Post

Navigating India's Dual Mandate: DPDPA and IT Rules for Intermediaries

Navigating India's Dual Mandate: DPDPA and IT Rules for Intermediaries

The landscape for digital intermediaries in India has fundamentally shifted. With the Digital Personal Data Protection Act, 2023 (DPDPA) now fully implemented, alongside the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (IT Rules), these platforms operate under a dual regulatory framework. While the IT Rules primarily govern content moderation, platform governance, and user safety, the DPDPA meticulously regulates the processing of personal data. Understanding the intricate interplay between these two powerful statutes is paramount for any intermediary operating in India today.

The Overlapping Spheres of Responsibility

At their core, both the DPDPA and the IT Rules aim to enhance user protection, albeit through different lenses. The IT Rules impose due diligence obligations on intermediaries to prevent the hosting or sharing of unlawful content (Rule 3) and establish robust grievance redressal mechanisms for content-related complaints (Rule 3(2)). For Significant Social Media Intermediaries (SSMIs), additional obligations include appointing a Chief Compliance Officer, a Nodal Contact Person, and a Resident Grievance Officer (Rule 4(1)).

The DPDPA, on the other hand, focuses squarely on safeguarding personal data. It mandates that Data Fiduciaries (which most intermediaries are, given their handling of user data) process personal data lawfully, fairly, and transparently (Section 6). Key responsibilities include obtaining valid consent (Section 6), adhering to purpose limitation (Section 6(1)(a)), ensuring data accuracy (Section 8(4)), implementing reasonable security safeguards (Section 8(5)), and establishing an effective grievance redressal mechanism for data principals (Section 15). For Significant Data Fiduciaries (SDFs), the DPDPA further requires the appointment of a Data Protection Officer (DPO) and undertaking data protection impact assessments and audits (Section 10).

The overlap is evident: an intermediary’s handling of user content often involves processing personal data. For instance, a user’s complaint under the IT Rules might reveal personal data, necessitating DPDPA compliance in its processing.

Synergies in Grievance Redressal and Officer Roles

The DPDPA’s requirement for a Data Protection Officer (DPO) for SDFs (Section 10(2)) and a general grievance redressal mechanism (Section 15) presents a unique opportunity for synergy with the IT Rules’ mandated officers. The IT Rules require a Grievance Officer (Rule 3(2)(a)) and, for SSMIs, a Chief Compliance Officer (Rule 4(1)(a)) and a Nodal Contact Person (Rule 4(1)(b)).

While the IT Rules’ Grievance Officer primarily addresses content-related complaints, the DPDPA’s grievance mechanism is broader, covering any concerns related to personal data processing and data principal rights. For intermediaries designated as both SSMIs and SDFs, integrating these roles or ensuring seamless coordination is crucial. A DPO, responsible for overseeing DPDPA compliance, will inevitably interact with the IT Rules’ officers, especially when a grievance involves both content and personal data aspects. This integrated approach can streamline user experience and ensure comprehensive resolution of complaints, preventing jurisdictional ambiguities for the user.

Heightened Data Security and Breach Notification

Both statutes implicitly and explicitly demand robust data security. The IT Rules’ due diligence requirements (Rule 3(1)(g)) necessitate reasonable efforts to ensure the security of user information. However, the DPDPA elevates this significantly. It explicitly obligates Data Fiduciaries to implement reasonable security safeguards to prevent personal data breaches (Section 8(5)). Crucially, in the event of a personal data breach, the DPDPA mandates notification to the Data Protection Board of India (DPB) and affected Data Principals (Section 17).

This creates a clear, reinforced standard for intermediaries. They must not only secure the data they process for platform operations but also have sophisticated breach detection, containment, and notification protocols in place. The DPB, established under Section 19 of the DPDPA, will oversee compliance and impose penalties for non-compliance, including failures in security and breach notification. This stands in contrast to the IT Rules, where penalties are often linked to non-compliance with government directives or content moderation failures.

The DPDPA places significant emphasis on transparency and consent. Data Fiduciaries must provide Data Principals with clear notice about the personal data being collected and the purpose of processing (Section 5). Consent must be freely given, specific, informed, and unambiguous (Section 6). This directly impacts how intermediaries design their user onboarding flows, privacy policies, and terms of service.

While the IT Rules require intermediaries to publish privacy policies and user agreements (Rule 3(1)(i)), the DPDPA mandates a much higher standard for data processing consent. Intermediaries must now ensure their privacy policies are not merely compliant with IT Rules’ disclosure requirements but also serve as the DPDPA-mandated notice, clearly outlining data processing activities and securing valid consent for each specific purpose. This holistic view of user information, from content interaction to personal data handling, necessitates a unified approach to transparency.

Practical takeaway

Indian businesses, particularly digital intermediaries, must adopt a holistic and integrated compliance strategy. It is no longer sufficient to treat IT Rules and DPDPA compliance as separate silos. Legal, compliance, IT security, and product teams must collaborate closely to ensure that platform features, data collection practices, privacy policies, and grievance redressal mechanisms are harmonized. Review your existing IT Rules compliance frameworks and embed DPDPA requirements, especially regarding consent mechanisms, data security safeguards, breach notification protocols, and the roles and responsibilities of statutory officers. Proactive integration will not only mitigate regulatory risks but also foster greater user trust in the evolving Indian digital ecosystem.

This post is licensed under CC BY 4.0 by the author.