This article was originally written as an academic paper and is republished here as a knowledge-sharing resource. It has been lightly formatted; statutory references reflect the law as it stood at the time of writing.
1 Raj Deepak Chaudhary, Research Scholar, School of Legal Studies, BBDU, Lucknow
Prof. (Dr.) Arun Verma, School of Legal Studies, BBDU, Lucknow
Abstract
The Government had enacted the Digital Personal Data Protection Act (“DPDP”) to its protect people's right to keep their information safe and to make sure that it is not processed illegally by putting responsibilities on data fiduciaries, government bodies and private companies as well. This law is a big step forward for India, but it still has a long way to go compared to many other economies that have been working on privacy and data protection concerns for more than 50 years.
The present research paper employs a qualitative doctrinal methodology to examine the evolution of the concept of privacy, highlighting judicial interventions and the subsequent legislative developments that have shaped the data protection framework in the country. This paper's arguments provide a comprehensive examination of the DPDP legislation by analysing its structure, fundamental concepts, and essential sections in relation to worldwide standards.
Judges and administrators have repeatedly said that vague phrases in the act can cause confusion, which means that the courts need to step in often. There are big problems with enforcement and operations because there are gaps in the rules about how much the government is exempt from, how independent the board is and also how hard it is for different corporations to comply. Also, there are areas that need to be addressed right away, like the function of artificial intelligence ("AI"), the Internet of Things ("IoT"), big data analytics and automated decision-making technology, among other emerging concerns. To bring the digital economy of India up to par with global leaders, these areas need to be changed, and new rules and regulations need to be made.
Keywords: India, data protection, privacy, history, provisions and challenges, Data fiduciary, Consent in data processing, Cross-border data transmission, Sensitive personal data, Data localisation, Data protection authority, etc.
Introduction
The Digital Age has fundamentally reshaped the world, transforming human life in unprecedented ways. From performing basic tasks to executing complex calculations, digital technology now permeates nearly every facet of our existence. Its widespread integration across sectors—banking, education, healthcare, business, and manufacturing—has revolutionised global economies. Simultaneously, the rise of digital connectivity through social media has redefined how we interact, communicate, and even think.
The Internet's arrival should definitely be praised for bringing forth an era of globalisation that people can access from the comfort of their own homes. But this blessing hasn't come without problems. This same technology that has made things easier has also made new threats possible that we couldn't have imagined before. People are now "users," and their personal information is now "data," which is a lucrative resource that is often called as the new oil. Tech businesses, motivated by their profits, started using the Internet's ability to collect massive amounts of data. Digital services that seem free typically use advanced ways to collect data, like algorithms that change how people act which helps AI to evolve. In this case, the proverb still holds true: if you don't pay for the goods, you are the product.
In the past, people tended kept their personal lives and private matters mostly to themselves. However, now, improvements in surveillance technologies, such as listening devices and cameras that are everywhere have made it harder for people to keep their privacy while still being connected to each other. In this age of digital dominance, the conflict between technical advancement and the safeguarding of essential liberties has reached unprecedented levels. The idea of privacy is not new or limited to modern legal discussions. It has strong roots in various areas such as culture, morality and religion. For a long time, the right to be alone and not be bothered by others has been recognized to be a basic part of human dignity. In ancient India, privacy was an important part of social norms and morals. For example, in the epic Ramayana, Ravana violated Sita's autonomy and dignity while she was in captivity and this ultimately shows the psychological and moral effects of invading someone's personal space. Likewise, Draupadi's public disrobing in the Mahabharata's renowned game of dice is a clear example of how privacy and dignity can be violated in a terrible way. This moral failure led to the great war of Kurukshetra, which was a sign of how not respecting people's private may break up social harmony. The idea of personal sovereignty in the home was also present in ancient Indian thinking, as seen by the statement सर्वाः स्व गृहे राजा (Sarvāḥ sva gṛhe rājā), which basically means that every man is king in his own home. This idea is very similar to the Western legal saying that, “a man's home is his castle.” In Semayne's Case (1604), Sir Edward Coke has also popularly said, "the house of every one is to him as his castle and fortress." This stressed the right to keep others, especially the state out of one's private space. The philosophical foundations of the right to privacy can be attributed to Enlightenment philosophers, including John Locke. His idea of the social contract and his definition of inalienable natural rights liberty and property, implicitly encompassed the right to privacy. Locke posited that individuals, when entering a social contract to establish society and government, did not forfeit their own natural rights. So, privacy stayed a protected and important part of personal freedom.
