What & Where
Definition: Draft rules to operationalise the Digital Personal Data Protection Act, 2023.
Authority: Issued by Ministry of Electronics & Information Technology, Government of India.
Processes: Notice-and-consent, user data rights, grievance redress, localisation obligations.
Quick Facts for MCQs
Legal & Policy
- Principle: Consent notices simplified to curb fatigue, align with global privacy norms.
- Obligation: SDFs face stricter localisation, compliance and audit duties.
- Gap: No independent regulator; powers centralised under Union government.
User Rights
- Provision: Individuals may access, correct, update, erase personal data.
- Issue: Practical procedures for exercising rights remain undefined.
- Empowerment: Rules seek to heighten transparency, autonomy in digital interactions.
Child Protection
- Requirement: Verifiable parental consent before processing data of minors under 18.
- Exemptions: Sectoral relaxations envisaged for education, healthcare.
- Concern: Vague age-verification standards invite inconsistent application.
Institutional Mechanism
- Body: DPB to handle breaches, disputes; independence limited.
- Limitation: Restricted adjudicatory powers may weaken impartial grievance redress.
- Recommendation: Stakeholders urge creation of an autonomous Data Protection Authority.
Key Data Points
| Feature | Data-Point |
|---|---|
| Parent ministry | MeitY |
| Act year | 2023 |
| Children age cut-off | Below 18 years |
| Oversight body | Data Protection Board (DPB) |
| Data transfer rule | Cross-border restricted; tighter for SDFs |
| Framework style | Principles-based, simplicity focus |
| Key user rights | Access, correction, update, erasure |
Related UPSC Prelims PYQs
सूचना का अधिकार अधिनियम, 2005 के बारे में निम्नलिखित में से कौन-सा/कौन-से कथन सही है/हैं ?








