Health Data Management Policy (under Ayushman Bharat Digital Mission)
ABDM participants must comply with the Health Data Management Policy. Healthcare laws include the Clinical Establishments Act, National Medical Commission Act provisions requiring physician confidentiality, and the proposed Digital Information Security in Healthcare Act (DISHA). Download PDF
Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016
The Aadhaar Act became law in March 2016 and regulates India’s biometric identification system. The Act includes provisions for authentication, offline verification, and informed consent. It governs the collection, storage, and use of biometric and demographic data for over 1 billion Indians. Download PDF
IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
These rules, known as SPDI Rules, are issued under the IT Act and define sensitive personal information to include passwords, financial information, physical/mental health conditions, sexual orientation, medical records, and biometric information. They establish requirements for collection, storage, and transfer of sensitive personal data by body corporates. Download PDF
NITI Aayog’s Principles for Responsible AI, 2021
NITI Aayog, the Government of India’s policy think tank, outlines India’s foundational principles for responsible Artificial Intelligence (AI), building upon the 2018 National Strategy on AI. It highlights AI’s economic and social potential while acknowledging the emerging risks and ethical challenges associated with its rapid deployment, such as bias, privacy breaches, and accountability issues. The document examines system and […]
NITI Aayog’s National Strategy for Artificial Intelligence, 2018
Building upon the National AI Strategy, these principles provide a comprehensive framework for ethical and responsible AI development and deployment in India. The document establishes seven core principles: safety and reliability, equality, inclusivity and non-discrimination, privacy and security, transparency, accountability, and protection and reinforcement of positive human values. Under privacy and security, it mandates that […]
Draft Digital Personal Data Protection Rules, 2025
Released on January 3, 2025 by MeitY for public consultation, these draft rules provide the operational framework for implementing the DPDP Act, including provisions for consent managers, data retention periods, security measures, breach notifications within 72 hours, and children’s data protection. Download PDF
RBI Framework for Self-Regulatory Organizations (SRO) in Fintech, 2024
This framework establishes a structured approach for recognizing and overseeing Self-Regulatory Organizations in the fintech sector. The framework aims to foster responsible innovation while ensuring consumer protection and market integrity through industry-led governance. It sets out eligibility criteria for SRO recognition, including requirements for membership diversity, governance structure, and financial resources. SROs are tasked with […]
RBI Guidelines on Digital Lending, 2023
These guidelines were issued by the Reserve Bank of India to regulate digital lending practices and protect consumer interests in the rapidly growing digital lending ecosystem. The guidelines establish comprehensive requirements for all digital lending platforms, including mandatory disclosure of all-inclusive cost of digital loans, standardization of key facts statement, restrictions on unsolicited commercial communications, […]
Information Technology Act, 2000 – Amended 2008)
The IT Act is based on the United Nations Model Law on Electronic Commerce and contains provisions on data protection and privacy, including Section 43A which provides for compensation in case of negligence in protecting sensitive personal data, and Section 72A which provides criminal punishment for unauthorized disclosure of personal information. The Act forms the foundation […]
Digital Personal Data Protection Act, 2023
This official document outlines India’s Digital Personal Data Protection Act, 2023, a comprehensive law enacted to regulate the processing of digital personal data. The Act aims to balance individual data protection rights with the necessity of processing such data for lawful purposes. It defines key terms like Data Fiduciary and Data Principal, establishes the Data Protection Board of India to oversee compliance, and […]