Post

Intermediaries in 2026: The DPDPA-IT Rules Nexus

Intermediaries in 2026: The DPDPA-IT Rules Nexus

The Indian digital landscape has undergone a significant transformation with the operationalisation of the Digital Personal Data Protection Act, 2023 (DPDPA) and its accompanying Rules. For intermediaries, already navigating the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (IT Rules), this new regime presents a complex, yet crucial, dual compliance challenge. The DPDPA fundamentally redefines their obligations, shifting from a content-centric due diligence framework to a comprehensive data principal-centric accountability model.

The Dual Mandate: Intermediaries as Data Fiduciaries

Under the DPDPA, an intermediary typically qualifies as a ‘Data Fiduciary’ (DF) as defined in Section 2(j), responsible for determining the purpose and means of processing personal data. This designation brings a host of new obligations beyond the general due diligence requirements of the IT Rules. While IT Rule 3(1)(a) mandates intermediaries to publish privacy policies, the DPDPA elevates the standard for consent. Section 6 of the DPDPA requires consent to be free, specific, informed, unambiguous, and clearly affirmative, a much higher bar than merely having a policy. Data fiduciaries must also ensure purpose limitation and data minimisation (Section 8(1), 8(2)), data accuracy (Section 8(3)), and strict retention limits (Section 8(7)), none of which are explicitly detailed in the IT Rules. This means intermediaries must re-evaluate their entire data lifecycle, from collection to deletion, through the lens of individual privacy rights.

Areas of apparent overlap between the DPDPA and IT Rules often reveal deeper DPDPA requirements. Take security: IT Rule 3(1)(g) generally requires intermediaries to exercise due diligence to prevent users from hosting or transmitting unlawful content, implicitly touching upon security. However, DPDPA Section 9(1) explicitly mandates Data Fiduciaries to implement “reasonable security safeguards to prevent personal data breach.” The DPDP Rules further elaborate on these safeguards, often aligning with global best practices like ISO 27001, pushing intermediaries towards a more robust, auditable security posture specifically for personal data.

Similarly, grievance redressal, a cornerstone of IT Rule 3(2) and Rule 4 for Significant Social Media Intermediaries (SSMIs), finds a new dimension under DPDPA. While IT Rules focus on content-related grievances and user complaints, DPDPA Section 13 mandates a mechanism for Data Principals to exercise their rights (Sections 11-15) and lodge grievances related to their personal data. This necessitates an integrated approach where existing grievance officers under IT Rules might need additional training or a dedicated DPO to handle DPDPA-specific requests like access, correction, or erasure of personal data.

The New Accountability Paradigm: SDFs and Data Principal Rights

The DPDPA introduces the concept of a ‘Significant Data Fiduciary’ (SDF) under Section 10, designated based on factors like processing volume, risk to data principals, and potential impact on India’s sovereignty. While SSMIs under IT Rule 4 already face enhanced obligations (Chief Compliance Officer, Nodal Contact Person), an SSMI is almost certainly an SDF, incurring additional duties: appointing a Data Protection Officer (DPO), conducting Data Protection Impact Assessments (DPIAs), and undergoing periodic data audits (Section 10(2)). These obligations are designed to foster proactive accountability, a departure from the reactive content moderation focus of the IT Rules.

Furthermore, the DPDPA empowers data principals with clear rights, including the right to access information (Section 11), correction and erasure (Section 12), and grievance redressal (Section 13). These rights extend beyond general user support and require intermediaries to establish verifiable processes for identity verification and timely response, a level of engagement not explicitly detailed in the IT Rules. While the GDPR in Europe also grants comprehensive data subject rights, the DPDPA carves its own path, balancing these rights with certain duties of data principals (Section 15).

Sectoral Nuances and Enforcement Realities

Sector-specific regulations from bodies like RBI, SEBI, and IRDAI, which already impose stringent data handling and security norms for financial and insurance intermediaries, will now operate concurrently with the DPDPA. For instance, RBI’s data localisation mandates for payment systems will need to be reconciled with DPDPA’s provisions on cross-border data transfers (Section 16), which are now subject to notification by the Central Government. The DPDPA acts as a foundational privacy law, requiring sectoral regulators to align their specific guidelines to ensure a cohesive compliance ecosystem.

Enforcement will be a critical area of interplay. The Data Protection Board of India (DPBI), established under DPDPA Section 27, will adjudicate on DPDPA violations, imposing significant penalties (Sections 33-37). MeitY, on the other hand, oversees IT Rules compliance. While the focus areas differ, a data breach resulting from inadequate security could trigger action from both the DPBI (under DPDPA Section 9) and MeitY (for general due diligence failures under IT Rule 3(1)(g)). This necessitates a harmonised approach from regulatory bodies and a clear internal strategy for intermediaries.

Practical takeaway Indian businesses operating as intermediaries must move beyond piecemeal compliance. A holistic strategy is essential, integrating DPDPA requirements into existing IT Rules frameworks. This involves a comprehensive data mapping exercise to understand personal data flows, a complete overhaul of consent mechanisms to meet DPDPA Section 6 standards, and a review of privacy policies and terms of service. Invest in robust security infrastructure (Section 9), enhance grievance redressal mechanisms to address data principal rights (Sections 11-15), and, for SDFs, operationalise DPOs, DPIAs, and audits (Section 10). Training for legal, IT, and customer service teams is paramount to navigate this complex, yet critical, regulatory landscape.

This post is licensed under CC BY 4.0 by the author.