CHAPTER IX - MISCELLANEOUS

Section 40 - Power to make rules

Official text

(1)The Central Government may, by notification, and subject to the condition of previous publication, make rules not inconsistent with the provisions of this Act, to carry out the purposes of this Act.

(2)In particular and without prejudice to the generality of the foregoing power, such rules may provide for all or any of the following matters, namely:—

(a)the manner in which the notice given by the Data Fiduciary to a Data Principal shall inform her, under sub-section (1) of section 5;

(b)the manner in which the notice given by the Data Fiduciary to a Data Principal shall inform her, under sub-section (2) of section 5;

(c)the manner of accountability and the obligations of Consent Manager under sub-section (8) of section 6;

(d)the manner of registration of Consent Manager and the conditions relating thereto, under sub-section (9) of section 6;

(e)the subsidy, benefit, service, certificate, licence or permit for the provision or issuance of which, personal data may be processed under clause (b) of section 7;

(f)the form and manner of intimation of personal data breach to the Board under sub-section (6) of section 8;

(g)the time period for the specified purpose to be deemed as no longer being served, under sub-section (8) of section 8;

(h)the manner of publishing the business contact information of a Data Protection Officer under sub-section (9) of section 8;

(i)the manner of obtaining verifiable consent under sub-section (1) of section 9;

(j)the classes of Data Fiduciaries, the purposes of processing of personal data of a child and the conditions relating thereto, under sub-section (4) of section 9;

(k)the other matters comprising the process of Data Protection Impact Assessment under sub-clause (i) of clause (c) of sub-section (2) of section 10;

(l)the other measures that the Significant Data Fiduciary shall undertake under sub-clause (iii) of clause (c) of sub-section (2) of section 10;

(m)the manner in which a Data Principal shall make a request to the Data Fiduciary to obtain information and any other information related to the personal data of such Data Principal and its processing, under sub-section (1) of section 11;

(n)the manner in which a Data Principal shall make a request to the Data Fiduciary for erasure of her personal data under sub-section (3) of section 12;

(o)the period within which the Data Fiduciary shall respond to any grievances under sub-section (2) of section 13;

(p)the manner of nomination of any other individual by the Data Principal under sub-section (1) of section 14;

(q)the standards for processing the personal data for exemption under clause (b) of sub-section (2) of section 17;

(r)the manner of appointment of the Chairperson and other Members of the Board under sub-section (2) of section 19;

(s)the salary, allowances and other terms and conditions of services of the Chairperson and other Members of the Board under sub-section (1) of section 20;

(t)the manner of authentication of orders, directions and instruments under sub-section (1) of section 23;

(u)the terms and conditions of appointment and service of officers and employees of the Board under section 24;

(v)the techno-legal measures to be adopted by the Board under sub-section (1) of section 28;

(w)the other matters under clause (d) of sub-section (7) of section 28;

(x)the form, manner and fee for filing an appeal under sub-section (2) of section 29;

(y)the procedure for dealing an appeal under sub-section (8) of section 29;

(z)any other matter which is to be or may be prescribed or in respect of which provision is to be, or may be, made by rules.

Commentary

Section 40 is the DPDPA’s principal delegated-legislation provision. It allows the Central Government to convert the Act’s broad statutory obligations into detailed operational requirements through rules dealing with matters such as notices, Consent Managers, security safeguards, breach reporting, retention, children’s data, Significant Data Fiduciaries, Data Principal rights, Board procedure and appeals.

The section does not give the Government unrestricted authority to rewrite the DPDPA. Rules must be made through the prescribed process, must carry out the purposes of the Act and must remain consistent with the legislation enacted by Parliament.

Commencement position: Section 40 came into force on13 November 2025. The Central Government exercised this power to notify the Digital Personal Data Protection Rules, 2025 through G.S.R. 846(E) dated 13 November 2025. The draft Rules had been published on 3 January 2025 for public consultation, and a corrigendum to the final Rules was subsequently issued in December 2025.

