with Autism, Cerebral Palsy, Mental Retardation and Multiple Disabilities Act, 1999 (44 of 1999);

(d)“person with disability” shall mean and include—

(i)an individual who has long term physical, mental, intellectual or sensory impairment which, in interaction with barriers, hinders her full and effective participation in society equally with others and who, despite being provided adequate and appropriate support, is unable to take legally binding decisions; and

(ii)an individual who is suffering from any of the conditions relating to autism, cerebral palsy, mental retardation or a combination of any two or more of such conditions and includes an individual suffering from severe multiple disability and who, despite being provided adequate and appropriate support, is unable to take legally binding decisions.

Cross-references

Rule 11

Commentary

Rule 11 addresses a narrow and legally sensitive situation. It applies where an individual claims authority to give consent as the lawful guardian of a person with disability. Before accepting that consent, the Data Fiduciary must verify that the claimed guardian has actually been appointed under the applicable guardianship law by a competent court, designated authority or local level committee.

The Rule does not mean that every person with a disability requires a guardian, lacks legal capacity or must act through another person. Disability and legal incapacity are not interchangeable. The guardianship route arises only where, despite adequate and appropriate support, the individual is unable to take legally binding decisions and a guardian has been lawfully appointed under the applicable statutory framework.

The central principle is therefore:

Key point

The Data Fiduciary must begin with the person’s own legal agency. It may accept substitute consent from a guardian only where the individual falls within Rule 11 and the claimed guardian’s legal authority has been properly verified.

The final DPDP Rules were notified on 13 November 2025. Rule 11 is scheduled to come into force on 13 May 2027. The Rules define “verifiable consent” by reference to the mechanisms prescribed in Rules 10 and 11.

1. The function of Rule 11

The DPDPA ordinarily treats the individual to whom personal data relates as the Data Principal. The individual gives consent, withdraws consent, exercises rights and raises grievances.

Where a person with disability has a lawful guardian acting on her behalf, the statutory definition of Data Principal includes that lawful guardian. Rule 11 ensures that a Data Fiduciary does not rely on a bare and potentially false assertion of guardianship.

Without Rule 11, a person could approach a bank, hospital, insurer, employer, platform or government service and simply state:

“I am her guardian. I consent on her behalf.”

That assertion may be inaccurate. The person may be:

  • a relative with no legal appointment;

  • a caregiver;

  • an employee of a care institution;

  • a friend;

  • a person whose appointment has expired or been cancelled;

  • a guardian appointed only for a different matter;

  • or someone attempting to obtain unauthorised access.

Rule 11 therefore requires verification of the source, validity and scope of the guardian’s legal authority.

This protects the person with disability against:

  • impersonation;

  • unnecessary substitution of her own decision;

  • disclosure to unauthorised relatives;

  • consent given outside a guardian’s legal powers;

  • misuse of financial or health information;

  • and indefinite control by a person whose guardianship has ended.

At the same time, the Rule enables processing where the person genuinely cannot make the relevant legally binding decision even after appropriate support and a recognised guardian must act.

2. Rule 11 must not be read as a presumption of incapacity

The most important interpretive safeguard is that a person does not lose legal capacity merely because she has a physical, mental, intellectual or sensory impairment.

The Rights of Persons with Disabilities Act, 2016 is founded on dignity, autonomy, freedom to make one’s own choices, non-discrimination, inclusion and equal participation. Its statutory structure separately addresses legal capacity, guardianship and authorities designated to provide support.

Rule 11 itself reinforces this approach. Its definition is not limited to the existence of an impairment. It requires the additional condition that the individual remains unable to take legally binding decisions despite being provided adequate and appropriate support.

Accordingly, the correct sequence is not:

  1. identify a disability;

  2. presume incapacity;

  3. demand guardian consent.

The legally sound sequence is:

  1. communicate directly with the person in an accessible manner;

  2. provide reasonable and appropriate support;

  3. determine whether the person can make the particular decision with that support;

  4. accept her own decision if she can;

  5. require guardian involvement only where she is unable to take the relevant legally binding decision and lawful guardianship exists.

This distinction is fundamental.

2.1 Illustration: Person with visual impairment

A visually impaired customer wishes to open an online account. She can understand the processing and give consent if the notice is made accessible through a screen reader.

The Data Fiduciary cannot require guardian consent merely because she has a disability. It should make the interface accessible and take consent directly from her.

