If you’re a parent who has ever felt cornered into signing a school form without really being told you could refuse — this update is for you. On 20 July 2026, the Supreme Court of India passed an important order that affects every parent whose child has been asked to enrol for an APAAR ID. In simple terms: the consent form your school gives you must now allow you to say no, and this rule applies across the entire country. Let’s break down what happened, why it matters, and what it means for you as a parent. What is APAAR, and why should you care? Back in 2023, the Ministry of Education (MoE), along with the Ministry of Electronics and IT (MeitY), rolled out the Automated Permanent Academic Account Registry — APAAR for short. The idea was a “one student, one ID” system, linking your child’s Aadhaar number to a lifelong digital record of their academic scores, achievements, and other data. To enrol a child, parents were asked to sign a “model consent form.” On paper, this sounds fine — consent is supposed to mean you have a real choice. The problem was that this form never actually gave parents the option to refuse. Schools across the country used a version that only asked you to agree, with no box to tick if you didn’t want to participate. Many parents reported they weren’t even told they had a choice in the matter — they simply signed because the school told them to. The Odisha case that started it all A parent named Rohit Anand Das challenged this before the Odisha High Court in February 2025, specifically objecting to the missing opt-out option. On 12 December 2025, the Odisha High Court ruled in his favour in Rohit Anand Das v. State of Odisha, W.P. (C) No. 8285 of 2025, and directed the State authorities to consider amending the model consent form to include an option to refuse or opt out. That was a good result — but it only bound authorities in Odisha. How it became a pan-India rule The story didn’t end there. In July 2026, a separate writ petition was filed before the Supreme Court itself, under Article 32 of the Constitution, by Abishek Baxi and other parents of children studying in CBSE-affiliated schools. Their case went further — they argued that the entire APAAR Scheme, as it was being implemented, functioned like a “State-run surveillance mechanism,” allowing long-term tracking and profiling of children’s educational lives. Senior Advocate Indira Jaising, appearing for the petitioners, made a few important points: The original 2023 circular said parental consent was required — but the consent form itself gave no way to decline. The form didn’t clearly explain the purpose of data collection, how long the data would be kept, or who it would be shared with. CBSE circulars issued in August 2025 had made getting an APAAR ID mandatory for Class IX to XII students to even register for Board exams from 2026 onwards. Her argument was straightforward: if you’re told your child can’t sit for board exams without an APAAR ID, “consent” stops being real consent — it becomes compulsion. She also relied on the Supreme Court’s landmark privacy judgment in Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1, arguing that this setup failed the tests of legality, legitimate aim, necessity, and proportionality that any State action touching the right to privacy must meet. The Bench — Chief Justice Surya Kant, Justice Joymalya Bagchi, and Justice V. Mohana — agreed with the approach the Odisha High Court had already taken. Rather than starting from scratch, the Supreme Court simply extended Odisha’s solution to the whole country. It directed that the directions in Paragraph 19 of the Odisha High Court’s judgment — requiring a proper opt-out option in the consent form — “shall be given effect to on a pan-India basis by the concerned authorities implementing the APAAR Scheme.” The data protection angle The Supreme Court didn’t stop at the consent form. It also made it clear that any data collected under APAAR must strictly comply with the Digital Personal Data Protection Act, 2023 — meaning the government bodies handling this data are bound by the same lawful, secure, and purpose-limited processing obligations that apply to any data fiduciary. Just as importantly, the Court stated that no personal information collected through APAAR can be shared with any private entity or third party except as strictly authorised by law. Any sharing beyond the Scheme’s stated purpose was called impermissible. What this actually means for you You now have a clear, court-backed right to say no to your child’s APAAR ID enrolment — anywhere in India, not just Odisha. Schools cannot treat APAAR ID as a mandatory precondition without offering a genuine opt-out. Any data collected must be handled under the DPDP Act, 2023 — with restrictions on retention, purpose, and third-party sharing. The Respondents (Union of India, MeitY, CBSE, and UIDAI) have been given liberty to seek clarifications, so the exact wording of the revised consent form is still to come. What to watch for next The Ministry of Education still needs to actually amend the model consent form to build in the opt-out option the courts have directed. Until that happens, if your child’s school hands you the old form, you have a strong legal basis to ask for the option to refuse, or to flag the school for non-compliance with the Supreme Court’s order. This article is for general awareness and does not constitute legal advice. If your child’s school is denying you the option to opt out of APAAR ID enrolment, or is linking it to exam eligibility, you may want to consult a lawyer about your specific situation.