1.1 Role of Section 40

The DPDPA establishes the principal legal framework. It identifies:

  • the grounds on which personal data may be processed;

  • the obligations of Data Fiduciaries;

  • the rights and duties of Data Principals;

  • special requirements concerning children;

  • additional obligations of Significant Data Fiduciaries;

  • the constitution and powers of the Data Protection Board;

  • complaint, inquiry and appeal mechanisms; and

  • the penalty framework.

However, the Act does not contain every technical or procedural detail necessary for day-to-day implementation. Section 40 enables those details to be prescribed through rules.

Example

For example:

  • Section 8(5) requires reasonable security safeguards, while Rule 6 identifies minimum categories of security measures.

  • Section 8(6) requires breach notification, while Rule 7 specifies the recipients, timing and content of the notifications.

  • Section 8(8) provides for deemed completion of specified purposes, while Rule 8 and the Third Schedule identify the relevant entities, purposes and periods.

  • Section 9 requires verifiable parental consent, while the Rules prescribe how verification is to be carried out.

  • Section 29 establishes an appeal, while the Rules provide procedural details for filing and dealing with that appeal.

The Act and Rules must therefore be read together. The Act creates the obligation, while the Rules often explain how that obligation must be performed.

1.2 Previous publication and consultation

Rules under Section 40 must be made by notification and are subject to previous publication.

In practical terms, this ordinarily requires the Government to:

  1. publish the proposed rules in draft form;

  2. make the draft available to affected persons;

  3. allow a specified period for objections and suggestions;

  4. consider the representations received; and

  5. publish the final rules through the Official Gazette.

The purpose is to give Data Principals, industry participants, civil society, legal practitioners, security specialists and technical experts an opportunity to identify:

  • legal inconsistencies;

  • technical difficulties;

  • implementation costs;

  • unintended consequences;

  • ambiguous drafting;

  • privacy risks; and

  • areas requiring clarification.

The Government is not required to accept every suggestion. The legal requirement is to provide the prescribed opportunity for consultation and consider the feedback before finalisation.

This process was followed for the DPDP Rules, 2025. The draft Rules were published on 3 January 2025, objections and suggestions were invited for forty-five days, and the final notification records that the feedback received was considered.

1.3 Matters covered by the rule-making power

Section 40(2) contains an extensive, but non-exhaustive, list of areas in which rules may be made. The major categories are explained below.

1.4 Privacy notices

Rules may prescribe how a Data Fiduciary must inform a Data Principal about:

  • the personal data being processed;

  • the purpose of processing;

  • the goods, services or uses connected with the processing;

  • withdrawal of consent;

  • exercise of rights; and

  • grievance redressal.

This allows the Government to prescribe operational standards for clarity, accessibility and presentation without reproducing the entire notice format in the Act itself.

Rules may regulate:

  • registration of Consent Managers;

  • eligibility conditions;

  • governance arrangements;

  • financial and technical capacity;

  • conflicts of interest;

  • accountability;

  • record keeping;

  • security;

  • interoperability; and

  • obligations toward Data Principals.

This is especially important because a Consent Manager may act as a common point through which individuals give, manage, review and withdraw consent across different Data Fiduciaries.

1.6 State benefits and services

Rules may specify the subsidies, benefits, services, certificates, licences and permits for which personal data may be processed by the State or its instrumentalities under Section 7(b).

The final framework approaches this through categories connected with:

  • provision or issuance under law;

  • government policy or instruction; and

  • use of public funds.

The Rules also prescribe standards concerning lawfulness, purpose, necessity, accuracy, retention, security, intimation and accountability for qualifying State processing.

1.7 Security safeguards

Although security safeguards are not separately listed in each detail in Section 40(2), the general rule-making power supports operational requirements necessary to carry out Section 8.

