/The Act · Chapter IX · Miscellaneous
Section 36: Power to call for information
DPDP Act, 2023 (No. 22 of 2023). Comes into force on 13 May 2027.
- Provision
- Section 36 of The Digital Personal Data Protection Act, 2023
- Status
- Comes into force on 13 May 2027 (phase 3) G.S.R. 843(E)
- Rules made under it
- Rule 23
- Source
- Ministry of Law and Justice (Legislative Department) · 11 August 2023 · Official PDF
The Central Government may, for the purposes of this Act, require the Board and any Data Fiduciary or intermediary to furnish such information as it may call for.
Section 36 gives the Central Government the authority to demand information from specific entities. This power must be used specifically for the purposes of carrying out the Digital Personal Data Protection Act. When the Central Government makes such a request, the named entities are required to furnish the information called for. The entities subject to this requirement are the Board, any Data Fiduciary, and any intermediary. A Data Fiduciary is an entity that determines the purpose and means of processing personal data. The Board refers to the regulatory body created by the Act. Intermediaries are also explicitly included in this list, meaning they too must provide the requested information if called upon by the Central Government for the purposes of the Act.
Key points
- The Central Government may require specific entities to furnish information.
- This power can be exercised against the Board, any Data Fiduciary, or any intermediary.
- The request for information must be made strictly for the purposes of the Act.
Common misreadings
- One might assume the Central Government can demand information for any reason, but the text restricts this power to the purposes of the Act.
- It might be assumed that only Data Fiduciaries must provide information, but the text explicitly includes the Board and intermediaries as well.
Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.
/MYND · DPDP practice
Putting this into practice?
MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.