CHAPTER IX - MISCELLANEOUS

Section 38 - Consistency with other laws

Official text

(1)The provisions of this Act shall be in addition to and not in derogation of any other law for the time being in force.

(2)In the event of any conflict between a provision of this Act and a provision of any other law for the time being in force, the provision of this Act shall prevail to the extent of such conflict.

Commentary

Section 38 explains how the DPDPA interacts with other Indian laws. The DPDPA generally operates alongside, rather than replacing, sectoral and general legislation. A Data Fiduciary must therefore comply with the DPDPA together with every other law applicable to its processing activities. Only where compliance with a provision of another law is irreconcilably inconsistent with a provision of the DPDPA does the DPDPA prevail, and even then only to the extent of that conflict.

Commencement position: Section 38 came into force on13 November 2025 and is already operational.

1.1 Cumulative compliance

The DPDPA does not create a complete legal code governing every aspect of personal-data processing. Organisations may remain subject to legal obligations arising under:

  • banking and financial-services laws;

  • insurance regulations;

  • securities-market requirements;

  • telecommunications law;

  • health and clinical-establishment laws;

  • employment and labour laws;

  • taxation and accounting requirements;

  • companies law;

  • anti-money-laundering requirements;

  • consumer protection law;

  • cybersecurity obligations under the Information Technology Act, 2000;

  • evidentiary and procedural laws;

  • court orders; and

  • professional confidentiality requirements.

Where these obligations can operate together, the organisation must comply with all of them. Compliance with the DPDPA is not a defence to non-compliance with another applicable law, and compliance with a sectoral regulation is not a substitute for complying with the DPDPA.

Example

For example, a bank may need to comply simultaneously with:

  • DPDPA notice, security and grievance obligations;

  • banking record-retention requirements;

  • Reserve Bank of India directions;

  • anti-money-laundering duties;

  • cybersecurity reporting requirements; and

  • lawful disclosure obligations.

The bank should not select whichever framework is more convenient. It must satisfy each applicable requirement unless a genuine legal conflict makes simultaneous compliance impossible.

1.2 Overlap is not the same as conflict

Different laws may regulate the same information without being in conflict.

A conflict does not arise merely because:

  • two laws apply to the same processing;

  • they use different terminology;

  • one imposes more detailed obligations;

  • one requires additional safeguards;

  • compliance with both is expensive;

  • one law requires a longer record-retention period; or

  • different regulators have jurisdiction over different aspects of the activity.

Where one law imposes an additional or stricter obligation that can be observed together with the DPDPA, both ordinarily continue to apply.

1.3 Illustration: Cybersecurity reporting

A personal data breach may require notification to the Board and affected Data Principals under the DPDPA. The same incident may also be a reportable cybersecurity incident under the CERT-In framework.

These requirements are cumulative. Reporting the incident to CERT-In does not automatically satisfy the DPDPA notification obligation, and reporting it to the Board does not automatically satisfy CERT-In requirements. The organisation must assess and comply with each applicable regime.

1.4 Direct conflict

A conflict arises where two legal provisions impose requirements that cannot reasonably be complied with at the same time.

Where such a conflict exists, the DPDPA prevails, but only to the extent necessary to resolve that incompatibility. The remainder of the other law continues to apply.

The analysis should proceed carefully:

  1. identify the precise DPDPA provision;

  2. identify the precise provision of the other law;

  3. determine whether both can be interpreted harmoniously;

  4. examine whether an exception within either law resolves the issue;

  5. distinguish inconvenience from legal impossibility; and

  6. apply the DPDPA only to the extent of an unavoidable conflict.

A general reference to “sectoral law” or “regulatory requirements” is not enough. The organisation should identify the actual provision requiring the supposedly conflicting conduct.

1.5 Statutory retention

Section 8 ordinarily requires erasure when consent is withdrawn or the specified purpose is no longer served, unless retention is necessary for compliance with law.

Accordingly, a sectoral law requiring records to be retained for a fixed period will usually not conflict with the DPDPA. The DPDPA itself recognises legally required retention.

1.6 Illustration: Closed bank account

A customer closes her bank account and withdraws consent for optional marketing. Banking and anti-money-laundering requirements require the bank to retain specified identity and transaction records for a prescribed period.

The bank may retain the records required by law. However, it should:

  • stop consent-based marketing;

  • retain only the legally required information;

  • restrict the retained records to compliance, investigation or other authorised purposes;

  • prevent unrelated profiling or commercial reuse; and

  • erase the information when the legal period expires, unless another lawful basis for retention exists.

The statutory retention rule and the DPDPA can operate together. Retention under law does not authorise every later use of the retained data.

1.7 Statutory disclosure

The DPDPA does not prevent every disclosure required under another law. A bank, employer, hospital or company may be legally required to disclose specified personal data to:

  • a tax authority;

  • a court;

  • a law-enforcement authority;

  • a financial regulator;

  • an auditor;

  • a statutory authority; or

  • another legally authorised recipient.