2.2 Illustration: Person who communicates differently

An individual has a speech impairment but can understand the notice and communicate a decision through writing, assistive technology or another accessible method.

The absence of conventional speech does not justify substitute consent. The Data Fiduciary must recognise an effective accessible communication method.

2.3 Illustration: Supported decision-making

An individual with an intellectual disability initially finds a complex insurance notice difficult to understand. The insurer simplifies the explanation, permits use of an accessible format and allows a trusted support person to assist without making the decision for her.

If the individual can then understand the essential processing and communicate her choice, her own consent should be obtained. Rule 11 should not be invoked merely because support was necessary.

3. The Rule is decision-specific, not a general declaration about the person

Capacity should not be treated as an all-or-nothing status.

An individual may be capable of deciding:

  • whether to receive service communications;

  • whether to share a photograph;

  • whether to use an entertainment application;

  • or whether to update contact information, while requiring lawful assistance for a highly complex financial or property transaction.

A guardianship arrangement may also be limited to particular matters. The Data Fiduciary should therefore examine whether the guardian’s appointment covers the processing decision in question.

3.1 Illustration: Limited financial guardianship

A guardian is appointed to assist with specified financial and property decisions. The person with disability separately wishes to choose privacy settings for an ordinary communication application.

The Data Fiduciary should not assume that the financial guardianship gives the guardian complete control over every personal-data decision. It must examine the governing appointment and the nature of the processing.

3.2 Illustration: Healthcare decision outside the appointment

A person produces a guardianship order limited to management of property and seeks access to the individual’s complete medical history.

The order may establish that the person is a guardian for a particular purpose, but not necessarily that she has authority over medical-data consent or disclosure. The healthcare provider must verify scope, not merely the existence of a document containing the word “guardian.”

4. The two guardianship frameworks recognised by Rule 11

Rule 11 recognises two principal statutory pathways.

4.1 Rights of Persons with Disabilities Act, 2016

The first applies to an individual with a long-term physical, mental, intellectual or sensory impairment which, in interaction with barriers, hinders full and effective participation in society on an equal basis with others, and who remains unable to take legally binding decisions despite adequate and appropriate support.

The relevant legal framework is the Rights of Persons with Disabilities Act, 2016 and the rules made under it.

Under that framework, guardianship must be understood alongside the principles of legal capacity, support and limited guardianship. Section 15 concerns designation of authorities to mobilise community resources and establish social networks to support persons with disabilities in exercising legal capacity.

The Rule recognises an authority designated under Section 15 as a “designated authority” for guardianship-verification purposes.

4.2 National Trust Act, 1999

The second pathway applies to a person covered by the National Trust for the Welfare of Persons with Autism, Cerebral Palsy, Mental Retardation and Multiple Disabilities Act, 1999, who remains unable to take legally binding decisions despite adequate and appropriate support.

Under the National Trust framework:

  • local level committees are constituted under Section 13;

  • applications for guardianship are considered under Section 14;

  • guardianship may concern the person, property or both;

  • and the framework includes monitoring and removal of guardians.

The National Trust describes guardianship as need-based and recognises that limited guardianship may be appropriate where enabling mechanisms allow varying degrees of independence.

The Data Fiduciary must identify which legal regime supports the claimed appointment. It should not treat every certificate of disability, medical record or caregiver declaration as a guardianship appointment.

5. What the Data Fiduciary must verify

The Data Fiduciary must verify more than the identity of the person claiming to be guardian. It should establish a reliable chain showing that:

  • the person with disability is the individual to whom the proposed processing relates;

  • the person claiming to act is identifiable;

  • a competent court, designated authority or local level committee made the appointment;

  • the appointment relates to the correct individual;

  • the appointment remains valid;

  • it has not been revoked, suspended or replaced;

  • the contemplated decision falls within its scope;

  • any conditions or limitations are respected;

  • and the guardian, rather than an unauthorised delegate, is giving the consent.

The Data Fiduciary should not demand more information than reasonably necessary, but it must obtain enough evidence to support the legal conclusion that the person has authority to act.

5.1 Illustration: Relative without appointment

A woman accompanies her adult brother with disability to a bank. She regularly assists him and identifies herself as his caregiver. She asks the bank to disclose his account information and says she consents to processing on his behalf.

