Skip to content Skip to left sidebar Skip to right sidebar Skip to footer

Digital Personal Data Protection Rules, 2025: Safeguarding Privacy and Child Protection

The Digital Personal Data Protection Rules, 2025, introduced by the Union Ministry of Electronics and Information Technology (MeitY) on January 3, propose measures to safeguard children’s personal data. These rules build upon the legislative framework established by the Digital Personal Data Protection Act, 2023, passed by Parliament in August 2023. Stakeholders are invited to submit objections and suggestions on the draft by February 18, 2025.

Child Protection Measures

The draft rules mandate that social media platforms and online services must obtain verifiable parental consent before processing children’s personal data. This requires explicit parental approval for collecting and using such data.

Data fiduciaries (entities that collect and manage personal data) are tasked with verifying the identity of individuals claiming to be a child’s guardian. Verification methods may include checking government-issued identification or utilizing digital tokens linked to identity services.

For example, if a child seeks to create an online account, the data fiduciary must enable their parent to authenticate their identity through secure means before processing the child’s data. The draft rules illustrate this as follows:

Example:

  • C is a child, P is her parent, and DF is a Data Fiduciary.
  • C wishes to create a user account on DF’s platform, which involves processing her personal data.
  • C informs DF that she is a child. DF must allow P to authenticate her identity through its website, app, or other secure methods.
  • P identifies herself as the parent and confirms that she is a registered user of DF, with her identity and age details already verified.
  • Before processing C’s data, DF must ensure that it holds reliable identity and age information about P.

Processing Personal Data by State Entities

The draft rules permit State entities to process personal data while providing subsidies, benefits, or services. This provision ensures adherence to established safeguards and reinforces accountability in public sector data handling.


Security Measures

To prevent data breaches, data fiduciaries are required to implement robust security measures, including:

  • Encrypting and securing personal data;
  • Controlling access to computer systems used for processing;
  • Maintaining access logs and monitoring for unauthorized use.

Breach Notification Requirements

In the event of a data breach, data fiduciaries must notify affected individuals promptly, providing details such as:

  • The nature and extent of the breach;
  • Potential consequences for affected individuals;
  • Measures taken to mitigate risks.

Additionally, fiduciaries are required to report breaches to the regulatory board within a specified timeframe, ensuring transparency and accountability.


Data Retention Policies

The draft rules mandate that personal data should be erased within a defined timeframe if it is no longer required for its intended purpose. This encourages periodic reviews of data retention practices and prevents unnecessary long-term storage of personal information. These measures, taken together, aim to bolster privacy and security while promoting accountability in data management practices.

Conclusion

The Draft Digital Personal Data Protection Rules, 2025 underscore the government’s commitment to protecting personal data in an increasingly digitized world. By emphasizing measures such as parental consent for processing children’s data, stringent security safeguards, transparent breach reporting, and clear data retention policies, these rules aim to balance privacy rights with the needs of innovation and governance. Stakeholder participation will play a crucial role in refining these regulations, ensuring they are both practical and effective in addressing modern data protection challenges.

0 Comments

There are no comments yet

Leave a comment

Your email address will not be published. Required fields are marked *