Authored by Utkarsh Rai & Prisha Chaudhary, 3rd-year law students at Jindal Global Law School, Sonepat

How Rule 23 of the DPDP Rules creates a surveillance apparatus inside a law meant to protect your data.

Imagine a demand that you will never see. A minister’s fiat directing your bank, your hospital, and the app on your phone to give up information about you and keep silent about it. You will never get notified; you will never be able to object. The information will be shared, and you will most likely never know about it, unless and until someone bothers to tell you, and there is no time limit within which this has to happen.

This is not a scene from a spy novel. It is Rule 23 of the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 and set to take effect eighteen months later, in May 2027, alongside Section 36 of the Digital Personal Data Protection Act, 2023.

What The Provision Actually Does

Rule 23(1) permits the Central Government, “for such purposes of the Act as are specified in Seventh Schedule”, acting through the corresponding authorised person specified in that Schedule, to require any Data Fiduciary or intermediary to furnish such information as may be called for. The Seventh Schedule lists three purposes: use by the State or its instrumentalities of a Data Principal’s personal data in the interest of the sovereignty and integrity of India or the security of the State; use by the State for the performance of any function under law, or the disclosure of information to fulfil an obligation under law; and the carrying out of an assessment for notifying a Significant Data Fiduciary. The authorised persons are, respectively, an officer designated under Section 17(2)(a), a person authorised under applicable law, and a MeitY officer designated by the Secretary.

Sub-rule (2) is the one that matters:

“Where the disclosure of furnishing of information as referred to in sub-rule (1) is likely to prejudicially affect the sovereignty and integrity of India or security of the State, the Central Government may require the Data Fiduciary or intermediary to not disclose such furnishing to affected Data Principal or any other person except with the previous permission, in writing, of the authorised person.”

This is a statutory gag order: a non-disclosure direction, issued at the instance of the government, operative for as long as the government says it should be, with no mechanism for the company to notify the data principal of its existence until permission is granted by the same authorised person who issued it.

Two features of the design deserve notice at the outset. The first is that the draft Rules published in January 2025 expressly anchored this power in Section 36 of the Act. The final Rules dropped that reference. Rule 23 now cites no parent provision at all; the Rules as a whole were made under Section 40(1) and (2). The second is Rule 8(3), which requires every Data Fiduciary to retain personal data, associated traffic data and processing logs for a minimum of one year “for the purposes as specified in the Seventh Schedule”. The same three purposes that authorise the demand also compel the corpus to exist. The State does not merely reach for information it happens to find; it requires that the information be kept for it.

The Legislative History Runs The Other Way

Section 36 of the Act reads: “The Central Government may, for the purposes of this Act, require the Board and any Data Fiduciary or intermediary to furnish such information as it may call for.” There is no qualification, no necessity requirement, no reasons to be recorded, no authority higher than “the Central Government”.

This was not the position the Bill was explained to Parliament as taking. The Notes on Clauses to the Digital Personal Data Protection Bill, 2023 record, against Clause 36, that the clause “seeks to empower the Board to call for information from any Data Fiduciary”. The power was described as the regulator’s. The enacted text places it in the Central Government, and extends it to the Board itself. No explanation for the shift appears anywhere on the record.

The Gag Has No Parent in The Act

There is no express or implied power in the Act for the government to issue a non-disclosure direction. Nowhere in the Act is such a direction mentioned, let alone the possibility of the government issuing one. Section 40(2) enumerates, in clauses (a) to (z), the matters on which rules may be made; each is tied to a specific provision of the Act that contemplates something being prescribed, and clause (z) is the standard residuary head covering “any other matter which is to be or may be prescribed”. Nothing in the Act contemplates the prescription of a direction restraining a data fiduciary from speaking to the person whose data it has been made to surrender. Section 40(1), which permits rules “not inconsistent with the provisions of this Act, to carry out the purposes of this Act”, does not help either.