Consent Manager Registration under the DPDP Rules, 2025: Eligibility Conditions Explained | Sam O Martin LLP
The Digital Personal Data Protection Act, 2023 (DPDP Act) introduces a new framework for protecting the digital personal data of individuals in India. One of the most significant features of this framework is the concept of a Consent Manager—an entity that enables individuals (Data Principals) to give, manage, review, and withdraw their consent for the processing of their personal data through an accessible, transparent, and interoperable platform. To operationalise this framework, the Draft Digital Personal Data Protection Rules, 2025 prescribe detailed conditions that an entity must satisfy before it can be registered as a Consent Manager. These conditions are set out in Part A of the First Schedule of the Draft Rules. They establish minimum standards relating to legal status, financial capacity, governance, technical capability, integrity, and operational readiness. The objective is to ensure that only competent, reliable, and accountable organizations are entrusted with managing the consent of Data Principals. This article explains each condition prescribed under Part A of the First Schedule in detail. What is a Consent Manager? A Consent Manager is an independent entity registered under the DPDP framework that acts as a trusted intermediary between a Data Principal and a Data Fiduciary. Its primary role is to provide a secure and interoperable platform through which individuals can: Give consent for processing their personal data. Review the consent they have already provided. Modify or manage existing consent preferences. Withdraw consent at any time. Maintain greater control over how their personal data is processed. A Consent Manager is expected to operate independently, transparently, and in the best interests of the Data Principal. Conditions for Registration of a Consent Manager The First Schedule – Part A of the Draft DPDP Rules, 2025 lays down the eligibility requirements for registration. 1. The Applicant Must Be a Company Incorporated in India The Rules provide: “The applicant is a company incorporated in India.” Only a company incorporated under the applicable laws of India is eligible to apply for registration as a Consent Manager. This requirement ensures that the entity is subject to Indian corporate laws, regulatory oversight, and legal accountability. Partnerships, sole proprietorships, trusts, or other forms of business organisations are not eligible unless they are incorporated as a company. 2. The Applicant Must Have Sufficient Technical, Operational and Financial Capacity The Rules provide: “The applicant has sufficient capacity, including technical, operational and financial capacity, to fulfil its obligations as a Consent Manager.” A Consent Manager is expected to manage sensitive personal data and provide continuous digital services. Therefore, the applicant must demonstrate adequate resources to discharge its statutory responsibilities effectively. This includes: Appropriate technological infrastructure. Reliable operational processes. Skilled human resources. Adequate financial resources. Business continuity mechanisms. Information security capabilities. The objective is to ensure that the Consent Manager can provide uninterrupted, secure, and efficient services to Data Principals. 3. The Financial Condition and General Character of Management Must Be Sound The Rules provide: “The financial condition and the general character of management of the applicant are sound.” The Government intends to register only organizations that demonstrate financial stability and responsible corporate governance. This assessment may include: Financial health of the company. Corporate governance practices. Regulatory compliance history. Reputation in the market. Quality of internal management. Overall business stability. A financially stable organization is more likely to maintain secure systems and provide long-term compliance support. 4. Minimum Net Worth Requirement of ₹2 Crore The Rules provide: “The net worth of the applicant is not less than two crore rupees.” Every applicant must possess a minimum net worth of ₹2 crore. This financial threshold demonstrates that the organization possesses sufficient capital to establish and maintain the technical infrastructure, cybersecurity measures, compliance framework, and operational capabilities necessary for performing the functions of a Consent Manager. The minimum net worth requirement also serves as a safeguard against undercapitalised entities entering a highly sensitive regulatory ecosystem. 5. Adequate Business Prospects and Capital Structure The Rules provide: “The volume of business likely to be available to and the capital structure and earning prospects of the applicant are adequate.” Registration is not based solely on existing financial strength. The authorities may also evaluate: Expected business volume. Sustainability of operations. Capital structure. Revenue model. Long-term financial viability. Future earning prospects. The objective is to ensure that the applicant can continue operating effectively while meeting ongoing compliance obligations. 6. Directors and Senior Management Must Have Integrity The Rules provide: “The directors, key managerial personnel and senior management of the applicant company are individuals with a general reputation and record of fairness and integrity.” Leadership plays a critical role in protecting personal data. Accordingly, the individuals responsible for managing the company should possess: Professional competence. Ethical conduct. Integrity. Fairness. Good corporate reputation. Responsible management practices. This requirement helps promote public trust in the Consent Management ecosystem. 7. Constitutional Documents Must Incorporate Compliance Obligations The Rules provide: “The memorandum of association and articles of association of the applicant company contain provisions requiring that the obligations under items 9 and 10 of Part B are adhered to, that policies and procedures are in place to ensure such adherence, and that such provisions may be amended only with the previous approval of the Board.” This is one of the most important governance requirements under the Rules. The applicant’s Memorandum of Association (MoA) and Articles of Association (AoA) must specifically provide that: The obligations contained in Items 9 and 10 of Part B will be complied with. Appropriate internal policies and procedures exist to ensure compliance. These constitutional provisions cannot be amended without obtaining prior approval from the Board. Embedding these obligations within the company’s constitutional documents demonstrates a long-term institutional commitment to compliance and accountability. 8. Operations Must Be in the Interests of Data Principals The Rules provide: “The operations proposed to be undertaken by the applicant are in the interests of Data Principals.” Every activity undertaken by a Consent Manager should prioritize the interests of the Data Principal. The platform should therefore be designed to: Promote transparency. Enable informed decision-making. Provide
DPO as a Service (DPOaaS): Why Your Business May Need a Data Protection Officer
