Homeβ€Ί Indiaβ€Ί Ministry of Electronics and Information Technologyβ€Ί Parliament Question: API Checks for User Consent under DPDP...
Date: 2025-07-30 Category: Not Applicable State: Union Government Country: India

Parliament Question: API Checks for User Consent under DPDP

Issued by Ministry of Electronics and Information Technology Β· Not Applicable

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task

Executive Summary & Key Takeaways

**Executive Summary:** The Ministry of Electronics and Information Technology addresses questions regarding the implementation of a real-time Consent Application Programming Interface (API) mechanism under the Digital Personal Data Protection (DPDP) Act, 2023. The Act establishes a consent-driven framework where Data Fiduciaries must obtain informed consent, including through APIs, before processing personal data. The Act also establishes the Data Protection Board, and draft Digital Personal Data Protection Rules, 2025, have been published for public consultation. **Key Points / Main Content:** * **Digital Personal Data Protection Act, 2023:** * Technology-agnostic legislation regulating digital personal data. * Establishes a rights-based, consent-driven framework. * Empowers individuals to control their personal data. * **Consent Requirements:** * Data Fiduciaries must obtain informed consent before processing personal data, including through APIs. * Notice provided by Data Fiduciaries must clearly specify: * What personal data is being collected. * Specific purpose for each data use. * How users may exercise their rights (access, erasure, grievance redressal, nomination, etc.). * Procedure for complaints to the Data Protection Board. * Individuals may give, manage, review, or withdraw consent through a Data Protection Board registered Consent Manager. * **Functional Flexibility:** * The Act provides Data Fiduciaries with functional flexibility in how they implement legal obligations, encouraging innovation. * **Data Protection Board:** * A digital-by-design entity with key functions: * Giving directions for remediating or mitigating data breaches. * Inquiring into data breaches and complaints and imposing financial penalties. * Referring complaints for Alternate Dispute Resolution and accepting Voluntary Undertakings from Data Fiduciaries. * Advising the Government to block the website/app of Data Fiduciaries repeatedly breaching the Act. * **Draft Digital Personal Data Protection Rules, 2025:** * Published for public consultation to operationalize the Act. **Impact Analysis:** * **Individuals:** * *Impact:* Empowered to exercise control over their personal data; granted rights to access, erasure, grievance redressal, and nomination. * *Action Required:* Understand their rights under the Act and utilize mechanisms for consent management and grievance redressal. * **Data Fiduciaries:** * *Impact:* Must obtain informed consent before processing personal data; increased compliance obligations related to data processing and user rights. * *Action Required:* Implement mechanisms for obtaining and managing user consent, providing clear and comprehensive notices, and adhering to the guidelines set by the Data Protection Board. * **Data Protection Board:** * *Impact:* Central role in auditing, monitoring, and enforcing compliance with consent protocols. * *Action Required:* Establish mechanisms for investigating data breaches, addressing complaints, and ensuring compliance with the Act. * **Consent Managers:** * *Impact:* Play a key role in enabling individuals to give, manage, review, or withdraw their consent to Data Fiduciaries. * *Action Required:* Register with the Data Protection Board and provide user-friendly interfaces for managing consent. * **Government:** * *Impact:* Responsible for enacting and enforcing the Digital Personal Data Protection Act, 2023. * *Action Required:* Monitor the implementation of the Act, provide guidance to stakeholders, and address any challenges that may arise.

Key Entities Referenced

Ministry of Electronics and Information Technology: The Indian government ministry responsible for electronics and information technology policy. Digital Personal Data Protection Act, 2023: An act of the Indian Parliament that addresses the regulation of digital personal data. Data Protection Board of India: An entity established under the Digital Personal Data Protection Act, 2023, responsible for auditing, monitoring, and enforcing compliance with consent protocols and data protection. Consent Application Programming Interface API: A realtime mechanism to ensure valid user consent under the Digital Personal Data Protection DPDP Act, 2023. Data Fiduciaries: Entities that determine the purpose and means of the processing of personal data under the Digital Personal Data Protection Act, 2023. Draft Digital Personal Data Protection Rules, 2025: Draft rules published for public consultation to operationalize the Digital Personal Data Protection Act, 2023. SHRI P P CHAUDHARY: Member of Parliament who raised a question in Lok Sabha. SHRI JITIN PRASADA: Minister of State for Electronics and Information Technology who answered the question in Lok Sabha.
Official Source Record View Original Source β†’
See Full Document Text
GOVERNMENT OF INDIA MINISTRY OF ELECTRONICS AND INFORMATION TECHNOLOGY LOK SABHA UNSTARRED QUESTION NO. 1655 TO BE ANSWERED ON: 30.07.2025 API CHECKS FOR USER CONSENT UNDER DPDP 1655. SHRI P P CHAUDHARY: SHRI CHHATRAPAL SINGH GANGWAR: SMT. SMITA UDAY WAGH: SMT. SHOBHANABEN MAHENDRASINH BARAIYA: Will the Minister of ELECTRONICS AND INFORMATION TECHNOLOGY be pleased to state: (a) whether the Government proposes to implement a real-time Consent Application Programming Interface (API) mechanism to ensure valid user consent under the Digital Personal Data Protection (DPDP) Act, 2023; (b) if so, the implementation timeline for rolling out this API system for organizations handling personal data; (c) the manner in which the system is likely to ensure that users provide separate informed consent for each distinct data-processing purpose; (d) whether entities will be mandated to integrate the Consent API before initiating any processing of personal data; and (e) the details of the specific role and powers of the Data Protection Board of India in auditing, monitoring and enforcing compliance with consent protocols under the Act? ANSWER MINISTER OF STATE FOR ELECTRONICS AND INFORMATION TECHNOLOGY (SHRI JITIN PRASADA) (a) to (e): The Digital Personal Data Protection Act, 2023 (β€œthe Act”) is a technology-agnostic legislation that addresses the evolving digital landscape and its socio-economic implications with respect to the regulation of digital personal data. It establishes a rights-based, consent-driven framework that empowers individuals to exercise control over their personal data. Under the act, Data Fiduciaries must obtain informed consent before processing personal data for lawful purpose, including through APIs. The notice to be provided by Data Fiduciaries, must clearly specify: ● What personal data is being collected ● Specific purpose for each personal data use;● How users may exercise their rights (access, erasure, grievance redressal, nomination etc); ● Procedure of complaints to the Data Protection Board. The Act provides Data Fiduciaries with functional flexibility in how they implement legal obligations. This approach encourages innovation without compromising on its compliance. In addition to it, individuals may give, manage, review, or withdraw their consent to Data Fiduciaries through a Consent Manager to be registered with the Data Protection Board. The Act envisages establishing the Data Protection Board, a digital by design entity, with the following key functions: ● To give directions for remediating or mitigating data breaches ● To inquire into data breaches and complaints and impose financial penalties ● To refer complaints for Alternate Dispute Resolution and to accept Voluntary Undertakings from Data Fiduciaries; and ● To advise the Government to block the website, app etc. of a Data Fiduciary who is found to repeatedly breach the provisions of the Act. Draft Digital Personal Data Protection Rules, 2025 (Rules), which seek to operationalize the Act have been published for public consultation. ********

Continue your research