Family relationship and practical care do not automatically establish lawful guardianship. The bank should first communicate with the account holder using appropriate support. If guardian authority is genuinely required, the sister must establish a valid appointment under the applicable law.

5.2 Illustration: Parent of an adult person with disability

A parent has supported an adult child for many years and assumes that parenthood automatically permits her to consent to all processing.

Rule 11 does not equate parenthood of an adult with lawful guardianship. The Data Fiduciary must verify whether the parent has actually been appointed under the applicable guardianship law and whether that appointment covers the relevant decision.

5.3 Illustration: Institutional caregiver

An employee of a residential care institution asks a hospital for the health records of a resident and states that the institution acts as guardian.

The employee’s caregiving role or employment does not by itself prove lawful guardianship. The hospital must verify the appointment and the employee’s authority to act for the appointed guardian or institution.

6. Court, designated authority and local level committee appointments

Rule 11 recognises three sources of lawful appointment.

A guardian may be appointed by:

  • a court of law;

  • a designated authority under the Rights of Persons with Disabilities Act framework; or

  • a local level committee under the National Trust Act framework.

These sources are not interchangeable pieces of identification. Each represents a legal authority from which the guardian’s power arises.

A Data Fiduciary should therefore examine the appointment rather than merely note that a document was produced.

The verification should ordinarily consider:

  • name of the appointing body;

  • legal provision under which the appointment was made;

  • order, certificate or reference number;

  • date of appointment;

  • identity of the guardian;

  • identity of the person represented;

  • scope of guardianship;

  • duration;

  • restrictions;

  • review conditions;

  • and revocation or substitution information.

Where the appointment is available through a reliable official verification mechanism, verifying the reference or status may be more appropriate than permanently retaining a complete copy of the order.

7. Scope of guardianship is central

The existence of guardianship does not necessarily mean that the guardian may make every decision for the person.

The appointment may be limited by:

  • subject matter;

  • duration;

  • transaction value;

  • type of service;

  • property or personal matters;

  • requirement for consultation;

  • joint decision-making;

  • periodic review;

  • or another condition.

The Data Fiduciary must match the consent sought with the guardian’s actual authority.

7.1 Illustration: Property-related authority

A guardian is appointed to manage the individual’s immovable property. A social-media platform accepts the same guardian’s consent for public sharing of photographs and behavioural profiling.

The platform cannot safely assume that property-management authority extends to all digital privacy decisions. The scope of the appointment must be examined.

7.2 Illustration: Limited banking authority

A guardian has authority to operate a particular bank account and make payments for the individual’s care.

Another financial institution seeks consent from the guardian to use the individual’s financial behaviour for targeted product advertising. That processing may lie outside both the guardianship purpose and the individual’s interests.

7.3 Illustration: Joint or consultative decision

An appointment requires the guardian to consult the person and assist her in reaching decisions instead of acting entirely in substitution.

A Data Fiduciary should not design the process so that the guardian alone clicks approval without any accessible communication with the person. The consent workflow should respect the legally prescribed decision-making arrangement.

8. Verification should not replace accessibility and support

A common implementation error would be to treat Rule 11 as the default route whenever an accessibility issue arises.

Example

For example:

  • an inaccessible website does not prove incapacity;

  • inability to read small text does not prove incapacity;

  • inability to hear an audio notice does not prove incapacity;

  • difficulty using a standard keyboard does not prove incapacity;

  • limited literacy does not automatically prove incapacity;

  • and communication through an interpreter does not transfer decision-making authority to the interpreter.

The Data Fiduciary should first remove barriers.

Appropriate support may include:

  • accessible electronic formats;

  • screen-reader compatibility;

  • captions;

  • sign-language support;

  • simplified language;

  • audio explanation;

  • additional time;

  • assistive input methods;

  • supported communication;

  • or a trusted person who assists communication without replacing the individual’s choice.

8.1 Illustration: Inaccessible consent interface

A website requires approval through a visual CAPTCHA that a blind user cannot complete. The company asks for guardian consent instead.

The problem is the inaccessible interface, not an established inability to make a legally binding decision. The Data Fiduciary should provide an accessible method rather than displace the person’s agency.

8.2 Illustration: Interpreter assistance

A person uses a sign-language interpreter during a healthcare consent discussion. The person understands the proposed processing and communicates her own choice through the interpreter.

The interpreter is facilitating communication, not acting as a lawful guardian. Consent remains the person’s own consent.

