Navigating the Dual Mandate: Intermediaries, DPDPA, and IT Rules in 2026
As of August 2026, India’s digital landscape operates under a matured regulatory framework, with the Digital Personal Data Protection Act, 2023 (DPDPA) fully operational and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (IT Rules 2021) continuing to shape the obligations of online platforms. For intermediaries, this means navigating a complex web of compliance, where the DPDPA sets the overarching standard for personal data handling, while the IT Rules impose specific duties related to content governance and platform operations. Understanding their interplay is crucial for any entity operating in India’s digital economy.
The Intermediary as a Data Fiduciary
Most intermediaries, by virtue of collecting user data for their services (e.g., user accounts, analytics, advertising), inherently act as ‘data fiduciaries’ under the DPDPA. This places them squarely under the Act’s primary obligations, including ensuring lawful processing of personal data. A core tenet is obtaining valid consent from data principals for processing their data (DPDPA Section 6(1)). This consent must be free, specific, informed, unconditional, and unambiguous, a higher bar than the general acceptance of terms and conditions often seen prior to the DPDPA. Furthermore, intermediaries must process data only for the specified purpose for which consent was obtained (DPDPA Section 6(1)(a)) and adhere to data minimization principles (DPDPA Section 8(1)).
While the IT Rules 2021 mandate intermediaries to inform users about their privacy policy and user agreement (IT Rules 2021 Rule 3(1)(a)), the DPDPA now dictates the fundamental requirements for what constitutes a valid privacy policy and how data processing must be communicated. For intermediaries, simply having a policy is insufficient; it must reflect DPDPA’s principles of transparency, purpose limitation, and data principal rights, including the right to access, correction, and erasure (DPDPA Sections 11, 12).
Overlapping Obligations: Consent, Grievance, and Retention
The DPDPA and IT Rules 2021 present both complementary and potentially conflicting requirements in several key areas.
- Grievance Redressal: Both laws mandate robust grievance mechanisms. The IT Rules 2021 (Rule 3(2)) require intermediaries to appoint a Grievance Officer to address user complaints, particularly concerning content. The DPDPA, on the other hand, empowers data principals to complain to the data fiduciary (DPDPA Section 13) and ultimately to the Data Protection Board of India (DPDPA Section 17) regarding data protection matters. For Significant Data Fiduciaries (SDFs), the DPDPA further mandates the appointment of a Data Protection Officer (DPDPA Section 10(2)(c)). Intermediaries must ensure their grievance redressal systems are integrated to handle both content-related and data protection-related complaints efficiently, providing clear channels for users.
- Data Retention: A notable point of tension arises in data retention policies. The IT Rules 2021 (Rule 3(1)(i)) require intermediaries to retain information related to user accounts and content for 180 days for investigative purposes. Conversely, the DPDPA (Section 8(7)) mandates data fiduciaries to erase personal data upon withdrawal of consent or when the purpose for which it was collected is no longer served, unless retention is “necessary for compliance with any law.” This “required by law” exception is critical. Intermediaries must carefully document the legal basis for any retention beyond the initial processing purpose, ensuring that IT Rules’ retention requirements are explicitly justified under DPDPA’s framework.
Enhanced Scrutiny for Significant Entities
Both laws identify categories of ‘significant’ entities that face heightened obligations. The IT Rules 2021 designate ‘Significant Social Media Intermediaries’ (SSMIs) based on user numbers (Rule 2(1)(v)), imposing additional duties like appointing a Chief Compliance Officer, Nodal Contact Person, and providing traceability of messages (Rule 4). The DPDPA designates ‘Significant Data Fiduciaries’ (SDFs) based on factors like processing volume, risk to data principals, and potential impact on public order (DPDPA Section 10(1)).
It is highly probable that any SSMI will also qualify as an SDF. This dual designation brings cumulative responsibilities. An SSMI acting as an SDF must not only comply with IT Rules’ content moderation and traceability mandates but also with DPDPA’s more stringent data protection requirements, including undertaking Data Protection Impact Assessments, conducting independent audits, and implementing robust data breach notification protocols (DPDPA Section 10(2)). This necessitates a consolidated approach to compliance, integrating security, privacy, and content governance functions.
The Content-Data Protection Divide: Traceability
The contentious ‘traceability’ requirement under IT Rules 2021 (Rule 4(2)), which mandates SSMIs to enable the identification of the first originator of messages, continues to pose challenges. From a DPDPA perspective, such a requirement raises concerns regarding data minimization (DPDPA Section 8(1)), purpose limitation (DPDPA Section 6(1)(a)), and the fundamental right to privacy. While the IT Rules aim to address public order and national security concerns, the DPDPA focuses on protecting individual personal data. Any implementation of traceability must be carefully balanced against DPDPA’s principles, ensuring that personal data is only processed to the extent strictly necessary and with adequate safeguards, and only if deemed “necessary for compliance with any law” under DPDPA Section 8(7). This remains an area where judicial interpretation or further regulatory guidance may be sought to reconcile the two frameworks.
Practical takeaway: Indian businesses, GCs, and DPOs operating as intermediaries must adopt a holistic compliance strategy that views the DPDPA as the foundational law for personal data, while integrating the specific requirements of the IT Rules 2021 for platform governance. This means consolidating grievance mechanisms, meticulously documenting legal bases for data retention, and ensuring that all data processing activities, including those driven by content moderation or traceability, are justifiable under DPDPA’s principles of consent, purpose limitation, and data minimization. For significant entities, a DPO and Chief Compliance Officer must collaborate closely to navigate the enhanced obligations and potential conflicts arising from both statutes, seeking clarity from regulators where ambiguity persists.