THE RULES

Rule 23 - Calling for information from Data Fiduciary or intermediary

Official text

(1)The Central Government may, for such purposes of the Act as are specified in Seventh Schedule, acting through the corresponding authorised person specified in the said Schedule, require any Data Fiduciary or intermediary to furnish such information as may be called for, within the specified period as may be given in such.

(2)Where the disclosure of furnishing of information as referred to in sub-rule (1) is likely to prejudicially affect the sovereignty and integrity of India or security of the State, the Central Government may require the Data Fiduciary or intermediary to not disclose such furnishing to affected Data Principal or any other person except with the previous permission, in writing, of the authorised person.

(3)For the purposes of this rule, the expression “intermediary” shall have the same meaning as assigned to it in the Information Technology Act, 2000 (21 of 2000).

Cross-references

Rule 23

Commentary

Rule 23 establishes a targeted information-gathering power for the Central Government. It enables the Government, acting through the authorised person identified in the Seventh Schedule, to require a Data Fiduciary or an intermediary to furnish information for specified purposes under the Digital Personal Data Protection Act, 2023. It also permits the Government to prohibit disclosure of the existence or content of that information request where disclosure is likely to prejudice the sovereignty and integrity of India or the security of the State.

The Rule is not a general authority for any government department or official to demand any information for any purpose. Its exercise is controlled by the Seventh Schedule, which identifies both the permitted purpose and the corresponding person authorised to call for information. The requesting authority, statutory purpose, information sought and period for compliance must therefore remain connected.

Rule 23 was notified as part of the final DPDP Rules under G.S.R. 846(E) dated 13 November 2025. It is scheduled to come into force eighteen months after publication, on 13 May 2027.

1.1 Scope and purpose of the information-gathering power

Rule 23 supports governmental functions under the DPDPA that cannot be performed effectively unless relevant information can be obtained directly from organisations possessing or controlling it. Its principal purposes, as identified in the Seventh Schedule, concern:

  • use of personal data by the State or its instrumentalities in the interests of the sovereignty and integrity of India or security of the State;

  • use of personal data by the State or its instrumentalities for performing a function under Indian law or disclosing information to fulfil an obligation under Indian law; and

  • assessment of whether a Data Fiduciary or class of Data Fiduciaries should be notified as a Significant Data Fiduciary.

The Rule therefore performs a different function from the Data Protection Board’s inquiry powers. The Board may call for information when conducting proceedings concerning a breach or another matter within its statutory jurisdiction. Rule 23 concerns information required by the Central Government through the authorised persons and for the purposes listed in the Seventh Schedule.

The distinction between the Board and the Central Government should be preserved. A demand under Rule 23 is not automatically a Board summons, inquiry notice or finding of non-compliance. It may support a sovereign or security function, a statutory obligation or an assessment for SDF designation without any allegation that the recipient has violated the DPDPA.

At the same time, the recipient should verify that a request genuinely falls within Rule 23 before releasing information. The communication should identify the authority under which it is issued, the authorised person, the information required, the applicable purpose and the period for furnishing the response.

1.2 The Seventh Schedule as the controlling boundary

The Seventh Schedule is central to Rule 23 because it limits the power through a pairing of permitted purposes and authorised persons.

For processing connected with sovereignty, integrity or State security, the authorised person is an officer of the State or one of its instrumentalities covered by the relevant notification under Section 17(2), designated by the Central Government or the head of the instrumentality, as applicable.

For performance of a function under Indian law or disclosure needed to fulfil a legal obligation, the authorised person is the person authorised under the applicable law.

For assessment of whether a Data Fiduciary or class should be designated as Significant Data Fiduciary, the authorised person is an officer of the Central Government in MeitY designated for that purpose by the Secretary in charge of the Ministry.

This structure prevents an official authorised for one Schedule purpose from automatically exercising the power for another. An officer authorised to obtain information for an SDF assessment does not, by that designation alone, acquire authority to demand information for a separate State-security purpose. Similarly, the existence of a general statutory function does not authorise any officer to issue a Rule 23 request unless that person is authorised under the applicable law.

