DPDP Removal of Difficulties Order, 2026: What the Clarifications to Sections 9 and 10 Mean

DPDP Removal of Difficulties Order, 2026: What the Clarifications to Sections 9 and 10 Mean

Article by

Audit Ready by Design:

Introduction 

On 5 October 2026, the Ministry of Electronics and Information Technology (MeitY) issued the Digital Personal Data Protection (Removal of Difficulties) Order, 2026. The order makes two limited but important corrections to the Digital Personal Data Protection Act, 2023 (DPDP Act), concerning Section 9 on children and persons with disabilities and Section 10 on Significant Data Fiduciaries (SDFs). 

The changes are largely textual. Section 9 now refers to personal data “of a child or of a person with disability who has a lawful guardian”, while Section 10 replaces “periodic audit” with “periodic data audit”. Neither amendment creates a new compliance obligation. Instead, the order removes drafting ambiguity and aligns the Act more closely with the Digital Personal Data Protection Rules, 2025. 

Why Was the Order Needed? 

The order has been issued under Section 43 of the DPDP Act, which allows the Central Government to remove difficulties in giving effect to the legislation, provided the resulting order remains consistent with the Act. 

The Government identified two drafting issues. The first concerned whether Section 9 clearly referred to the personal data of both children and persons with disabilities who have lawful guardians. The second concerned the nature of the periodic audit required from SDFs. The order resolves both without changing the broader structure of the DPDP regime. 

Section 9: Clarifying the Consent Requirement 

Section 9 contains additional safeguards for processing the personal data of children and persons with disabilities who have lawful guardians. The original provision required verifiable consent before processing “any personal data of a child or a person with disability who has a lawful guardian”. The addition of the word “of” now makes the intended construction clearer: the provision concerns personal data of a child and personal data of a person with disability who has a lawful guardian. The change is especially important because Section 9 does not require guardian consent for every person with a disability. It applies specifically where the individual has a lawful guardian. 

The DPDP Rules, 2025 reinforce this distinction. Rule 10 deals with verifiable parental consent in relation to children, while Rule 11 concerns verification of lawful guardianship for persons with disabilities. In the latter case, the Data Fiduciary must verify that the guardian has been appointed under the applicable legal framework. The amendment therefore improves clarity without expanding the category of individuals subject to guardian-based consent. 

Section 10: Clarifying the Audit Obligation 

The second amendment concerns Significant Data Fiduciaries. Under Section 10, SDFs are subject to enhanced compliance requirements, including the appointment of a Data Protection Officer in India, appointment of an independent data auditor, Data Protection Impact Assessments and periodic audits. 

The original wording of Section 10(2)(c)(ii) referred simply to a “periodic audit”. This created some uncertainty because Section 10(2)(b) separately referred to an independent data auditor conducting a “data audit." 

The order replaces “periodic audit” with “periodic data audit”, making clear that the requirement concerns compliance with data protection obligations rather than a general corporate, financial or operational audit. The amendment also brings the Act into closer alignment with Rule 13 of the DPDP Rules, 2025, which requires SDFs to conduct periodic assessments and audits relating to compliance with the Act and Rules. 

What Does This Mean for Significant Data Fiduciaries? 

For SDFs, the clarification narrows the focus of the periodic audit. The audit should assess whether personal data processing complies with the DPDP framework, including governance arrangements, technical and organisational safeguards, risks to Data Principals and compliance with statutory obligations. Rule 13 further requires SDFs to conduct a Data Protection Impact Assessment and an audit once in every twelve-month period after being designated as an SDF or included within a notified class. The order itself does not create a new audit cycle or additional compliance process. It simply confirms that the periodic audit contemplated by Section 10 is specifically a data audit. 

Does the Order Expand DPDP Compliance Obligations? 

No substantive expansion appears to be intended. The Section 9 amendment clarifies the grammatical construction of the consent requirement, while the Section 10 amendment clarifies the subject matter of the audit obligation. 

These changes are nevertheless useful because Sections 9 and 10 form part of the DPDP provisions being implemented in phases. Correcting their wording before they become fully operational reduces interpretive uncertainty for Data Fiduciaries preparing their compliance frameworks. 

What Should Organisations Do Now? 

Organisations should treat the Order primarily as a clarification exercise rather than a reason to redesign their entire DPDP compliance programme. 

  • Review consent mechanisms: Ensure that workflows involving children correctly incorporate verifiable parental consent. 


  • Distinguish disability from guardianship: Do not assume that every person with a disability requires consent through another individual. Section 9 specifically refers to persons with disabilities who have lawful guardians. 


  • Update internal documentation: Policies, compliance manuals and consent procedures should reflect the amended wording of Section 9. 


  • Review SDF audit frameworks: Organisations that may fall within the SDF category should ensure that their audit programmes are designed specifically around data protection compliance. 


  • Prepare for periodic assessments: Potential SDFs should establish processes for Data Protection Impact Assessments, data audits and reporting in accordance with Rule 13. 

Conclusion 

The Digital Personal Data Protection (Removal of Difficulties) Order, 2026 makes only two textual changes, but both improve the precision of the DPDP framework. Section 9 now clearly addresses personal data of a child or of a person with disability who has a lawful guardian, while Section 10 now expressly requires SDFs to undertake a periodic data audit. The order does not materially expand the obligations of Data Fiduciaries. Instead, it resolves drafting ambiguities before key parts of the DPDP regime become operational. For organisations, the immediate priority is therefore not wholesale compliance reform, but ensuring that consent processes and SDF audit frameworks reflect the clarified language of the Act. 


Want to Stay Ahead?  


Reach out to the experts at GoTrust today.  


 

Found this useful? Share it.

WhatsAppFacebookXLinkedIn
WhatsAppFacebookXLinkedIn

Automate AI & Privacy Compliance Assessments

Managing AI and privacy compliance can be complex as regulations continue to evolve. GoTrust helps simplify this process by connecting AI systems with ISO/IEC 42001 and NIST AI RMF requirements. It also supports privacy automation and cookie consent management, helping businesses identify compliance gaps, manage assessments, and stay prepared for audits.

Automate AI & Privacy Compliance Assessments

Managing AI and privacy compliance can be complex as regulations continue to evolve. GoTrust helps simplify this process by connecting AI systems with ISO/IEC 42001 and NIST AI RMF requirements. It also supports privacy automation and cookie consent management, helping businesses identify compliance gaps, manage assessments, and stay prepared for audits.

Automate AI & Privacy Compliance Assessments

Managing AI and privacy compliance can be complex as regulations continue to evolve. GoTrust helps simplify this process by connecting AI systems with ISO/IEC 42001 and NIST AI RMF requirements. It also supports privacy automation and cookie consent management, helping businesses identify compliance gaps, manage assessments, and stay prepared for audits.