Skip to Content

DATA PRIVACY AND PROTECTION IN INDIA

A CRITICAL ANALYSIS OF THE DIGITAL PERSONAL DATA PROTECTION ACT, 2023
9 October 2026 by
Veena solanki, BALLB 7th semester, Renaissance law college
​

ABSTRACT

The rapid growth of digital technology has significantly increased the collection, storage, processing, and sharing of personal data. While digitalisation has made communication and access to services easier, it has also created serious concerns regarding privacy, unauthorised use of personal information, data breaches, and misuse of personal data. Therefore, effective legal protection of personal data has become an important issue in the field of cyber law. This research examines data privacy and protection in India with special reference to the Digital Personal Data Protection Act, 2023. This study focuses on the legal framework established by the Act for regulating the processing of digital personal data and protecting the privacy of individuals. It also considers the relationship between data protection and the constitutional right to privacy and examines the Digital Personal Data Protection Rules, 2025. Through doctrinal legal research, the study analyses statutory provisions, constitutional principles, judicial decisions, and relevant government materials.

INTRODUCTION

Today, everything is digital. We use mobile phones, internet banking, social media, online shopping, and many apps. Whenever we use these, we share our personal information like name, phone number, location, and photos. This information is called personal data. In India, there are more than 850 million internet users, so a huge amount of personal data is being created every day. This data is very valuable, but it can also be misused. Many companies, hackers, or even agencies can misuse our data. So there is a big need for a strong law to protect our privacy. In India, earlier we had only the Information Technology Act, 2000. That law was not enough to protect personal data. Everything changed in 2017. In the famous case of K.S. Puttaswamy v. Union of India, the Supreme Court of India said the right to privacy is a fundamental right under Article 21 of the Constitution.[1] The Court also said that the government must make a proper law for data protection. After this judgment, the government started working on a new law. First, Justice B.N. Srikrishna Committee gave a report in 2018. Then Bills came in 2019 and 2021, but they were withdrawn because many experts and companies said they were too complicated.

Finally, on 11th August 2023, the Indian government passed a new law — The Digital Personal Data Protection Act, 2023. This is the first law in India which is fully made for the protection of digital personal data.[2]

RESEARCH QUESTIONS

  1. Is the Digital Personal Data Protection Act, 2023 enough to provide effective data protection in India or does it have gaps?

  2. Is the immediate applicability of the DPDP Act, 2023 justified without a long transition period?

OBJECTIVES AND METHODOLOGY

The objectives of this research are:

  1. To study the legal provisions and concept of the DPDP Act, 2023;

  2. To make a comparative analysis of implementation of the DPDP Act and EU GDPR; and

  3. To find out gaps in the Act and suggest reforms.

The methodology adopted is primarily doctrinal. The research is based on statutory provisions, constitutional principles, judicial decisions, and relevant government materials.

CHAPTER 1: LEGAL PROVISIONS AND CONCEPTS UNDER THE DPDP ACT, 2023

The DPDP Act, 2023 is a concise law with 44 sections in 9 chapters. It is based on the consent model.

1.1 Applicability and Definitions (Section 2 and Section 3)

Section 3 says the Act applies to digital personal data. If you collect data offline on paper and later make it digital, the Act will apply. If a foreign company collects data of Indian users, the Act will apply.[3]

1.2 Definitions (Section 2)

Personal data (Section 2(t)): Any data about an individual who can be identified. Examples — name, phone number, email, location.

Data principal (Section 2(j)): The individual whose data is collected.

Data fiduciary (Section 2(i)): The person or company who decides the purpose of data collection. Example — Flipkart, Jio, school.

Data processor (Section 2(k)): The person who processes data on behalf of the fiduciary.

Data protection officer (Section 2(i)): Person appointed by a significant data fiduciary to handle data-protection duties.

1.3 Section 4

Says data can be processed only for a lawful purpose and only with consent.

1.4 Section 5

Before taking your consent, the company must tell you what data it wants, why it wants it, how you can exercise your rights, and how you can complain. If a person had already given consent before this Act came into force, the data fiduciary must give them notice as soon as reasonably practicable.

1.5 Section 6

Consent must be:

  1. Free — given without pressure;

  2. Specific — for a particular purpose;

  3. Informed — person must know what data is taken;

  4. Unconditional — no condition to take extra data;

  5. Clear affirmative action.

If any part of consent violates the Act, its rules, or another applicable law, that part of the consent is invalid. Every request for consent must be presented in clear language. The data principal has the right to withdraw consent at any time. You can withdraw consent anytime with the same ease as you gave it. After withdrawal, the company must stop processing. But old processing before withdrawal remains legal. If you gave consent before this Act came (like to Facebook in 2022), that consent will continue till you withdraw. But if old consent doesn't match the new law, the company must send you fresh notice. If consent is taken by video or audio recording, it must follow the prescribed procedure.[4]

1.6 Section 7 — Legitimate Uses Without Consent

In some situations, a company can use data without consent:

  1. When the State provides subsidy or benefit;

  2. For compliance with any law or court order;

  3. For medical emergency;

  4. For employment purpose;

  5. For public interest.

1.7 Section 8 — Duties of Data Fiduciary

The data fiduciary is responsible for following the Act and its rules. This responsibility remains even if the data principal does not perform her duties or even if there is an agreement saying otherwise. The responsibility also applies when a data processor processes the data on behalf of the data fiduciary.

