આ પસંદગી જ આ પાનાનો મુદ્દો છે. કલમ ૫(૩) અને ૬(૩) મુજબ વ્યક્તિને નોટિસ અને સંમતિની વિનંતી અંગ્રેજીમાં અથવા બંધારણની આઠમી અનુસૂચિની કોઈ પણ ભાષામાં જોવાનો વિકલ્પ મળવો જોઈએ. ગુજરાતી એમાં છે. This choice is the page's own point. Sections 5(3) and 6(3) require that the individual be given the option to access the notice and the consent request in English or any language in the Eighth Schedule to the Constitution. Gujarati is one of them.
DPDP Core · Gujarat

ગુજરાતના ઉદ્યોગો માટે DPDP: એક પાનું

મિલ, હીરાના કારખાના, કેમિકલ પ્લાન્ટ, સિરામિક, એન્જિનિયરિંગ યુનિટ અને નિકાસકારો માટે. તમારું જોખમ ગ્રાહકના ડેટામાં નથી, કામદારોના ડેટામાં છે.

DPDP for Gujarat industry: one page

For mills, diamond units, chemical plants, ceramics, engineering units and exporters. Your exposure is not customer data. It is workforce data.

૧૩ નવેમ્બર ૨૦૨૫વ્યાખ્યાઓ, બોર્ડની રચના અને નિયમો બનાવવાની સત્તા. તમારા પર કોઈ ફરજ આવતી નથી.
13 November 2025Definitions, the Board's machinery and the rule making powers. No duty falls on you.
૧૩ નવેમ્બર ૨૦૨૬Consent Manager ની નોંધણી, કલમ ૬(૯), અને એની નોંધણીની શરતોના ભંગની તપાસ કરવાની બોર્ડની સત્તા, કલમ ૨૭(૧)(d). ઉત્પાદક એકમને આમાંનું કંઈ સ્પર્શતું નથી.
13 November 2026Consent Manager registration under section 6(9), and the Board's power under section 27(1)(d) to inquire into a breach of a Consent Manager's registration conditions. None of it reaches a manufacturer.
૧૩ મે ૨૦૨૭કલમ ૩ થી ૧૭ ની બધી ફરજો, ૬(૯) સિવાય જે વહેલી આવે છે, અને કલમ ૨૮ થી ૩૪, જેમાં કલમ ૩૩ ના દંડ છે. આ જ ખરી તારીખ છે.
13 May 2027Every operative duty in sections 3 to 17, apart from 6(9) which arrives earlier, plus sections 28 to 34, which is where the section 33 penalties sit. This is the date that matters.
ACT · Section 1(2); notification G.S.R. 843(E), 13 November 2025.

શું આ કાયદો અમને લાગુ પડે છે?

હા, ભલે તમારો એક પણ છૂટક ગ્રાહક ન હોય.

આ કાયદો "ડિજિટલ પર્સનલ ડેટા" ને લાગુ પડે છે, "ગ્રાહકના ડેટા" ને નહીં. તમારા કામદારો, નોકરી માટે અરજી કરનારા, અને દરેક ખરીદનાર, સપ્લાયર કે ટ્રાન્સપોર્ટર પાસેની નામવાળી સંપર્ક વ્યક્તિ, આ બધા વ્યક્તિઓ છે.

ત્રણસો કામદારો હોય અને એક પણ છૂટક ગ્રાહક ન હોય, તો પણ તમે આ કાયદાની અંદર છો. ઔદ્યોગિક વસાહતોમાં આ સૌથી વધુ થતી ભૂલ છે.

Does this law apply to us?

Yes, even with no retail customers at all.

The Act applies to digital personal data, not to customer data. Your workers, your job applicants and the named contact person at each buyer, supplier and transporter are all individuals.

A unit with three hundred workers and not a single retail customer is squarely inside the Act. This is the most common misreading in an industrial estate.

ACT · Sections 3 and 4; the definition of personal data in section 2(t).

તમારો ઉદ્યોગ, વિગતવાર

આ નવ ઉદ્યોગો Sector Reference માં ઉમેરાયા છે, જ્યાં કુલ ૨૬ ક્ષેત્રો છે. દરેકમાં લખ્યું છે કે વ્યવહારમાં શું processing થાય છે, કઈ જોગવાઈ હેઠળ, એની હદ ક્યાં પૂરી થાય છે, અને ઉદ્યોગમાં જે વાતો કહેવાય છે તેની સામે કાયદો ખરેખર શું કહે છે.

