Home India Ministry of Electronics and Information Technology Parliament Question: Implementation of Rules under DPDP Act,...
Date: 2026-08-12 Category: LOKSABHA_QNA State: Union Government Country: India

Parliament Question: Implementation of Rules under DPDP Act, 2023

Issued by Ministry of Electronics and Information Technology · Not Applicable

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task
Official Source Record View Original Source →
See Full Document Text
GOVERNMENT OF INDIA MINISTRY OF ELECTRONICS AND INFORMATION TECHNOLOGY LOK SABHA UNSTARRED QUESTION NO. 3943 TO BE ANSWERED ON: 12.08.2026 IMPLEMENTATION OF RULES UNDER DPDP ACT, 2023 3943. SMT. JUNE MALIAH: Will the Minister of ELECTRONICS AND INFORMATION TECHNOLOGY be pleased to state: (a) whether the Government has finalized the implementation rules under the Digital Personal Data Protection Act, 2023; (b) if so, the timeline for rollout and enforcement; and (c) the details of safeguards being ensured to protect citizens' data from misuse and cyberattacks? ANSWER MINISTER OF STATE FOR ELECTRONICS AND INFORMATION TECHNOLOGY (SHRI JITIN PRASADA) (a) to (c): The policies of the Government of India are aimed at ensuring an open, safe, trusted and accountable cyberspace for users in the country. Government of India has taken major initiatives like the enactment of the Information Technology Act, 2000 (IT Act), the setting up of the Indian Computer Emergency Response Team (CERT-In), the release of the National Cyber Security Policy 2013, and the enactment of the Digital Personal Data Protection Act 2023 (DPDP Act), thus ensuring security and protecting the privacy of users in India. Information Technology Act, 2000 (IT Act): (i) The Information Technology (IT) Act, 2000 provides a technology-neutral legal framework governing electronic transactions, protection of computer resources, cybersecurity, intermediary due diligence and cyber offences. (ii) The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 prescribe due diligence obligations for intermediaries, including significant social media intermediaries, with a view to promoting a safe, trusted and accountable online environment. Digital Personal Data Protection Act 2023 (DPDP Act): (i) DPDP Act 2023 provides for the processing of digital personal data in a manner that recognises both the rights of the individual to protect their personal data and the need to process such personal data for lawful purposes. (ii) The Act, and the Digital Personal Data Protection Rules, 2025 (“Rules”) notified on 13 November, 2025 provide a timeline for phased implementation of its provisions over an eighteen- month transition period, including the establishment of the Data Protection Board. The Rules specify the following implementation timelines: ● Phase 1: Establishment and operationalisation of the Data Protection Board of India ● Phase 2 (within one year): Registration and functioning of Consent Managers● Phase 3 (within eighteen months): Compliance obligations for Data Fiduciaries including data principal rights, security safeguards and breach notification (iii) The Act requires all Data Fiduciaries to ensure lawful processing of personal data. It lays down clear obligations relating to transparency, purpose limitation, data minimization, accuracy, security safeguards and respect for the rights of Data Principals. (iv) It requires Data Fiduciaries to implement strong security safeguards, erase personal data upon withdrawal of consent (unless retention is legally required), and comply within the transition period. (v) The Rules further require Data Fiduciaries to adopt appropriate technical and organizational safeguards, such as encryption or masking, to protect personal data and prevent breaches. The Act envisages the Data Protection Board to address violations of the Act. It can investigate breaches, issue corrective directions, and impose penalties. Penalties are to be determined based on factors like the nature of the breach, harm caused, safeguards in place, severity, and recurrence. (vi) In the event of a personal data breach, Data Fiduciaries are required to promptly notify the affected Data Principals and the Data Protection Board of India. Upon receipt of breach intimation, the Data Protection Board may conduct an inquiry and impose monetary penalties in accordance with the Act. (viii) The Board is empowered to investigate breaches, issue corrective directions, and impose penalties up to ₹250 crore, taking into account factors like nature of breach, harm caused, safeguards in place, severity and recurrence. Public Awareness Activities: (i) The Government is implementing the Information Security Education and Awareness (ISEA) project to build human resources in information security and promote awareness on cyber hygiene and cyber security among citizens. (ii) Under the ISEA project, over 6,650 awareness workshops have been conducted across the country, covering more than 11.37 lakh participants, including school and college students, teachers, law enforcement personnel, government officials and the general public. (iii) Multilingual awareness material, including handbooks, short videos, posters, brochures and cartoon stories for children, has been developed and disseminated through print, electronic and social media, as well as through the ISEA and Stay Safe Online portals i.e. www.isea.gov.in & https://staysafeonline.in/. (iv) The Government also organises nationwide awareness campaigns such as Cyber Security Awareness Month and Safer Internet Day to promote safe online behaviour, secure digital transactions and responsible use of digital services. (v) Cyber security advisories are issued regularly on emerging cyber threats, mitigation strategies and best practices. Initiatives such as the Cyber Swachhta Kendra (Botnet Cleaning and Malware Analysis Centre) and the National Cyber Coordination Centre (NCCC) strengthen cyber resilience by detecting and mitigating malicious activities and enhancing situational awareness. (vi) Indian Computer Emergency Response Team (CERT-In) regularly disseminates cyber safety and security advisories, awareness posters, infographics and videos through its official website and social media platforms to sensitise internet users about cyber threats, online frauds and safe online practices, including online safety measures for children. (vii) The Ministry of Education issued the PRAGYATA Guidelines on Digital Education in July 2020, providing a framework for safe and effective online learning, including the promotion of students' well-being and responsible use of social media and digital devices.(viii) The Central Board of Secondary Education (CBSE) has supplemented these efforts by issuing guidelines on digital etiquette, conducting cyber security training for teachers, publishing the Cyber Security Handbook, and advising schools to establish Cyber Clubs to promote cyber safety awareness. (ix) The National Council of Educational Research and Training (NCERT) has integrated cyber safety into the school curriculum, including a chapter on "Societal Impacts" for Classes XI and XII. In addition, CIET-NCERT has developed and disseminated educational resource materials on cyber safety. (x) The Government has taken various measures to promote widespread awareness and adoption of the Digital Personal Data Protection (DPDP) Act by educating citizens on their rights & duties and capacity-building initiatives, including workshops, conferences, expert sessions, and digital outreach campaigns. *******

Continue your research