Small Words, Big Consequences: Reading the DPDP (Removal of Difficulties) Order, 2026
Introduction
Lawyers love saying that the devil lies in the detail, and privacy professionals in India have had a neat reminder of this. The Digital Personal Data Protection (Removal of Difficulties) Order, 2026, was issued by MeitY on 5 October and published in the Official Gazette on 7 October. It is brief: it makes two editorial corrections to the Digital Personal Data Protection Act, 2023, and these are described by MeitY as textual and editorial corrections that serve to give effect to the intention of the Parliament. This is fair language, but a careful reader will note the importance of the nuances.
What the Order is and what it is not
The Order is based on section 43(1) of the Act that allows the Central Government to make provision not inconsistent with the Act if difficulty arises in giving effect to the Act. This power is subject to some conditions. Section 43(2) states that no such order can be made after the expiry of three years from the commencement, and section 43(3) says that such order shall be laid before each House of the Parliament. So, it is just a tool for tidying up and not for rewriting the Act. According to India Briefing, the Order came into operation on the date of its publication in the Gazette.
Fix one: guardian consent for children and persons with disabilities
Section 9(1) of the Act says a Data Fiduciary must obtain verifiable consent from the parent or lawful guardian before processing the personal data of “a child or a person with disability who has a lawful guardian”. The Order inserts one small preposition so that the provision reads as the personal data of a child or of a person with a disability. As reported, the missing “of” created a grammatical disjunction between the two categories and could cloud the intended meaning, and the fix puts them side by side.
Why would that matter? Here is one way to see the risk, and to be clear, this is my own illustration and not something the Order says. Read the old phrase quickly, and you could ask whether “who has a lawful guardian” qualifies only the person with a disability or whether it also hangs on the child. The Act’s own definitions point to the answer. Section 2(j) treats the parents or lawful guardian of a child and the lawful guardian of a person with a disability as part of the Data Principal in parallel terms. Parallel treatment in the definitions and slightly tangled treatment in the operative clause is exactly the kind of mismatch that invites an argument later. The extra word shuts that door.
The stakes are not small. The Schedule to the Act sets a penalty of up to Rs 200 crore for breach of the additional obligations relating to children under section 9. Nobody wants to be in a hearing where the question is what a missing preposition was supposed to mean.
Fix two: “audit” becomes “data audit"
Section 10 adds duties for Significant Data Fiduciaries. Clause (b) of sub-section (2) requires them to appoint an independent data auditor to carry out a data audit. Clause (c)(ii), a few lines later, requires a “periodic audit” and nothing more. Same section, two audit duties, two slightly different vocabularies. The Order replaces “audit” with “data audit” in section 10(2)(c)(ii).
The reasoning behind the argument given by India Briefing is that the bare word could leave the scope of the audit ambiguous and subject of different interpretations by regulatory or supervisory authorities. One can only speculate what questions an SDF may have had to answer in the meanwhile. Does a periodic audit entail a financial audit, an information security audit, a generic internal audit or something completely different? With the amendment, the periodic audit has been tied to the compliance with data protection and data processing; fitting into the overall audit framework which the Act provides for SDFs. The Order does not combine the two obligations. The independent auditor and the periodic audit remain separate obligations. What changes is that the two now share a common language. The stakes, again, are real here as the Schedule permits a penalty of up to Rs 150 crore for violation of the additional obligations of an SDF under section 10.
Is “editorial” the right label?
Mostly, yes. India Briefing concludes that the Order does not substantially expand the Act’s obligations, and Zee Business reaches a similar view, noting that it clears up wording rather than creating a new compliance system.
Nevertheless, a label is no protection. Labelling it an editorial correction will not stop a regulator or a litigant from asserting that the text previously meant something else or that the amended text now conveys something different. Section 43 only permits the inclusion of provisions that are not inconsistent with the Act, which is exactly the point that the Government takes care to make through this text. My recommendation is that you read the Gazette text (not summaries of it) and retain a copy in your compliance file.
What privacy teams can do now
Nothing here is urgent, and that is the good news. The DPDP Rules, 2025, were notified in November 2025 with a phased timeline, and as Bar and Bench reports, most operational duties are due after an 18-month transition ending on 13 May 2027. The Rules also operationalise age verification and guardian validation, including through Digital Locker based methods, and expect enhanced governance from SDFs, including audits and risk assessments, as Khurana and Khurana notes. That leaves room to make small corrections calmly. A sensible short list looks like this:
- Check the wording of your consent flows. Make sure notices and policies that deal with children and persons with disabilities use language consistent with the amended section 9(1), and that the guardian route is clearly described.
- Align your audit vocabulary. If you are or may be notified as an SDF, use “data audit” consistently in policies, audit charters, checklists and engagement letters with your independent data auditor.
- Update your statutory reference library. Many teams quote the Act in templates and training decks. Those quotes should now match the amended text.
- Set up a Gazette watch. Notifications, rules and orders under this Act will keep arriving.
Conclusion
Privacy work is often couched in terms of grand themes such as consent, accountability and cross-border transfers. In practice, a substantial part of the work takes the form of close reading. Data Fiduciaries, auditors and the Data Protection Board will all be working from the same words, so that the distinction between 'audit' and 'data audit', or between a phrase including or omitting 'of', is the sort of gap that can decide an argument.
We therefore invite you to treat this order as a prompt to read your own documents as a regulator would. Spot points at which two terms are being used for one purpose or one term is being used to cover two purposes. Rectifying such issues now costs an afternoon's work; waiting until an inquiry is underway will require significantly more resources.
Sources
- Digital Personal Data Protection Act, 2023 (official text), Ministry of Electronics and Information Technology
- DPDP (Removal of Difficulties) Order 2026 Clarifies Consent and Data Audit Requirements in India, India Briefing
- DPDP Order 2026 clarifies data protection, consent and data audit requirements for businesses in India, Zee Business
- MeitY notifies final Digital Personal Data Protection Rules 2025, Bar and Bench
- Update: MeitY Notifies Rules Operationalising the DPDP Framework in India, Khurana and Khurana
.webp)