Your industry, in detail

These nine sit inside the Sector Reference alongside seventeen others, twenty six in all. Each one sets out what is processed in practice, under which provision, where that permission stops, and what the Act actually says in reply to the claims the industry makes.

ACT · Sections 4, 7 and 8; RULES · Rules 6 and 7.

કામદારોની સંમતિ જોઈએ?

ના. અને આ રાહતના સમાચાર છે.

નોકરી એ કલમ ૭(i) હેઠળ "certain legitimate use" છે. પગાર, હાજરી, ગેટ પાસ, એક્સેસ કન્ટ્રોલ, આના માટે સંમતિ જોઈતી નથી.

નોટિસ પણ નહીં. કલમ ૫(૧) મુજબ નોટિસ ત્યારે જ આપવી પડે જ્યારે કલમ ૬ હેઠળ સંમતિ માંગવામાં આવે. અહીં સંમતિ માંગવાની જ નથી, એટલે નોટિસની ફરજ ઊભી થતી નથી.

સંમતિ ફોર્મ પર ભરોસો રાખવો ખરેખર નબળી સ્થિતિ છે. સંમતિ ગમે ત્યારે પાછી ખેંચી શકાય છે. Legitimate use પાછું ખેંચી શકાતું નથી.

Do we need worker consent?

No. And that is the relief in this law, not the burden.

Employment is one of the certain legitimate uses under section 7(i). Payroll, attendance, gate passes and access control do not run on consent at all.

Nor is a notice owed. Section 5(1) requires a notice where a request for consent is made under section 6. Here no consent is requested, so no notice duty arises.

Leaning on a signed consent form is actually the weaker position. Consent can be withdrawn at any time with comparable ease. A legitimate use cannot be withdrawn.

ACT · Sections 4, 5(1), 6(4) and 7(i).

તો શું કરવાનું છે?

સંમતિ ન જોઈતી હોય તો પણ કલમ ૮ ની બધી ફરજો લાગુ પડે છે. આધાર ગમે તે હોય, આ છ વસ્તુઓ બાકી રહે છે.

Then what do we actually owe?

A legitimate use removes the need to ask. It removes nothing else. Every section 8 obligation still applies, whatever basis you rely on, and these six carry most of the weight.