Digital spying and data breaches are now worryingly widespread. The end of World War II and the ideological wars that followed between fascism, communism and liberalism made liberal democratic ideals the most important in the post war world. But George Orwell's apocalyptic vision in Nineteen Eighty-Four, where the phrase “Big Brother is watching you,” has become more and more relevant throughout the Cold War and subsequently. What was once a made-up story has become a real thing with 24/7 surveillance, data collecting and the ensuing loss of civil liberties. Governments around the world deployed surveillance technologies like wiretapping, hidden cameras and electronic monitoring which is always supposedly done for national security. This extensive infiltration has produced moral and legal issues, which has led several countries to create strong laws to protect people's privacy and personal information. These events show that the entitlement of privacy is not only a legal right, but along with it a sign of our common human dignity and freedom. As we deal with the problems of the digital era, it is important to find the right balance between technical advancement and maintaining this important right.
Although India has only recently recognized the challenges of the digital age—most notably through the landmark K.S. Puttaswamy v. Union of India case, which upheld privacy a fundamental right under the contours of Article 21 of the Constitution and provided constitutional foundation for data protection—this recognition came significantly later compared to developed countries that have been discussing and enacting data protection legislation for the past half century.
As India rapidly digitalized with widespread adoption of digital platforms in governance (through initiatives like Digital India), finance (via Aadhaar and UPI/online payment systems), education (ABC ID), health services (Ayushman cards), and virtually every sector of the economy, the volume of personal data collected, stored, and processed has grown exponentially. While these transformative changes have undoubtedly driven economic growth and innovation, they have also exposed Indian citizens to new and unprecedented risks of surveillance, data breaches, and unauthorised use of personal information. In response to these challenges, the Indian Parliament enacted the Digital Personal Data Protection Act, 2023 (DPDP Act), which represents the country's first comprehensive legislative framework specifically designed to address the protection of digital personal data in an increasingly connected world.
This paper undertakes a comprehensive analysis beginning with the historical development of privacy rights and assessment of 'privacy' as a concept in India, followed by tracing the evolution of data protection law, focusing on key provisions of the DPDP Act while comparing them with provisions under the GDPR and other developed jurisdictions. The analysis concludes with an examination of implementation challenges and future considerations for India's evolving data protection landscape.
Historical Evolution Of Privacy As A Right
Constitutional Framework
Although the idea of confidentiality has always existed in India, the initial draft of the Indian Constitution did not stipulate the "right to privacy." Nonetheless, the drafters of the founding document intended for the Directive Principles of State Policy ("DPSP"), which are found in Part IV, to act as foundational values for the general welfare of the populace. The role of the state was conceived as the enabler of individual progress.
However, as constitutional experience demonstrated, the state is also prone to excess, despite being constrained by the effective implementation of both vertical (federal structure between Centre and State) and horizontal (Judiciary, Executive, and Legislature as three separate organs of government) separation of powers. Article 21 under the aegis of the Part III of the India’s Constitution stipulates that “No person shall be deprived of his life or personal liberty except according to procedure established by law”, and this term ‘life or personal liberty’ has been progressively extended and interpreted through various judicial precedents to encompass within the right to privacy and various aspects of it, including Freedom of Consciousness, the Ability to Choose, the Right to be Left Alone, the Right to Refuse Self-Incrimination and also the right to be Forgotten/Erased.
Judicial Evolution of Privacy Rights
Early Restrictive Approach
Beginning with the instance of “M.P. Sharma v. Satish Chandra, D.M., Delhi & Ors.”, where the constitutional validity of the comprehensive confiscation and search of M/s Dalmia Jain Airways Ltd. & its affiliated group of business's information was raised before the Honourable Apex Court of the country as a violation of Fundamental Rights under Articles 20(3) & 19(1)(f), the Highest Court, taking the constitutional provisions literally, upheld that fact there consists no apparent right to privacy under the Indian Constitutional scheme. This judicial approach to privacy rights was noticeably restrictive in the beginning. Then, by a vote of 4:2, the majority in the instance of “Kharak Singh v. State of U.P.”, argued that the police's powers of surveillance violated fundamental rights provided by Articles 19(1)(d) & 21. The majority judgment cited the privacy doctrine established in the US ruling of Wolf v. Colorado. However, for the very first instance, the minority opinion acknowledged the right to privacy encompassed as the necessary component of both individual autonomy and freedom of movement, notwithstanding courts' repeated ruling that it is not a Fundamental Right under the Indian Constitution.
