Governance· Prelims · GS-II
Data protection and the DPDP Act, 2023: privacy meets the state
The DPDP Act’s consent-based architecture, the Data Protection Board, penalties up to Rs 250 crore, wide state exemptions, and the privacy-versus-transparency collision with the RTI Act.

The Digital Personal Data Protection Act, 2023 is India’s first comprehensive data protection law. It rests on a single constitutional moment: the nine-judge bench in K.S. Puttaswamy v. Union of India (2017), which held privacy to be a fundamental right under Article 21 and laid down the test of legality, necessity and proportionality for any state intrusion. Built on consent and accountability, the Act names three actors, creates a Data Protection Board, and threatens fines of up to Rs 250 crore.
The Act also carries the tensions of the Indian model: wide exemptions for the state on grounds of sovereignty and public order, a Board appointed by the government it must regulate, and a direct collision with the RTI Act through Section 44(3). This article maps the architecture, the rights and duties, the enforcement machinery, and the privacy-versus-transparency debate that examiners are now probing.
The road to the Act
Before Puttaswamy, India’s data regime was the IT Act of 2000 and its 2011 reasonable-security-practices rules: a patchwork. Puttaswamy (2017) changed the constitutional baseline by making privacy a fundamental right. The Justice B.N. Srikrishna Committee followed with a draft Bill in 2018, and after several iterations Parliament passed the DPDP Act in August 2023. The pattern is familiar from the governance module: India builds the infrastructure and institutions first (Aadhaar, UPI, DigiLocker) and brings statutory regulation later.
The Act is built on the foundation of consent and accountability, and the source material identifies seven core principles underpinning it. It applies to digital personal data, whether collected online or digitised from offline records, and it has extra-territorial reach: any entity offering goods or services to individuals in India is covered, wherever it sits.
Three actors and the consent rule
- Data Principal: the citizen to whom the personal data relates.
- Data Fiduciary: the entity that collects and decides the purpose of processing the data.
- Data Processor: the entity that processes data on behalf of the fiduciary.
Processing is consent-centric: data can be processed for a lawful purpose only with the individual’s free, specific, informed, unconditional and unambiguous consent. Carved out as legitimate uses without consent are voluntary sharing for a specific purpose, provision of government subsidies and benefits, and medical emergencies or employment-related purposes. The subsidy carve-out is what keeps DBT and welfare delivery legally workable under the Act.
Rights of the Data Principal
- Right to access: to know what data is held and with whom it is shared.
- Right to correction and erasure: to update inaccurate data or request deletion once the purpose is served.
- Right to grievance redressal: access to a mechanism for resolving complaints against the fiduciary.
- Right to nominate: to appoint a person to exercise these rights in case of death or incapacity.
Children get special protection: platforms must obtain verifiable parental consent for users under 18, using methods like ID tokens or government databases, and behavioural tracking and targeted advertising directed at children are strictly banned.
One flexibility examiners may probe: the Act lets the government
Actor | Right or duty | What the Act says |
|---|---|---|
Data Principal | Right to access | Know what data is held and with whom it is shared |
Data Principal | Right to correction and erasure | Update inaccurate data; request deletion once the purpose is served |
Data Principal | Right to grievance redressal | A mechanism for resolving complaints against the fiduciary |
Data Principal | Right to nominate | Appoint a person to exercise these rights in case of death or incapacity |
Data Principal | Consent rule | Processing for a lawful purpose only, with free, specific, informed, unconditional and unambiguous consent |
Children under 18 | Parental consent | Verifiable parental consent required; behavioural tracking and targeted advertising banned |
Data Fiduciary | Accuracy and security | Ensure data accuracy and completeness; implement reasonable security safeguards against breaches |
Data Fiduciary | Storage limitation | Delete the data once the specific purpose is met |
Significant Data Fiduciary | Data Protection Officer | Appoint a DPO based in India |
Significant Data Fiduciary | Impact assessments and audits | Conduct periodic Data Protection Impact Assessments and undergo independent data audits |
Duties of fiduciaries, and the Significant ones
Every fiduciary must ensure data accuracy and completeness, implement reasonable security safeguards against breaches, and observe storage limitation: delete the data once the specific purpose is met. Entities the government notifies as Significant Data Fiduciaries, based on the volume and sensitivity of data they handle, carry heavier duties: appointing a Data Protection Officer based in India, conducting periodic Data Protection Impact Assessments, and undergoing independent data audits.
