**Executive Summary**
This document is the answer provided by the Minister of State for Electronics and Information Technology to Unstarred Question No. 1739 raised in Lok Sabha concerning the staggered rollout for large tech firms under the Digital Personal Data Protection (DPDP) Rules, 2025. The document addresses the rationale behind the phased implementation, the composition of the Data Protection Board of India (DPBI), and measures to ensure the DPBI's independence. The original question was slated to be answered on December 10, 2025.
**Key Points / Main Content**
* **Digital Personal Data Protection (DPDP) Act and Rules:**
* The Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025 were notified on November 13th, 2025, providing a phased implementation framework.
* Organisations have an eighteen-month period to implement technical and organisational measures for compliance with the Act.
* This timeline was established after extensive consultation with stakeholders.
* **Data Protection Board of India (DPBI):**
* The Act provides for the establishment of the DPBI, comprising a Chairperson and four members.
* Members will be appointed through a Search-cum-Selection Committee.
* **Independence of the Data Protection Board:**
* The DPDP Act ensures the DPBI functions as an independent body through several provisions.
* These include:
* A Search-cum-Selection Committee recommending suitable candidates.
* Fixed two-year terms for the Chairperson and members with eligibility for reappointment.
* Protection against changes to salaries, allowances, or service conditions to their disadvantage.
* Specification of grounds for disqualification.
* An opportunity to be heard before removal.
**Impact Analysis**
**Stakeholder: Large Tech Firms**
* **Impact:** Affected by the compliance requirements and deadlines of the DPDP Act, 2023 and DPDP Rules, 2025.
* **Action Required:** Implement the necessary technical and organizational measures within the eighteen-month period to comply with the provisions of the Act.
**Stakeholder: Data Protection Board of India (DPBI) Chairperson and Members**
* **Impact:** Roles and responsibilities within the DPBI, including the terms of appointment, conditions of service, and provisions for ensuring independence.
* **Action Required:** Chairperson and members should understand their responsibilities and rights, including the conditions that ensure their independence and fairness in operation.
**Stakeholder: Central Government**
* **Impact:** Responsible for ensuring the independence of the DPBI and appointing members through the Search-cum-Selection Committee.
* **Action Required:** Uphold the outlined procedures for member selection and ensure compliance with the provisions aimed at maintaining the DPBI's independence.
**Stakeholder: Stakeholders (General)**
* **Impact:** Required to be consulted in the establishment of the rules and timeframes for compliance with the Act.
* **Action Required:** Compliance and awareness.
Key Entities Referenced
Digital Personal Data Protection Act, 2023: The primary act that governs personal data protection in India.
Digital Personal Data Protection Rules, 2025: Rules providing the operational framework for the Digital Personal Data Protection Act, 2023.
Data Protection Board of India (DPBI): The regulator established under the Digital Personal Data Protection Act to enforce and oversee data protection.
Search-cum-Selection Committee: Committee responsible for recommending candidates for appointment to the Data Protection Board of India.
Ministry of Electronics and Information Technology: The ministry responsible for administration of the Digital Personal Data Protection Act, 2023 and related policies.
GOVERNMENT OF INDIA
MINISTRY OF ELECTRONICS AND INFORMATION TECHNOLOGY
LOK SABHA
UNSTARRED QUESTION NO. 1739
TO BE ANSWERED ON: 10.12.2025
STAGGERED ROLLOUT FOR LARGE TECH FIRMS
1739. DR. MALLU RAVI:
Will the Minister of ELECTRONICS AND INFORMATION TECHNOLOGY be pleased to state:
(a) the details of specific rationale for granting large tech firms a "staggered rollout" with compliance
deadlines extending as far as May 2027 in reference to the Digital Personal Data Protection (DPDP)
Rules, 2025, notified on November 14, 2025;
(b) the names and qualifications of the Chairperson and four members appointed to the Data Protection
Board of India (DPBI); and
(c) the manner in which the Government is likely to ensure the independence of the DPBI, given that
its members are appointed by the Central Government along with the status of the controversial
amendment to the RTI Act which is also now in force?
ANSWER
MINISTER OF STATE FOR ELECTRONICS AND INFORMATION TECHNOLOGY
(SHRI JITIN PRASADA)
(a) to (c): The Digital Personal Data Protection Act, 2023 (“Act”), and the Digital Personal Data
Protection Rules, 2025 (“Rules”), were notified on 13th November 2025. It provide for a phased
implementation framework.
The Rules mandate an eighteen-month period to allow organisations to implement appropriate technical
and organizational measures to achieve compliance with the provisions of the Act. This was done after
extensive consultation with all stakeholders.
The Act also provides for the establishment of the Data Protection Board of India (DPB). As notified, the
DPB comprises a Chairperson and four other Members who shall be appointed through Search-cum-
Selection Committee.
Independence of the Data Protection Board
The DPDP Act states that the DPB shall function as a digital office and as an independent body, ensured
through:
1. Search-cum-Selection Committee comprising senior officials and experts, recommending for
appointment the suitable candidates possessing ability, integrity, and specialised knowledge in
relevant fields
2. Fixed term of two years for Chairman and other Members, with eligibility for re-appointment
3. No change in salaries, allowances, and other service conditions of Chairman and other Members
to their disadvantage after their appointment4. Specification of grounds for disqualification from appointment or continuance, such as insolvency,
conviction for an offence involving moral turpitude, incapacity, prejudicial financial or other
interest, or abuse of position;
5. Opportunity of being heard to be given to the Chairperson or any other Member before their
removal.
*****