Then, in the historic case of “Govind v. State of M.P.”, which was brought against police monitoring, the Supreme Court at last acknowledged that the right to privacy is in fact a fundamental right that stems from the freedom of speech, movement and life. The personal details of the house, family, marriage, motherhood, reproduction and child-rearing were all considered to be covered and protected by the right to privacy. Nevertheless, it was also decided that the right to privacy might be restricted in the case of genuine and compelling "state interest."
Progressive Approach Development
The Hon'ble Apex Court ruled in “R. Rajagopal v. State of T.N”., which dealt with the prohibition on publishing an account of a condemned inmate (Auto Shankar), that one's right to privacy is a component of a constitutionally protected right to personal liberty and that it is both a fundamental right and a tort (meaning, an actionable claim). The Highest judicial authority further pointed out that a person has the right to protect the privacy of his or her own family members, marriage, procreation, parenthood, conceiving, and learning, among other matters and that no one may publish anything about them unless (i) the individual agrees or willingly puts themselves in dispute, (ii) the publication uses information that is in the public domain (apart from instances of rape, abduction and kidnapping ), or (iii) the individual is a public servant and the issue pertains to the performance of their official responsibilities.
A Multifaceted Methodology
In the context of the landmark ruling of “People's Union of Civil Liberties v. Union of India,” the highest court in the country interpreted Article 21 of the Constitution more broadly and held that telephone tapping violates privacy. It also established standards that serve as the foundation for the mechanisms for oversight in India's interception provisions, including: (i) only Central and state level home secretaries may issue surveillance orders; (ii) considerations such as the requirement of information and whether the data can be obtained through other means have been taken into account when approving its interception; (iii) address information and the individuals whose communications must be intercepted must be included in the order, indicating that the order can't be broadly reasoned; and (iv) a two-month limit was imposed on the duration of the interception made.
The right to privacy is a derivative of personal liberty, freedom of making an expression, and arguable also the freedom of movement, according to the ruling in this instance of “District Registrar and Collector, Hyderabad and others v. Canara Bank and others”. It was also decided that a person's privacy may be infringed by (1) statutory regulations, (2) administrative or even executive directives, and (3) court rulings.
If we look at the monumental “Selvi and others v. State of Karnataka and others”, the Supreme Court in this case established the confluence of the right to privacy with paragraph (3) of Article 20 of the Constitutional framework, acknowledging the significant distinction between the bodily/physical autonomy and psychological independence from intrusion of others. The Indian criminal and evidence-based system, according to the Honourable Apex Court, requires intrusion with the right to corporeal and physical privacy under specific conditions. That being said, it is not possible to force someone "to impart personal knowledge about a relevant fact." There should be no room for anyone else to attempt to subject someone to a narcoanalysis, polygraph test, or the Brain Electrical Activation Profile ("BEAP") examination without the individual's permission. This is because it would violate the subject's intellectual privacy and clashes with their self-determination, as their decision to make an assertion is a private one.
The Puttaswamy Watershed Moment
Last but not least, the constitutional bench of the Hon'ble Supreme Court upheld the constitutional validity of the Aadhaar Act, 2016 and the government's call to make it essential in the historical instance of “Justice K.S. Puttaswamy (Retd.) v. Union of India”. The judiciary held that users were free to disclose their Aadhaar data, but that doing so is not required unless they are using government subsidies. Because it failed to pass the proportionality test, the need to link Aadhaar to a mobile SIM card was declared unlawful. According to this criteria, the government must pass the legality, need or legitimacy, proportionality and procedural protections tests before it may enact legislation that subsumes privacy; as a result, the use of the Aadhaar databases for police investigations was deemed legitimate. Some clauses were declared unlawful, including Regulation 27(1) of the Authentication Regulations, which gave the UIDAI the authority to keep "authentication transactional data" (including metadata) for five years; however, the five-year archival period was shortened to six months. Additionally, Section 33(1) regarding the release of details in the event of a court order was overturned, with the stipulation that those who’s data has been disclosed must be given the chance to be heard. Additionally, Section 33(2)—which allowed for the dissemination of information in the name of national security—was invalidated. Additionally, it was determined that it was constitutional to link Aadhaar with PAN for income tax filing, and it was deemed unconstitutional and void for the State or any organisation or individual to use Aadhaar under any contract. It was also decided that Aadhaar cannot be made mandatory by institutions such as CBSE, NEET, JEE, UGC, etc.
