
DPDPA Section 40: Government Rule-Making Powers and Practical Implications
Prepare your compliance team for upcoming regulations. DPDPA Section 40 outlines government rule-making powers and the DPDP Act rules notification process.
Written by
Sahil Pugalia
Date
Read time
6 min

The Digital Personal Data Protection Act, 2023 tells you what is required. DPDPA Section 40 tells you exactly how the government expects you to prove it.
This section authorizes the Central Government to issue the rules that operationalize the Act. These rules cannot contradict the statute, and they must be notified after “previous publication.” In practice, this means draft rules will be published before they take effect, giving institutions a brief window to review and prepare.
This is the provision that supplies the missing operational details. It tells you where the Government will prescribe the exact formats, timelines, standards, and procedures that are not hard-coded into the law itself.
What Section 40 Actually Covers
Section 40 allows rules on any matter necessary to carry out the Act. But it also lists specific, high-stakes areas where rules will definitely be issued. For compliance teams, these are the hotspots to watch:
- Notices to individuals under Section 5
- Manner in which Data Fiduciaries must inform individuals under Section 5(1) and Section 5(2).
- Publication of a Data Protection Officer’s business contact information under Section 8(9).
- Consent and Consent Managers under Section 6
- Accountability and obligations of Consent Managers under Section 6(8).
- Registration of Consent Managers and related conditions under Section 6(9).
- Processing for government benefits under Section 7
- Which subsidy, benefit, service, certificate, licence, or permit may involve processing personal data without consent under Section 7(b).
- Security incidents and breach handling under Section 8
- Form and manner for notifying the Data Protection Board of a personal data breach under Section 8(6).
- Time period after which a specified purpose is deemed no longer served for retention purposes under Section 8(8).
- Verifiable consent and children’s data under Section 9
- Manner of obtaining verifiable consent under Section 9(1).
- Classes of Data Fiduciaries, purposes, and conditions for processing children’s data under Section 9(4).
- High-risk processing and Significant Data Fiduciaries under Section 10
- Additional matters in the Data Protection Impact Assessment process under Section 10(2)(c)(i).
- Additional measures a Significant Data Fiduciary must undertake under Section 10(2)(c)(iii).
- Data Principal rights operations under Sections 11 to 14
- Manner for individuals to request information from Data Fiduciaries under Section 11(1).
- Manner for individuals to request erasure under Section 12(3).
- Time period within which Data Fiduciaries must respond to grievances under Section 13(2).
- Manner of nomination of another individual by the Data Principal under Section 14(1).
- Exemptions under Section 17
- Standards for processing personal data for an exemption under Section 17(2)(b).
- Data Protection Board and appeals under Sections 19, 20, 23, 24, 28, and 29
- Manner of appointing the Chairperson and Members of the Board under Section 19(2).
- Salary, allowances, and terms of service for the Board under Section 20(1).
- Authentication of orders, directions, and instruments under Section 23(1).
- Terms of appointment and service of Board officers and employees under Section 24.
- Techno-legal measures the Board will adopt under Section 28(1), and other matters under Section 28(7)(d).
- Form, manner, and fee for filing appeals under Section 29(2), and appeal procedures under Section 29(8).
- Residual authority
- Any other matter that must or may be prescribed by rules.
What This Means in Plain Terms
The Act sets the destination. Section 40 supplies the vehicle.
Many obligations refer to a “manner,” “form,” “time period,” or “conditions” that are not yet fixed. Those details will arrive through a DPDP Act rules notification under Section 40. Once notified, they are binding.