Even after lawful guardianship is verified, the consent must satisfy Section 6.

It must be:

  • free;

  • specific;

  • informed;

  • unconditional;

  • unambiguous;

  • expressed through clear affirmative action;

  • and limited to personal data necessary for the specified purpose.

The guardian must receive the notice required under Section 5 and Rule 3. The Data Fiduciary should explain:

  • what personal data will be processed;

  • why it is required;

  • what service or use it enables;

  • which purposes are optional;

  • who will receive the information;

  • how long it will be retained;

  • how consent may be withdrawn;

  • and how rights and grievances may be exercised.

A guardianship order proves authority. It does not prove that the guardian was adequately informed or that the processing is necessary.

9.1 Illustration: Bundled healthcare platform consent

A lawful guardian registers the person for a healthcare service. The platform presents one consent covering:

  • appointment management;

  • treatment records;

  • advertising;

  • commercial profiling;

  • sharing with wellness businesses;

  • and training a commercial AI model.

Even if the guardianship is properly verified, the consent may remain invalid because distinct purposes are bundled and the requested processing exceeds what is necessary for the health service.

10. The guardian must act within the represented person’s interests and authority

Rule 11 does not expressly set out a complete standard for conflicts between the guardian and the person with disability. The wider guardianship framework, however, exists to support and protect the represented person, not to create a commercial power over her personal data.

A Data Fiduciary should not accept guardian instructions blindly where obvious circumstances suggest:

  • conflict of interest;

  • financial exploitation;

  • disclosure for the guardian’s private benefit;

  • contradiction with the individual’s expressed wishes;

  • use beyond the appointment;

  • or abuse of authority.

The Data Fiduciary is not expected to resolve every family or guardianship dispute. But it should have an escalation process for suspicious or conflicting cases.

10.1 Illustration: Financial conflict

A guardian seeks the individual’s complete bank statements to support the guardian’s own loan application.

Even if the guardian has authority concerning some financial matters, the requested use appears directed toward the guardian’s personal benefit. The bank should not treat the guardianship certificate as unlimited authorisation for unrelated disclosure.

10.2 Illustration: Person objects to marketing

A lawful guardian consents to commercial marketing, but the person with disability clearly communicates that she does not want promotional communications.

The Data Fiduciary should not assume that legal guardianship requires it to ignore the individual’s preference. It should examine whether the guardian’s authority covers the matter, whether the processing is necessary and whether consent remains free and properly exercised in the represented person’s interests.

11. No automatic application to every person covered by disability legislation

Rule 11’s definition is narrower than the broad population of persons with disabilities.

It covers individuals who:

  • have the relevant impairment or covered condition; and

  • despite adequate and appropriate support, are unable to take legally binding decisions.

A person may hold a disability certificate, qualify for statutory benefits or fall within a recognised disability category while remaining fully capable of giving consent.

The Data Fiduciary should not use:

  • disability status;

  • medical diagnosis;

  • physical appearance;

  • use of assistive technology;

  • presence of a caregiver;

  • or receipt of disability benefits as a substitute for the legal-capacity inquiry.

11.1 Illustration: Employee with mobility impairment

An employee uses a wheelchair and receives workplace accommodation. The employer routes all privacy choices to a family member.

That approach has no basis under Rule 11. A mobility impairment does not establish inability to take legally binding decisions.

11.2 Illustration: Autism diagnosis

An autistic adult seeks to use an online service and communicates a clear, informed choice. The service demands guardian consent solely because of the diagnosis.

Rule 11 does not permit diagnosis-based substitution. The relevant question is whether the person can make the particular legally binding decision with adequate and appropriate support and whether a lawful guardian has been appointed.

12. Processing before guardian verification

Where the Data Fiduciary proposes to rely on a guardian’s consent, it should not begin the consent-based processing before verifying the guardianship and obtaining valid consent.

Some limited processing may be necessary to:

  • identify the person;

  • communicate with the claimed guardian;

  • verify the appointment;

  • secure the process;

  • prevent fraud;

  • and record an incomplete request.

That limited processing should remain proportionate and temporary.

12.1 Illustration: Financial-service application

A claimed guardian submits an application for an investment account in the name of a person with disability.

Before verification is complete, the financial institution may process limited information needed to verify identity and guardianship. It should not activate the investment account, disclose the individual’s existing holdings or begin promotional profiling while the authority remains unverified.

