DPDP Wiki Talk to us

/The Rules · 2025

Rule 23: Calling for information from Data Fiduciary or intermediary

DPDP Rules, 2025, G.S.R. 846(E) dated 13 November 2025. Comes into force on 13 May 2027.

UpcomingOfficial textComes into force on 13 May 2027 (phase 3) · rule 1(4)
Provision
Rule 23 of The Digital Personal Data Protection Rules, 2025
Status
Comes into force on 13 May 2027 (phase 3)
Made under
s. 36 Power to call for information
Schedules referenced
Seventh Schedule
Source
Ministry of Electronics and Information Technology · G.S.R. 846(E) · 13 November 2025 · Official PDF

Rule 23. Calling for information from Data Fiduciary or intermediary

Verbatim from the Gazette of India
(1)

The Central Government may, for such purposes of the Act as are specified in Seventh Schedule, acting through the corresponding authorised person specified in the said Schedule, require any Data Fiduciary or intermediary to furnish such information as may be called for, within the specified period as may be given in such.

(2)

Where the disclosure of furnishing of information as referred to in sub-rule (1) is likely to prejudicially affect the sovereignty and integrity of India or security of the State, the Central Government may require the Data Fiduciary or intermediary to not disclose such furnishing to affected Data Principal or any other person except with the previous permission, in writing, of the authorised person.

(3)

For the purposes of this rule, the expression “intermediary” shall have the same meaning as assigned to it in the Information Technology Act, 2000 (21 of 2000).

Corrected by G.S.R. 892(E) (10 December 2025). The text above is as first printed. The Ministry's corrigendum directs:
  • in page 32, line 4, for “given in such”, read “given in such order”;

Interpretation in plain English

Interpretation · not legal advice
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.
Central GovernmentData FiduciaryIntermediaryData Principal

The Central Government has the power to demand information from a Data Fiduciary (an entity determining the purpose and means of processing personal data) or an intermediary. This request must be for specific purposes listed in the Seventh Schedule of the Act and made through an authorized person named in that Schedule. The Data Fiduciary or intermediary must provide the information within the time limit specified in the request.\n\nIn certain sensitive situations, the Central Government can order the Data Fiduciary or intermediary to keep this information request a secret. This applies if revealing the request would likely harm the sovereignty and integrity of India or the security of the State. In these cases, the entity cannot tell the affected Data Principal (the individual to whom the data relates) or anyone else without getting prior written permission from the authorized person.\n\nThe rule clarifies that the term intermediary has the exact same meaning as it does in the Information Technology Act, 2000.

Key points

  • The Central Government can require a Data Fiduciary or intermediary to provide information for purposes specified in the Seventh Schedule. [(1)]
  • These requests must be made through an authorized person and fulfilled within a specified time limit. [(1)]
  • The Government can prohibit the Data Fiduciary or intermediary from telling the Data Principal or others about the request if disclosure harms India's sovereignty, integrity, or security. [(2)]
  • Written permission from the authorized person is required to disclose a restricted information request. [(2)]
  • The term intermediary is defined according to the Information Technology Act, 2000. [(3)]

Common misreadings

  • Assuming a Data Fiduciary can always notify a Data Principal when the government requests their data; the government can explicitly forbid this if it harms state security.
  • Believing any government official can demand this information; the request must come through an authorized person specified in the Seventh Schedule.

Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.

/MYND · DPDP practice

Putting this into practice?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.