As businesses become increasingly digital, they collect and process large amounts of personal data every day. Customer information, employee records, vendor details, financial data, website analytics, and mobile application data have become essential to business operations. However, with this growth comes greater responsibility to protect personal data. The Digital Personal Data Protection Act, 2023 (DPDP Act) has introduced a new era of privacy and accountability in India. Organizations are now expected to implement strong data protection practices, maintain proper governance, and protect the rights of individuals whose personal data they process. Many companies do not have the resources or expertise to appoint a full-time Data Protection Officer (DPO). This is where DPO as a Service (DPOaaS) provides an effective solution. A virtual or outsourced DPO gives businesses access to experienced privacy professionals without the cost of hiring a full-time employee. What is a Data Protection Officer (DPO)? DPO as a Service (DPOaaS) is an outsourced service where an experienced legal and privacy team performs the role of a Data Protection Officer for your organization. Instead of recruiting a full-time DPO, businesses receive continuous guidance from professionals who help establish and maintain a comprehensive privacy compliance programme. This model is particularly beneficial for startups, SMEs, growing businesses, and organizations that require expert guidance without the expense of maintaining a dedicated in-house privacy department. Which Companies Should Consider DPO as a Service? While every organization should establish good privacy practices, certain businesses benefit significantly from DPO services. These include: Technology and Software Companies SaaS Companies E-commerce Businesses Healthcare Providers and Hospitals Educational Institutions Financial Institutions Insurance Companies Law Firms Human Resource Consultancies Marketing and Advertising Agencies Real Estate Companies Manufacturing Companies Logistics Companies BPO and KPO Organizations FinTech Companies Mobile Application Developers Companies handling large employee databases Businesses processing sensitive personal information If your organization regularly collects or processes customer or employee data, appointing a DPO or engaging a DPO as a Service provider is a proactive step towards stronger governance. Key Responsibilities of a Data Protection Officer A DPO performs much more than reviewing privacy policies. The role covers legal, operational, technical, and governance functions. 1. Advise on Data Protection Laws Provide guidance on compliance with the Digital Personal Data Protection Act, 2023, and other applicable privacy requirements. 2. Develop Privacy Policies Prepare and review: Privacy Policies Data Protection Policies Data Retention Policies Data Breach Response Plans Employee Privacy Policies Cookie Policies Internal Standard Operating Procedures (SOPs) 3. Conduct Data Mapping Identify: What personal data is collected Why it is collected Where it is stored Who has access How it is shared How long it is retained This provides visibility over the organization’s data processing activities. 4. Conduct Compliance Gap Assessments Evaluate current business practices and identify areas requiring improvement. A compliance assessment helps businesses prepare a practical roadmap towards DPDP compliance. 5. Advise on Consent Management Assist organizations in implementing transparent consent mechanisms and maintaining proper consent records. 6. Review Vendor Agreements Review contracts with: Cloud service providers HR software providers Payment gateways Marketing agencies IT vendors Data processors This helps ensure that third-party relationships appropriately address data protection obligations. 7. Monitor Compliance Privacy compliance is an ongoing process. A DPO periodically reviews: Internal policies Security controls Business processes Vendor management Employee awareness Compliance documentation Regular monitoring helps identify emerging risks and opportunities for improvement. 8. Employee Training Privacy awareness is one of the most important aspects of compliance. The DPO conducts training programmes covering: Data privacy principles Secure handling of personal information Password management Phishing awareness Reporting security incidents Confidentiality obligations 9. Assist During Data Incidents In the event of a suspected data breach, the DPO helps: Assess the incident Coordinate internal response Document the incident Recommend corrective actions Strengthen future controls 10. Build a Privacy-First Culture Beyond legal compliance, a DPO promotes responsible handling of personal information throughout the organization. A strong privacy culture improves customer trust and supports long-term business growth. Benefits of DPO as a Service Outsourcing the DPO function offers several advantages: Cost-Effective :- Avoid the cost of hiring a full-time senior privacy professional. Access to Experienced Professionals :- Benefit from legal, compliance, governance, and privacy expertise. Independent Advice :- Receive objective guidance based on regulatory requirements and industry best practices. Continuous Compliance Support :- Privacy compliance is not a one-time exercise. A DPO provides ongoing monitoring, updates, and practical advice as your business evolves. Scalable Solutions :- As your organization grows, DPO services can expand to meet new operational and regulatory requirements. Reduced Compliance Risk :- Regular reviews and structured governance help reduce privacy risks and improve organizational preparedness. When Should Your Company Engage a DPO? Consider engaging a DPO if your organization: Collects large volumes of customer data. Processes employee records digitally. Operates an e-commerce platform. Runs a mobile application. Uses cloud-based systems. Handles financial or healthcare information. Shares personal data with third-party vendors. Expands internationally. Wants to strengthen corporate governance. Is preparing for DPDP compliance. Even where a dedicated DPO is not legally mandated, having experienced privacy professionals oversee your compliance programme is a recognised governance best practice. Why Businesses Choose DPO as a Service Instead of Hiring In-House For many businesses, appointing a full-time DPO may not be practical. DPO as a Service offers: Lower operational costs Immediate access to experienced professionals No recruitment or training burden Flexible engagement models Ongoing compliance support Access to multidisciplinary legal and compliance expertise This makes outsourced DPO services an ideal solution for startups, SMEs, and growing enterprises. How Sam O Martin LLP Can Assist Sam O Martin LLP assists businesses in developing and maintaining data protection compliance frameworks under the Digital Personal Data Protection Act, 2023 (DPDP Act). Our approach focuses on practical implementation, ongoing compliance, and governance measures tailored to the operational needs of each organisation. Our team has hands-on experience in advising organisations on the design, implementation, and review of data protection compliance programmes across a range of sectors. Our DPO as a Service offering may include assistance with: DPDP compliance
Data Protection Compliance Checklist for Companies: A Complete Guide for Indian Businesses
