Sweet & Soft's Law Of Digital Personal Data Protection In India - Edition 2026
| Author : | JUSTICE R. N. PANDEY |
|---|
| Law of Digital Personal Data Protection in India by Justice Rang Nath Pandey, published by Sweet & Soft, brings together India's digital personal data protection framework in a single volume. It contains the Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) and the Digital Personal Data Protection Rules, 2025, together with material on Electronic Authentication Techniques, Security Guidelines, the Information Technology Rules, protocols and guidelines, national policies, the usage of AADHAAR, United Nations guidelines and principles, and a Digital Glossary. It is intended for advocates, in-house counsel, compliance and data protection officers, IT and information security professionals, and students of cyber and technology law. |
Tags: Cyber Law, Information Technology Law, Data Protection Rights, Digital Data Protection
Law of Digital Personal Data Protection in India by Justice Rang Nath Pandey, published by Sweet & Soft, assembles India's digital personal data protection framework in a single working volume — the statute, the rules made under it, and the surrounding body of technical guidance, national policy and international principle that a practitioner has to read alongside them.
India's data protection regime moved from principle to obligation with the Digital Personal Data Protection Act, 2023 and became operational with the Digital Personal Data Protection Rules, 2025. Compliance questions now turn as much on the Rules and the associated technical standards as on the Act itself, which is why this volume reproduces them together.
Contents
- The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023)
- The Digital Personal Data Protection Rules, 2025
- Electronic Authentication Technique
- Security Guidelines
- Information Technology Rules
- Protocol and Guidelines
- National Policies
- Usage of AADHAAR
- United Nations Guidelines and Principles
- Digital Glossary
Important Areas Covered
The Digital Personal Data Protection Act, 2023 governs the processing of digital personal data in India. Its scheme runs through the grounds for processing — consent and certain legitimate uses — the obligations of the Data Fiduciary, the treatment of Significant Data Fiduciaries, the rights and duties of the Data Principal, special protection for children's data, the role of the Consent Manager, the constitution and powers of the Data Protection Board of India, appeals, and the penalties set out in the Schedule.
The Digital Personal Data Protection Rules, 2025 put that framework into operation, dealing with the form and manner of notice to Data Principals, registration and obligations of Consent Managers, reasonable security safeguards, the procedure on a personal data breach, retention and erasure, verifiable consent for children, and the functioning of the Data Protection Board.
The supporting material covers electronic authentication techniques and security guidelines, the Information Technology Rules that continue to operate alongside the new regime, applicable protocols, guidelines and national policies, and the usage of AADHAAR — an area where identity, authentication and personal data questions meet in practice. United Nations guidelines and principles place the Indian position in its international context, and a Digital Glossary explains the technical vocabulary the legislation uses.
Who Should Buy This Book?
- Advocates and legal practitioners advising on data protection and privacy
- In-house counsel and corporate legal departments
- Data Protection Officers and compliance teams
- Data Fiduciaries and Significant Data Fiduciaries assessing their obligations
- IT, information security and cybersecurity professionals
- Company Secretaries and risk and governance professionals
- Technology, fintech, e-commerce and healthcare businesses handling personal data
- Government departments and public authorities processing citizen data
- Law students and researchers in cyber law, technology law and privacy
- Academicians teaching information technology law
Why Choose This Book?
The practical difficulty with the DPDP regime is that the answer to a compliance question is rarely contained in the Act alone: it sits across the Act, the 2025 Rules, the Information Technology Rules that remain in force, and the technical standards on authentication and security. Having those sources in one volume, with a glossary for the technical terms, removes most of the cross-referencing.
The inclusion of the material on AADHAAR usage and the United Nations guidelines also gives the reader the wider frame — how identity and authentication interact with personal data obligations in India, and how the Indian approach sits against internationally recognised data protection principles.