The Schedule therefore provides both substantive and institutional limits. The purpose must be one listed, and the request must come through the corresponding authorised person.

1.3 Information required for SDF assessment

The SDF-assessment limb is closely connected with Section 10 of the Act. The Central Government may notify a Data Fiduciary or class of Data Fiduciaries as Significant Data Fiduciaries after considering relevant factors, including:

  • the volume and sensitivity of personal data processed;

  • risk to the rights of Data Principals;

  • potential impact on the sovereignty and integrity of India;

  • risk to electoral democracy;

  • security of the State; and

  • public order.

Rule 23 enables the designated MeitY officer to obtain information required for that assessment. Depending on the stated request, relevant information could concern the scale and categories of personal data processed, the number or classes of Data Principals affected, the nature of algorithmic or technical systems, cross-border processing, security arrangements, breach history, Data Processor dependencies or other matters connected with the Section 10 factors.

The power should remain directed towards the statutory assessment. It should not become an open-ended collection mechanism for information unrelated to whether the organisation or class satisfies the SDF criteria.

A recipient of such a request should provide a complete and accurate response within the specified period. It should also identify whether any requested figure is estimated, whether systems measure the requested information differently and whether the data relates to the entire corporate group or only the relevant legal entity. Inaccurate aggregation or mixing information belonging to separate group companies could distort the designation assessment.

A request for information does not itself designate the recipient as an SDF. Enhanced obligations under Section 10 and Rule 13 arise only if the Central Government subsequently notifies the particular Data Fiduciary or a class within which it falls.

1.4 Application to Data Fiduciaries and intermediaries

Rule 23 applies both to Data Fiduciaries and intermediaries.

A Data Fiduciary is a person who determines, alone or jointly, the purpose and means of processing personal data. An intermediary is understood according to the Information Technology Act, 2000 rather than through an independent definition in the DPDP Rules. The IT Act framework uses the expression for a person who, on behalf of another, receives, stores or transmits an electronic record or provides services relating to that record. Depending on the facts, this may encompass categories such as telecommunications service providers, network service providers, internet service providers, web-hosting providers, search engines, online payment sites, online marketplaces and cyber cafés.

The two statuses may overlap in practice. An online platform may act as an intermediary for user-generated content while acting as a Data Fiduciary for account administration, advertising, security or analytics. Rule 23 avoids dependence on the DPDPA role alone by expressly covering intermediaries under the IT Act definition.

The recipient’s responsibility is to furnish the information that it possesses or controls and that falls within the lawful request. Rule 23 should not ordinarily be interpreted as requiring an entity to produce information that does not exist, fabricate estimates without qualification or obtain information from unrelated third parties outside its control. The recipient may nevertheless need to compile, extract or organise existing information into the form reasonably required by the request.

Where another entity holds information as a Data Processor or service provider, the Data Fiduciary may need to invoke contractual assistance rights. Organisations should therefore ensure that vendor arrangements permit lawful cooperation with governmental information requests while protecting against unauthorised disclosure.

1.5 Specified period and management of the response

The authorised request must provide a period within which the information is to be furnished. The Rule does not prescribe one uniform period for all requests. The time allowed may therefore depend on the urgency, purpose, volume, technical complexity and location of the information.

The recipient should treat the stated period as binding. A suitable response process should identify:

  • the authenticity and authority of the request;

  • the applicable Seventh Schedule purpose;

  • the legal entity to which the request is addressed;

  • internal and Processor-held sources of information;

  • the scope and date range;

  • confidentiality or secrecy restrictions;

  • responsible personnel;

  • the approval required before submission; and

  • evidence of what was furnished and when.

If the request is unclear, technically impossible within the period or appears to seek information outside the recipient’s control, the organisation should raise the issue promptly with the authorised person. It should not remain silent until the deadline expires.

A request for an extension does not itself suspend the deadline unless the authorised person grants an extension or modifies the request. The recipient should preserve a reliable audit trail of communications concerning clarification, extension and production.

1.6 Necessity, relevance and proportionality

Rule 23 does not expressly reproduce a detailed proportionality test, but its design limits information gathering to purposes specified in the Seventh Schedule. The information called for should have a rational connection with the authorised purpose.

