NEW DELHI, October 6 — The Ministry of Electronics and Information Technology (MeitY) on Tuesday issued exhaustive operational guidelines and security technical specifications governing Consent Managers and Significant Data Fiduciaries (SDFs) under the Digital Personal Data Protection (DPDP) Act, 2023.
The notified framework operationalizes an interoperable, transparent, and multi-lingual electronic consent architecture designed to empower citizens—designated as 'Data Principals' under the statute—to grant, manage, review, and withdraw consent for data processing through secure digital interfaces. To safeguard citizen privacy, entities seeking registration as Consent Managers must maintain technical interoperability standards certified by the Data Protection Board of India (DPBI) and are strictly barred from pooling or commercially monetizing user interaction telemetry.
The regulatory mandate imposes specialized obligations upon Significant Data Fiduciaries handling massive volumes of sensitive information, requiring periodic independent data audits, Algorithmic and Data Protection Impact Assessments (DPIA), and the appointment of an India-resident Data Protection Officer (DPO). The statutory framework reiterates that systemic non-compliance or negligent data breaches will attract punitive fiscal penalties scaling up to ₹250 crore per violation, adjudicated by the DPBI.
The right to privacy under Article 21 (K.S. Puttaswamy judgment, 2017), the institutional framework of the Data Protection Board of India, and cross-border data transfer regulations constitute core themes across UPSC Civil Services (GS-II: Governance and Fundamental Rights; GS-III: Cybersecurity). Aspirants should note that the DPDP Act, passed by Parliament in August 2023, superseded earlier draft versions following recommendations of the Justice B.N. Srikrishna Committee (2018) and the Joint Parliamentary Committee on Personal Data Protection.