The DPDP Rules, 2025, notified in November 2025, flesh out the machinery: privacy notices must be standalone and in plain language, not buried in terms of service; withdrawing consent must be as easy as giving it; Consent Managers, registered intermediaries with a minimum net worth of Rs 2 crore, let citizens manage consent across platforms from a single dashboard; technical safeguards like encryption, masking and tokenisation are specified; and certain high-interaction platforms must auto-delete data after three years of user inactivity. The rules were notified in November 2025 with phased commencement: the Board provisions took effect at once, while the substantive obligations on fiduciaries phase in over about 18 months, targeting May 2027.
The Board, breaches and penalties
- The Data Protection Board of India: the adjudicating body that monitors compliance, imposes penalties, handles data-breach responses and hears grievances.
- Breach notification: fiduciaries must notify the Board and the affected individuals within 72 hours of becoming aware of a breach.
- Penalties: up to Rs 250 crore for security failures, Rs 200 crore for breach-notification and children-related violations, and Rs 50 crore for other contraventions.
- Appeals: lie to the TDSAT (Telecom Disputes Settlement and Appellate Tribunal).
- Cross-border transfers: permitted globally except to countries on a government-notified restricted list, which had not yet been released in the source material.
The state exemption problem
The Act’s sharpest criticism concerns the state itself. Notified government agencies are exempted on grounds of national security, sovereignty and public order, and Justice Srikrishna publicly criticised the breadth of these exemptions. The Board is government-appointed, which raises the independence question familiar from every Indian regulator: the umpire is chosen by one of the teams. CERT-In’s exemption from the RTI in 2023 further reduced the accountability of cybersecurity agencies over breach disclosures.
This is where
Capacity is the quieter crisis. Most government departments lack trained Data Protection Officers, under 9% of sensitive cloud data in India is encrypted (Check Point, 2025), and data sits in silos with no semantic interoperability across ministries. The breach record is sobering: the BSNL breach of May 2024 leaked 278 GB, the eMigrate portal exposed 2 lakh records, and CERT-In recorded cyber incidents rising from 10.29 lakh in 2022 to 22.68 lakh in 2024.
Two more challenges from the examiner's checklist. Strict compliance costs can
Privacy versus transparency: the RTI collision
Section 44(3) of the DPDP Act amends Section 8(1)(j) of the RTI Act into a blanket ban on disclosing “personal information,” removing the public-interest override. The government defends it as harmonisation with Puttaswamy and a bright-line rule for PIOs; critics, including the Srikrishna Committee’s narrow-exemption logic, call it a shield that can hide asset declarations and file notings from scrutiny. The collision is structural: two fundamental-rights regimes, privacy and the right to know, now share one statute book.
The unfinished agenda sits in non-personal data: the draft National Data Governance Framework Policy (2022) and the India Data Management Office under MeitY address government data sharing, but non-personal data still lacks an enforceable regime. The way forward sketched in the source material runs through Estonia’s “once-only” principle (citizen data submitted once, reused across ministries), common metadata standards across all 52 ministries, privacy-by-design in every government IT system, and sectoral data frameworks for health and finance.
What examiners keep asking
- Privacy as intrinsic to life and personal liberty under Article 21, from the Puttaswamy line of questions.
- The privacy-versus-transparency conflict: how the DPDP Act’s personal-information bar reshapes the RTI Act.
- Data governance challenges: silos, breaches, state exemptions and capacity deficits.
Key Terms
- Digital Personal Data Protection Act, 2023: The Digital Personal Data Protection Act, 2023 is India's first comprehensive data protection law, which received Presidential assent in August 2023. It governs the processing of digital personal data, giving individuals (Data Principals) rights of access, correction and erasure, and imposing obligations on data fiduciaries, with penalties up to Rs 250 crore per contravention. Example: it creates the Data Protection Board of India to adjudicate breaches. Key for UPSC: privacy as a fundamental right after Puttaswamy (2017). A user can demand that an app delete her personal data, and the app must comply or face Board proceedings.