If verification fails or the request is abandoned, the Data Fiduciary should retain only what is legally necessary for security, fraud prevention, dispute handling or another applicable requirement.

13. Evidence of verification

A Data Fiduciary should maintain sufficient evidence to show that it did not accept an unverified guardianship assertion.

The compliance record should ordinarily permit reconstruction of:

  • the identity of the represented person;

  • the identity of the guardian;

  • the appointing court, authority or committee;

  • the appointment reference;

  • validation method;

  • date of verification;

  • scope and duration of authority;

  • limitations or conditions;

  • notice version presented;

  • purposes and personal data covered;

  • affirmative consent;

  • subsequent modification or withdrawal;

  • and later change, revocation or expiry of guardianship.

This does not necessarily require permanent storage of the entire guardianship order. Depending on the risk and available verification method, the Data Fiduciary may retain:

  • an official reference;

  • verified status;

  • relevant scope extract;

  • validation timestamp;

  • and audit trail.

The evidence should be sufficient without collecting or retaining information unrelated to the processing decision.

A record stating only “guardian verified” is weak because it does not establish:

  • who verified the guardian;

  • against what source;

  • what authority the guardian possessed;

  • whether the authority covered the consent;

  • or whether the appointment remained valid.

14. Data minimisation and protection of guardianship records

Guardianship records can reveal highly sensitive facts about the represented person, including disability status, decision-making support needs, family relationships, legal proceedings and financial or personal arrangements.

The Data Fiduciary should limit:

  • the documents collected;

  • the fields extracted;

  • the persons who can view them;

  • the purposes for which they are used;

  • and the period for which they are retained.

A customer-support employee may need to know that a verified guardian is authorised for a particular function. The employee may not need access to the complete court order or medical history underlying the appointment.

A suitable system may show:

  • guardian status verified;

  • permitted function;

  • validity period;

  • restrictions;

  • and escalation contact, while storing the supporting legal record in a more restricted environment.

The information must be protected through appropriate Rule 6 safeguards, including access controls, secure transmission, logging, masking where appropriate, Processor controls and incident response.

14.1 Illustration: Internal overexposure

A bank uploads a full guardianship order into the ordinary customer profile, making it visible to all branch, sales and call-centre personnel.

The bank may have verified the guardian correctly but still fail to protect and minimise the additional personal data disclosed by the order. Verification and security must operate together.

15. Periodic review and change in guardianship

Guardianship should not be treated as permanently valid merely because it was verified once.

The Data Fiduciary should consider re-verification where:

  • the appointment has a fixed duration;

  • the order requires periodic review;

  • the person’s decision-making position changes;

  • a designated authority modifies the arrangement;

  • a court issues a later order;

  • another guardian is appointed;

  • the guardian dies or becomes unavailable;

  • the guardian’s authority is suspended or removed;

  • the person disputes the authority;

  • or a high-risk transaction materially exceeds previous activity.

The National Trust framework provides for monitoring and removal of guardians, including removal where abuse, neglect or misappropriation is alleged.

A Data Fiduciary that continues relying on a removed guardian may process and disclose personal data without valid authority.

15.1 Illustration: Removed guardian

A bank verified a guardian three years earlier. The local level committee later removed that guardian and appointed another person. The former guardian attempts to obtain account information using the old appointment document.

A system that treats the initial verification as permanent may allow an unauthorised disclosure. Appropriate due diligence requires a mechanism to check current validity where the circumstances warrant it.

A guardian who validly gave consent may withdraw or modify that consent within the scope of the guardianship arrangement.

The Data Fiduciary should make withdrawal as easy as giving consent and should:

  • authenticate the guardian;

  • verify continuing authority where appropriate;

  • identify the relevant processing purposes;

  • record the withdrawal;

  • stop consent-based processing within a reasonable time;

  • instruct Data Processors;

  • explain genuine service consequences;

  • and retain only records required by law.

Where the individual becomes capable of making the relevant decision with appropriate support, the Data Fiduciary should not continue treating guardian control as the only available route.

16.1 Illustration: Limited withdrawal

A guardian withdraws consent for optional promotional profiling but wishes the person to continue receiving the core service.

The Data Fiduciary should separate the optional purpose from the necessary service processing. It should not close the entire account merely because marketing consent was withdrawn.

16.2 Illustration: Individual assumes direct control

A supported decision-making arrangement enables the person to understand and manage an online health account directly. She wishes to make her own future privacy choices.