The right to privacy is a fundamental right that flows from the Constitution's fundamental rights to life and personal liberty, according to the Aadhaar ruling. The Supreme Court acknowledged that privacy is not a fundamental right that cannot be restricted in certain specific situations. To do so, three requirements must be met: first, the state must have a legitimate interest in limiting the right; second, the restriction must be necessary and proportionate to accomplish that interest; and third, the restriction must be authorised by law. Since this historic ruling, India has come to recognise privacy as one of the most important rights in the contemporary digital world.
Development Of Data Protection Law In India
The Information Technology Act, 2000: Initial Framework and Limitations
Prior to comprehensive data protection legislation, India's initial approach to digital privacy was primarily governed by the Information Technology Act, 2000 (IT Act), enacted on October 17, 2000. This legislation represented India’s first systematic attempt to address issues arising from digital transactions and electronic communications, though its approach to privacy protection was limited and reactive rather than comprehensive. The IT Act included provisions that touched upon privacy and data security, but these were primarily focused on addressing specific harms rather than establishing a proactive framework for data protection. The Act's scope was largely confined to electronic records and digital signatures, with limited provisions addressing the broader spectrum of personal data protection that would become crucial in the subsequent digital transformation.
The IT Act's Section 2(o) establishes "data" as an expression of knowledge, information, facts, ideas, or instructions that are being or have been created in a standardised way and are meant to be handled in a computing system or network of computers. Data can be stored within the memory of a machine or in any other form and mediums such as machine printouts, magnetised or optical storage media, punched cards, or punched tapes. Data, messages, words, pictures, sounds, speech, programs, program code, software, databases, microfilmed material, and machine-generated microfilms are all considered forms of information under the aegis of this Act. Additionally, its Section 28 also gives the Controller or any person designated by him, the authority to look into any violations of the terms of this Act, rules, or regulations formed therein. According to Section 43, anyone who downloads, damages, or destroys data without the owner's or person in charge of the computer's consent is liable for compensation. Upon examination, Section 66E provides that the violation of an individual's physical privacy (private region) may result in a fine of up to two lakh rupees, a maximum of three years in prison, or both. Section 69 grants the appropriate government the authority to order the interception, monitoring, or presentation of any information using any computer resource in order to protect India's sovereignty, credibility, safety, protection, friendly interactions with different nations, general population order, or to prevent provocation to commit any crime that can be prosecuted or assessed. The Telecom Disputes Settlement and Appellate Tribunal was formed under Section 14 of the Telecom Regulatory Authority of India Act 1997. The Central Government may use any computer to monitor and gather network data or information thanks to Section 69B. According to Section 72, violating privacy or confidentiality by unapproved publication can result in a fine of up to one lakh rupees, two years in prison, or both. Those affected may petition the Adjudicating Authority designated according to section 46 for compensation.
Since, there was no specific provision which provided for data protection by body corporate, hence through IT (Amendment) Act, 2008 section 43A was added which obligated companies to protect all ‘sensitive personal data & information’, failure to secure it makes them responsible to undertake payment of damages by way of compensation to affected persons so affected and in instances of breach of confidentiality by private contractors as per section 72A, a penalty of confinement for a period that may even extend to a sum total of three years or a fine that may be as extensive as rupees five lakhs or both is stipulated. Also, the Indian Computer Emergency Response Team (“CERT-In”) was formed which was designated as the nodal agency for performing various tasks in the spectrum of cybersecurity in India.
Information Technology (Procedure and Safeguards for Interception, Monitoring and Decryption of Information) Rules, 2009
The Information Technology (Procedure and Safeguards for Interception, Monitoring and Decryption of Information) Rules, 2009 were brought in to lay down a legal procedure framework for interception & intermediaries are obligated to provide assistance. Absent permission coming from the Secretary of the Ministry of Home Affairs, the Central Government, or the State Government, as applicable, the Rule 24 forbids the detection, surveillance, or decoding of information. Except when it is needed for additional research, a security organisation ought to keep the obtained sensitive data maintained and it is to be destroyed after six months. Central Monitoring System was set up operating at pan-India level with headquarters at Delhi and 22 Regional Monitoring Centres giving centralised access to the Indian telecommunication network for intercepting & recording ordinary calls, emails, chat, location of persons, etc. The Rules were notified for blocking access to the website after being approved by the Designated Officer, confirmed by the Secretary of IT. Rule 11 provides that all such sensitive information gathered in such observations is to be destroyed within a period of nine months from the date of the order.
Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules") received notification under the aegis of Section 43A of the IT Act in response to the Government of India's 2010 Approach Paper on Privacy. The previously ambiguous term "sensitive personal data or information" was now defined to encompass private data such as credentials, financial data, medical information, biometric data, or any additional data that is maintained or processed under an authorised agreement or otherwise. Rule 2(b) also defined ‘Biometrics’ & 2(i) defined ‘Personal Information’.
The SPDI Rules obligated every corporate body to provide privacy policies and disclosure information while implementing and maintaining reasonable security practices. Failure to comply resulted in liability to compensate affected parties. Rule 5 specifically mandated obtaining consent via means such as email, letter or fax, prior to collecting, utilizing, or disseminating the concerned sensitive personal information for lawful and necessary purposes. The rules permitted disclosure of information only under specific circumstances: (i) when required by contract with the information provider; or (ii) when disclosed to governmental agencies mandated under law. Corporate entities also had to put in place thorough security procedures and guidelines, which included written security of information procedures and initiatives along with operational, technical, managerial and physical security controls appropriate for the informational assets under protection..
Justice AP Shah Group of Experts on the Privacy Issues of 2012
A list of suggested national privacy standards which ought to be adhered to in the development of a privacy legislation was included in the report, which was produced by the Planning Commission during sessions of the Group of Experts on Privacy Issues all through 2012. The group was presided over by Justice AP Shah, formerly the chief justice of the High Court of Delhi. These principles were primarily (i) Principle of Notice, (ii) Principle of Selection and Ascent, (iii) Principle of Collection Limitations, (iv) Principle of Purpose Limitations, (v) Principle of Access and Correction, (vi) Principle of Dissemination of Information, (vii) Principle of Security, (viii) Principle of Openness, and lastly (ix) Principle of Accountability.
The Digital Personal Data Protection Act, 2023: A Thorough Analysis
The Government of India established the J. B N Srikrishna Expert Panel in July 2017. The Committee published its final recommendation in July 2018 along with a draft Personal Data Protection Bill, 2019; however, the Bill was subsequently pulled in response to the ruling in “Justice K.S. Puttaswamy and Anr. v. Union of India and Ors.” on September 26, 2018, and an updated version of the Digital Personal Data Protection Bill, 2022 was circulated for public comment in November 2022. The Digital Personal Data Protection Act, 2023 took effect on August 11, 2023, after the aforementioned Bill was approved by both chambers of the legislature.
The Digital Personal Data Protection Act of 2023 (“DPDP Act”) has been brought to address comprehensive worries and parameters regarding personal data disseminated by Indians, incorporating their concerns, hopes, along with values of freedom through consent and control mechanisms. The Act emphasises fairness in data processing, which represents a cornerstone of India's constitutional framework and reflects the fundamental rationale behind the country's struggle for independence. The DPDP Act serves dual purposes: safeguarding persons' privacy from threats posed by both state and along with them, non-state entities, while advancing the general welfare and national interest. This legislation represents India's answer to the threats imposed by rapid digitalisation along with the exponential growth in personal data collection, storage, and processing across various sectors.
Under the scheme of the DPDP Act, Chapter 1 provides for important Definitions and the Applicability of this enactment. Chapter 2 pertains to the Obligation of Data Fiduciary, The concerned Chapter 3 deals with the Rights and Duties of Data Principle, additionally, Chapter 4 provides for Special Provisions regarding processing of data outside India & Exemptions, and Chapter 5 provides for the Data Protection Board of India. Powers, duties and procedures of the Board have been explained in Chapter 6, followed by Appeal and Alternate Dispute Resolution under Chapter 7. Chapter 8 deals with Penalty and Adjudication, and Chapter 9 provides for other Miscellaneous Provisions.
Definitions & Applicability (Chapter I)
According to the Section 2(h) of this statute, "data" is defined as a representation of facts, ideas, opinions, information, or instructions that can be processed, interpreted, or communicated by humans or by machines. If we compare the same to the IT Act, the DPDP Act uses the terminology ‘opinions’ instead of ‘knowledge’ to encompass a greater amount of information, including unsolicited views expressed by individuals.
The individual (including child, Person with Disability) whose information is being gathered is called the Data Principal. The entity/ persons which determine the concerned rationale and methods of handling of this personal data are called the Data Fiduciaries, and anyone who is processing this data to be used for the utilization of the Data Fiduciary is called a Data Processor. Also, the term ‘processing’ has been defined concerning digital personal data, including collecting, organising, storing, using, indexing, sharing or otherwise making accessible, limiting, deleting, or destroying.
