---
title: "Section 40: Power to make rules"
url: https://dpdp.myndsolution.com/wiki/act/section-40-power-to-make-rules/
description: "Section 40 of the Digital Personal Data Protection Act, 2023 (Power to make rules). Official text verbatim, in force since 13 november 2025, with…"
kind: act-section
updated: 2026-09-09
official_source: https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
text_type: official-text-plus-interpretation
publisher: MYND Integrated Solutions
license: Official Government of India texts are reproduced verbatim (public domain / open government data). Interpretation is CC BY 4.0, MYND Integrated Solutions.
disclaimer: Not legal advice. Official text prevails over any interpretation.
html_version: https://dpdp.myndsolution.com/wiki/act/section-40-power-to-make-rules/
---
# Section 40: Power to make rules

*The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), Chapter IX: MISCELLANEOUS. In force since 13 November 2025.*

## Official text

- **(1)** The Central Government may, by notification, and subject to the condition of previous publication, make rules not inconsistent with the provisions of this Act, to carry out the purposes of this Act.

- **(2)** In particular and without prejudice to the generality of the foregoing power, such rules may provide for all or any of the following matters, namely:—
  - **(a)** the manner in which the notice given by the Data Fiduciary to a Data Principal shall inform her, under sub-section (1) of section 5;
  - **(b)** the manner in which the notice given by the Data Fiduciary to a Data Principal shall inform her, under sub-section (2) of section 5;
  - **(c)** the manner of accountability and the obligations of Consent Manager under sub-section (8) of section 6;
  - **(d)** the manner of registration of Consent Manager and the conditions relating thereto, under sub-section (9) of section 6;
  - **(e)** the subsidy, benefit, service, certificate, licence or permit for the provision or issuance of which, personal data may be processed under clause (b) of section 7;
  - **(f)** the form and manner of intimation of personal data breach to the Board under sub-section (6) of section 8;
  - **(g)** the time period for the specified purpose to be deemed as no longer being served, under sub-section (8) of section 8;
  - **(h)** the manner of publishing the business contact information of a Data Protection Officer under sub-section (9) of section 8;
  - **(i)** the manner of obtaining verifiable consent under sub-section (1) of section 9;
  - **(j)** the classes of Data Fiduciaries, the purposes of processing of personal data of a child and the conditions relating thereto, under sub-section (4) of section 9;
  - **(k)** the other matters comprising the process of Data Protection Impact Assessment under sub-clause (i) of clause (c) of sub-section (2) of section 10;
  - **(l)** the other measures that the Significant Data Fiduciary shall undertake under sub-clause (iii) of clause (c) of sub-section (2) of section 10;
  - **(m)** the manner in which a Data Principal shall make a request to the Data Fiduciary to obtain information and any other information related to the personal data of such Data Principal and its processing, under sub-section (1) of section 11;
  - **(n)** the manner in which a Data Principal shall make a request to the Data Fiduciary for erasure of her personal data under sub-section (3) of section 12;
  - **(o)** the period within which the Data Fiduciary shall respond to any grievances under sub-section (2) of section 13;
  - **(p)** the manner of nomination of any other individual by the Data Principal under sub-section (1) of section 14;
  - **(q)** the standards for processing the personal data for exemption under clause (b) of sub-section (2) of section 17;
  - **(r)** the manner of appointment of the Chairperson and other Members of the Board under sub-section (2) of section 19;
  - **(s)** the salary, allowances and other terms and conditions of services of the Chairperson and other Members of the Board under sub-section (1) of section 20;
  - **(t)** the manner of authentication of orders, directions and instruments under sub-section (1) of section 23;
  - **(u)** the terms and conditions of appointment and service of officers and employees of the Board under section 24;
  - **(v)** the techno-legal measures to be adopted by the Board under sub-section (1) of section 28;
  - **(w)** the other matters under clause (d) of sub-section (7) of section 28;
  - **(x)** the form, manner and fee for filing an appeal under sub-section (2) of section 29;
  - **(y)** the procedure for dealing an appeal under sub-section (8) of section 29;
  - **(z)** any other matter which is to be or may be prescribed or in respect of which provision is to be, or may be, made by rules.


## Rules made under this section

- [Rule 1: Short title and commencement](https://dpdp.myndsolution.com/wiki/rules/rule-1-short-title-and-commencement/)
- [Rule 2: Definitions](https://dpdp.myndsolution.com/wiki/rules/rule-2-definitions/)

## Interpretation in plain English (not legal advice)

> This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.

Section 40 gives the Central Government the power to create rules that put the Digital Personal Data Protection Act into practice. The Government must publish these rules in advance and notify the public. Any rules created under this section must align with the main provisions of the Act.\n\nThe section provides a long list of specific topics that these rules can cover. For example, the rules will define exactly how a Data Fiduciary (a person or entity determining the purpose and means of processing personal data) must give notice to a Data Principal (the individual to whom the data relates). They will also set the procedures for how a Data Principal can request information, ask for their data to be erased, or nominate someone to exercise their rights.\n\nAdditionally, the rules will detail the registration and obligations of a Consent Manager (a platform that helps individuals manage their consent), the steps for reporting a personal data breach to the Board, and the methods for obtaining verifiable consent for children. The section also allows the Government to set the terms for appointing members to the Board and the procedures for filing appeals.

### Key points

- The Central Government has the authority to make rules to carry out the purposes of the Act, subject to previous publication [(1)].
- The rules can specify how a Data Fiduciary must provide notice to a Data Principal [(2)(a)], [(2)(b)].
- The rules may detail the registration, accountability, and obligations of a Consent Manager [(2)(c)], [(2)(d)].
- The rules will establish the form and manner for reporting a personal data breach to the Board [(2)(f)].
- The rules can define the procedures for a Data Principal to request information, erase data, or nominate another individual [(2)(m)], [(2)(n)], [(2)(p)].
- The rules may cover the appointment and salaries of the Board, as well as the process for filing appeals [(2)(r)], [(2)(s)], [(2)(x)].

### Common misreadings

- Readers might think this section contains the actual rules, but it only grants the Central Government the power to create and publish those rules later.
- Readers might assume the Government can make any rule it wants, but the text explicitly states that rules cannot be inconsistent with the provisions of the Act.

*Interpretation prepared 2026-09-09 from the official text only; the official text prevails.*

---
Cite as: Digital Personal Data Protection Act, 2023, s. 40. Official source: https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