The Data Fiduciary should examine the current guardianship arrangement and applicable law instead of automatically preserving substitute decision-making forever.

17. Conflicting instructions

A Data Fiduciary may receive inconsistent instructions from:

  • the person with disability;

  • the verified guardian;

  • another family member;

  • a newly appointed guardian;

  • a healthcare provider;

  • a court;

  • or a designated authority.

The Data Fiduciary should not resolve such conflicts through an automatic “guardian always wins” rule.

The appropriate response may involve:

  • pausing non-essential processing;

  • verifying the current legal appointment;

  • checking the scope of authority;

  • communicating accessibly with the person;

  • obtaining legal review;

  • complying with a valid court or authority order;

  • protecting the person from avoidable harm;

  • and preserving a record of the decision.

17.1 Illustration: Direct objection to disclosure

A guardian requests disclosure of the person’s complete medical record to a private organisation. The person clearly objects.

The healthcare provider should verify:

  • the purpose of disclosure;

  • scope of guardianship;

  • legal authority;

  • necessity;

  • and whether the instruction is consistent with the represented person’s interests and applicable healthcare law.

The existence of guardianship does not remove the need for careful processing analysis.

18. Data Processors and service providers

A Data Fiduciary may use a Data Processor to:

  • operate the consent interface;

  • verify guardianship references;

  • host records;

  • manage access;

  • send communications;

  • or provide the underlying service.

The Data Fiduciary remains responsible for Rule 11 compliance.

The Processor should receive clear instructions regarding:

  • permitted guardianship data;

  • verification sources;

  • access control;

  • authentication;

  • scope limitations;

  • consent records;

  • security;

  • breach reporting;

  • retention;

  • withdrawal;

  • deletion;

  • and subprocessors.

A verification vendor should not use guardianship information for unrelated identity profiling, advertising or product development without a separate legal basis and accurate allocation of processing roles.

19. Application in common sectors

19.1 Banking and financial services

Financial institutions may need to verify a guardian before permitting:

  • account operation;

  • payments;

  • disclosure of statements;

  • investment decisions;

  • account changes;

  • or access to financial information.

The institution must examine whether the guardian is appointed for:

  • the person;

  • property;

  • specified financial matters;

  • or both person and property.

An appointment concerning personal care may not automatically authorise investment decisions. Conversely, a property-related appointment may not authorise unrelated health disclosures.

High-risk transactions may justify fresh status and scope checks.

19.2 Healthcare

A healthcare provider should first determine whether the patient can make the relevant decision with appropriate support.

Where guardian consent is required, the provider should verify the appointment and scope. It should distinguish:

  • consent to care;

  • consent to process health data for treatment;

  • disclosure to family members;

  • research;

  • advertising;

  • AI training;

  • and sharing with unrelated service providers.

Authority to assist with treatment does not automatically extend to commercial reuse of medical records.

19.3 Employment

An employer should not assume that an employee with disability requires guardian consent for HR processing.

Where a lawful guardian does exist, the employer must still examine whether the appointment covers:

  • employment documentation;

  • salary administration;

  • benefits;

  • disciplinary matters;

  • health accommodations;

  • or other specific decisions.

Disclosure of the employee’s full personnel file to a guardian should not occur merely because the guardian has some limited authority.

19.4 Digital services

A digital platform should provide accessible direct consent before invoking the guardian route. Its system should allow different account states, including:

  • direct adult control;

  • supported decision-making;

  • verified guardian assistance;

  • time-limited or function-limited guardian authority;

  • and transition where guardianship changes.

A single binary field stating “disabled user: guardian required” would be legally and ethically defective.

Rules 10 and 11 both concern verifiable consent, but they address different problems.

Rule 10 concerns a child and requires verification that the person giving parental consent is an identifiable adult acting as the parent.

Rule 11 concerns a person with disability who is unable to take legally binding decisions despite adequate support and has a lawful guardian. The Data Fiduciary must verify the guardian’s formal legal appointment.

The difference is significant:

  • parental status under Rule 10 is verified through the child-parent consent framework;

  • guardian status under Rule 11 must arise from a court, designated authority or local level committee under the applicable guardianship law.

A caregiver or family member may assist either person without necessarily becoming the legally authorised decision-maker.