The Act's Section 2(t) enunciates "personal data" as any information about someone that can be enumerated by or in relation with such data points, while Section 2(n) further specifies that "digital personal data" refers to private data in digitized form.
"Board" is defined in Section 2(c) as the Data Protection Board of India, which the Federal Government would create. An entity duly registered with such Board who runs as the sole locus for communication between these Data Principals and Data Fiduciaries is referred to as a "Consent Manager" under Section 2(g). According to Section 2(l), a "Data Protection Officer" is a person designated by a Significant Data Fiduciary.
According to section 2(u), a "personal data breach" is any unapproved handling of personal data or an unintentional publication, acquiring, communication, utilisation, modification, damage, or loss of control over personal data that jeopardises its availability, confidentiality, or integrity.
If digital personal data is processed both inside and outside of India and is related to providing the Data Principal with goods and services within India, Section 3 of the DPDP Act becomes applicable. It goes on to say that in the event the data is handled for any home or personal reason, the Act does not apply.
The DPDP Act regulates the handling of digital personal data, which includes data collected electronically or data that has been digitalised subsequent to being obtained directly or in another way. Processing that is done for domestic or personal purposes, as well as processing pertaining to public or publicly available personal data, is not covered by the DPDP Act.
Obligations of Data Fiduciary (Chapter II)
The justifications for handling personal data are outlined in Section 4 and include legitimate uses or permissible purposes with the data principal's agreement. According to Section 5, any inquiry for the Data Principal's consent must be accompanied by or precede notice from the Data Fiduciary about (i) the reason for data processing, (ii) how rights may be exercised, and (iii) how to file a complaint with the Board. Section 5(2) allows for post-enactment compliance, meaning that the data fiduciary was required to deliver the Data Principal Notice as specified in this section if permission was obtained prior to the Act's effective date. Regardless of any arrangement to the contrary, Section 8 puts a residuary duty on the data fiduciary, which is to uphold the completeness and accuracy of data, keeping data secure via the use of suitable administrative and technological safeguards, and destroy data after its purpose has been fulfilled. The Data Fiduciary must notify the Board and other impacted Data Principals of any breach involving personal data.
Special provisions are made in Section 9 for handling children's or people with disabilities' private information only with the parent's verified agreement. The Act also forbids tracking, behavioural evaluation, and individualised marketing, among other data processing and uses that could endanger children.
Based on an evaluation of pertinent factors, such as the amount and sensitive nature of private information processed, the risk to the privileges of the data principal, the possible effect on Indian sovereignty and integrity, the risk to the democratic processes, the safety of the State, and law and order, Section 10 permits the Central Government to designate a data fiduciary or class of data fiduciaries as Significant Data Fiduciaries.
Big tech companies like Alphabet Inc. (Google), Meta Platforms Inc. (Facebook, Instagram, WhatsApp), IBM, Microsoft, Amazon, and others are subject to extra responsibilities under this section, including the requirement of naming a Data Protection Officer and an unbiased Data Auditor, as well as regular Data Security and impact Assessments as well.
Responsibilities and Rights of Data Principal (Chapter III)
Right to recommend, right to complaint redress, right to acquire information about personal information, and right to have personal data corrected and erased. In addition to rights, the Data Principal is subject to a number of obligations under section 15. They are not allowed to: (i) file a baseless or fraudulent complaint; (ii) provide any fake information or pretend to be someone else. A data principal must (a) abide by the terms of every relevant laws, (b) make sure that no material information is suppressed, (c) make sure that no baseless or fraudulent complaints or grievances is filed with the Board or a data fiduciary, and (d) only provide information that can be verified as authentic.
Special Provisions (Chapter 4)
With the exception of nations or areas that the Central Government has restricted by notification, Section 16 permits Data Fiduciary to transmit personal data to be processed purposes elsewhere than India.
Exemptions from Section 17 and the implementation of the Data Principal's rights and the Data Fiduciaries' duties (apart from data security) for (i) preventing and investigating offences and (ii) upholding legal entitlements or demands. Additionally, it gives the Central Government requisite mandate to exclude specific operations from the Act's application, such as Data Fiduciary and start-ups. These actions include (i) handling by government entities for the purpose of general safety and security of the state, and (ii) investigation, recording, or statistical analysis.
Data Protection Board of India (Chapter 5)
Section 18 allows the Central Government to bring out the Data Protection Board of India ("DPBI") via issuing a notification to that effect. The DPBI is a corporation with a continuous succession. The Central Government notifies the Board, which consists of a chairperson and other members with ability, honesty, and position who have particular knowledge or real-world experience in the subject matter of data governance. They are qualified for reappointment after their two-year tenure. Provisions under Section 21 to 25 of the DPDP Act contain measures pertaining to resignation, removal, board procedures, and board staff.
