← Back to list

Digital Personal Data Protection Act, 2023 and Rules 2025 and the Modern SOC: From Detection to…

Understanding Personal Data Processing Under DPDPA and Why Security Operations Centers (SOC) & Platforms Must Care

Tsaaro Consulting · 2025-12-11 09:24 · 0 claps · 3.7 min read
#dpdp #dpdpa #dpdp-rules
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity

Digital Personal Data Protection Act, 2023 and Rules 2025 and the Modern SOC: From Detection to Documentation

  1. Understanding Personal Data Processing Under DPDPA and Why Security Operations Centers (SOC) & Platforms Must Care

Under the DPDP Act 2023, ‘personal data’ refers to any information about an identifiable individual, whether directly or indirectly referring to them. This broad definition covers details such as name, age, address, occupation, or email, and any other information that can identify a person. Under the IT/SPDI Rules 2011, certain categories of information are classified as ‘sensitive personal data’ and these demand extra protection. SPDI specifically includes passwords, financial information like bank or card details, biometric data, medical history and health conditions, sexual orientation, and any information relating to these categories that is provided for a service.

SOCs are centralized technical and organizational units within a data fiduciary or data processor that are responsible for continuous monitoring, detection, logging, analysis, and response to security incidents affecting personal data. SOCs, digital platforms and sectoral industries are now directly accountable under the DPDPA and the 2025 Rules because their routine telemetry, logs and operational datasets inherently contain personal data, including identifiers and sensitive information. Platforms also collect large volumes of demographic, behavioural and transactional information, bringing all such processing squarely within the Act’s consent and purpose-limitation framework (rules 3, 6 and Part B of the First Schedule obligations for Consent Managers). Any use of such data must now be preceded by verifiable consent, demonstrable necessity and retention-limitation requirements being fulfilled, and the Consent Managers providing traceability, withdrawal and enforceable user rights. This moves organisations away from thinking only about security and pushes them toward a model where security steps, logs, and monitoring also have to meet privacy rules, valid legal grounds for processing, and clear accountability requirements.

  1. Legal & Regulatory

a. DPDP Rules / DPDP Act Mandatory lawful basis:

Under the DPDP Act and Rules, consent is the default lawful basis for processing personal data. Consent must be “free, specific, informed, unconditional and unambiguous,” given by a clear affirmative action. The consent notice must be standalone, transparent, articulate exactly what categories of data are collected and for what specified purposes, and must inform the data principal how to withdraw consent easily. Pre-ticked boxes or bundled consents are not valid.

Duties of Data Fiduciaries:

The Act further imposes some duties on Data Fiduciaries, including purpose limitation (processing only for the purpose stated in the notice), data minimisation (collecting only data necessary for that purpose), accuracy (ensuring data is correct and updated), and storage limitation (retaining data only for as long as necessary to fulfil the purpose or comply with law), as reflected in Sections 4, 5, and 8 of the statute. Once the purpose is fulfilled or consent withdrawn, data must be erased or anonymised. However, retention is still lawful where required by another statute, regulatory mandate, court order, government direction, or law-enforcement request. Data may also be retained for establishing or defending legal claims, fulfilling tax and audit obligations, maintaining security and fraud-prevention logs, completing grievance redressal processes, or meeting sector-specific minimum retention periods (such as telecom, financial, or significant-data-fiduciary requirements). In all such cases, data can be kept only for the legally necessary duration.

Role & accountability of Consent Managers:

A Consent Manager operates a neutral platform that allows individuals to give, manage, review and withdraw consent for processing of their personal data, including routing consents through other data fiduciaries when needed, while ensuring it cannot read the underlying data. It must maintain detailed records of all consents, notices and data-sharing actions for at least seven years (this applies to every Consent Manager uniformly, regardless of whether they serve private-sector data fiduciaries, government entities or both), provide individuals access to these records in machine-readable form, run its services through a website or app, and cannot subcontract any of its statutory functions. The Consent Manager must take security safeguards, act in a fiduciary capacity toward users, avoid conflicts of interest with data fiduciaries (including ensuring that promoters, directors and key managerial personnel have no conflicting interests), and publicly disclose information about its ownership and management.

b. IT Act, 2000

Section 43A of the Information Technology Act, 2000 imposes liability on a body corporate that, while possessing, dealing with, or handling sensitive personal data or information in a computer resource, fails to implement and maintain reasonable security practices and procedures. If such negligence results in wrongful loss or wrongful gain, the affected person is entitled to claim compensation from the body corporate. The provision is civil in nature and is directly tied to the obligation to protect Sensitive Personal Data or Information as defined under the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

Section 72A makes it a criminal offence for any person, including an intermediary or service provider, to disclose personal information to a third party without the consent of the person concerned, in breach of a lawful contract, and with the intent to cause, or with knowledge that such disclosure is likely to cause, wrongful loss or wrongful gain. The section prescribes penal consequences in the form of imprisonment of up to three years, or a fine up to five lakh rupees, or both. This provision focuses on the unauthorised, intentional misuse of personal information and operates independently of civil compensation under Section 43A.

Read the original article here: Digital Personal Data Protection Act, 2023 and Rules 2025 and the Modern SOC: From Detection to Documentation


메타데이터
post_id
b52ff7bb06c8
slug
digital-personal-data-protection-act-2023-and-rules-2025-and-the-modern-soc-from-detection-to-b52ff7bb06c8
url
https://medium.com/@tsaaro-consulting/digital-personal-data-protection-act-2023-and-rules-2025-and-the-modern-soc-from-detection-to-b52ff7bb06c8
canonical_url
https://medium.com/@tsaaro-consulting/digital-personal-data-protection-act-2023-and-rules-2025-and-the-modern-soc-from-detection-to-b52ff7bb06c8
author_url
https://medium.com/@tsaaro-consulting
status
ok
fetched_at
2026-07-23 16:39:33