Decoding the Digital Personal Data Protection (Removal of Difficulties) Order, 2026: Clarifications on Sections 9 and 10

Decoding the Digital Personal Data Protection (Removal of Difficulties) Order, 2026: Clarifications on Sections 9 and 10

Decoding the Digital Personal Data Protection (Removal of Difficulties) Order, 2026: Clarifications on Sections 9 and 10

Decoding the Digital Personal Data Protection (Removal of Difficulties) Order, 2026: Clarifications on Sections 9 and 10

Decoding the Digital Personal Data Protection (Removal of Difficulties) Order, 2026: Clarifications on Sections 9 and 10 

The Ministry of Electronics and Information Technology (MeitY) has notified statutory amendments under Gazette Notification S.O. 5458(E) titled the Digital Personal Data Protection (Removal of Difficulties) Order, 2026.  

Issued under the executive powers conferred by Section 43(1) of the DPDP Act, 2023 (which empowers the Central Government to remove textual and operational difficulties within the first three years of enforcement), this order makes surgical editorial and textual rectifications to Section 9(1) (Processing of personal data of children and persons with disabilities) and Section 10(2)(c)(ii) (Obligations of Significant Data Fiduciaries).  

While seemingly minor grammatical and phrasing adjustments, these corrections eliminate legal ambiguities that have caused significant debate across enterprise risk, privacy, and compliance teams.  

1. The Clarification in Section 9(1): Precision in Guarded Data 

The Statutory Change 

  • Previous Phrasing: The Data Fiduciary shall, before processing “any personal data of a child or a person with disability who has a lawful guardian…” 

  • Amended Phrasing: The phrase is amended to substitute “child or a person with disability” with “child or of a person with disability” (and in Hindi, “बालक या ऐसे दिव्यांग व्यक्ति”).  

The Legal Problem 

In the original text, the missing preposition “of” created syntactic ambiguity. A strict grammatical reading created a structural disjunction:  

  1. Did the fiduciary process “any personal data of (a child)” OR was it processing “(a person with disability)” directly? 

  2. More critically, did the qualifying clause “who has a lawful guardian” attach solely to the person with disability, or did it introduce grammatical confusion about the scope of parental versus guardian consent?  

Legal Interpretation & Intent 

By inserting “of”, Parliament’s true intent is grammatically cemented through strict parallelism:  

The processing applies equally to the personal data of both categories, ensuring that verifiable consent must be obtained from the parent (in the case of a child) or the lawful guardian (in the case of a person with disability) before any processing begins.  

2. The Clarification in Section 10(2)(c)(ii): Defining the Scope of SDF Audits 

The Statutory Change 

  • Previous Phrasing: Section 10(2)(b) mandates the appointment of an independent data auditor to carry out a “data audit,” while Section 10(2)(c)(ii) mandated undertaking “periodic audit”.  

  • Amended Phrasing: In Section 10(2)(c)(ii), the generic word “audit” is officially substituted with “data audit”. 

The Legal Problem 

Section 10 outlines enhanced obligations for Significant Data Fiduciaries (SDFs). The unanchored, generic use of the word “audit” under sub-clause (c)(ii) created substantial regulatory exposure:  

  • Enterprises and audit firms raised concerns that regulatory or supervisory authorities could interpret "periodic audit" broadly to encompass general IT security audits, financial systems audits, or broader corporate governance reviews.  

  • It was unclear whether the “periodic audit” under (c)(ii) was a distinct, open-ended compliance exercise compared to the “data audit” mandated under clause (b). 

Legal Interpretation & Intent 

MeitY's order clarifies that both references are tied strictly to "data protection audit" or "data audit".  

The amendment binds the scope of Section 10(2)(c)(ii) directly to the operational boundaries of data privacy and personal data governance. The audit mandate is not an open check on broader enterprise IT infrastructure, but a structured evaluation of compliance with the DPDP Act—including data inventorying, consent lifecycle management, security safeguards, and Data Principal rights workflows.  

What Does This Clarification Mean for Industry? 

1. Guardrail Against Regulatory Overreach in SDF Audits 

For banking, fintech, healthcare, and enterprise e-commerce entities likely to be designated as Significant Data Fiduciaries, the amendment provides essential scope limitation:  

  • Defined Audit Charters: Enterprise internal audit and compliance teams do not need to conflate Section 10 audits with general SOC 2, ISO 27001, or financial/statutory IT audits. 

  • Standardized DPBI Scrutiny: The Data Protection Board of India (DPBI) and supervisory authorities cannot expand the statutory periodic audit beyond data governance and personal data compliance.  

2. Streamlining Verifiable Parental/Guardian Consent Systems 

For platforms designing Consent Management Platforms (CMPs) and age-gating mechanisms: 

  • The clear grammatical linkage between parental/guardian mandates and data processing ensures product and legal teams can build clear IT/ICT flows. 

  • Verifiable consent mechanisms under Section 9 can now standardise on dual tracks: verifying parental consent for minors under 18 years of age, and verifying legal guardianship credentials for individuals with disabilities where a guardian has been appointed under law.  

3. Readiness for Full Enforcement 

By invoking the Section 43 "Removal of Difficulties" clause to resolve grammatical anomalies and audit ambiguities, MeitY is systematically finalizing the DPDP statutory framework. Enterprise fiduciaries should treat this as a signal to finalize their internal audit charters, engage accredited independent data auditors, and streamline consent architectures ahead of enforcement deadlines.