In today’s digital world, every business collects and uses personal data. Whether you are a startup, IT company, law firm, hospital, educational institution, manufacturing company, or e-commerce business, you likely handle information such as customer names, phone numbers, email addresses, employee records, financial details, and other personal information. With increasing digital transactions and growing concerns about data privacy, businesses are expected to handle personal data responsibly. India’s Digital Personal Data Protection Act, 2023 (DPDP Act) has introduced a legal framework that governs how organizations collect, process, store, and protect digital personal data. Data protection compliance is no longer just a legal requirement—it is an important part of building customer trust, protecting business reputation, and reducing operational risks. This guide provides a practical Data Protection Compliance Checklist that every company can use to strengthen its privacy and compliance framework. What is Data Protection Compliance? Data protection compliance means implementing the legal, technical, and organizational measures required to protect personal data throughout its lifecycle. A compliant organization ensures that personal information is: Collected for lawful purposes. Used only for legitimate business activities. Protected against unauthorized access. Stored securely. Retained only for as long as necessary. Deleted securely when no longer required. Effective compliance also demonstrates accountability and responsible corporate governance. Why is Data Protection Compliance Important? Strong data protection practices benefit businesses in several ways. They help organizations: Build customer confidence. Protect sensitive business information. Reduce the risk of cyber incidents. Improve internal governance. Strengthen relationships with clients and business partners. Support regulatory compliance. Enhance the organization’s reputation. Customers are increasingly choosing businesses that demonstrate a commitment to protecting personal information. Which Companies Should Implement Data Protection Compliance? Almost every organization that processes digital personal data should establish a compliance programme. This includes: Startups IT and software companies Law firms Chartered Accountancy firms Hospitals and healthcare providers Educational institutions E-commerce businesses Manufacturing companies Financial institutions Real estate companies Human resource consultancies Marketing agencies NGOs Mobile application developers If your organization stores or processes employee, customer, or vendor information digitally, data protection compliance should be a priority. Data Protection Compliance Checklist for Companies 1. Identify the Personal Data You Collect Start by understanding what personal data your organization collects. Examples include: Customer records Employee files Vendor information Website enquiries Marketing databases Recruitment records Mobile application data Knowing what data you collect is the first step towards effective compliance. 2. Prepare a Data Inventory Create a detailed inventory that records: Types of personal data Purpose of collection Storage locations Departments using the data Third-party sharing Retention periods A data inventory helps organizations maintain visibility over their information assets. 3. Map the Flow of Personal Data Understand how personal data moves across your organization. Map each stage, including: Collection Processing Internal access Third-party sharing Cloud storage Archiving Deletion Data flow mapping helps identify operational and security risks. 4. Collect Only the Data You Need Avoid collecting excessive information. Every category of personal data should have a legitimate business purpose. Limiting data collection reduces both compliance risks and cybersecurity exposure. 5. Implement Proper Consent Practices Where consent is required, it should be: Clear Specific Informed Easy to understand Easy to withdraw Maintain records showing how and when consent was obtained. 6. Review Your Privacy Policy Ensure your privacy notice clearly explains: What personal data is collected Why it is collected How it is used Whether it is shared How long it is retained The rights available to individuals Contact details for privacy-related concerns Use simple language that customers can easily understand. 7. Strengthen Information Security Protect personal data through appropriate technical safeguards such as: Encryption Multi-factor authentication Access controls Secure backups Firewalls Antivirus protection Regular software updates Security monitoring Security measures should be regularly reviewed and updated. 8. Review Third-Party Vendors Many organizations rely on external service providers. Review vendors that process personal data, including: Cloud service providers HR software providers Payroll processors Payment gateways Marketing agencies IT support companies Ensure contractual obligations require vendors to protect personal data appropriately. 9. Develop a Data Retention Policy Personal data should not be retained indefinitely. Your policy should define: Retention periods Archiving procedures Secure deletion methods Legal retention requirements Removing unnecessary data reduces privacy risks. 10. Prepare for Data Breaches Develop a documented incident response plan covering: Detection Investigation Containment Recovery Documentation Notification procedures A prepared organization can respond more effectively when incidents occur. 11. Establish a Grievance Redressal Process Individuals should have a clear process to: Raise complaints Request corrections Update their information Seek assistance regarding their personal data A transparent grievance mechanism strengthens accountability. 12. Train Employees Regularly Employees play a key role in protecting personal data. Training should include: Privacy awareness Secure handling of information Password security Phishing prevention Reporting incidents Confidentiality obligations Regular awareness programmes help reduce human error. 13. Maintain Proper Compliance Records Keep records of: Privacy policies Internal procedures Consent records Vendor agreements Employee training Security assessments Incident reports Internal reviews Proper documentation demonstrates responsible governance and supports future audits. 14. Conduct Periodic Compliance Reviews Business operations and technology continue to evolve. Review your compliance programme regularly to identify: New risks Policy gaps Process improvements Security enhancements Regulatory developments Compliance should be viewed as an ongoing process rather than a one-time exercise. 15. Seek Professional Compliance Support Many organizations benefit from experienced legal and compliance professionals who can assist with: Compliance gap assessments Data mapping Privacy documentation Internal policies Vendor contract reviews Employee training Compliance audits Ongoing advisory services Professional guidance helps businesses implement practical and sustainable compliance measures. Common Data Protection Mistakes Companies Should Avoid Some of the most common compliance issues include: Collecting unnecessary personal data. Using outdated privacy policies. Weak cybersecurity controls. Poor access management. Inadequate employee training. Lack of documentation. Failing to review third-party vendors. Keeping personal data longer than necessary. Treating compliance as a one-time project. Identifying and addressing these issues early can significantly improve an organization’s privacy framework. Data protection has become an essential part of modern business governance. Organizations that adopt responsible privacy practices
DPDP Compliance Checklist for Businesses: A Complete Guide to DPDP Compliance Services in Delhi
