The Digital Personal Data Protection Act’s draft regulations were made public by the Ministry of Electronics and Information Technology.
Since the Act was approved by Parliament in August 2023, the regulations have been eagerly anticipated. Through the MyGov portal, the government is accepting comments on the proposed regulations until February 18, 2025.
The regulations are supposed to provide light on a number of legal elements, such as the data fiduciary’s notice to individuals, the consent manager’s registration and duties, the processing of children’s personal data, and more. Additionally, it clarifies the Data Protection Board’s structure as well as the appointment and terms of duty for the chairperson and other board members.
MeitY has said that just a summary of the comments received will be released following the guidelines’ finalization, and that the submissions made during the consultation will not be made public.
Data processing for children
According to the draft regulations, data custodians must use government-issued identification documents or digital tokens connected to identity services like digital lockers to confirm parental authorization before processing a child’s data.
According to the proposed draft regulations, the government would also grant exemptions to educational institutions and child welfare organizations from these particular laws pertaining to the processing of children’s data.
Framework for consent managers
According to the draft regulations, consent managers need to have a minimum net worth of Rs 12 crore and register with the Data Protection Board.
Creating a Data Protection Board
The rules also suggested creating a regulating agency called the Data Protection Board. According to the draft regulations, it will function as a digital office with remote hearings and the authority to look into violations, impose sanctions, and more.
-NSH Digidesk




