DPDP Removal of Difficulties Order, 2026: what changed in Sections 9 and 10?
Two very small wording changes have practical consequences. One clarifies when guardian consent applies. The other makes clear that a Significant Data Fiduciary’s periodic audit is a data audit.
The short version: this is a notified correction, not a new draft law. It does not create new penalties or bring the main DPDP commencement date forward. But organisations should check two things: how they handle consent for a person with disability who has a lawful guardian, and—if they are notified as a Significant Data Fiduciary—whether their periodic audit is genuinely a data-protection/data audit.
What exactly was notified?
The Ministry of Electronics and Information Technology issued the Digital Personal Data Protection (Removal of Difficulties) Order, 2026 under Section 43 of the DPDP Act. The Order is numbered S.O. 5458(E), dated 5 October 2026, and was published in the Gazette of India on 7 October 2026 under Gazette ID CG-DL-E-07102026-276885.
The Order makes only two textual substitutions in the Act:
| Provision | Earlier wording | After the 2026 Order |
|---|---|---|
| Section 9(1) | “child or a person with disability” | “child or of a person with disability” |
| Section 10(2)(c)(ii) | “periodic audit” | “periodic data audit” |
Change 1: disability alone does not automatically mean guardian consent
Section 9(1) deals with verifiable consent before processing personal data of a child or of a person with disability who has a lawful guardian. Adding the missing word “of” makes the sentence read the way the surrounding provision was intended to work.
For employees and operational teams, the practical message is simple: do not assume that every person with a disability requires guardian consent. The lawful-guardian qualification matters. Where your organisation handles this kind of data, the approved consent and verification process should reflect that distinction.
Change 2: “periodic audit” is now expressly “periodic data audit”
Section 10 applies to organisations that the Central Government notifies as Significant Data Fiduciaries (SDFs). The Act already requires an SDF to appoint an independent data auditor to carry out a data audit. The 2026 Order now also changes the separate reference to “periodic audit” so that it expressly says “periodic data audit.”
That matters because an ordinary financial audit, a generic cybersecurity review, or an ISO certificate should not simply be assumed to satisfy this requirement. The audit is about observance of the DPDP Act and Rules.
How often is the data audit required?
The 2026 Order does not create a new frequency. The final DPDP Rules already provide that an SDF must undertake a Data Protection Impact Assessment and an audit once in every twelve-month period from the date on which it is notified as an SDF. The person carrying out the assessment and audit must furnish a report of significant observations to the Board.
What the Order does not change
- It does not create a new category of Significant Data Fiduciary.
- It does not introduce a new penalty.
- It does not change the definition of a child.
- It does not say that every person with a disability needs guardian consent.
- It does not introduce a new audit frequency.
- It does not, by itself, bring forward the separate commencement dates of Sections 9 and 10.
Do employee-awareness courses need to change?
For a general employee-awareness course, the answer is only slightly. If training material discusses a person with disability, it should not suggest that disability by itself triggers guardian consent. The employee-facing message should refer to a person with disability who has a lawful guardian and tell the employee to follow the organisation’s approved process.
The new “data audit” wording does not justify adding a detailed audit-law module to a normal employee course. Independent data auditors, DPIAs and SDF audit cycles belong primarily with privacy, compliance and governance teams—not every employee.
What should organisations do now?
- Review consent wording and onboarding flows where data of children or persons with disability may be processed.
- Check training material for any blanket statement that disability automatically means guardian consent.
- If you are or expect to be an SDF, review the scope of your audit engagement so it clearly covers DPDP compliance rather than relying on a general-purpose audit.
- Keep evidence of the controls you actually operate. Policies are useful; organised records showing what was done are much easier to demonstrate during a review.
When someone asks “Who was trained?” — answer in seconds.
With the DPDPA Awareness Course on the Abhisam LMS, enrolment, completion status and Final Assessment results are already organised in one place. Export the records to Excel or CSV instead of rebuilding the evidence from emails and spreadsheets when an internal reviewer or auditor asks for it.
The dashboard makes the employee-training evidence part of reviews and audits easier. It does not itself perform or replace the statutory data audit required of a Significant Data Fiduciary.
Primary sources
- Gazette of India eGazette — search Gazette ID CG-DL-E-07102026-276885 / S.O. 5458(E).
- Digital Personal Data Protection Rules, 2025 — official MeitY Gazette PDF.
- Digital Personal Data Protection Act, 2023 — official MeitY PDF.
DPDPA Employee Training