A data fiduciary can appoint a data processor to process personal data on its behalf, but there must be a valid contract between them.

If personal data will be used to make a decision affecting the data principal, or if it will be shared with another data fiduciary, the data fiduciary must make sure that the data is complete, accurate, and consistent.

The data fiduciary must keep personal data safe and take reasonable security measures to prevent a personal data breach.

The data fiduciary must take suitable technical and organisational measures to make sure that the Act and its rules are properly followed.

If a personal data breach happens, the data fiduciary must inform the Data Protection Board and every affected data principal in the prescribed manner.

When the purpose for which the data was collected is over, the data fiduciary should delete the personal data if keeping it is not required by any law. It must also tell its data processor to delete the data that was given to it.

The data fiduciary must publish the contact details of its data protection officer, where applicable, or another person who can answer questions raised by the data principal about the use of her personal data.

The data fiduciary must create an effective system for solving complaints or grievances of data principals regarding their personal data.

The data principal is considered not to have approached the data fiduciary if she has not contacted it — either personally, electronically, or physically — for the purpose during that period.

1.8 Rights and Duties of Data Principal (Sections 11 to 14)

Section 11: A data principal has the right to ask the data fiduciary what personal data of hers is being processed. The data principal can ask for a summary of personal data, information about sharing of data, and other information. This right does not apply when the data fiduciary is legally required to share the personal data with another data fiduciary, for example, for the prevention, detection, or investigation of offences or cyber incidents or prosecution or punishment of offences.[5]

Section 12: Right to correction and erasure of personal data. The data principal has the right to ask the data fiduciary to correct, complete, update, or erase her personal data. If the personal data is incorrect, incomplete, or outdated, the data principal can request the data fiduciary to correct or update it. After receiving the request, the data fiduciary must: (1) correct inaccurate or misleading data; (2) if some necessary information is missing, it must be completed; (3) if the information has changed, it should be updated. The data principal can request deletion of her personal data. The fiduciary should erase it unless keeping the data is necessary for the specified purpose or required by law.

Section 13: Right of grievance redressal. The data principal has the right to have an easy and effective system for making complaints. If a data fiduciary or consent manager does something wrong or fails to perform its duties, the data principal can make a complaint. The data fiduciary or consent manager must respond to the complaint within the prescribed time. Before approaching the Data Protection Board, the data principal must first use the grievance redressal system provided by the data fiduciary or consent manager.

Section 14: Right to nominate. The data principal has the right to nominate another person who can exercise her rights under the Act if she dies or becomes incapable of exercising those rights. Incapacity means being unable to exercise one's rights because of unsoundness of mind or body.

1.9 Section 15 — Duties of Data Principal

The data principal must follow all applicable laws while exercising her rights under the Act.

A person must not pretend to be someone else while providing her personal data for a specified purpose.

A person must not hide important information while providing personal data for a document, unique identifier, proof of identity, or proof of address issued by the State or its instrumentalities.

1.10 Data Protection Board of India (Sections 18 to 22)

Section 18: Establishment of Data Protection Board of India. The Central Government can establish a body called the Data Protection Board of India by notification. The Board will be a body corporate. This means that the Board has its own legal identity. It can own property, hold property, dispose of property, enter into contracts, and sue or be sued in its own name. The headquarters of the Board will be at the place decided by the Central Government.

Section 19: Composition and qualification of the Board. The Board will consist of a chairperson and such number of other members as the Central Government may notify. The chairperson and members will be appointed by the Central Government according to the prescribed procedure. The chairperson and members should have ability and integrity, special knowledge, or practical experience in areas such as data governance, administration, law, social or consumer protection, dispute resolution, information and communication technology, digital economy, regulation, or techno-regulation.

Section 20: Salary, allowances, and term of office. The salary, allowance, and other service conditions of the chairperson and members will be decided according to the prescribed rules. The chairperson and members will normally hold office for 2 years and will be eligible for re-appointment.

Section 21: Disqualification for appointment and continuation. A person cannot be appointed or continue as chairperson or member if: insolvent; convicted of an offence involving moral turpitude; physically or mentally incapable; having financial or other interest; or misuse of position. The Central Government cannot remove the chairperson or a member without giving that person an opportunity to be heard.

