DPDP Wiki Talk to us

/The Rules · 2025

Rule 11: Verifiable consent for processing of personal data of person with disability who has lawful guardian

DPDP Rules, 2025, G.S.R. 846(E) dated 13 November 2025. Comes into force on 13 May 2027.

UpcomingOfficial textComes into force on 13 May 2027 (phase 3) · rule 1(4)
Provision
Rule 11 of The Digital Personal Data Protection Rules, 2025
Status
Comes into force on 13 May 2027 (phase 3)
Made under
s. 9 Processing of personal data of children
Source
Ministry of Electronics and Information Technology · G.S.R. 846(E) · 13 November 2025 · Official PDF

Rule 11. Verifiable consent for processing of personal data of person with disability who has lawful guardian

Verbatim from the Gazette of India
(1)

A Data Fiduciary, while obtaining verifiable consent from an individual identifying herself as the lawful guardian of a person with disability, shall observe due diligence to verify that such guardian is appointed by a court of law, or by a designated authority or by a local level committee, under the law applicable to guardianship.

(2)

In this rule, the expression—

(a)

“designated authority” shall mean an authority designated under section 15 of the Rights of Persons with Disabilities Act, 2016 (49 of 2016) to support persons with disabilities in exercise of their legal capacity;

(b)

“law applicable to guardianship” shall mean, —

(i)

in relation to an individual who has long term physical, mental, intellectual or sensory impairment which, in interaction with barriers, hinders her full and effective participation in society equally with others and who despite being provided adequate and appropriate support is unable to take legally binding decisions, the provisions of law contained in Rights of Persons with Disabilities Act, 2016 (49 of 2016) and the rules made thereunder; and

(ii)

in relation to a person who is suffering from any of the conditions relating to autism, cerebral palsy, mental retardation or a combination of such conditions and includes a person suffering from severe multiple disability, the provisions of law of the National Trust for the Welfare of Persons with Autism, Cerebral Palsy, Mental Retardation and Multiple Disabilities Act, 1999 (44 of 1999) and the rules made thereunder;

(c)

“local level committee” shall mean a local level committee constituted under section 13 of the National Trust for the Welfare of Persons with Autism, Cerebral Palsy, Mental Retardation and Multiple Disabilities Act, 1999 (44 of 1999);

(d)

person with disability” shall mean and include—

(i)

an individual who has long term physical, mental, intellectual or sensory impairment which, in interaction with barriers, hinders her full and effective participation in society equally with others and who, despite being provided adequate and appropriate support, is unable to take legally binding decisions; and

(ii)

an individual who is suffering from any of the conditions relating to autism, cerebral palsy, mental retardation or a combination of any two or more of such conditions and includes an individual suffering from severe multiple disability and who, despite being provided adequate and appropriate support, is unable to take legally binding decisions.

Interpretation in plain English

Interpretation · not legal advice
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.
Data FiduciaryData PrincipalLawful guardians

When a Data Fiduciary (an entity that determines the purpose and means of processing personal data) needs to process the personal data of a person with a disability, it must obtain verifiable consent from that person's lawful guardian. Rule 11 requires the Data Fiduciary to exercise due diligence to confirm the guardian's legal status. Specifically, the Data Fiduciary must verify that the guardian was officially appointed by a court of law, a designated authority, or a local level committee. The rule defines a person with disability as an individual who has long-term physical, mental, intellectual, or sensory impairments, or conditions like autism, cerebral palsy, or mental retardation, and who is unable to make legally binding decisions even with adequate support. To verify the guardian, the Data Fiduciary must look to the specific laws applicable to guardianship. Depending on the nature of the disability, this means checking appointments made under either the Rights of Persons with Disabilities Act, 2016, or the National Trust for the Welfare of Persons with Autism, Cerebral Palsy, Mental Retardation and Multiple Disabilities Act, 1999.

Key points

  • A Data Fiduciary must use due diligence to verify the legal status of anyone claiming to be the lawful guardian of a person with a disability (1).
  • The guardian must be verified as appointed by a court of law, a designated authority, or a local level committee (1).
  • A person with a disability is defined as someone who cannot make legally binding decisions despite receiving adequate support (2)(d).
  • The applicable guardianship laws include the Rights of Persons with Disabilities Act, 2016, and the National Trust Act, 1999, depending on the specific disability (2)(b).

Common misreadings

  • Assuming anyone claiming to be a guardian can give consent; the Data Fiduciary must actively verify their official appointment by a court or specific authority.
  • Assuming this rule applies to all persons with disabilities; it specifically applies to those who are unable to take legally binding decisions despite adequate support.

Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.

/MYND · DPDP practice

Putting this into practice?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.