This is precisely the situation Kunj Behari Lal Butail v. State of Himachal Pradesh addresses. A three-judge Bench there held that a delegated power to make rules for carrying out the purposes of an Act is a general delegation laying down no guidelines, and cannot be exercised so as to bring into existence substantive rights, obligations or disabilities not contemplated by the provisions of the Act itself. A gag on a data fiduciary, enforceable and open-ended, is a disability of exactly that kind. State of Tamil Nadu v. P. Krishnamurthy sets out the grounds on which subordinate legislation may be struck down, and failure to conform to the parent statute stands first among them.

The demand under sub-rule (1) is on weaker ground than the gag, but it is not clean either. Rule 23(1) describes the Seventh Schedule purposes as “purposes of the Act”, which is the language Section 36 uses as a limitation. Whether they are is contestable. The first entry traces to Section 17(2)(a), which is not a purpose of the Act at all but the mechanism by which the Act switches itself off the provision under which the Central Government notifies instrumentalities to which the Act does not apply, in the interest of sovereignty and security. Information gathered under a data protection statute, for a purpose that the same statute defines as lying outside its own application, is at least circular. Having removed the Section 36 reference from the final Rules, the government has also removed the textual anchor by which that circularity might have been defended.

Subordinate legislation can fill gaps; it cannot create them and then fill them. Rule 23(2) is an ultra vires exercise that ought to be struck down. This matters, because the ability of the government to conceal information, including from citizens, has serious implications for transparency and accountability.

Shreya Singhal Built A Floor. This Walks Under It.

The Court has already laid down principles of reviewability for closely analogous situations. In Shreya Singhal v. Union of India, while striking down Section 66A and reading down the intermediary liability provisions, yet upholding Section 69A and the Blocking Rules, the Court took care to distinguish between the two kinds of censorship. Section 66A was unconscionable precisely because it lacked procedure or safeguards; the blocking regime survived because it did not it carried, on the Court’s reading, a reasoned order passed by a designated authority, an opportunity for hearing, and an order that could be reviewed by a court.

A reasoned order passed by a designated authority is what ultimately saved Section 69A from being struck down for vagueness and overbreadth. We have seen since how the confidentiality that Rule 16 of the Blocking Rules imposes on intermediaries operates to the detriment of users. In the Tanul Thakur petition before the Delhi High Court, where a satirical web page had been taken offline, the central grievance was exactly this: the user could not act on his rights because the order was known only to the intermediary, and the intermediary was bound to keep it secret.

The same problem applies with greater force to Rule 23(2). What is reachable under Rule 23 is more pervasive than anything a blocking order under Section 69A can achieve; it touches every data fiduciary holding any information about you, and Rule 8(3) guarantees that a year’s worth of it is there to be reached. The protections Shreya Singhal gives to internet users do not extend to data principals, because Rule 23(2) contains none of the safeguards the Court treated as necessary: no reasoned order, no opportunity for hearing, no reviewability by a court. It goes further: by making the fact of the demand confidential, it renders the whole exercise inaccessible even to the person whose data is taken. A law which makes demands of citizens while keeping them in ignorance of the terms of those demands cannot be just, and certainly not one that upholds the right to privacy.

The Proportionality Floor, And Who Gets To Lift The Gag

Puttaswamy holds that an intrusion into informational privacy must satisfy legality; there must be a law, not an executive direction or order, a legitimate State aim, and proportionality of means to that aim. Kaul J., in his separate opinion, added a fourth requirement: procedural guarantees against abuse. It is the fourth that Rule 23(2) cannot meet.

The content of that requirement comes from PUCL v. Union of India, where the Court, examining the phone-tapping power under Section 5(2) of the Telegraph Act, mandated safeguards before such surveillance could be justified: authorisation at a specified level of seniority, a review committee, limited retention of intercepted material, and limits on the duration of interception. Extensive surveillance intruding into the privacy of a citizen’s conversation required procedural prerequisites to prevent abuse.