Data is one of the most valuable assets for every business today. Companies collect personal information from customers, employees, vendors, website visitors, and business partners every day. This information may include names, phone numbers, email addresses, Aadhaar numbers, PAN details, bank information, photographs, IP addresses, and much more. As businesses become more digital, protecting personal data has become a legal responsibility. To address this, the Government of India introduced the Digital Personal Data Protection Act, 2023 (DPDP Act). The Act establishes rules for collecting, using, storing, sharing, and protecting digital personal data. Whether you operate a startup, IT company, law firm, hospital, school, e-commerce platform, manufacturing business, or multinational corporation, you should understand your obligations under the DPDP Act. This guide explains the DPDP compliance checklist for businesses, outlines the compliance process, and discusses how professional DPDP compliance services in Delhi can help organizations build a practical compliance program. What is DPDP Compliance? DPDP Compliance means following the requirements of the Digital Personal Data Protection Act, 2023. Compliance is not limited to creating a privacy policy. It involves establishing processes, policies, technical safeguards, employee awareness, vendor management, and governance measures to protect personal data throughout its lifecycle. A compliant organization demonstrates that it: Collects personal data only for lawful purposes. Informs individuals how their information will be used. Protects personal information with appropriate security measures. Allows individuals to exercise their rights under the law. Maintains records and procedures to demonstrate accountability. DPDP compliance is therefore both a legal obligation and an important part of good corporate governance. Which Businesses Need DPDP Compliance? Almost every organization that processes digital personal data should evaluate its obligations under the DPDP Act. This may include: Startups IT and software companies Law firms Chartered Accountancy firms Hospitals and clinics Educational institutions E-commerce businesses Real estate companies Manufacturing companies Financial institutions HR consultancies Marketing agencies NGOs Online platforms Mobile application developers If your business collects customer or employee information digitally, DPDP compliance should be part of your governance framework. Why DPDP Compliance is Important DPDP compliance provides several benefits beyond meeting legal requirements. A strong compliance program can: Build customer confidence. Improve data security. Reduce the risk of data breaches. Enhance corporate reputation. Support business partnerships. Improve operational discipline. Demonstrate responsible data management. Prepare the organization for future regulatory developments. Companies that protect personal data effectively are often viewed as more trustworthy by customers, investors, and business partners. DPDP Compliance Checklist for Businesses The following checklist provides a practical roadmap for organizations beginning their compliance journey. Step 1: Understand What Personal Data You Collect The first step is identifying the personal data your organization collects. Examples include: Customer information Employee records Vendor information Job applicant details Website enquiries Mobile app registrations Marketing databases CCTV records linked to individuals Understanding your data is the starting point for effective compliance. Step 2: Create a Data Inventory Prepare a detailed inventory of personal data. Record: What data is collected Why it is collected Where it is stored Who can access it Whether it is shared How long it is retained This exercise helps identify unnecessary data collection and improves governance. Step 3: Map Your Data Flow Understand how personal data moves throughout your organization. Map the journey from: Collection Processing Internal use Storage Sharing Archiving Deletion A data flow map helps identify security and compliance gaps. Step 4: Review the Purpose of Data Collection Only collect information that is genuinely required for your business activities. Avoid collecting excessive or unnecessary personal information. Every category of personal data should have a clearly documented business purpose. Step 5: Implement Consent Management Consent should be: Clear Specific Easy to understand Voluntary Easy to withdraw Organizations should maintain proper records showing when and how consent was obtained. Step 6: Update Your Privacy Policy A privacy notice should explain: What information is collected Why it is collected How it will be used Whether it will be shared How long it will be retained The rights available to individuals Contact details for privacy-related queries Use plain, simple language instead of complex legal terms. Step 7: Review Vendor Agreements Many businesses share personal data with: Cloud providers HR software vendors Payroll companies Marketing agencies Payment gateways IT support providers Review contracts to ensure vendors are required to protect personal data appropriately. Step 8: Strengthen Cybersecurity Compliance depends on good security practices. Businesses should implement: Strong passwords Multi-factor authentication Data encryption Secure backups Firewalls Antivirus protection Access controls Regular security updates Vulnerability assessments Security protects both the organization and the individuals whose data is processed. Step 9: Create a Data Retention Policy Do not store personal data indefinitely. Develop policies covering: Retention periods Secure storage Archiving Permanent deletion Once personal data is no longer needed or required by law, it should be securely deleted. Step 10: Prepare for Data Breaches No organization is completely immune from cyber incidents. Prepare a documented incident response plan that defines: How breaches are identified Who should be informed internally How incidents are investigated Recovery measures Documentation procedures Being prepared reduces business disruption and supports timely response. Step 11: Establish a Grievance Redressal Process Individuals should have an accessible process to: Raise complaints Correct inaccurate information Withdraw consent where applicable Seek assistance regarding their personal data A documented grievance mechanism promotes accountability and transparency. Step 12: Train Employees Technology alone cannot achieve compliance. Regular employee training should cover: Privacy principles Secure handling of personal data Password hygiene Phishing awareness Reporting security incidents Confidentiality obligations Employees who understand privacy obligations are less likely to make mistakes that lead to data breaches. Step 13: Maintain Compliance Documentation Keep records of: Privacy policies Internal procedures Consent records Vendor agreements Training sessions Security assessments Incident reports Internal reviews Good documentation demonstrates responsible governance. Step 14: Conduct Regular Compliance Reviews Compliance should be reviewed periodically. Internal reviews help identify: New risks Changes in business processes New technologies Security weaknesses Policy gaps Continuous improvement strengthens the overall compliance program. Step 15: Seek Professional DPDP Compliance Assistance Many
Digital Personal Data Protection Act, 2023-Key Compliance Requirements under the Legal Framework
