The Ministry of Electronics and Information Technology, (MoEITY), on January 03, 2025, notified the Draft Digital Personal Data Protection Rules, 2025.
Objections and suggestions, if any, may be submitted on MyGov's website. The draft rules will be considered after February 18, 2025.
The following has been stated-
•The rules embrace a “digital by design” philosophy. Consent mechanisms, grievance redressal and the functioning of the Data Protection Board are all envisaged as “born digital”, to ensure Ease of Living and Ease of Doing Business. The Board will function as a digital office, with a digital platform and app to enable citizens to approach it digitally and to have their complaints adjudicated without their physical presence being required.
•From processing complaints to interacting with Data Fiduciaries, workflows are optimised to ensure speed and transparency. This reflects India’s forward-looking approach to governance and builds trust between citizens and Data Fiduciaries.
•Businesses benefit from a pragmatic framework. Graded responsibilities cater to startups and MSMEs with lower compliance burdens, while Significant Data Fiduciaries have higher obligations. Sector-specific data protection measures can complement the core personal data protection framework created by the Act and the rules.
•The Data Protection Board’s digital office approach would ensure quick and transparent resolution of complaints. The Board is required to take into consideration factors such as the nature and gravity of default, efforts made to mitigate impact, etc., while imposing penalties for defaults. Further, Data Fiduciaries may voluntarily give undertakings at any stage of proceedings, which if accepted by the Board would result in the dropping of the same. This balances the need to protect the rights of citizens while providing a fair adjudicatory framework for those processing personal data.
•Provisions for annual data protection impact assessments and audits for Significant Data Fiduciaries ensure effective arrangements to secure compliance.
•The purpose and Scope are to establish a legal framework for protecting personal data and balancing individual rights with business needs. The framework applies to entities processing data within India and those handling Indian citizens' data from abroad.
•Core Principles emphasise fairness, transparency, purpose limitation, and data minimization in processing personal data.
•Rights of Individuals ensure rights such as access, correction, erasure, portability, and grievance redressal for data principals (individuals).
•Obligations of Data Fiduciaries require clear consent, strong security measures, breach notifications, and accountability in data processing.
•Cross-Border Data Transfers permit international transfers only to jurisdictions with adequate protection levels as determined by the Indian government.
•Penalties for Non-Compliance impose monetary fines and operational restrictions for violations, enforced by a Data Protection Board.
•Exemptions is that it allows exemptions for processing related to national security, law enforcement, or other public interest objectives.
•Implementation Timeline provides a phased rollout to allow stakeholders to effectively comply with the new regulations.
[Notification No. G.S.R. 02(E)]