Rule 6 accordingly prescribes minimum categories such as:

  • encryption, masking, obfuscation or tokenisation;

  • access controls;

  • logging and monitoring;

  • detection and investigation of unauthorised access;

  • remediation;

  • continuity and backups;

  • retention of relevant logs;

  • processor-contract provisions; and

  • appropriate technical and organisational measures.

The Rule does not replace Section 8(5). It supplies detailed minimum expectations for satisfying that statutory obligation.

1.8 Personal data breach notification

Rules may prescribe the form and manner in which the Board must be informed of a personal data breach.

The final Rules also operationalise notification to affected Data Principals. They address:

  • immediate or without-delay communications;

  • the nature and extent of the breach;

  • timing and likely consequences;

  • mitigation;

  • protective measures;

  • contact information;

  • the initial report to the Board; and

  • the detailed report generally required within seventy-two hours.

1.9 Retention and deemed completion of purpose

Rules may prescribe periods after which a specified purpose is deemed no longer served where the Data Principal has neither approached the Data Fiduciary for performance of the purpose nor exercised her rights.

The final Rules apply prescribed inactivity periods to specified large e-commerce entities, online gaming intermediaries and social-media intermediaries. They also require a warning before erasure under that mechanism and prescribe separate minimum retention of relevant data and logs for specified purposes.

These prescribed periods apply only to the classes and purposes identified in the Rules and Schedules. They should not be applied indiscriminately to every Data Fiduciary or processing activity.

1.10 Privacy contact information

Rules may prescribe how a Data Fiduciary must publish the contact details of:

  • its Data Protection Officer, where applicable; or

  • another person capable of answering questions on the Data Fiduciary’s behalf.

The operational requirement ensures that Data Principals have a visible and functioning contact rather than a theoretical right with no accessible channel.

1.11 Children’s personal data

Rules may prescribe:

  • the method of obtaining verifiable parental consent;

  • the method of verifying a lawful guardian;

  • classes of Data Fiduciaries that may qualify for specified exemptions;

  • permitted purposes;

  • conditions attached to those exceptions; and

  • related safeguards.

These rules must remain consistent with Section 9. They cannot generally remove the statutory protections for children or create an exemption unsupported by the Act.

1.12 Significant Data Fiduciaries

Rules may supplement the additional obligations of Significant Data Fiduciaries, including requirements concerning:

  • Data Protection Impact Assessments;

  • audits;

  • reporting of significant observations;

  • due diligence concerning algorithmic software;

  • periodic compliance processes; and

  • restrictions concerning specified personal data and traffic data.

Rule 13 requires an SDF to conduct a DPIA and audit once in every twelve-month period and imposes algorithmic due-diligence and specified localisation-related requirements.

1.13 Data Principal rights and grievances

Rules may prescribe the manner in which a Data Principal:

  • requests information about processing;

  • seeks correction;

  • requests erasure;

  • submits a grievance;

  • exercises rights through the Data Fiduciary’s designated channel; and

  • nominates another individual to exercise rights in specified circumstances.

Rules may also prescribe the period within which grievances must be answered.

These procedural requirements should facilitate the underlying rights. They should not make rights practically impossible to exercise through unnecessary complexity, excessive identity collection or inaccessible digital channels.

1.14 Research, archiving and statistical processing

Rules may prescribe standards for processing that receives the exemption under Section 17(2)(b).

Those standards are important because the exemption is conditional. Research, archiving or statistical processing does not become entirely unregulated merely because it falls within the stated purpose. It must comply with the standards prescribed under the Rules.

1.15 Board composition and administration

Rules may govern:

  • appointment of the Chairperson and Members;

  • salaries, allowances and service conditions;

  • authentication of orders and directions;

  • appointment and service conditions of officers and employees;

  • digital functioning;

  • meeting procedures;

  • document handling;

  • electronic filing; and

  • other institutional matters.

These rules enable the Board to operate as a digital office and establish the administrative machinery required for its statutory functions.

