Digital Data Protection India: Digital Personal Data Protection in India (DPDP) The rules of Act 2023 have now formally come into force. The Central Government has issued notification of the final rules under this law, after which a comprehensive Federal Digital Privacy Law has become effective for the first time in the country. The objective of this law is to strengthen the standards to data handling, storage and security, so that users can have complete control over their data. The new rules also impose strict responsibilities on digital platforms, government institutions and private companies.
Under the DPDP Act, any company will now have to obtain clear, simple and transparent consent before collecting personal data from the user.
This is considered a major change to prevent misuse of data.
It will now be mandatory for companies to implement advanced security measures such as data encryption, masking, security logs and monitoring.
Under the new rules, users will be able to access, correct, transfer, delete and track their data. If a user remains inactive for three years,
Platforms with more than 5 million users will now come under the category of Significant Data Fiduciary. They are required to conduct annual audits, impact assessments, and security reviews of their algorithms to ensure that their systems do not harm user rights. It will have the biggest impact on e-commerce, social media and gaming platforms. In case of sensitive data, restrictions may also be imposed on cross-border data transfer.
The government has given companies 12 to 18 months to comply with all the provisions.
As per the rules, data can be sent abroad, provided the government has not restricted that country. If the data is going to a foreign government or its controlled entity, companies will have to follow additional security guidelines.
E-commerce, social media and online gaming platforms, which have 20 million and more than 5 million users respectively, will have to delete data of customers who have been inactive for three years. It is mandatory to send a notice to the user 48 hours before removal.