  1. સુરક્ષાRule 6 એન્ક્રિપ્શન, obfuscation, માસ્કિંગ કે virtual token માંથી કોઈ એક માંગે છે, સાથે એક્સેસ કન્ટ્રોલ, લોગ જે કોઈ ખરેખર તપાસે, અને બેકઅપ. એ લોગ અને એ ડેટા એક વર્ષ સાચવવા પડે, સિવાય કે બીજો કોઈ કાયદો જુદું કહે. કલમ ૮(૫), Rule 6(1).
  2. SecurityRule 6 asks for one of encryption, obfuscation, masking or virtual tokens, along with access control, logs that somebody actually reviews, and backups. Those logs and that data must be retained for one year, unless another law in force requires otherwise. Section 8(5), Rule 6(1).
  3. Breach ની જાણદરેક અસરગ્રસ્ત વ્યક્તિને વિલંબ વગર. બોર્ડને બે તબક્કે: વિલંબ વગર breach નું વર્ણન, અને પછી ૭૨ કલાકમાં વિગતવાર અહેવાલ, જે મુદત બોર્ડ લેખિત વિનંતી પર જ લંબાવી શકે. કોઈ લઘુત્તમ મર્યાદા નથી, નાનામાં નાનો breach પણ ગણાય. કલમ ૮(૬), Rule 7.
  4. Breach reportingEvery affected person without delay. The Board in two stages: a description without delay, then the detailed report within seventy two hours, extendable only on a written request the Board allows. There is no materiality threshold, so the smallest breach counts. Section 8(6), Rule 7.
  5. Retentionહેતુ પૂરો થાય એટલે ભૂંસી નાખો, સિવાય કે કોઈ કાયદો રાખવાનું કહે. PF, ESI અને આવકવેરાના રેકોર્ડ રાખવા જ પડે. વહેલા ભૂંસી નાખવું એ પોતે એ કાયદાનો ભંગ બની શકે. કલમ ૮(૭).
  6. RetentionErase when the purpose is served, unless another law in force requires you to keep it. Provident fund, employees state insurance and income tax records do. Deleting early can itself breach that other law. Section 8(7).
  7. નામવાળો સંપર્કવેબસાઇટ કે app પર એવી વ્યક્તિનું નામ અને સંપર્ક પ્રગટ કરો જે તમારા ડેટા વિશે જવાબ આપી શકે, અને અધિકારો અંગેના દરેક જવાબમાં એ સંપર્ક લખો. આ ફક્ત મોટી કંપનીઓ માટે નથી, દરેક માટે છે. કલમ ૮(૯), Rule 9.
  8. A named contactPublish on your website or app the business contact information of a person who can answer questions about your processing, and repeat that contact in every response to a communication about rights. This is not a large company duty. It is everyone's. Section 8(9), Rule 9.
  9. કામદારના અધિકારો, અને એની ખરી હદફરિયાદનો અધિકાર, કલમ ૧૩, હંમેશા લાગુ પડે છે, અને પ્રગટ કરેલી વ્યવસ્થાએ ૯૦ દિવસથી વધુ ન લેવો જોઈએ. પણ "શું રાખ્યું છે તે જણાવો", કલમ ૧૧, અને "સુધારો કરો", કલમ ૧૨, એ બંને સાંકડા છે: એ ફક્ત એવા ડેટા સુધી પહોંચે છે જે વ્યક્તિએ સંમતિથી અથવા કલમ ૭(a) હેઠળ પોતે આપ્યો હોય. કલમ ૭(i) હેઠળ તમે પોતે બનાવેલા રેકોર્ડ, જેમ કે appraisal કે monitoring log, એ બે અધિકારોની બહાર છે. કલમ ૧૧ થી ૧૩, Rule 14.
  10. Worker rights, and their real limitThe grievance right in section 13 always applies, and the published system must respond within a period not exceeding ninety days. Access under section 11 and correction under section 12 are narrower: both reach only processing the person consented to, or voluntarily provided under section 7(a). Records you generated about her under 7(i), an appraisal or a monitoring log, sit outside those two rights. Sections 11 to 13, Rule 14.
  11. કોન્ટ્રાક્ટર સાથે લેખિત કરારકલમ ૮(૨) કરાર ફરજિયાત બનાવે છે, પણ એના શબ્દો "Data Principals ને માલ કે સેવા આપવા સંબંધિત પ્રવૃત્તિ" પૂરતા મર્યાદિત છે, એટલે ફક્ત પગાર બનાવતી એજન્સી કદાચ એમાં ન આવે. તેમ છતાં કરાર જોઈએ જ, કારણ કે કલમ ૮(૧) મુજબ તમારા વતી થતા processing ની જવાબદારી કરારમાં ગમે તે લખ્યું હોય તો પણ તમારી રહે છે, કલમ ૮(૫) સુરક્ષાની ફરજ processor પર થતા કામને પણ આવરી લે છે, અને Rule 6(1)(f) મુજબ કરારમાં સુરક્ષાની જોગવાઈ હોવી જોઈએ. કલમ ૮(૧), ૮(૨), ૮(૫), Rule 6(1).
  12. A written contract with contractorsSection 8(2) makes a contract compulsory, but its words reach only an activity related to offering goods or services to Data Principals, so an agency that merely runs your payroll may fall outside it. You still need the contract, because section 8(1) leaves the responsibility with you irrespective of any agreement to the contrary, section 8(5) extends your security duty to processing carried out on your behalf, and Rule 6(1)(f) requires security provisions in that contract wherever applicable. Sections 8(1), 8(2), 8(5), Rule 6(1).

Biometric હાજરી અને CCTV

ચાલશે. તમને જે કહેવાયું છે તે ખોટું છે.

આ કાયદામાં "sensitive data" જેવી કોઈ અલગ કેટેગરી જ નથી. આંગળીની છાપ અને નામ, બંને એક જ સ્તરે છે. એટલે biometric હાજરી માટે કોઈ ખાસ પરવાનગી કે અલગ ફોર્મ જોઈતું નથી.