1.16 Proceedings and appeals

Rules may address:

  • techno-legal measures used by the Board;

  • procedural matters concerning inquiries;

  • electronic conduct of proceedings;

  • filing of appeals;

  • fees;

  • documents accompanying an appeal; and

  • the procedure followed by the Appellate Tribunal.

The Rules can regulate procedure, but cannot remove the statutory right of appeal or contradict requirements of natural justice and hearing contained in the Act.

1.17 The list in Section 40(2) is not exhaustive

Section 40(2) states that the listed matters are “without prejudice to the generality” of the overall power in Section 40(1). It also includes a residual provision allowing rules on other matters that are to be, or may be, prescribed.

This means that the Government’s authority is not confined to the exact wording of clauses (a) to (z). It may make other rules necessary to carry out the DPDPA, provided that those rules:

  • remain connected with the Act’s purposes;

  • fall within the delegated legislative framework;

  • do not contradict the Act; and

  • comply with the required publication process.

The residual power is not an independent authority to legislate on matters unrelated to the DPDPA.

1.18 Rules remain subordinate to the Act

The most important limitation is that rules must not be inconsistent with the DPDPA.

Parliament enacted the Act. The Central Government makes the Rules under authority delegated by Parliament. Therefore, the Rules cannot override the parent legislation.

A rule may validly:

  • prescribe a form;

  • establish a procedure;

  • specify a period;

  • identify technical measures;

  • prescribe conditions;

  • define operational standards;

  • regulate registration; or

  • provide digital filing requirements.

A rule cannot validly:

  • abolish a right granted by the Act;

  • remove an obligation imposed by the Act;

  • create a new lawful basis inconsistent with Sections 4 to 7;

  • authorise conduct prohibited by the Act;

  • eliminate a required opportunity of hearing;

  • enlarge the Board’s monetary penalty powers beyond the Schedule;

  • convert a discretionary statutory power into an automatic result contrary to the Act; or

  • create an exemption for which the Act provides no authority.

1.19 Illustration: Breach notification

Section 8(6) requires notification to the Board and affected Data Principals.

Rules may specify:

  • timing;

  • form;

  • content;

  • communication method;

  • initial report; and

  • follow-up report.

A rule could not validly provide that affected Data Principals never need to be informed, because that would contradict the statutory obligation.

1.20 Illustration: Consent withdrawal

The Act permits a Data Principal to withdraw consent with ease comparable to the process used to give consent.

Rules may prescribe the interface or procedure. They could not validly require a Data Principal to undergo a materially more difficult process that defeats the statutory right.

Once validly made, notified and brought into force, the Rules are binding subordinate legislation. They are not merely guidance or recommended practice.

Compliance must therefore be assessed against:

  1. the DPDPA;

  2. the final DPDP Rules;

  3. applicable Schedules;

  4. commencement notifications;

  5. amendments and corrigenda; and

  6. relevant statutory notifications issued under particular provisions.

Example

For example, an organisation assessing breach compliance must read:

  • Section 8(6);

  • Rule 7;

  • the applicable definitions;

  • the commencement position; and

  • any binding procedural requirements issued by the Board.

Reading only Section 8(6) would omit essential operational details. Reading only Rule 7 would omit the statutory duty from which the Rule derives.

1.22 Draft Rules and final Rules must be distinguished

The draft DPDP Rules published in January 2025 were consultation material. They were not the final legal standard.

The final Rules were notified in November 2025 after consideration of public feedback, and a corrigendum was issued in December 2025. Compliance analysis must therefore rely on:

  • the final Gazette notification;

  • the corrigendum;

  • the relevant commencement dates; and

  • subsequent valid amendments or notifications.

A company cannot rely on a procedure built solely around the draft Rules if the final Rules differ.

Illustration

A company designed its breach-response procedure using the January 2025 draft. The final Rule 7 changes or clarifies the information and timing required.

Before the Rule becomes operational, the company must update its procedure to match the final Gazette text. Reliance on the earlier draft will not excuse non-compliance.