Where the person with disability is also a child, the Data Fiduciary must identify the correct legal representation and avoid unnecessary duplication or contradictory processes. It should not assume that disability automatically adds a guardianship requirement beyond the parental-consent framework. Any claimed guardianship must still be established under the applicable law.

21. Rule 11 and the Fourth Schedule should not be conflated

The Fourth Schedule concerns conditional exemptions from specified children’s-data obligations under Section 9. Rule 11 concerns lawful guardianship for a person with disability.

A healthcare, educational or governmental activity appearing in the Fourth Schedule does not automatically exempt a Data Fiduciary from verifying guardianship when it chooses to rely on a guardian’s consent for an adult person with disability.

Similarly, Rule 11 is not a general exemption from consent. It is a method of verifying substitute consent where a lawful guardian is entitled to act.

The two frameworks address different legal questions:

  • the Fourth Schedule asks whether specified child-related processing is exempt from particular provisions of Section 9;

  • Rule 11 asks whether a claimed guardian of a person with disability has lawful authority to give verifiable consent.

22. Common compliance failures

The most serious implementation failures are likely to arise where a Data Fiduciary:

  • assumes that every person with disability lacks legal capacity;

  • substitutes guardian consent without first providing support;

  • accepts a relative or caregiver as guardian without legal appointment;

  • verifies existence of guardianship but ignores its scope;

  • relies on an expired, revoked or superseded appointment;

  • collects complete legal and medical records where a limited verification reference would suffice;

  • exposes guardianship documents broadly within the organisation;

  • bundles necessary processing with advertising or commercial profiling;

  • ignores the person’s own preferences;

  • fails to provide an accessible notice;

  • begins full processing while verification is incomplete;

  • prevents withdrawal;

  • or continues recognising a former guardian after removal.

These are not merely documentary defects. They may result in processing or disclosure without valid authority and may undermine the dignity and autonomy that the disability-rights framework is intended to protect.

23. Enforcement implications

A significant failure to comply with Rule 11 may be treated as a breach of the DPDPA or Rules under the applicable penalty framework.

Depending on the facts, additional contraventions may arise where:

  • consent was not validly obtained;

  • the notice was defective;

  • excessive personal data was collected;

  • data was disclosed to an unauthorised guardian;

  • reasonable security safeguards were absent;

  • a personal data breach was not intimated;

  • rights were frustrated;

  • or personal data was retained after the lawful purpose ended.

The seriousness of a failure would likely depend on matters such as:

  • whether the Data Fiduciary ignored the person’s own capacity;

  • whether sensitive financial, health or identity information was involved;

  • whether the false guardian obtained access;

  • whether the conduct was systematic;

  • whether the person suffered loss or deprivation of service;

  • whether the organisation had accessible procedures;

  • whether it corrected the issue promptly;

  • and whether the failure continued after notice.

Conclusion

Rule 11 is not a rule for replacing the decisions of persons with disabilities. It is a safeguard governing the exceptional situation in which another person lawfully gives consent on their behalf.

Its operation should follow four principles.

First, disability does not equal incapacity. The person’s ability to make the particular decision must be considered after adequate and appropriate support has been provided.

Second, assistance does not equal guardianship. A relative, caregiver, interpreter, support person or institutional employee cannot give substitute consent merely because she assists the individual.

Third, guardianship must be legally verified and applied within scope. The appointment must come from a competent court, designated authority or local level committee under the applicable law, remain valid and cover the relevant processing decision.

Fourth, verified guardianship does not cure defective processing. The consent must still be specific, informed and affirmative. The personal data processed must be necessary, securely handled, properly retained and subject to withdrawal and rights.

A sound process therefore requires the Data Fiduciary to communicate accessibly with the person, provide support, verify whether substitute decision-making is truly required, authenticate the lawful appointment, examine its scope, minimise the guardianship information collected, obtain valid consent for the specific processing and periodically review whether the authority remains current.

Key point

Rule 11 protects against two opposite errors. A Data Fiduciary must not accept consent from an unauthorised person claiming to be a guardian, but it must also not displace the autonomy of a person with disability merely because support is required. Lawful guardian consent is valid only where the person cannot make the relevant legally binding decision despite appropriate support, the guardian has been formally appointed under the applicable law, and the proposed consent falls within that guardian’s verified authority.

Reproduced from official sources for reference. Not legal advice. In case of any discrepancy, the text published in the Gazette of India prevails.