Chapter II of the Digital Personal Data Protection Act, 2023 (DPDPA) outlines the obligations of the Data Fiduciary. The Act first establishes the grounds on which personal data may be processed. According to these provisions, a data fiduciary may process personal data of a data principal only in accordance with the provisions of the Act and for a lawful purpose, meaning any purpose that is not expressly forbidden by law. The Act further prescribes specific compliance obligations that must be followed by data fiduciaries when processing personal data. Two central requirements under this framework are consent and notice. Consent Consent forms the foundation of lawful personal data processing under the Act. The DPDPA specifies several conditions that must be fulfilled for consent to be valid. First, the consent must be free, specific, informed, unconditional, and unambiguous, and it must involve a clear affirmative action by the data principal. Such consent signifies that the data principal agrees to the processing of their personal data only for the specified purpose. However, if the consent contradicts any provision of the Act or any other law currently in force in India, the consent will be invalid to the extent of such infringement. The Act also requires that the request for consent must be communicated in clear and plain language. The data principal must have the option to access the request in English or in any of the languages specified in the Eighth Schedule of the Constitution of India. These languages include Assamese, Bengali, Gujarati, Hindi, Kannada, Kashmiri, Konkani, Malayalam, Manipuri, Marathi, Nepali, Oriya, Punjabi, Sanskrit, Sindhi, Tamil, Telugu, Urdu, Bodo, Santhali, Maithili, and Dogri. The consent request must also include contact details of a Data Protection Officer or another authorised person designated by the data fiduciary to respond to queries or communications from data principals regarding the exercise of their rights under the Act. A Data Protection Officer (DPO) is an individual who represents Significant Data Fiduciaries (SDFs). The DPO must be based in India and is responsible to the Board of Directors or a similar governing body. The officer acts as the point of contact for data principals in case they face any grievances. The Act further requires data fiduciaries to ensure that data principals can easily withdraw their consent whenever they wish. Once consent is withdrawn, the data fiduciary must stop processing the personal data within a reasonable time. An exception exists where law permits continued processing of such data even after the withdrawal of consent. In such cases, the data fiduciary may continue the processing. It is also important to note that when consent is withdrawn, the data principal must bear any resulting consequences, and the withdrawal does not affect the legality of data processing that occurred before the withdrawal. Notice Another crucial compliance requirement under the Act is the notice provided to the data principal. The notice either accompanies or precedes the request for consent. Its purpose is to inform the data principal about important aspects of data processing. The notice must inform the data principal of: Which personal data is being accessed and the purpose for processing it The manner in which the data principal can exercise their rights The process through which a complaint can be made to the Data Protection Board of India Further requirements relating to notice are specified in the DPDP Rules. According to these rules, the notice must be presented in an understandable form and independent of other information provided by the data fiduciary. It must provide clear and simple information enabling the data principal to give specific and informed consent for the processing of personal data. The notice must include: A clear, item-by-item description of the personal data being collected The exact purpose for collecting such data, along with a clear explanation of the goods, services, or uses that the data will enable Additionally, the notice must provide the specific link to the data fiduciary’s website or application and explain other available methods through which the data principal can: Withdraw consent as easily as it was given Exercise their rights under the Act File a complaint with the Data Protection Board of India Through these provisions, the Digital Personal Data Protection Act, 2023 establishes structured compliance requirements governing how personal data may be processed and how data principals must be informed and empowered during the process.
Digital Personal Data Protection Act, 2023 – Applicability of the Act to Companies and Organisations
The Digital Personal Data Protection Act, 2023 (DPDPA) adopts a broad and comprehensive approach while defining personal data. Personal data refers to any information that can be used to identify an individual, who is referred to under the Act as a Data Principal. This definition is intentionally wide in scope to ensure that various forms of personal information receive adequate legal protection. Personal data includes traditional identifiers such as names and addresses, as well as modern digital identifiers like IP addresses and browsing history. In addition to these, financial information, opinions, and even biometric data fall within the scope of the Act, provided that such information can be linked to a specific individual. By adopting this wide definition, the Act ensures that a broad range of personal information is covered and protected. The applicability of the Act is addressed under Section 3 of the DPDPA. This provision specifies the situations in which the Act applies to the processing of personal data. Firstly, the Act applies to the processing of digital personal data within India. This includes personal data that is collected directly in digital form. It also includes data that is originally collected in non-digital form but is subsequently digitised. Therefore, physical records that are later scanned, converted into digital format, or stored electronically fall within the scope of the Act. This provision ensures that personal data receives protection regardless of the form in which it was originally collected. Despite its broad applicability, the Act also provides certain specific exclusions. The provisions of the Act do not apply to personal data that is used by individuals for domestic purposes. Additionally, personal data that has been made publicly available by the Data Principal themselves, or personal data that has been made public because it was required by law, is also excluded from the scope of the Act. The Act applies broadly to entities or persons that determine the purpose and means of processing personal data. Such entities are referred to as Data Fiduciaries under the Act. The term Data Fiduciary includes a wide range of entities such as individuals, Hindu Undivided Families, companies, firms, associations of persons, bodies of individuals (whether incorporated or not), the State, and every other artificial juristic person. These entities are responsible for ensuring that the processing of personal data complies with the obligations laid down under the Act. Furthermore, the Act provides for the designation of certain entities as Significant Data Fiduciaries (SDFs). This designation is based on factors such as the volume and sensitivity of personal data processed, as well as the risk posed to the sovereignty and integrity of India, electoral democracy, or public order. Entities classified as Significant Data Fiduciaries are required to comply with additional obligations under the Act, reflecting the higher level of risk associated with large-scale or sensitive data processing. Through these provisions, the Digital Personal Data Protection Act, 2023 establishes a framework that determines the entities and circumstances to which the law applies, while also identifying situations where its provisions do not extend.
