The Ministry of Electronics and Information Technology (MeitY) has issued the Digital Personal Data Protection (Removal of Difficulties) Order, 2026 (S.O. 5458(E)), dated October 5, 2026, making two textual corrections to the Digital Personal Data Protection Act, 2023 (DPDP Act). The Order came into force on publication on October 6, 2026. MeitY stated that the difficulties being removed are textual, editorial in nature and that the corrections rectify anomalies in Sections 9 and 10 in accordance with the legislative intent.
Section 9 of the DPDP Act requires a data fiduciary to obtain the verifiable consent of a parent or lawful guardian before processing the personal data of a child or of a person with a disability who has a lawful guardian, and the manner of obtaining such consent was addressed in the DPDP Act and the Rules under it. Section 10 sets out the additional obligations of Significant Data Fiduciaries (SDFs). The Digital Personal Data Protection Rules, 2025, were notified in November 2025, with Sections 9 and 10 among the provisions scheduled to come into force 18 months later.
Key Changes
- Section 9(1): The words “child or a person with disability,” are substituted with “child or of a person with disability”. MeitY stated that the omission of the preposition “of” created a disjunction between “any personal data of a child” and “a person with disability”, obscuring the intended parallelism between the two categories. The provision now refers expressly to personal data of a child or of a person with a disability who has a lawful guardian.
- Section 10(2)(c)(ii): The word “audit” is substituted with “data audit”, so the periodic audit an SDF must undertake is now a periodic data audit. Section 10(2)(b) separately requires an SDF to appoint an independent data auditor to carry out a data audit. MeitY stated that the repeated use of “audit” created interpretive ambiguity about the scope of the two audits and that both references are intended to mean a “data protection audit” or “data audit”.