Section 22: Resignation and filling of vacancy. The chairperson or any member can resign by giving written notice to the Central Government. The resignation becomes effective when: the Central Government permits the person to leave office; or three months have passed from the date of receiving the resignation notice; or a properly appointed successor takes charge; or the person's term ends; or if the position becomes vacant because of resignation, removal, death, or any other reason.

CHAPTER 2: CASE LAW ANALYSIS — JUDICIAL BACKGROUND OF DATA PROTECTION

Case 1: K.S. Puttaswamy v. Union of India, (2017) 10 SCC 1

Facts: In 2012, Justice K.S. Puttaswamy, a retired High Court Judge, filed a writ petition in the Supreme Court challenging the Aadhaar scheme. He argued that Aadhaar collects biometric data (fingerprint, iris) of 1.3 billion people without any law, which violates the Right to Privacy. The Government argued that the Constitution does not recognize the right to privacy as a fundamental right and cited old cases — M.P. Sharma (1954) and Kharak Singh (1962).[6]

Issues:

  1. Whether the Right to Privacy is a fundamental right under Part III;

  2. Whether M.P. Sharma and Kharak Singh are correctly decided.

Judgment: A nine-judge bench headed by CJI J.S. Khehar gave judgment on 24 August 2017. The Court overruled M.P. Sharma and Kharak Singh. Justice D.Y. Chandrachud wrote that privacy includes three aspects:

(a) Bodily privacy — protection of body;

(b) Informational privacy — protection of data;

(c) Decisional autonomy — right to take own decisions.

The Court also laid down the Proportionality Test. Any law that violates privacy must pass:

(i) Legality — there must be law;

(ii) Legitimate aim — aim must be valid;

(iii) Proportionality — means must be proportionate to aim;

(iv) Procedural safeguards — there must be safeguards against misuse.

Case 2: K.S. Puttaswamy v. Union of India, (2019) 1 SCC 1 — Aadhaar Judgment

Facts: After the first judgment, petitioners challenged the Aadhaar Act, 2016 itself. They said Aadhaar violates the privacy test.[7]

Judgment: A five-judge bench by 4:1 majority upheld Aadhaar. The Court held that Aadhaar collects minimal data for welfare purpose and has the legitimate aim of preventing leak. But the Court struck down many provisions:

  1. Section 33(2) which allowed sharing Aadhaar data for national security without judicial warrant — STRUCK DOWN. The Court said sharing needs a warrant from a High Court judge.

  2. Section 47 which allowed only the government to file a complaint for Aadhaar data breach.

  3. Mandatory linking of Aadhaar with bank account and mobile SIM.

  4. Section 57 which allowed private companies to use Aadhaar.

CHAPTER 3: CRITICAL ANALYSIS OF THE DPDP ACT, 2023

FeaturesDigital Personal Data Protection Act, 2023General Data Protection Regulation
Data ScopeOnly digital personal dataAll personal data
Data categoriesStandard classification (no sensitive data split)Special categories (health, biometric, political views)
Child consent ageUnder 18 yearsUnder 16 years
Data portabilityNot explicitly providedExpressly provided

1. State Exemptions and Surveillance Risks

Section 17 gives the Central Government wide powers to exempt its agencies on grounds such as national security and public order. This may increase the risk of excessive surveillance and misuse of personal data.[8]

2. Independence of the Data Protection Board

The Data Protection Board is controlled to a large extent by the Central Government, including its appointment and removal of members. This raises concerns about whether the Board can work independently and fairly, especially against government agencies.

3. Impact on the RTI Act

Section 44(3) changes the RTI Act regarding disclosure of personal information. Critics argue that this may reduce government transparency, especially in cases involving corruption or misuse of public funds.

CONCLUSION

The DPDP Act, 2023 is India's first data protection law after the Puttaswamy judgment. It is a good start as it is based on consent and gives rights to citizens. But it is not enough. It has no protection for sensitive data, no compensation to victims, no independence of the Board, and gives wide exemption to the government.

Reference

[1] K.S. Puttaswamy v. Union of India (2017) 10 SCC 1.

[2] Digital Personal Data Protection Act, 2023.

[3] Digital Personal Data Protection Act, 2023, s 3.

[4] Digital Personal Data Protection Act, 2023, s 6.

[5] Digital Personal Data Protection Act, 2023, s 11.

[6] K.S. Puttaswamy v. Union of India (2017) 10 SCC 1.

[7] K.S. Puttaswamy v. Union of India (2019) 1 SCC 1.

[8] Digital Personal Data Protection Act, 2023, s 17.

Veena solanki, BALLB 7th semester, Renaissance law college 9 October 2026
Share this post
Category
Sign in to leave a comment