અને કલમ ૭(i) સ્પષ્ટ શબ્દોમાં કહે છે કે માલિકને નુકસાન કે જવાબદારીથી બચાવવા માટેનું processing પણ legitimate use છે, જેમાં corporate espionage અટકાવવું અને trade secrets ની ગુપ્તતા સામેલ છે. હીરાના કારખાનામાં ટેબલ પર લાગેલા કેમેરા આ જ કલમ પર ઊભા છે.

મર્યાદા આટલી: એ ફૂટેજ બીજા કોઈ કામ માટે ન વાપરો, હેતુ પૂરો થયા પછી ન રાખો, અને કામની બહાર કામદાર પર નજર ન રાખો.

Biometric attendance and CCTV

Both are lawful. What you have been told is wrong.

The Act has no sensitive data category at all. A fingerprint sits on exactly the same footing as a name, so biometric attendance needs no special permission and no separate form.

Section 7(i) goes further and says so in its own words: processing related to safeguarding the employer from loss or liability is a legitimate use, and it names prevention of corporate espionage and confidentiality of trade secrets as examples. The cameras over a polishing table stand on that provision.

The limits are these. Do not use that footage for something unrelated, do not keep it once the purpose it was taken for has passed, and do not watch a worker outside work.

ACT · Section 7(i); 8(5) and 8(7); RULES · Rule 6.

નિકાસ અને વિદેશમાં ડેટા મોકલવો

ભારતની બહાર ડેટા મોકલવો by default ખુલ્લો છે.

કલમ ૧૬(૧) સરકારને એવો દેશ notify કરીને એના પર પ્રતિબંધ મૂકવાની સત્તા આપે છે. એટલે પ્રતિબંધ પહેલાં જાહેર થવો પડે. તમારે પહેલાં એ સાબિત કરવાનું નથી કે સામેનો દેશ સલામત છે.

યુરોપ જેવું "adequacy decision" ભારતના કાયદામાં છે જ નહીં. કોઈ સલાહકાર ભારતીય કાયદા હેઠળ એ માંગે, તો એ એવો દસ્તાવેજ માંગે છે જે આ કાયદો બનાવતો જ નથી.

બે અપવાદ ધ્યાનમાં રાખો. કલમ ૧૬(૨) મુજબ બીજો કોઈ ભારતીય કાયદો વધુ કડક હોય તો એ પૂરેપૂરો ચાલુ રહે છે. અને Rule 15 મુજબ વિદેશી સરકાર કે એના નિયંત્રણ હેઠળની સંસ્થાને ડેટા આપવા બાબતે સરકાર શરતો મૂકી શકે છે.

SEZ યુનિટ માટે કોઈ છૂટ નથી. કસ્ટમ્સ ટેરિટરીની બહાર હોવું એ કસ્ટમ્સનો સવાલ છે, આ કાયદાનો નહીં.

Exports and sending data abroad

Transfer out of India is open by default.

Section 16(1) gives the Central Government a power to restrict transfer to a country it notifies, which means a restriction has to be announced before it bites. You are not required to establish first that a destination is safe.

There is no Indian adequacy decision. If a consultant asks you to produce one under this Act, they are asking for a document the Act does not create.

Two things do sit on top. Section 16(2) preserves any Indian law that already imposes a stricter transfer rule, so sectoral requirements keep their full force. And Rule 15 lets the Government specify requirements about making data available to a foreign State, or to a person or entity under its control.

There is no exemption for a special economic zone. Being outside the customs territory answers a customs question, not this one.

ACT · Sections 16(1) and 16(2); RULES · Rule 15.

નાના યુનિટ માટે છૂટ છે?

નથી. કોઈ પણ પ્રકારની નથી.

ટર્નઓવર, કામદારોની સંખ્યા, MSME નોંધણી, આમાંથી કોઈ threshold આ કાયદામાં નથી.

મોટા હોવાનું પરિણામ ઊલટું છે. કલમ ૧૦(૧) મુજબ સરકાર કેટલાંક પરિબળો જોઈને કોઈને Significant Data Fiduciary જાહેર કરી શકે છે, જેમાં ડેટાનું પ્રમાણ, વ્યક્તિના અધિકારો સામેનું જોખમ, અને દેશની સુરક્ષા જેવાં પરિબળો છે. એવું જાહેર થાય તો દર વર્ષે impact assessment અને audit સહિતની વધારાની ફરજો આવે છે. ફરજો વધે છે, ઘટતી નથી.

