DPDP Wiki Talk to us

/The Rules · 2025

Rule 9: Contact information of person to answer questions about processing

DPDP Rules, 2025, G.S.R. 846(E) dated 13 November 2025. Comes into force on 13 May 2027.

UpcomingOfficial textComes into force on 13 May 2027 (phase 3) · rule 1(4)
Provision
Rule 9 of The Digital Personal Data Protection Rules, 2025
Status
Comes into force on 13 May 2027 (phase 3)
Made under
s. 8 General obligations of Data Fiduciary
Source
Ministry of Electronics and Information Technology · G.S.R. 846(E) · 13 November 2025 · Official PDF

Rule 9. Contact information of person to answer questions about processing

Verbatim from the Gazette of India

Every Data Fiduciary shall prominently publish on its website or app, and mention in every response to a communication for the exercise of the rights of a Data Principal under the Act, the business contact information of the Data Protection Officer, if applicable, or a person who is able to answer on behalf of the Data Fiduciary the questions of the Data Principal about the processing of her personal data.

Interpretation in plain English

Interpretation · not legal advice
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.
Data FiduciaryData PrincipalData Protection Officer

Rule 9 requires every Data Fiduciary (the entity that decides how and why personal data is processed) to provide specific contact information so that a Data Principal (the individual to whom the data relates) can ask questions about how their personal data is being handled. The Data Fiduciary must share the business contact information of its Data Protection Officer, if it is required to have one. If it does not have a Data Protection Officer, it must provide the contact details of another person who is capable of answering questions on behalf of the Data Fiduciary regarding the processing of personal data. This contact information must be prominently published on the Data Fiduciary's website or app. Additionally, the Data Fiduciary must include these contact details in every response it sends when a Data Principal communicates to exercise their rights under the Act.

Key points

  • A Data Fiduciary must provide business contact information for someone who can answer questions about personal data processing.
  • This person must be the Data Protection Officer, if applicable, or another capable representative.
  • The contact information must be prominently published on the Data Fiduciary's website or app.
  • The contact information must also be included in every response to a Data Principal exercising their rights under the Act.

Common misreadings

  • Assuming every Data Fiduciary must appoint a Data Protection Officer to fulfill this rule; the rule allows for another person to answer questions if a Data Protection Officer is not applicable.
  • Believing that just publishing the contact information on a website is enough; it must also be included in every response to a Data Principal exercising their rights.

Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.

/MYND · DPDP practice

Putting this into practice?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.