The Union Ministry of Electronics and Information Technology (MeitY) has issued the Digital Personal Data Protection (Removal of Difficulties) Order 2026, making two targeted textual amendments to the Digital Personal Data Protection Act 2023 (DPDP Act).
Published in a gazette notification on 7 October 2026, the Order clarifies provisions concerning the processing of personal data of children and persons with disabilities and the audit obligations applicable to Significant Data Fiduciaries (SDFs). The order was issued on 5 October 2026 under Section 43(1) of the DPDP Act, which permits the central government to address difficulties in implementing the Act.
The changes have been described as textual and editorial corrections intended to address ambiguities and give effect to the legislative intent of the DPDP Act.
DPDP Compliance Readiness
Prepare your firm for upcoming DPDP obligations by reviewing consent processes, data governance frameworks and data audit procedures.What does the DPDP (Removal of Difficulties) Order 2026 change?
The Order makes two amendments:
- It clarifies the wording of Section 9(1) concerning verifiable consent for processing personal data of children and persons with disabilities who have lawful guardians.
- It replaces the term “audit” with “data audit” in Section 10(2)(c)(ii), clarifying the periodic audit obligation of Significant Data Fiduciaries.
The Order came into force on the date of its publication in the Official Gazette.
Clarification on consent for children’s and persons with disabilities’ data
What does Section 9(1) provide?
Section 9(1) requires a Data Fiduciary, before processing personal data of a child or a person with a disability who has a lawful guardian, to obtain verifiable consent from the parent of the child or the lawful guardian, as applicable.
The government identified a drafting issue in the wording of this provision. The original wording referred to:
“personal data of a child or a person with disability”
According to the Order, the omission of the preposition “of” before “a person with disability” created a grammatical disjunction between the two categories and could obscure the intended legislative meaning.
What has changed?
The Order replaces the relevant wording with:
“personal data of a child or of a person with disability”
This amendment clarifies that the provision addresses the two categories in parallel.
The amendment is therefore primarily a textual clarification. It does not establish a new category of consent or otherwise alter the underlying requirement for verifiable parental or lawful-guardian consent.
CLICK HERE: Can Companies Use Publicly Available Personal Data Under India’s DPDP Act?
Clarification of data audit requirements for Significant Data Fiduciaries
The second amendment concerns Significant Data Fiduciaries, which are subject to additional compliance requirements under Section 10 of the DPDP Act.
What was the issue with the existing wording?
Section 10(2) includes requirements relating to audits by Significant Data Fiduciaries. The Act requires an SDF to appoint an independent data auditor to carry out a data audit, while another provision requires the SDF to carry out periodic audits.
The government considered the repeated use of the generic term “audit” potentially ambiguous because it could create uncertainty about the scope of the different audit requirements. This could, in turn, lead to inconsistent interpretations by regulatory or supervisory authorities.
What has changed?
The Order replaces the word “audit” with “data audit” in Section 10(2)(c)(ii).
The amendment clarifies that the periodic audit requirement is specifically related to data protection and data processing compliance, rather than an unspecified or general audit.
These explanation states that the relevant references to audit are intended to refer to a “data protection audit” or “data audit.”
What does the DPDP Order mean for businesses?
The Order is relatively narrow and should not be treated as a new standalone compliance framework. The government expressly characterises the changes as textual and editorial amendments designed to rectify anomalies and clarify legislative intent.
Data Fiduciaries
Businesses that process personal data of children or persons with disabilities who have lawful guardians should ensure that their consent mechanisms and privacy documentation use the clarified statutory terminology.
Their compliance processes should continue to account for the requirement to obtain verifiable consent from the relevant parent or lawful guardian where applicable.
Significant Data Fiduciaries
SDFs should incorporate the clarified term “data audit” into their compliance documentation and audit processes.
This may require updates to:
- DPDP compliance policies
- Data governance frameworks
- Internal audit procedures
- Data auditor engagement documentation
- Audit checklists
- Records supporting periodic data audits
Data Audit Readiness
Significant Data Fiduciaries should ensure their data audit frameworks, internal procedures, and supporting documentation reflect the latest DPDP requirements.Compliance documentation
Businesses do not need to create a separate compliance regime solely because of the Order. Instead, they should update existing DPDP documentation. This would reflect the amended language and ensure that internal compliance processes remain aligned with the Act.
|
Key changes under the DPDP (Removal of Difficulties) Order 2026 |
||
|
Provision |
Change |
Business implication |
|
Section 9(1) |
Adds “of” before “a person with disability” |
Clarifies the parallel application of the consent provision to children and persons with disabilities |
|
Section 10(2)(c)(ii) |
Replaces “audit” with “data audit” |
Clarifies the nature of the periodic audit obligation for SDFs |
|
Section 43(1) |
Provides the legal basis for the Order |
Enables the government to address implementation difficulties |
|
Effective date |
Effective from publication in the Official Gazette |
Amendments apply from 5 October 2026 |
It should be noted that, under the phased implementation of the DPDP Act and the DPDP Rules, Sections 9 and 10 are scheduled to come into effect on 13 March 2027. This will mark the final phase of the DPDP regulatory implementation, bringing the remaining substantive obligations under these provisions into force.
KNOW MORE: India’s DPDP Compliance Deadline Is Approaching: What Businesses Need to Do Before May 2027
What businesses should do next
Companies should treat the Order primarily as a compliance clarification and incorporate the amendments into their existing DPDP implementation processes.
Data Fiduciaries should verify that consent procedures and privacy documentation accurately reflect the clarified language concerning children and persons with disabilities. Significant Data Fiduciaries should, in addition, review their audit frameworks and use the clarified “data audit” terminology across relevant policies, procedures, and documentation.
Overall, the Digital Personal Data Protection (Removal of Difficulties) Order 2026 does not substantially expand the DPDP Act’s obligations. Instead, it removes specific drafting ambiguities to provide greater clarity on consent requirements and the scope of data audits.