Is there an exemption for small units?

No. There is none of any kind.

There is no turnover threshold, no headcount threshold and no MSME exemption anywhere in the Act.

Being large cuts the other way. Section 10(1) lets the Government notify a Data Fiduciary as a Significant Data Fiduciary after weighing several factors, among them the volume of data processed, the risk to the rights of individuals, and the security of the State. Being notified brings extra duties, including an annual impact assessment and audit. It adds duties. It never subtracts them.

ACT · Sections 3, 10(1) and 17; RULES · Rule 13(1).

દંડ

આ ટોચમર્યાદા છે. "May extend to" એટલે વધુમાં વધુ. આ "per record" દંડ નથી, અને દરેક ભૂલ માટે આખી રકમ લાગુ પડતી નથી.

Penalties

These are ceilings. "May extend to" means at most. They are not per record figures, and the full amount does not attach to every failure.

શેની ચૂકવધુમાં વધુ
The failureCeiling
સુરક્ષાની વાજબી વ્યવસ્થા ન રાખવી, કલમ ૮(૫)રૂ. ૨૫૦ કરોડ
Failing to take reasonable security safeguards, section 8(5)Rs 250 crore
Breach ની જાણ બોર્ડ કે વ્યક્તિને ન કરવી, કલમ ૮(૬)રૂ. ૨૦૦ કરોડ
Failing to notify the Board or the affected person of a breach, section 8(6)Rs 200 crore
બાળકોના ડેટા અંગેની વધારાની ફરજો, કલમ ૯રૂ. ૨૦૦ કરોડ
The additional obligations on children's data, section 9Rs 200 crore
Significant Data Fiduciary ની વધારાની ફરજો, કલમ ૧૦રૂ. ૧૫૦ કરોડ
The additional obligations of a Significant Data Fiduciary, section 10Rs 150 crore
આ કાયદા કે નિયમોની બીજી કોઈ પણ જોગવાઈરૂ. ૫૦ કરોડ
Any other provision of the Act or the RulesRs 50 crore
ACT · The Schedule, read with section 33.

આ મહિને કરવા જેવી ત્રણ વસ્તુ

એક. જુઓ કે કામદારોના ડેટાની નકલો ક્યાં ક્યાં પડી છે. મોટે ભાગે જવાબ છે: સુપરવાઇઝરના ફોનમાં અને WhatsApp ગ્રુપમાં. ઓળખના દસ્તાવેજો અને બેંક વિગતો ત્યાં હોય તો ત્યાં તમારું કોઈ એક્સેસ કન્ટ્રોલ નથી, તપાસવા જેવો કોઈ લોગ નથી, અને પછી ભૂંસી શકાતું નથી.

બે. લેપટોપ પર full disk encryption ચાલુ કરો અને એનો પુરાવો રાખો. Rule 6(1) એન્ક્રિપ્શન, obfuscation, માસ્કિંગ કે virtual token માંથી કોઈ એક માંગે છે, અને લેપટોપ પર એન્ક્રિપ્શન સૌથી સહેલું અને સૌથી સહેલાઈથી સાબિત થાય એવું છે.

ત્રણ. એક નામ નક્કી કરો જે ડેટા વિશે જવાબ આપશે, અને એ નામ અને સંપર્ક વેબસાઇટ પર મૂકો. આમાં ખર્ચ કંઈ નથી અને આ કલમ ૮(૯) ની સીધી ફરજ છે.

Three things worth doing this month

One. Find out where copies of worker data actually sit. The answer is usually a supervisor's phone and a WhatsApp group. Identity documents and bank details there have no access control you own, no log anyone reviews, and no realistic way to erase them later.

Two. Turn on full disk encryption centrally and keep the evidence. Rule 6(1) asks for one of encryption, obfuscation, masking or virtual tokens, and on a laptop encryption is both the easiest to apply and the easiest to prove.

Three. Name one person who will answer questions about your data, and publish that name and contact on your website. It costs nothing and it is a direct duty under section 8(9).