Next due
11 OCTGSTR-1 · Outward supplies · Sep 2026in 2 days 15 OCTPF & ESI · Contributions · Sep 2026in 6 days 20 OCTGSTR-3B · Summary return · Sep 2026in 11 days 21 OCTTax Audit Report · Form 3CA/3CB · AY 2026-27 · extended from 30 Sepin 12 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 21 days 7 NOVTDS / TCS deposit · Deducted in Oct 2026in 29 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 43 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 51 days
All due dates
Home › Blog › Data Protection
TaxClue / DATA PROTECTION

Data Protection — Guides, Updates & Practical Insights

The DPDP Act, consent, data fiduciary duties and breach reporting.

104Articles
33In-depth Guides
↻Updated Regularly
Start Here

The complete Data Protection guide

§
DATA PROTECTION · COMPLETE GUIDE

Rule 23 and the Seventh Schedule of the Digital Personal Data Protection Rules, 2025: calling for information from a Data Fiduciary or intermediary

Rule 23 is in the group that, under rule 1(4), comes into force eighteen months after the date of publication of the Gazette. The Central Government may, for the purposes in the Seventh Schedule, acting through the corresponding authorised person, require a Data Fiduciary or intermediary to furnish...

Updated 09 Oct 20268 min read✓ Reviewed
Read Complete Guide →
Fresh

Latest Data Protection insights

§
Data Protection

Rules 1-2 of the Digital Personal Data Protection Rules, 2025: short title, staged commencement and definitions

The Rules are called the Digital Personal Data Protection Rules, 2025. Rules 1, 2 and 17 to 21 came with publication in the Official Gazette; rule 4 follows one year after the date of publication of the Gazette; rules 3, 5 to 16, 22 and 23 follow eighteen months after it. Rule 2 defines "Act"...

7 min read09 Oct 2026
§
Data Protection

Rule 3 of the Digital Personal Data Protection Rules, 2025: the notice a Data Fiduciary must give a Data Principal

Rule 3 is in the group that, under rule 1(4), comes into force eighteen months after the date of publication of the Gazette. The notice must be understandable independently of any other information, give a fair account of the details needed for specific and informed consent, include at the minimum...

7 min read07 Oct 2026
§
Data Protection

Rule 4 of the Digital Personal Data Protection Rules, 2025: registration of a Consent Manager and powers of the Board

Rule 4 is the only rule in the group that, under rule 1(3), comes into force one year after the date of publication of the Gazette. A person meeting the conditions in Part A of the First Schedule may apply to the Board for registration; the Board may inquire, then register or reject with reasons. A...

6 min read09 Oct 2026
§
Data Protection

First Schedule to the Digital Personal Data Protection Rules, 2025: Part A, conditions for registration of a Consent Manager

The First Schedule follows rule 4, which under rule 1(3) comes into force one year after the date of publication of the Gazette. An applicant must be a company incorporated in India, have sufficient technical, operational and financial capacity, and have net worth of not less than two crore rupees...

7 min read07 Oct 2026
§
Data Protection

First Schedule to the Digital Personal Data Protection Rules, 2025: Part B, Consent Manager platform, records and security obligations

These obligations apply through rule 4(3), which comes into force one year after the date of publication of the Gazette (rule 1(3)). The platform must let consent flow directly or through another Data Fiduciary; the Consent Manager must make sure it cannot read the contents, keep a record for at...

7 min read08 Oct 2026
§
Data Protection

First Schedule to the Digital Personal Data Protection Rules, 2025: Part B, Consent Manager fiduciary duty, conflict of interest and audit

These items apply through rule 4(3), in the group that comes into force one year after the date of publication of the Gazette (rule 1(3)). The Consent Manager must act in a fiduciary capacity towards the Data Principal, avoid conflict of interest with Data Fiduciaries and their promoters and key...

7 min read09 Oct 2026
§
Data Protection

Rule 5 of the Digital Personal Data Protection Rules, 2025: processing by the State for a subsidy, benefit, service, certificate, licence or permit

Rule 5 is in the group that, under rule 1(4), comes into force eighteen months after the date of publication of the Gazette. It has two sub-rules. Sub-rule (1): processing "under this rule" is done following the standards specified in the Second Schedule. Sub-rule (2): it defines under law, under...

6 min read07 Oct 2026
§
Data Protection

Rule 16 of the Digital Personal Data Protection Rules, 2025: the research, archiving and statistics exemption and the Second Schedule standards

Rule 16 is in the group that, under rule 1(4), comes into force eighteen months after the date of publication of the Gazette. The exemption has one condition: the processing must be necessary for research, archiving or statistical purposes and carried on in accordance with the standards in the...

7 min read07 Oct 2026
§
Data Protection

Rule 6 of the Digital Personal Data Protection Rules, 2025: reasonable security safeguards, encryption, access control and logs

Rule 6 is in the group that, under rule 1(4), comes into force eighteen months after the date of publication of the Gazette. A Data Fiduciary must protect personal data in its possession or under its control, including processing by a Data Processor on its behalf, by reasonable safeguards that...

6 min read08 Oct 2026

Need help with Data Protection?

From the first step to full compliance, get professional assistance from the TaxClue team — matched to your exact Data Protection requirement.

Talk to a Data Protection Expert →