The power under Rule 23 ought to satisfy the same floor. It is broader in reach than the interception power in PUCL, since it applies to every entity handling any information about a person rather than to a communication channel. Yet the safeguards are minimal, and the objective is stated at a level of generality from the security of the State to the performance of the State’s own statutory functions that does no limiting work. Authorisation comes from a designated officer of the same government making the demand. There is no review committee. There is no time-limit on the gag, and the retention floor runs the other way. The order, if there is one in writing at all, is confidential, which means the very fact and manner of its issuance is placed beyond judicial scrutiny. A framework that claims procedural safeguards while keeping the existence of those safeguards confidential has not met the requirement; it has restated it.

The person who can lift the gag is the authorised person who issued the demand. The justification is “security of the State”. The phrase is not itself the objection; it appears in Section 5(2) of the Telegraph Act and in Section 69A of the IT Act, and both survived. They survived because they were fenced: PUCL supplied the review committee and the retention limits, Shreya Singhal supplied the reasoned order and the reviewability. The phrase is constitutionally tolerable only when fenced. Rule 23(2) borrows the phrase and supplies no fence.

Even the surveillance states do better than this

The closest analogy is the National Security Letter, which the FBI has used to demand information from third parties, usually telecom and internet companies, under a statutory bar on the recipient disclosing that the demand was made. NSLs operated much as Rule 23(2) will: the recipient was silenced, the individual was never told, no reason was given, and no route to challenge was offered.

In John Doe, Inc. v. Mukasey, the Second Circuit held that the non-disclosure provisions of the NSL statute failed First Amendment scrutiny. Applying Freedman v. Maryland, it held that a gag of this kind requires the government, not the recipient, to bear the burden of initiating prompt judicial review, and that the statutory provisions treating the executive’s certification as effectively conclusive could not stand. The court declined to rewrite the statute to create that obligation, holding it beyond judicial authority to do so; instead it set out a “reciprocal notice” procedure the government could adopt voluntarily to tell the recipient it may object, and if it objects, go to court within a set period and justify the secrecy there, subject to time limits. Congress subsequently codified a review-and-termination requirement in the USA FREEDOM Act, 2015, so that a gag must be revisited and lifted when its justification lapses. None of this is present in Rule 23(2).

That comparison points to the argument that an Indian court is best placed to hear. Doe was a speech case. So is this. Rule 23(2) restrains the data fiduciary from telling anyone what it has been made to hand over: a prior restraint on the fiduciary’s own speech, imposed without an order, without reasons, and without a terminus. A restriction on Article 19(1)(a) must be imposed by “law” within the meaning of Article 19(2), and a rule with no parent in the statute is not law for that purpose. This also answers the standing problem the framework otherwise creates. The data principal cannot challenge an order she will never hear about. The fiduciary can, because it is the one being silenced.

A measure that lets the State take information without disclosure to the person affected, and without any process by which anyone can test its existence or seek a remedy, is unreasonable on its own terms. That the country which pioneered such secrecy has since walked it back, under pressure from its own courts, does not make the Indian version look better by comparison.

This is fixable, and the clock hasn’t run

There is time. The provision is not yet in force, and that is the most important point in this piece. The fixes are not complicated: impose a standard of reasonableness and a set of procedural prerequisites on the issuing of the gag; make it time-bound, so that secrecy is imposed for a limited duration at a time and must be renewed on reasons; make the review independent of the officer who made the demand; and ensure that the person affected learns of the demand’s existence at some point. Above all, put the power in the Act, where Parliament can see it, rather than in a rule that claims a parent it does not have.

None of these compromises the stated objective. A law that can demand the secrecy of your information from every entity that holds it, without oversight or reasonableness, is a law that has given up on transparency and accountability, both of which Puttaswamy treats as integral to a constitutional order. A law which protects your data from every private actor while granting the State a perpetual ability to conceal and access it without notice or review is not a law which protects your privacy. It is a law which transfers the threat to your privacy to another entity, and covers it up.

Latest Publications

Recent Published Posts

GET IN TOUCH

Collaborate with us for Research and Policy Innovation

We welcome collaborations, research partnerships, and inquiries related to cyber law, governance, and digital policy. Whether you are an academic, policymaker, or institution, we’d be delighted to explore how CRGCL can work with you on impactful research and outreach initiatives.

Why Collaborate with CRGCL:
Reach Out to Our Research Team