- National Consumer Disputes Redressal Commission: The National Consumer Disputes Redressal Commission is the apex consumer forum under the Consumer Protection Act, 2019, succeeding the body under the 1986 Act. It hears complaints where the value exceeds Rs 2 crore and appeals against State Commission orders, with further appeal lying to the Supreme Court. It matters for UPSC for questions on consumer rights and the three-tier redressal architecture. Its rulings on medical negligence and real-estate developer disputes.
- What the Act says: What the Act says is a heading that distils the operative provisions of a statute into plain language: definitions, prohibitions, penalties and authorities created. It matters for UPSC because polity and governance questions test the letter of important laws; a concise 'what the Act says' summary is more reliable than memory of headlines, and it anchors answers in legal text rather than commentary.
- Central Information Commission: The Central Information Commission is the apex statutory body set up under the Right to Information Act, 2005, to adjudicate appeals and complaints on information requests made to central public authorities. Headed by the Chief Information Commissioner, its members are appointed by the President on the recommendation of a committee including the Prime Minister and the Leader of the Opposition in the Lok Sabha. It matters for UPSC as a key transparency institution in GS-2.
- Significant Data Fiduciary: A Significant Data Fiduciary is a category under the Digital Personal Data Protection Act, 2023 for data fiduciaries that the Central Government notifies on the basis of the volume and sensitivity of personal data they process and the associated risks to data principals, sovereignty or public order. Such fiduciaries face additional duties, including appointing a data protection officer and conducting audits and impact assessments. For UPSC it is the key compliance concept in India's data protection law.
- Data Protection Board: The Data Protection Board is the Data Protection Board of India, the adjudicatory body created by the Digital Personal Data Protection Act, 2023. It inquires into breaches of the Act, directs remedial or mitigation measures, and can impose penalties of up to Rs 250 crore per contravention on data fiduciaries. Example: a company leaking customer data could face Board proceedings following a user complaint. For UPSC, it represents India's institutional model for enforcing digital privacy rights. If a bank's customer database is breached, the Board can investigate and penalise the bank after due inquiry.
- Children under 18: Children under 18 is the legal definition of a child in most Indian statutes, including the Juvenile Justice (Care and Protection of Children) Act, 2015 and the POCSO Act, 2012. The 18-year threshold governs juvenile-justice procedures, child-labour protections, and child-marriage prohibitions. It matters for UPSC in GS-2, where age-based legal categories underpin questions on child rights, protection frameworks, and the conflict between personal laws and statutory safeguards.
- Age of consent: The age of consent under the DPDP Act is 18 for verifiable parental consent, but the government may lower it for specified classes of fiduciaries, to keep safe internet access workable for older minors.
- DPDP Act, 2023: The DPDP Act, 2023 is the Digital Personal Data Protection Act, India's first comprehensive data protection law, which received Presidential assent in August 2023. It governs the processing of digital personal data, giving individuals (Data Principals) rights of access, correction and erasure, and imposing obligations on data fiduciaries, with penalties up to Rs 250 crore per contravention. Example: it creates the Data Protection Board of India to adjudicate breaches. Key for UPSC: privacy as a fundamental right after Puttaswamy (2017). A user can demand that an app delete her personal data, and the app must comply or face Board proceedings.
- Right or duty: Right or duty is a generic pairing that, in the UPSC context, points to the constitutional idea that rights and duties are two sides of citizenship: Fundamental Rights in Part III are balanced by Fundamental Duties in Part IV-A, which remind citizens that liberty is exercised responsibly. It matters for GS-2 polity and GS-4 ethics answers on the relationship between individual claims and obligations to the community.
- RTI Act, 2005: The RTI Act, 2005 is the Right to Information Act enacted in 2005 and in force from 12 October 2005. It empowers citizens to inspect records, take copies and obtain information from public authorities within 30 days, subject to exemptions for national security and privacy under Section 8. Amendments in 2019 changed the tenure and service conditions of Information Commissioners. It matters for UPSC because transparency, citizen charters and accountability in mains answers routinely cite it as a landmark reform. the RTI (Amendment) Act, 2019
- Blacklisting mechanism: The blacklisting mechanism is the DPDP Act's device for cross-border data flows: transfers are permitted globally except to countries the government notifies on a restricted list. It replaces a whitelisting approach with a blacklist one.
