Data Protection and Digital Rights in India

This article is written by Muskan Kaur, St. Wilfred Law College, Jaipur.

India’s digital transformation has been extraordinary. From online banking and digital payments to social media and AI-driven platforms, technology now shapes almost every aspect of daily life. However, as digital dependence increased, concerns regarding the misuse of personal data, surveillance, and privacy violations also grew rapidly. For many years, India relied mainly on the Information Technology Act, 2000, which was not designed to address modern challenges such as big data, artificial intelligence, algorithmic profiling, and large-scale digital surveillance.

The enactment of the Digital Personal Data Protection (DPDP) Act, 2023, marks a significant turning point in India’s legal and constitutional framework. The law aims to balance two equally important objectives: protecting the privacy rights of individuals and enabling the lawful processing of personal data for economic and administrative purposes.

The Digital Personal Data Protection Act, 2023 received Presidential assent on 11 August 2023 and serves as India’s primary legislation governing digital personal data. It introduces a consent-based framework for data processing, defines the obligations of entities handling personal data, and establishes a Data Protection Board to ensure compliance and accountability.

What is the DPDP Act, 2023?

The DPDP Act, 2023, provides a legal framework for processing digital personal data in a manner that recognises both the right of individuals to protect their personal data and the legitimate need to process such data for lawful purposes.

The Act applies to:

  • Personal data collected in digital form within India.
  • Offline personal data that is later digitized.
  • Processing of personal data outside India if it relates to offering goods or services to individuals within India.

The DPDP Rules, 2025 further clarify how personal data should be collected, processed, stored, and secured.

User Consent under the Act

One of the most important features of the DPDP Act is the requirement of informed consent. Organizations collecting personal data must provide a clear and simple notice explaining:

  • That personal data is being collected.
  • The purpose behind collecting the data.
  • The rights available to individuals regarding their data.
  • The method through which individuals can exercise those rights.

The Act emphasizes that consent must be free, specific, informed, unconditional, and unambiguous.

Rights of Citizens

The DPDP Act empowers individuals, referred to as “Data Principals,” by granting them several important rights:

  1. Right to Information – Individuals can seek details regarding how their personal data is being processed.
  2. Right to Correction and Erasure – Individuals can correct inaccurate or incomplete data and request deletion of data that is no longer necessary.
  3. Right to Grievance Redressal – Individuals can file complaints against data fiduciaries through accessible grievance mechanisms.
  4. Right to Nominate – Individuals may nominate another person to exercise their rights in the event of death or incapacity.

These rights strengthen individual control over personal information and promote accountability among organizations handling data.

Data Protection Board of India

The DPDP Act provides for the establishment of the Data Protection Board of India by the Central Government. The Board consists of a Chairperson and other members possessing expertise in fields such as law, information technology, data governance, and the digital economy.

The Board plays a crucial role in enforcing the provisions of the Act. Its primary functions include:

  • Investigating data breaches and non-compliance.
  • Issuing directions to organizations for corrective measures.
  • Imposing financial penalties for violations.
  • Ensuring adherence to data protection standards.

The establishment of the Board reflects India’s attempt to create a dedicated regulatory authority for digital privacy and data governance.

The Puttaswamy Judgment

The foundation of data protection law in India can be traced to the landmark judgment in justice K.S. Puttaswamy (Retd.) v. Union of India, Supreme Court of India, 2017

In this case, a nine-judge Constitutional Bench of the Supreme Court unanimously held that Article 21 of the Constitution of India protects the right to privacy as a fundamental right.

The Court recognised the close connection between privacy, human dignity, autonomy, and individual liberty. It further emphasised that every human being inherently possesses certain rights and that the State does not grant those rights. The judgment laid the constitutional foundation for modern data protection laws in India and directly influenced the creation of the DPDP Act.

Obligations of Data Fiduciaries

The Act imposes several obligations on organizations processing personal data, referred to as “Data Fiduciaries.” Certain entities categorized as “Significant Data Fiduciaries” are subject to additional responsibilities due to the scale and sensitivity of the data they handle.

Key obligations include:

  • Appointment of a Data Protection Officer (DPO): The DPO must be based in India and act as a point of contact for grievance redressal.
  • Data Protection Impact Assessments (DPIA): Periodic assessments must be conducted to evaluate risks associated with data processing.
  • Implementation of Security Safeguards: Organizations must adopt reasonable security measures to prevent data breaches.
  • Data Minimization: Only necessary data should be collected.
  • Storage Limitation: Data must not be retained longer than required.

These obligations encourage organizations to adopt a “privacy by design” approach.

Critical Challenges and Concerns

Despite being a major legislative development, the DPDP Act has attracted criticism from legal scholars, privacy advocates, and civil society organizations.

1. Broad State Exemptions

The Act allows the Central Government to exempt certain government agencies from its provisions on grounds such as sovereignty, national security, and public order. Critics argue that such broad exemptions could potentially enable excessive state surveillance.

2. Impact on the Right to Information (RTI) Act

The DPDP Act amends certain provisions of the Right to Information Act, 2005 by restricting disclosure of personal information. Some experts fear that this may reduce transparency and limit public accountability.

3. Practical Challenges of Informed Consent

In a country with diverse literacy levels and varying digital awareness, ensuring truly informed consent remains a significant challenge. Many users may accept privacy notices without fully understanding their implications.

Compliance and Digital Culture

For businesses and digital platforms, compliance with the DPDP Act requires more than legal documentation. Organizations must integrate privacy safeguards into their technical systems and operational structures.

Important compliance measures include:

  • Strong encryption and cybersecurity systems.
  • Timely breach-notification procedures.
  • Transparent privacy policies.
  • Responsible data handling practices.

The law encourages companies to treat privacy not merely as a legal obligation, but as an essential aspect of ethical digital governance.

Conclusion

The Digital Personal Data Protection Act, 2023 represents a landmark step in India’s journey toward a more secure and accountable digital ecosystem. The legislation acknowledges that personal data and privacy are central to individual freedom in the digital age.

While the Act creates a comprehensive framework for data governance, its effectiveness will ultimately depend on proper implementation, regulatory independence, and judicial oversight. Lawmakers and courts must continue to carefully examine concerns relating to government exemptions, transparency, and surveillance to ensure adequate protection of the right to privacy.

As India continues to expand its digital economy, the balance between innovation and individual rights will become increasingly important. In the modern era, digital rights are not merely technological concerns; they are essential components of democracy, liberty, and human dignity.

Frequently Asked Questions

Who must comply with the DPDP Act?

Any entity processing digital personal data within India, or outside India while offering goods or services to individuals in India, must comply with the Act.

What type of data is covered?

The Act applies to personal data in digital form and offline data that is later digitized.

Can an individual request deletion of personal data?

Yes. Individuals have the right to access, correct, update, and erase their personal data.

Does the Act apply to publicly available data?

No. The Act does not apply to publicly available data voluntarily disclosed by the individual.

What are the penalties for non-compliance?

Organizations may face heavy financial penalties, which can extend up to ₹250 crore for serious violations such as failure to implement adequate security safeguards.