1.23 Phased commencement of the final Rules

The Rules do not all take effect on the same date.

The final commencement structure provides that:

  • Rules 1, 2 and 17 to 21 came into force on publication in the Official Gazette;

  • Rule 4 comes into force one year after publication; and

  • Rules 3, 5 to 16, 22 and 23 come into force eighteen months after publication.

This requires organisations to distinguish between four separate questions:

  1. Has the Act been enacted?

  2. Has the relevant provision commenced?

  3. Has the relevant Rule been notified?

  4. Has that Rule commenced?

A final rule may be available for compliance planning before it becomes legally operative. Organisations should use that period to redesign systems, contracts and procedures, but should describe the legal status accurately.

1.24 Parliamentary supervision

Rules made under Section 40 are subject to the parliamentary laying process under Section 41.

This means the Rules must be placed before both Houses of Parliament for the prescribed period. Parliament may agree to:

  • modify the Rules; or

  • annul them.

This mechanism preserves legislative oversight over the Central Government’s use of delegated power.

The Rules therefore operate within three layers of control:

  1. Statutory control: they must remain consistent with the DPDPA;

  2. Procedural control: they are subject to previous publication; and

  3. Legislative control: they are laid before Parliament under Section 41.

They also remain subject to judicial review where they exceed the authority granted by the Act, contradict the parent statute, violate constitutional requirements or are otherwise legally invalid.

1.25 Practical compliance significance

Section 40 means that DPDPA implementation cannot be completed by reading the Act once and preparing a static privacy policy.

Organisations need an ongoing regulatory-monitoring process covering:

  • Gazette notifications;

  • final Rules;

  • commencement dates;

  • amendments;

  • corrigenda;

  • new schedules;

  • changes to prescribed procedures;

  • notifications concerning Significant Data Fiduciaries;

  • restrictions on cross-border transfers;

  • approved forms and digital systems;

  • Board procedures; and

  • future rulemaking under the residual power.

Changes to the Rules may require corresponding changes to:

  • privacy notices;

  • consent interfaces;

  • Consent Manager integrations;

  • processor contracts;

  • security safeguards;

  • breach-response plans;

  • retention schedules;

  • children’s-data controls;

  • Data Principal rights procedures;

  • grievance mechanisms;

  • AI-governance controls;

  • cross-border arrangements; and

  • regulatory reporting processes.

The legal team should not monitor Section 40 in isolation. Privacy, information security, IT, HR, procurement, marketing, customer service, product development and vendor-management teams may all need to implement requirements created through the Rules.

1.26 Common interpretive points

  • The Rules are legally binding once validly made and commenced.

  • The Rules cannot contradict or override the DPDPA.

  • The matters listed in Section 40(2) do not exhaust the rule-making power.

  • The residual rule-making power must still remain connected to the Act.

  • Previous publication requires consultation, not acceptance of every public suggestion.

  • Draft rules are not substitutes for the final Gazette text.

  • Notification and commencement are different events.

  • A corrigendum must be read with the original notification.

  • Guidance may explain the law but cannot amend the Act or Rules.

  • Parliament retains supervisory authority through Section 41.

1.27 Concluding interpretation

Section 40 is the bridge between the DPDPA’s legislative framework and its practical implementation. Parliament has established the substantive rights, obligations, institutions and enforcement structure, while the Central Government may prescribe the detailed procedures and standards needed to make that framework operational.

The rule-making power is intentionally broad because digital processing practices, security measures, institutional procedures and compliance mechanisms require detailed regulation. But it remains a delegated power. Rules must be preceded by publication, must advance the purposes of the DPDPA and must remain consistent with the Act.

Key point

Section 40 allows the Central Government to operationalise the DPDPA, not to rewrite it. The Act supplies the authority and limits; the Rules supply the detailed machinery for compliance.

Reproduced from official sources for reference. Not legal advice. In case of any discrepancy, the text published in the Gazette of India prevails.