Implications and Consequences of Non-Compliance, including Relevant Penalties under DPDP Act
The Digital Personal Data Protection Act, 2023 (DPDPA) establishes a structured enforcement framework to ensure compliance with data protection obligations. One of the most significant mechanisms under the Act is the imposition of monetary penalties for violations. These penalties are administered by the Data Protection Board of India, which has the authority to investigate contraventions and impose financial sanctions where necessary. The power to impose penalties arises when a person—typically a data fiduciary—is found to have violated obligations prescribed under the Act or the rules framed under it. The penalties are not arbitrary but are determined according to the Schedule to Section 33 of the Act, which specifies maximum limits for different categories of violations. Factors Considered by the Board While Imposing Penalties Before determining the appropriate penalty, the Data Protection Board must take into account several important factors to assess the seriousness of the violation. These considerations ensure that the enforcement process remains balanced and proportionate. The Board evaluates: Nature, gravity, and duration of the breach Type and nature of personal data affected Whether the breach was repetitive in nature Whether the entity took steps to mitigate the breach Whether any financial gain was derived from the violation These criteria help ensure that penalties reflect the severity of the violation and the conduct of the entity involved. Another important feature of the Act is that penalties collected are credited to the Consolidated Fund of India. The monetary penalties imposed by the Board are therefore regulatory in nature and do not directly compensate affected individuals. Penalty Structure under Section 33 of the Act The Act establishes a categorical penalty structure, where specific violations correspond to specific maximum penalty limits rather than a single uniform fine. According to the official Schedule under Section 33(1), the following maximum penalties may be imposed: Failure to Implement Reasonable Security Safeguards (Section 8(5))Maximum penalty: ₹250 crores Failure to Notify the Board and Affected Data Principals of a Personal Data Breach (Section 8(6))Maximum penalty: ₹200 crores Failure to Fulfil Additional Obligations Relating to Children’s Data (Section 9)Maximum penalty: ₹200 crores Failure to Fulfil Additional Obligations of a Significant Data Fiduciary (Section 10)Maximum penalty: ₹150 crores Breach of Duties under Section 15This includes situations such as filing a false complaint by a data principal.Maximum penalty: ₹10,000 Breach of Any Other Provision of the Act or RulesMaximum penalty: Up to ₹50 crores Breach of a Voluntary Undertaking Accepted by the Board (Section 32)In such cases, the penalty applicable is the same as that prescribed for the original breach. This structured penalty framework ensures that violations are addressed in proportion to their nature and seriousness. Enforcement and Compliance Mechanism The Data Protection Board does not impose penalties automatically. It conducts an evaluation of the circumstances surrounding the violation. In particular, the Board examines: Whether the entity gained commercially from the violation Whether steps were taken to mitigate the breach Whether the processing activity was stopped promptly The overall impact of the breach on individuals and their data rights This approach introduces an element of regulatory flexibility, allowing entities that take prompt remedial actions to potentially face reduced penalties. In addition to imposing penalties, the Board also has the authority to issue directions to ensure compliance. If a data fiduciary fails to follow such directions, the Board may impose additional penalties. In serious cases of non-compliance, these penalties may reach the highest tier permitted under the relevant category. Conclusion The penalty framework under the Digital Personal Data Protection Act, 2023 is designed to function as a strong deterrent against data protection violations. By specifying clear penalty limits and requiring the Board to consider contextual factors, the Act seeks to balance strict enforcement with procedural fairness. The system ultimately encourages organisations to adopt robust data protection practices and ensures accountability in the handling of personal data.