Rules must be consistent with the Act. If a practice violates the statute, no rule will magically legitimize it. Conversely, if the statute is broad, the rules will tighten the operational guardrails.
The requirement of previous publication matters. Expect draft rules to be issued before they take effect. This creates a narrow but real planning window. Use it to assess gaps, update internal procedures, and train teams before enforcement begins. It is the difference between reading about a new compliance mandate and scrambling to build it over a weekend.
Practical Implications for Compliance Teams
Treat the list above as a working roadmap for upcoming compliance change. You will need to translate each rule into changes across process, systems, and documentation.
Focus on these execution points:
- Notices and transparency
- Build modular notice templates that can be adapted for content, sequence, and delivery channels once the exact manner is notified.
- Prepare a public location and process to publish and maintain the Data Protection Officer’s business contact information.
- Consent and Consent Managers
- Map your consent flows now, so you can plug in the notified method for verifiable consent later.
- If you operate as a Consent Manager, be ready for registration steps, accountability documentation, and audits aligned to Section 6.
- Government benefits processing
- If you support public schemes, inventory processing linked to subsidies, benefits, services, certificates, licences, or permits. Align to the specific items notified under Section 7(b).
- Incident response and retention
- Define a breach triage and escalation path. Keep placeholders in your playbooks for the notified breach reporting form and channel, and for any timing requirement.
- Catalog your processing purposes and link them to retention triggers. Configure systems to enforce deletion when a purpose is deemed no longer served under the notified time period.
- Children’s data
- Ringfence processing of children’s data. Prepare age gates and parental consent controls that can be tuned to the notified classes, purposes, and conditions.
- DPIA and Significant Data Fiduciary
- Stand up a DPIA method that can absorb additional notified elements. Keep artifact templates ready.
- If you are likely to be designated a Significant Data Fiduciary, prepare for added measures under Section 10, including independent assessments and governance enhancements as rules specify.
- Data Principal rights operations
- Create intake channels for access, information, erasure, and grievance requests. Design them to capture identity, scope, and consent withdrawal if applicable.
- Set internal service levels that can be tightened to meet the notified grievance timeline. Automate acknowledgments and status tracking.
- Build a simple nomination workflow so individuals can appoint someone to act for them in line with the notified manner.
- Exemptions and standards
- If you rely on any exemption under Section 17(2)(b), map controls to the standards once they are notified. Document the rationale and safeguards.
- Board governance and appeals
- Legal and compliance teams should monitor notifications on Board procedures, authentication of orders, and appeals. Align your response protocols to the prescribed forms and fees.
How to Prepare Without Overbuilding
You cannot build a system for rules that do not exist yet. But you can build the scaffolding.
- Maintain a live register of “rule-dependent” obligations with owners, current practice, and readiness status.
- Build flexible templates, not hard-coded text. Parameterize deadlines, forms, and references.
- Keep one breach playbook with configurable timing and reporting fields. Pre-test the pipeline to the extent possible.
- For DPIAs, adopt a baseline framework that can be extended to meet any notified requirements under Section 10.
- Train frontline teams on intake and triage for rights and grievances. They will be the ones meeting the notified timelines.

Boundaries and Timing
Rules under Section 40 cannot dilute statutory rights or obligations. They operationalize the Act; they do not rewrite it. You should not expect rules to create new legal bases for processing that the Act does not already allow.
Previous publication signals a draft stage before rules take effect. Use that interval to gap assess and adjust, but do not bank on long transition periods unless a notification explicitly provides one. Hope is not a compliance strategy.
Closing
Section 40 is where the DPDP Act gets its operating manual. The Government will use it to set the formats, timelines, and methods that determine whether your compliance program runs smoothly or trips at the first audit. Track these notifications closely, build for flexibility, and be ready to implement fast once the details land.
Ready to simplify compliance?
Real execution is where organizations stumble. You need structure to track rule-dependent obligations, update procedures on short notice, and actually prove compliance.
Regodit offers a practical way to manage these moving parts without the chaos. Explore how Regodit can centralize your DPDPA obligations and help you operationalize new rules with less friction. If this is on your desk, schedule a discussion with our team and see how we can support your execution plan.
Disclaimer: The views and explanations shared in this blog are based on our team's understanding of the relevant compliance frameworks. While every effort has been made to ensure accuracy, readers are encouraged to refer to the original legal provisions and official notifications for authoritative guidance. Please reach out to us at connect@solsphere.ai.
Keep reading
All blogs →DPDPA Rule 23: Government Requests for Information from Data Fiduciaries and Intermediaries
Handling a notice under DPDP Act Rule 23 requires strict confidentiality. Discover how to respond to government data requests and ensure full compliance.
DPDPA Rule 22: Appeals to the Appellate Tribunal
Lost at the Data Protection Board? DPDPA Rule 22 governs the digital-first appeals process. Read our complete guide to filing an appeal with the Tribunal.
DPDPA Rule 21: The Machinery Behind the Data Protection Board of India
Ensure your business meets DPDP Act compliance requirements. Discover key obligations for data fiduciaries, penalty risks, and steps to protect user privacy.