Where the disclosure is lawfully required, the Data Fiduciary should comply with that obligation while limiting the disclosure to what the law requires.

1.8 Illustration: Tax disclosure

An employer is legally required to provide specified salary and tax information to the relevant authority.

The employer should disclose the required fields through the prescribed channel. It should not treat the statutory obligation as authority to provide:

  • unrelated health information;

  • complete personnel files;

  • private communications;

  • performance appraisals; or

  • family information not required by law.

The disclosure law and the DPDPA ordinarily coexist because the legal obligation establishes the reason for disclosure, while the DPDPA continues to govern accuracy, security, minimisation and accountability.

1.9 Sectoral standards may be stricter

A sectoral regulator may require safeguards beyond the general DPDPA minimum, such as:

  • shorter incident-reporting periods;

  • stronger authentication;

  • local storage of specified records;

  • detailed audit trails;

  • longer retention;

  • specialised grievance procedures;

  • periodic cybersecurity assessments; or

  • additional customer communications.

Where those requirements do not contradict the DPDPA, the organisation must comply with both. Section 38 does not reduce more protective sectoral obligations merely because the DPDPA contains a general rule on the same subject.

1.10 Illustration: Six-hour and DPDPA reporting

A reportable cyber incident involving personal data may trigger a six-hour CERT-In reporting requirement and separate DPDPA notifications.

The shorter CERT-In period does not conflict with the DPDPA merely because the timelines differ. The organisation can satisfy both by making each required notification within its applicable period.

1.11 Contracts cannot override the DPDPA

Section 38 concerns interaction with other laws, not private contracts.

A contract cannot displace a statutory DPDPA duty by providing that:

  • a Processor bears all responsibility and the Data Fiduciary bears none;

  • personal data may be retained indefinitely;

  • breach notification may wait thirty days;

  • Data Principals waive all statutory rights;

  • a vendor may use personal data for any purpose; or

  • statutory complaints are prohibited.

Contractual terms should be revised to comply with the DPDPA. The fact that the contract predates the Act does not give it priority over statutory requirements.

1.12 More specific law does not automatically prevail

General interpretive principles sometimes favour a more specific law over a general law. Section 38(2), however, contains an express statutory rule: where a provision of another law conflicts with a DPDPA provision, the DPDPA prevails to the extent of that conflict.

It would therefore be unsafe to assume that a sectoral provision automatically defeats the DPDPA merely because it is more specific. The correct approach is first to determine whether a genuine conflict exists and then apply Section 38’s express priority rule.

At the same time, Section 38 should not be read as invalidating an entire sectoral statute. Only the conflicting provision, and only to the extent of the incompatibility, yields to the DPDPA.

1.13 Practical compliance approach

Organisations should maintain a legal-obligations map for each important processing activity, identifying:

  • the DPDPA ground and obligations;

  • applicable sectoral laws;

  • regulatory directions;

  • statutory disclosure duties;

  • mandatory retention periods;

  • cybersecurity reporting obligations;

  • confidentiality restrictions;

  • court or government orders; and

  • any apparent inconsistencies.

Where an apparent conflict arises, the organisation should document:

  • the provisions compared;

  • whether simultaneous compliance is possible;

  • any relevant exceptions;

  • the interpretation adopted;

  • advice obtained;

  • operational controls; and

  • the reason for concluding that the DPDPA or another obligation governs the particular action.

1.14 Common misunderstandings

  • The DPDPA replaces all existing privacy and sectoral laws: Incorrect. It generally operates in addition to them.

  • The stricter rule always wins: Not as an automatic statutory test. Both rules apply where they can coexist; Section 38(2) resolves actual conflicts in favour of the DPDPA.

  • A longer statutory retention period necessarily conflicts with erasure: Usually incorrect, because Section 8 recognises retention required by law.

  • Compliance with a regulator’s directions guarantees DPDPA compliance: Incorrect. Separate DPDPA obligations may continue to apply.

  • A contract is another law for Section 38 purposes: Incorrect. Private agreements cannot override the Act.

  • Any inconsistency invalidates the entire other law: Incorrect. The DPDPA prevails only to the extent of the particular conflict.

1.15 Concluding interpretation

Section 38 establishes a two-stage rule:

  1. Cumulative operation: The DPDPA and other applicable Indian laws must ordinarily be complied with together.

  2. Limited priority: If a direct and irreconcilable conflict remains, the DPDPA prevails only to the extent of that conflict.

Key point

Section 38 does not make the DPDPA the only law governing personal data. It makes the DPDPA an additional layer of regulation and gives it targeted priority only where simultaneous compliance with another legal provision is genuinely impossible.

Reproduced from official sources for reference. Not legal advice. In case of any discrepancy, the text published in the Gazette of India prevails.