Digital Personal Data Protection Act, 2023 – Legislative Evolution: Withdrawal of the 2019 Bill and Enactment of the DPDP Framework
Withdrawal of the Personal Data Protection Bill, 2019 (2022) An important stage in the legislative journey towards the Digital Personal Data Protection Act, 2023 occurred on 3 August 2022, when the Government of India formally withdrew the Personal Data Protection Bill, 2019 from Parliament. This decision followed extensive parliamentary deliberations and the submission of the Joint Parliamentary Committee (JPC) report in December 2021. The withdrawal of the Bill did not signify the abandonment of India’s data protection policy objectives. Rather, it reflected the Government’s recognition that the existing Bill required substantial restructuring instead of incremental amendments. Reasons for Withdrawal Several factors led to the decision to withdraw the 2019 Bill: Need for Comprehensive RedraftingThe recommendations of the Joint Parliamentary Committee suggested extensive structural changes to the Bill. Implementing these recommendations would have required rewriting significant portions of the legislation, making piecemeal amendments impractical. Shift Toward a Simpler Legislative FrameworkThe Government indicated that a new approach would focus on creating a simpler and more streamlined legal structure that could be implemented efficiently and reduce regulatory complexity. Alignment with India’s Digital Governance PrioritiesIndia’s rapidly expanding digital ecosystem required a regulatory framework capable of supporting innovation, digital commerce, and governance initiatives. The Government therefore decided to draft a new law that would align more closely with evolving digital policy objectives. Importantly, the withdrawal was largely procedural in nature. It was not a rejection of the need for data protection legislation but rather a strategic step toward developing a revised framework. Digital Personal Data Protection Act, 2023 1. Enactment Following the withdrawal of the earlier Bill, the Government introduced a new legislative proposal which ultimately led to the enactment of the Digital Personal Data Protection Act, 2023 in August 2023. This Act marked India’s first dedicated statute governing the processing and protection of personal data in the digital environment. 2. Key Characteristics of the Act The Digital Personal Data Protection Act, 2023 reflects a more focused and operational framework compared to the earlier legislative proposals. Applicability to Digital Personal DataThe Act applies specifically to digital personal data, including data collected online as well as data collected offline that is subsequently digitised. Establishment of the Data Protection Board of IndiaInstead of the Data Protection Authority proposed in earlier drafts, the Act creates a Data Protection Board of India, responsible for adjudicating complaints and enforcing compliance. Penalty-Based Enforcement FrameworkThe Act primarily relies on financial penalties and regulatory enforcement mechanisms rather than criminal liability. This approach aims to ensure compliance while maintaining regulatory efficiency. Cross-Border Data TransfersUnlike earlier localisation-heavy proposals, the Act permits cross-border transfer of personal data, except to countries specifically restricted by the Central Government. State Exemption PowersThe legislation retains provisions allowing the State to exempt certain agencies from its application on specified grounds, supported by statutory authority. Overall, the Act represents a narrower but more implementable framework, designed to facilitate regulatory clarity and practical enforcement. Rules and Implementation (2024–2025) Following the enactment of the Act, the Government began working on its implementation through subordinate legislation and institutional mechanisms. Between 2024 and 2025, the focus shifted toward operationalising the law through several measures: Drafting and notification of Digital Personal Data Protection Rules Establishment and regulation of consent managers Development of enforcement and grievance redressal mechanisms Introduction of phased compliance timelines for organizations processing personal data These steps marked the transition of the law from a purely legislative framework to a functional regulatory regime. Concluding Analysis The legislative development of India’s data protection framework can be understood through distinct phases: 2018 Draft: Expert-driven and rights-oriented framework. 2019 Bill: Government-led proposal with broader regulatory ambition and state exemptions. JPC Phase: Parliamentary scrutiny leading to structural critique and expansionist recommendations. Withdrawal (2022): Recognition that the Bill required fundamental redesign. DPDP Act, 2023: A streamlined, digital-focused, and implementation-oriented statute. This evolution illustrates India’s effort to balance constitutional privacy protections, economic development, governmental interests, and the realities of technological governance in an increasingly digital society.
Whether a deceased member’s flat can be transferred, mutated, or endorsed in favour of the surviving family in the record of Real Estate Developers/ Registered Societies/ RWAs/ Cooperative Group Housing Societies?
At SAM O MARTIN, we regularly advise Real Estate Developers, Resident Welfare Associations, Cooperative Group Housing Societies, and individual owners on succession, mutation, title verification, and related property matters. Recently, we were approached by the management of a well-known multi-storeyed residential building in a prime commercial-cum-residential locality of New Delhi to advise on applications and supporting documents of surviving members of two deceased flat owners for transfer/mutation/endorsement. These requests are often urgent, as Societies cannot keep records in limbo, and families cannot move forward with maintenance, sale, or occupation until the paperwork is settled. Matter One: A Clean Title, A Clear Answer In the first instance, the original allottee of a flat had passed away, and her two sons approached the Society seeking endorsement of their names as owners. We were furnished with the original licence deed, a registered Will bequeathing the property to the sons in equal share, the death certificate, and the municipal mutation correspondence. On a careful reading of these documents, we were able to confirm that the Society’s own allotment records consistently reflected the original allottee as owner, that municipal mutation records do not by themselves confer title, and that the registered Will left no ambiguity as to the testatrix’s intention. There being no material suggesting any dispute or challenge to the Will, we were able to render our opinion promptly advising the Society that it could proceed to endorse the names of the legal heirs, subject to a standard written undertaking and indemnity bond to protect the Society against any future third-party claims. Matter Two: When Caution Serves the Client Best The second instance, concerning two other flats in the same building, was materially different. Here, two of several legal heirs sought endorsement of their names to the exclusion of the other heirs, relying on an unregistered and unprobated Will, notarised affidavits from some (but not all) family members, an unsigned and unwitnessed family settlement on plain paper, and a Special Power of Attorney executed abroad. On examination, we found that none of these documents, individually or collectively, could legally establish exclusive ownership or a valid relinquishment of rights by the remaining heirs. An unprobated Will does not suffice for transfer of immovable property in Delhi; affidavits are not a substitute for a registered relinquishment deed; and an unsigned, unwitnessed settlement cannot extinguish inheritance rights. We accordingly advised the Society against endorsing the applicants’ names on the basis of the documents then available, and set out precisely what would be required before any change could safely be made. We advised our client to seek probate of the Will, registered relinquishment deeds, a competent court’s decree, or a duly executed and registered family settlement with the consent of all heirs along-with undertaking and indemnity bond. Our Approach Both opinions were delivered to the Society within a short turnaround of the documents being placed before us. What distinguishes sound legal advice in such matters is not merely speed, but the discipline to reach different conclusions on similar-looking facts, recommending action where the title trail is clear, and recommending restraint where it is not. This protects our clients, in this case a Society acting as custodian of its members’ records, from being drawn into inheritance disputes that are properly for the parties (and, if necessary, the courts) to resolve.