DATA PRIVACY UPDATE | DPDP ACT, 2023
GOVERNMENT ISSUES DIGITAL PERSONAL
DATA PROTECTION (REMOVAL OF
DIFFICULTIES) ORDER, 2026
The Ministry of Electronics and Information Technology (MeitY) issued the Digital Personal Data Protection (Removal of Difficulties) Order, 2026, vide S.O. 5458(E) dated 5 October 2026, to address textual and editorial ambiguities in two provisions of the DPDP Act, 2023. The Order came into force upon publication in the Official Gazette.
KEY CLARIFICATIONS
1. Section 9(1) – Personal Data of Children and Persons with Disabilities
The wording “child or a person with disability” has been replaced with “child or of a person with disability”.
This clarifies the provision concerning the requirement to obtain verifiable consent from the parent of a child or the lawful guardian of a person with disability who has a lawful guardian, before processing the relevant personal data.
2. Section 10(2)(c)(ii) – Audit Obligations of Significant Data Fiduciaries
The word “audit” has been replaced with “data audit”.
This aligns the periodic audit reference with the data audit terminology used elsewhere in Section 10 and clarifies the nature of the compliance obligation applicable to Significant Data Fiduciaries.
WHY DOES THIS MATTER?
These amendments address drafting ambiguities while clarifying two important areas of data protection compliance:
Consent management: Organisations should review their procedures for obtaining and verifying parental or lawful guardian consent, wherever applicable.
Data audit readiness: Significant Data Fiduciaries should review their periodic data audit arrangements and related compliance documentation.
COMPLIANCE TAKEAWAY
Companies, compliance officers, legal professionals and data protection teams should take note of these clarifications while preparing for compliance with the DPDP framework.
The Order makes targeted textual clarifications; it should not be interpreted as a blanket relaxation of data protection obligations.