This matters because the responsive material may include personal data, commercially confidential information, system architecture, security records, internal assessments or information concerning third parties. The request should be interpreted according to its lawful objective rather than as unlimited authority to obtain every record held by the recipient.

The Data Fiduciary or intermediary should not disclose materially more information than the request requires. Overproduction can expose unrelated Data Principals and commercially sensitive information without advancing the statutory purpose. Underproduction, on the other hand, may omit information necessary for the Government to perform the relevant function.

Where possible, a response may distinguish between:

  • information directly responsive to the request;

  • explanatory information necessary to understand it;

  • information unavailable or not maintained;

  • information held by a Processor;

  • and material withheld or separately handled under another applicable law.

The organisation should not use confidentiality as a blanket basis to disregard a lawful Rule 23 request. Confidentiality should instead be managed through secure transmission, restricted access, marking of sensitive material and any protective procedure allowed by law.

1.7 Confidentiality direction under sub-rule (2)

Rule 23 permits the Central Government to direct the recipient not to disclose the furnishing of information where disclosure is likely to prejudicially affect the sovereignty and integrity of India or the security of the State.

This is a statutory confidentiality or non-disclosure mechanism. It may apply not only to the contents of the information furnished but also to the fact that information has been requested or supplied.

The direction may prevent disclosure to:

  • an affected Data Principal;

  • employees without a need to know;

  • customers;

  • the public;

  • business partners;

  • or any other person, unless prior written permission is obtained from the authorised person.

The power is conditional. It arises where disclosure is likely to cause the stated prejudicial effect. It should not be treated as an automatic secrecy rule attaching to every information request under Rule 23.

Once a direction is issued, the Data Fiduciary or intermediary must integrate it into the handling of the request. Access should be restricted to personnel genuinely required to identify, collect, review and furnish the information. Ordinary customer-support, transparency-reporting or rights-response processes may need to be adjusted so that the organisation does not inadvertently reveal the protected request.

At the same time, the restriction should be applied according to its scope. A direction concerning one request should not automatically justify withholding all information about the organisation’s governmental disclosures or suspending every Data Principal right. Where a later disclosure is proposed, the organisation may seek prior written permission from the authorised person.

Rule 23 does not expressly prescribe a maximum duration for such a restriction. The terms of the particular direction, the continuing security risk and any later written permission will therefore be important. The organisation should not independently assume that the direction has expired merely because the underlying information was furnished.

1.8 Interaction with Data Principal rights and transparency

A Rule 23 request may overlap with a Data Principal’s request for access to information about processing or disclosure. Ordinarily, a Data Fiduciary should respond to rights requests in accordance with the Act and Rules. However, where a valid sub-rule (2) direction prohibits disclosure, the organisation must not reveal the protected furnishing without prior written permission.

This creates a specific statutory limit on transparency in the affected case. The Data Fiduciary should not provide a false response, but it may be unable to disclose the existence or details of the governmental request. Rights-response teams should therefore have a secure escalation mechanism so they do not answer inconsistently with the confidentiality direction.

The restriction should not be informally invented by the Data Fiduciary. The text contemplates a requirement imposed by the Central Government. An organisation cannot refuse transparency merely by claiming that disclosure might generally implicate national security when no applicable legal restriction exists.

1.9 Security and handling of the furnished information

The information furnished under Rule 23 may itself contain personal data. The collection, extraction and transmission process should therefore be securely managed.

The recipient should verify the authorised communication channel before transmitting the material. Sensitive information should not be sent to an address or portal merely because a communication appears to bear a government name or logo. Appropriate verification may include confirmation of the authorised officer, official contact details, reference number and secure submission mechanism.

The information should also be protected against:

  • unauthorised internal access;

  • alteration;

  • accidental inclusion of unrelated records;

  • transmission to the wrong recipient;

  • insecure attachments;

  • retention of unnecessary working copies;

  • and disclosure contrary to a sub-rule (2) direction.

The Government’s power to obtain information does not remove the need for careful data handling by the furnishing entity. A personal data breach occurring during preparation or transmission may engage the ordinary security and breach-notification framework where applicable.