Powers, Functions and Procedures of the Board (Chapter 6)
Section 26 confers the Chairperson with the power of superintendent & administrative control over the Board, its Members and employees.
The DPDP Act's Section 27 enshrines the Board's functions and authoritative power, namely the authority to order immediate corrective or mitigating actions upon learning of a breach involving personal data. Investigating a violation by the Consent Manager or another party and applying sanctions to a Data Principal's grievance, an official referral, or a judicial order.
The Board has been made an unbiased body to work as a digital space and is not bound by the strict procedural law; however, the authority of the civil court under the Code of Civil Procedure, 1908, has been vested for summoning persons, receiving evidence, and inspection. Further, while hearing a complaint & passing orders, principles of natural justice are to be followed.
Appeal and Alternate Dispute Resolution (Chapter 7)
A person who is unsatisfied by the order of the Board may make an appeal before the appellate authority and this can be done for a period of 60 days, and the determination made by the concerned appellate tribunal is executed as a decision of the Civil Court.
If the board believes that any grievance can be addressed by the process of mediation, then it has enough authority to order the concerned people to try to allay the matter with the assistance of a Mediator as per the law. Section 32 allows the Board to accept a voluntary commitment (undertaking) from an individual or entity at any stage of a proceeding related to compliance with the Act.
Penalty and Adjudication (Chapter 8)
Section 33 empowers the Data Protection Board of India to impose penalties to be timely deposited under the Consolidated Fund of India on Data Fiduciaries and Consent Managers for the concerned violations of this Act’s stipulations. The penalties prescribed in the Schedule of the Act range from ₹10,000 to ₹250 crores, the quantum of penalty is determined according to elements such as the kind and character of the impacted personal data, the severity and length of the violation and the recurring nature of it, proportionality and effectiveness, etc. Notably, in the entire DPDP Act, there is no mention of criminal sanctions or the possibility of imprisonment.
Miscellaneous Provisions (Chapter 9)
Regarding any action taken in honest belief, Section 35 safeguards the Central Government, the Board, its Chairman, Members, and Officers. Additionally, the Central Government has the authority to request information, create regulations to implement the Act's goals, and give orders to restrain the public from getting their hands on any information that the Board indicates following an inquiry with the Data Fiduciary.
Guidelines and notifications pertaining to the handling of individual accounts of information beyond the country, as well as the sanctions outlined in the Schedule, must be presented to the two houses of Parliament before they can take effect.
Through section 44, certain Acts were amended to bring conformity among laws. It is notable that Section 14(c) of the Telecom Regulatory Authority of India Act, 1997, was also amended to give the concerned Telecom Disputes Settlement and Appellate Tribunal (“TDSAT”) appellate power pursuant to the DPDP legislation. Also, the Section 43A, that earlier provided for compensation for non-adherence of the mandate to conserve data & along with it, section 87(2)(ob) of the Information Technology Act, 2000, stood omitted, and with the aim to protect the exercise of rights under this new DPDP Act, in proviso of section 81, the title of the DPDP Act was added. Also, section 8(1)(j) of the Right to Information Act, 2005 was substituted, thereby exempting disclosure of all and any personal information.
The Digital Personal Data Protection Rules of 2025
Effective implementation of the Act depends on the comprehensiveness of the Rules, from 11.08.2023, it took 2 years for the Ministry of Electronics and Information Technology (“MeitY”) to bring forth the draft Rules. Feedback/comments on the draft ‘Digital Personal Data Protection Rules, 2025’ were invited from 03.01.2025 till 05.03.2025.
The draft contains 22 Rules and 7 schedules focusing on provisions related Notice to be given by Data Fiduciary to Data Principal, registration of Consent Manager, reasonable security safeguards, timeline of personal data retention as per class of data, 72 hours timeline for communication of personal data violation to the Board by Data Fiduciary, procedure regarding verify for handling data of child and persons with disability, exemptions of certain obligations and explaining additional obligation for Significant Data Fidiciary. The Schedules relate to various requirements to guide Data Fiduciary to remain compliant as per law, i.e., registration of Consent Manager with the Board, obligations of Consent Manager. data retention period, technical and organisational measures.