Practice questions
The constitutional foundation of the DPDP Act, 2023 is:
Show answer
Answer: (A) The nine-judge Puttaswamy bench (2017) held privacy to be a fundamental right under Article 21, supplying the constitutional basis for the DPDP Act.
Consider the following statements about the DPDP Act, 2023:
- Consent for processing must be free, specific, informed, unconditional and unambiguous.
- Provision of government subsidies and benefits is a legitimate use that does not require consent.
- The Act applies to digital personal data and has extra-territorial jurisdiction.
Which of the statements given above is/are correct?
Show answer
Answer: (D) All three statements are correct: the consent standard, the subsidy/benefits carve-out, and the Act’s coverage of digital personal data with extra-territorial reach.
Under the DPDP Act, 2023, the maximum penalty for failure to maintain reasonable security safeguards is:
Show answer
Answer: (D) Failure to maintain reasonable security safeguards attracts up to Rs 250 crore, the Act’s highest penalty slab.
Appeals against the orders of the Data Protection Board of India lie to:
Show answer
Answer: (B) Appeals against the Data Protection Board’s orders lie to the TDSAT.
Section 44(3) of the DPDP Act, 2023 amends which provision of the RTI Act, 2005?
Show answer
Answer: (B) Section 44(3) amends Section 8(1)(j) of the RTI Act, converting the personal-information exemption into a blanket ban and removing the public-interest override.
Answer key
- (a): The nine-judge Puttaswamy bench (2017) held privacy to be a fundamental right under Article 21, supplying the constitutional basis for the DPDP Act.
- (d): All three statements are correct: the consent standard, the subsidy/benefits carve-out, and the Act’s coverage of digital personal data with extra-territorial reach.
- (d): Failure to maintain reasonable security safeguards attracts up to Rs 250 crore, the Act’s highest penalty slab.
- (b): Appeals against the Data Protection Board’s orders lie to the TDSAT.
- (b): Section 44(3) amends Section 8(1)(j) of the RTI Act, converting the personal-information exemption into a blanket ban and removing the public-interest override.
Mains Practice question
Q. The DPDP Act, 2023 promises privacy to the citizen but retains wide exemptions for the state. Critically examine the Act’s architecture in the light of the Puttaswamy judgment. (250 words)
Framing hintOpen with Puttaswamy’s legality-necessity-proportionality test as the constitutional yardstick. Then map the architecture: consent rule, principal rights, fiduciary and SDF duties, the Board, 72-hour breach notification, the penalty slabs. Test each against the yardstick: sovereignty and public-order exemptions, the government-appointed Board, the RTI collision via Section 44(3). Close with the capacity deficit and the unfinished non-personal-data agenda.
Related GS-II themes: the RTI article’s treatment of Section 44(3) versus Section 8(1)(j), and the e-governance article’s digital-divide and surveillance concerns.
Frequently asked questions
What are the three actors under the DPDP Act, 2023?
The Data Principal (the citizen whose data it is), the Data Fiduciary (the entity that collects data and decides the purpose of processing), and the Data Processor (the entity that processes data on behalf of the fiduciary).
What standard of consent does the Act require?
Consent must be free, specific, informed, unconditional and unambiguous, given for a lawful purpose. Legitimate uses without consent include provision of government subsidies and benefits, medical emergencies and employment-related purposes.
What rights does a Data Principal have?
The right to access data and know with whom it is shared, the right to correction and erasure, the right to grievance redressal, and the right to nominate someone to exercise these rights in case of death or incapacity.
What are the penalties under the DPDP Act?
Up to Rs 250 crore for failure to maintain reasonable security safeguards, Rs 200 crore for breach-notification failures and children-related violations, and Rs 50 crore for other contraventions. Breaches must be notified within 72 hours.
How does the DPDP Act affect the RTI Act?
Section 44(3) of the DPDP Act amends Section 8(1)(j) of the RTI Act into a blanket ban on disclosing personal information, removing the public-interest override. The government calls it harmonisation with Puttaswamy; critics call it a shield for corruption.
What are the main criticisms of the DPDP Act?
Wide state exemptions on sovereignty and public-order grounds, a government-appointed Data Protection Board, CERT-In’s RTI exemption, weak state capacity (few trained DPOs, under 9% of sensitive cloud data encrypted), and the unresolved non-personal-data regime.
In current affairs
This topic in the news