1.10 Relationship with other statutory information powers

Rule 23 does not necessarily replace information-gathering powers available under the Information Technology Act, sectoral legislation, criminal procedure, tax law, telecommunications law or other statutes.

A request should be identified according to its actual legal basis. Different powers may involve different:

  • authorised officers;

  • purposes;

  • procedures;

  • deadlines;

  • secrecy requirements;

  • review mechanisms;

  • and consequences of non-compliance.

The fact that an organisation is a Data Fiduciary or intermediary does not mean every governmental request made to it is a Rule 23 request. Equally, a request validly made under another law should not be treated as invalid merely because it does not follow the Seventh Schedule.

Rule 23 is specifically concerned with the purposes under the DPDPA identified in the Seventh Schedule.

A Data Fiduciary or intermediary should maintain a controlled process for responding to Rule 23 requests. The process should ensure lawful cooperation without treating every incoming demand as automatically valid.

The organisation should be able to establish:

  • who issued the request;

  • how the person’s authority was verified;

  • the Seventh Schedule purpose relied upon;

  • the information requested;

  • the period for compliance;

  • searches or collection undertaken;

  • Processors involved;

  • information furnished;

  • security controls used;

  • applicable non-disclosure direction;

  • and personnel who approved the response.

Where the recipient believes that a request is outside Rule 23, issued by an unauthorised person, excessively unclear or inconsistent with another binding legal obligation, the issue should be escalated for legal review and, where appropriate, raised with the authorised person. The organisation should not casually disregard the request, but neither should it disclose information without satisfying itself that the demand has a lawful basis.

1.12 Consequences of non-compliance

Rule 23 does not specify a separate monetary penalty exclusively for failure to furnish information. A significant breach may fall within the residual entry in the Schedule to the DPDPA for contravention of another provision of the Act or Rules, carrying a maximum monetary penalty of up to ₹50 crore.

The maximum is not automatic. Any monetary penalty under the DPDPA must follow the applicable statutory process and consideration of the factors governing penalty determination.

The seriousness of non-compliance may depend on whether the recipient:

  • ignored a lawful request;

  • supplied materially false or misleading information;

  • concealed relevant records;

  • missed the deadline without explanation;

  • disclosed the request despite a valid confidentiality direction;

  • furnished personal data to an impostor or unauthorised official;

  • or failed to control a Processor holding responsive information.

The same event may also engage other legal provisions. An insecure disclosure may constitute a personal data breach. Deliberate obstruction or false information may have consequences under another applicable law. Unauthorised disclosure of a security-related request may also implicate obligations beyond the DPDPA.

1.13 Concluding interpretation

Rule 23 equips the Central Government with a structured power to obtain information needed for limited statutory purposes, including State-security functions, performance of duties under Indian law and assessment of whether a Data Fiduciary should be designated as significant.

The power is not legally unbounded. It must be exercised:

  • for a purpose identified in the Seventh Schedule;

  • through the corresponding authorised person;

  • against a Data Fiduciary or intermediary;

  • through a request identifying the information required;

  • and within the specified compliance period.

Where disclosure of the request or furnishing is likely to prejudice India’s sovereignty, integrity or State security, the Government may impose a binding non-disclosure requirement. That restriction must be observed unless the authorised person provides prior written permission.

Rule 23 consequently requires a balance between lawful governmental access and controlled information governance. A recipient must neither obstruct a valid request nor disclose information mechanically without verifying authority, scope, purpose and confidentiality. Its compliance process should permit accurate and timely cooperation while ensuring that only responsive information is furnished, the transmission is secure, secrecy directions are respected and a reliable record of the complete process is maintained.

Key point

Rule 23 is a purpose-bound governmental information power, not a general licence for unrestricted data collection. Its legality depends on the link between the Seventh Schedule purpose, the authorised person and the information demanded. The Data Fiduciary or intermediary must furnish validly required information within the specified period, protect its transmission and preserve confidentiality where directed, while ensuring that the request is handled through a traceable and legally controlled process.

Reproduced from official sources for reference. Not legal advice. In case of any discrepancy, the text published in the Gazette of India prevails.