Despite the issuance of comprehensive Rules, the Rules remain silent on who will be considered as a Significant Data Fiduciary, the Registration requirement of an in-house Consent Manager with the Board, the timeline for Data Principal Rights and the grievance redressal system. A list of prohibited countries for restricting the transfer of has not been provided. Further, the journalistic exemption for the enforcement of the fundamental right to freedom of expression and right to information in the public interest has also not been considered. The threshold volume, nature of personal data, and class of data fiduciary start-up have not been mentioned, as well as the definition of traffic data and metadata remains a grey area under the current Digital Personal Data Protection legislation of India.
Challenges To Data Protection Law In India
The broad exemptions given to government departments under section 17(2)(a) from any requirements of the DPDP Act in the face of importance facets like that of autonomy, the integrity of India, the safety of the nation, bureaucratic ties with foreign economies, and the safeguarding of general order are among the most controversial obstacles that the present information protection law must overcome in order to effectively enforce and meaningfully guard citizens' right to privacy. Such exemption to undefined ‘instrumentalities of state’ has been unprecedented in its scope and has widespread surveillance without adequate safeguards and has potential to create parallel system. The additional exemption for law-enforcement person possess granted under section 17(1)(c) requires additional provisional safeguards and judicial oversight mechanism otherwise, as often found, such power leads to abuse rather than use.
The DPDP Act imposes significant operational and financial challenges for Micro, Small and Medium Enterprises (“MSMEs”) which is the cornerstone of the India’s economic health, as about 7.34 crore MSMEs employees more than 26 crore individuals spread across various sectors, having share of 30.1% in FY2022-23 in the countries Gross Value Added (GVA) highlighting growing role in national economic output. Implementing comprehensive data security system, hiring legal and technical experts significantly raises compliance cost and infrastructure challenges will adversely affect Indian economy and will discourage businesses.
The DPDP Act also faces complex challenge of protecting individual right while maintaining India’s stance as a fast evolving informational economy while also tackling the challenges of emerging avenues like Artificial Intelligence (“AI”), Machine Learning (“ML”), big data etc. The Act provides for up to ₹ 250 crore per violation, representing some of the highest financial penalties globally, however, enforcement, effectiveness and fairness possess great question. The Act heavily realise on Central Government and Data Protection Board, the Board till date remains non-operational with extensive power given to Central Government highlighting centralised enforcement model that would create difficulty and significant enforcement gap in effective implementation for such large and diverse country like India.
Though the DPDP act draws significant inspiration from the use JDPR incorporating fundamental principles, however, while the DPDP legislation only applies to digitalised data, the GDPR encompasses all types of personal data, digital and non-digital. Further, the GDPR provides for multiple lawful bases for processing of data, however, the DPDP Act has more consent-centric approach relying predominantly on explicit consent of Data Principal. GDPR also classify personal data under various categories with each having different protection requirements. However, DPDP act lakhs such categorisation and applies uniformly on all data types. While the GDPR offers a complex system of compliance determinations, standardised contractual clauses, and obligatory corporate norms to regulate transfer, the DPDP Act makes cross-border transfers of information straightforward by prohibiting transmission to just selected countries. India is required to take lessons from the international experience to undertake best practices of truly independent data protection authorities like UK’s Information Commissioners Office, Germany’s federal and state data protection commissioners. Further different sectors (like technological sector, financial services sector, healthcare sector etc.) specific guidelines is necessary to bring transparency, enforcement of rights and enforcement mechanism.
Conclusion
The extent to which (or not) individual information's confidentiality is protected will be determined by the institutional structures and law enforcement developments that occur over the following few decades. While the recently passed legislation provides the necessary structure, it is lacking for establishing actual data privacy. The legal framework is typically sensible and practicable. This is a positive development. Because the central government has a considerable amount of flexible jurisdiction over substantial matters, much of it hinges on how geared the state is to ensuring privacy.
The relationship between Data Principle and Data Controller, being developed on the premise of a fiduciary relationship, is the one that is fundamentally based on the expectation of trust that the personal data will be carefully used and not misused. The successful implementation of India's data protection framework will require careful attention to these multifaceted challenges while maintaining the delicate balance between privacy protection, innovation promotion, and economic growth. The experience of other jurisdictions, combined with India's unique socioeconomic context, provides valuable guidance for addressing these challenges and building a robust, effective data protection regime that serves both individual rights and broader societal interests.
When To Call Sarvā Nyāy
You do not have to work this out alone. A short first conversation tells you what to preserve, where to file and whether you need us at all. No obligation, no pressure.
Response within 24 hours · Advocate-client confidentiality · Lucknow

