Legal Register
ACT-11 Tranche 3 (13 May 2027) — Core Operating Cliff
Status: scheduled, not yet operative
Section 11: Request after prior consent including s7(a)
Not a general portability right or a 72-hour SLA; do not apply blindly to every s7 ground.
Regulated Actor: Data Principal; said Data Fiduciary
Gazette Baseline: Lines 441–462
Statutory Trigger
Request after prior consent including s7(a)
Applies to: Data Principal; said Data Fiduciary
Substantive Conditions
Summary of data/activities; identities and shared-data description; prescribed further information.
Statutory Exceptions
s11(2) excludes (1)(b)/(c) for qualifying written requests by law-authorised fiduciaries for specified offence/cyber purposes.
Official Gazette Text (Verbatim Publication)
Ministry of Law and Justice publication, Digital Personal Data Protection Act, 2023.
11. (1) The Data Principal shall have the right to obtain from the Data Fiduciary to Right to
whom she has previously given consent, including consent as referred to in clause (a) of access
information
section 7 (hereinafter referred to as the said Data Fiduciary), for processing of personal about personal
data, upon making to it a request in such manner as may be prescribed,— data.
(a) a summary of personal data which is being processed by such Data Fiduciary
and the processing activities undertaken by that Data Fiduciary with respect to such
personal data;
(b) the identities of all other Data Fiduciaries and Data Processors with whom
the personal data has been shared by such Data Fiduciary, along with a description of
the personal data so shared; and
(c) any other information related to the personal data of such Data Principal and
its processing, as may be prescribed.
(2) Nothing contained in clause (b) or clause (c) of sub-section (1) shall apply in
respect of the sharing of any personal data by the said Data Fiduciary with any other Data
Fiduciary authorised by law to obtain such personal data, where such sharing is pursuant
10 THE GAZETTE OF INDIA EXTRAORDINARY [PART II—
to a request made in writing by such other Data Fiduciary for the purpose of prevention or
detection or investigation of offences or cyber incidents, or for prosecution or punishment
of offences.
Mapped Operational Controls (1)
Enterprise obligations in the Control Master Matrix grounded in this statutory provision.