Draft Data Protection Rules Mandate Due Diligence, Explicit Consent for Processing Children's Data

The draft rules have been issued after 14 months of Parliament approving the Digital Data Protection Bill 2023.

Advertisement
By Press Trust of India | Updated: 6 January 2025 13:45 IST
Highlights
  • The Digital Personal Data Protection Rules were published last week
  • The draft focuses on controlling the exposure of kids to social media
  • Parliament first approved the Digital Data Protection Bill in 2023

E-commerce, social media and gaming platforms will fall under the category of data fiduciaries

Photo Credit: Pixabay

The government on Friday released the long-awaited draft of Digital Personal Data Protection Rules which specify that parent's verifiable consent will have to be obtained by social media or online platforms before children can create any account. Further, parents' identity and age will also have to be validated and verified through voluntarily provided identity proof "issued by an entity entrusted by law or the Government", as per the draft rules.

As per the rules, entities will be able to use and process personal data only if individuals have given their consent to consent managers – which will be entities entrusted to manage records of consents of people.

In case of children data processing, digital platforms will need to carry out due diligence for checking that the individual identifying herself as the parent of the child is an adult and is identifiable if required in connection with any legal compliance.

Advertisement

"A Data Fiduciary shall adopt appropriate technical and organisational measures to ensure that verifiable consent of the parent is obtained before the processing of any personal data of a child," the draft rule said.

Advertisement

E-commerce, social media, and gaming platforms will fall under the category of data fiduciaries.

According to the draft rules, data fiduciaries will have to keep the data only for the time being for which consent has been provided and delete it thereafter.

Advertisement

The draft rules have been issued after 14 months of Parliament approving the Digital Data Protection Bill 2023.

"Draft of rules proposed to be made by the central government in exercise of the powers conferred by sub-sections (1) and (2) of section 40 of the Digital Personal Data Protection Act, 2023 (22 of 2023), on or after the date of coming into force of the Act, are hereby published for the information of all persons likely to be affected thereby," the draft notification said.

Advertisement

The draft rules have mentioned the process of suspending or cancelling registration of consent manager in case of repeated violation, but there is no mention of penalties that were approved under the DPDP Act, 2023. The Act has the provision to impose a penalty of up to Rs 250 crore on data fiduciaries.

IndusLaw Partner Shreya Suri said that there was an anticipation of introducing thresholds for data breach reporting, where minor breaches could have had fewer compliance obligations.

"However, the current draft treats all breaches uniformly, requiring the same level of reporting and notification to the Data Protection Board and affected data principals, without granting any discretion whatsoever to data fiduciaries. Additionally, while the rules outline certain considerations for reasonable security practices, the lack of detailed guidance leaves room for varied interpretations," Suri said.

The draft rules, which have been published for public consultations, will be taken into consideration for making the final rule after February 18. The draft is available on MyGov website for the public comments.

Mayuran Palanisamy, Partner at Deloitte India, said the draft rules are quite detailed and give much needed direction to the businesses in India by expounding upon compliance to be carried out by them, such as obligations measures for Significant Data Fiduciaries, registration and obligations of Consent Managers, the establishment and functioning of the Data Protection Board, including specifics of data breach intimation to Data Principles and the Board, process for the Principals to exercise their rights and timelines for Data Fiduciaries to respond to grievances.

"We foresee that businesses will face some complex challenges in managing consent as it forms the heart of the law. Maintaining consent artefacts and offering the option to withdraw consent for specific purposes could necessitate changes at the design and architecture level of applications and platforms," Palanisamy said.

Further, organisations will need to invest in both technical infrastructure and processes to meet the requirements effectively. This includes relooking into data collection practices, implementing consent management systems, establishing clear data lifecycle protocols and actually percolating down these practices at an implementation level, Palanisamy added. 

(This story has not been edited by NDTV staff and is auto-generated from a syndicated feed.)

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. Xiaomi 17 Ultra With Leica-Tuned Cameras Confirmed to Launch Soon
  2. OnePlus 15R Review
  3. OnePlus Watch Lite With Up to 10 Days Battery Life Launched: See Price
  4. OnePlus 15s Visits BIS Certification Website; Could Launch in India Soon
  5. OTT Releases of the Week: Thamma, Mrs Deshpande, Nayanam, and More
  6. Apple's iPhone 18 Pro, iPhone Fold May Feature a Relocated Selfie Camera
  7. OnePlus 15R With 7,400mAh Battery, Snapdragon 8 Gen 5 Debuts at This Price
  8. Infinix Xpad Edge With 13.2-Inch Display, 8,000mAh Battery Launched
  9. Vivo V70 Stops By US FCC Database Along With RAM and Storage Details
  10. JWST observations may unlock new clues about dark matter
  1. Nvidia to Reportedly Cut GeForce RTX 50 Series GPU Production Amid Global RAM Shortage
  2. Apple Allows Third-Party App Stores, Relaxes Payment Restrictions in Japan to Comply With MSCA Act
  3. Hogwarts Legacy Has Sold 40 Million Copies, Warner Bros. Games Announces
  4. OnePlus 15s Listing on BIS Certification Website Hints at Imminent Launch in India
  5. Infinix Xpad Edge Launched With 13.2-Inch Display, 8,000mAh Battery: Price, Specifications
  6. Ethirneechal Thodargiradhu Now Streaming on SunNXT: What You Need to Know
  7. The Villainess Is Adored by the Prince of the Neighbor Kingdom OTT Release Date: Know When and Where to Watch This Japanese Anime Series Online
  8. Easygoing Defense by the Optimistic Lord Anime to Stream on Crunchyroll in January 2026
  9. Eko OTT Release Reportedly Revealed: When and Where to Watch it Online?
  10. Pornhub User Data Reportedly Stolen by Hacker Group ShinyHunters, Threaten to Expose
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.