Section 36 gives the Central Government a formal information-gathering power for administering the DPDPA. It may require the Data Protection Board of India, any Data Fiduciary or an intermediary to furnish information necessary for purposes recognised under the Act. The provision does not itself establish that the recipient has committed a breach. An information request may support governmental administration, performance of a legal function, State-security purposes or assessment of whether a Data Fiduciary should be notified as a Significant Data Fiduciary.

The applicable provision is Rule 23 of the DPDP Rules, 2025, read with the Seventh Schedule. For requests addressed to Data Fiduciaries and intermediaries, Rule 23 limits the power to the purposes specified in that Schedule and requires the request to be made through the corresponding authorised person. The Seventh Schedule covers:

  • use of personal data by the State or its instrumentalities in the interests of the sovereignty and integrity of India or security of the State;

  • use of personal data by the State or its instrumentalities to perform a function, or fulfil an obligation, under an applicable Indian law; and

  • assessment of whether a Data Fiduciary or class of Data Fiduciaries should be notified as a Significant Data Fiduciary.

The Government’s power is broad, but it remains purpose-bound. It should not be understood as unrestricted authority to demand information for a purpose unrelated to the DPDPA. A request should identify the authorised person, the relevant statutory purpose, the information required and the period within which it must be furnished.

Information requested for Significant Data Fiduciary assessment may include details concerning:

  • the scale and volume of processing;

  • categories of Data Principals;

  • types of personal data;

  • children’s data;

  • profiling and automated decision-making;

  • security arrangements;

  • processing locations;

  • cross-border data flows;

  • processors and subprocessors;

  • previous personal data breaches; and

  • risks arising from the processing.

Such a request is part of a regulatory assessment. It does not by itself mean that the Data Fiduciary has violated the Act or will necessarily be designated as a Significant Data Fiduciary.

Rule 23 requires the recipient to furnish the requested information within the period stated in the request. There is no single statutory response period for every request. A Data Fiduciary or intermediary should therefore promptly verify the request, preserve responsive records, identify relevant systems and processors, and organise an accurate response. If the deadline is genuinely impracticable, the recipient should raise the issue promptly and seek an appropriate extension rather than allowing the period to expire without response.

The information furnished should be responsive, accurate and secure. Compliance does not ordinarily require disclosure of unrelated databases merely because they are available. For example, if the Government requests transaction logs for identified accounts during a specified period, the recipient should not automatically disclose its entire customer database. The response should contain the information called for, together with any context needed to prevent it from being misleading.

Where responsive information is held by a Data Processor, the Data Fiduciary may need to obtain it from that Processor. Processor contracts should therefore enable the Data Fiduciary to:

  • retrieve personal data and logs;

  • preserve relevant evidence;

  • obtain information within regulatory deadlines;

  • verify its accuracy;

  • transmit it securely; and

  • comply with applicable confidentiality restrictions.

A Data Fiduciary cannot assume that information falls outside Section 36 merely because it is stored by a cloud provider, payroll company, analytics vendor or another Processor acting on its behalf.

Rule 23 also contains a restricted non-disclosure mechanism. Where disclosure of the fact that information has been furnished is likely to prejudice the sovereignty and integrity of India or security of the State, the Central Government may direct the Data Fiduciary or intermediary not to reveal the furnishing of that information to an affected Data Principal or any other person. Disclosure may then be made only with the prior written permission of the authorised person. This restriction is not automatic for every Section 36 request. It depends on the stated security circumstances and an applicable governmental direction.

1.1 Illustration: Significant Data Fiduciary assessment

A large digital platform processes personal data relating to several crore users in India and operates advertising, recommendation and identity-matching systems. The designated MeitY officer requests information concerning the platform’s user base, data categories, children’s-data processing, algorithmic systems, overseas processing, security incidents and processor arrangements.

The platform should verify the authority and scope of the request, collect accurate information from relevant teams and processors, review the response for completeness and transmit it securely. Receipt of the request does not establish non-compliance. It enables the Government to assess whether the platform should be designated as a Significant Data Fiduciary.

1.2 Illustration: Information held by a cloud provider

A Data Fiduciary receives a request requiring specified access and processing logs within ten days. The logs are maintained by its cloud provider.

The Data Fiduciary should immediately require the provider to preserve and supply the relevant records under the processor contract. It remains responsible for coordinating an accurate and timely response and should not simply inform the Government that the information is held by a vendor.

1.3 Illustration: State-security confidentiality direction

An intermediary receives a request from the properly authorised officer for information connected with a State-security purpose. The request includes a direction prohibiting disclosure of the furnishing of information.

If the affected Data Principal later asks whether her data was disclosed to a government authority, the intermediary must comply with the non-disclosure direction unless it obtains prior written permission from the authorised person. It should nevertheless maintain a secure internal record of the request, authority, data furnished, response date and confidentiality restriction.

Organisations should maintain a controlled process for Section 36 requests. This should include verification of authenticity, legal and privacy review, identification of responsive records, processor coordination, preservation of evidence, minimisation of unrelated information, secure transmission, approval of the response and maintenance of an audit trail. Requests should not be answered informally by whichever employee happens to receive them, because that can lead to impersonated requests, excessive disclosure, compromised confidentiality or incomplete responses.

Section 36 should also be distinguished from the Board’s inquiry powers under Sections 27 and 28. Section 36 is exercised by the Central Government for purposes of the Act. A Board inquiry concerns the Board’s examination of a complaint, breach or other matter within its statutory jurisdiction. A Section 36 request is therefore an information-gathering measure, not a finding of breach or a penalty proceeding.

Commencement position: Section 36 and Rule 23 are scheduled to come into force on13 May 2027. As of 18 August 2026, they are enacted and notified but not yet operational.

In summary, Section 36 enables the Central Government to obtain information needed for administration of the DPDPA, while Rule 23 and the Seventh Schedule identify the permitted purposes and authorised officials for requests to Data Fiduciaries and intermediaries. A recipient should treat such a request as a formal legal demand requiring verified authority, accurate and proportionate disclosure, secure transmission, processor cooperation and compliance with any valid non-disclosure direction.