Data Privacy in India: How Well Are Individuals Rights Protected? : Author: Shivani Jesingbhai Vadhel
In a modern world, a person’s personal information is often at risk. Many people use smartphones interact with social networks, various apps, shop online and make online payments. They provide their names, phone numbers, photographs, locations, and financial details on platforms. While technology has made everyday activities easier and more convenient, it has also increased the amount of personal information being collected and processed. This raises an important question regarding how well people’s personal/private information and data are protected when they are collected, stored and used?
ARTICLE


Introduction
In a modern world, a person’s personal information is often at risk. Many people use smartphones interact with social networks, various apps, shop online and make online payments. They provide their names, phone numbers, photographs, locations, and financial details on platforms. While technology has made everyday activities easier and more convenient, it has also increased the amount of personal information being collected and processed.
This raises an important question regarding how well people’s personal/private information and data are protected when they are collected, stored and used?
Information privacy has become a legal and constitutional issue, not only a technological one. In India, the Supreme Court recognized the right to privacy as a fundamental right in Justice K.S. Puttaswamy (Retd.) v. Union of India (2017). India has also introduced the Digital Personal Data Protected (DPDP) Act, 2023, providing a specific legal framework for the processing of digital personal data.
However, despite such legal protection on paper, actual control over knowledge remains an issue for many individuals. Issues such as lack of awareness, excessive collection of personal information, consent, data security, and effective enforcement continue to create challenges. Consequently, this article aims to explore the legal rights which protect citizens in India, and how well they are supported within the increasing digital space.
What is Data Privacy and Why Does It Matter?
Data Privacy means giving individuals control over their personal information, including knowledge of how it’s collected, shared and secured.
Data privacy has been recognized since 1948, but modern legal framework like GDPR and CCPA emerged within the last decade and breaches bring massive consequences as seen by Amazons 750 million euros GDPR fine.
From credit card details to genomic data, political views or health records, different data types required tailored privacy protection.
Good data privacy, earns consumers trust, prevents scandals, avoid fine, and give business a competitive edge. Laws vary, but common themes an individual’s control, lawful use, transparency and security. If data privacy isn’t woven into your business you are at risk.
Organization struggle with scattered data, unmonitored application, divergent global loss, and inadequate access control which leave privacy vulnerable.
Security and privacy go hand in hand. Security keeps data safe while privacy ensures that people govern how their data is used.
To protect data effectively, known when it is slurped classify slashte, assign accountability, limit access, embed privacy from the start, automate controls, train your team, privacy is essential not optional, the right framework fosters trust, mitigates, risk, and drives growth, tools like security can help (schedule and demo).
Historical Timelines
· Constituent Assembly Debates (1948): During 1947-48 while the constitution was being drafted, a debate has already begun over whether the Right to privacy should be given the status of a fundamental right.
· MP Sharma v. Satish Chandra (1954)
· Kharak Singh v. State of uttar Pradesh (1962)
· Justice K.S. Puttaswamy v. Union of India (2017)
· Govind v. State of Madhya Pradesh and Another
1. 1948 – Constituent Assembly Debates :
· First attempt to protect the privacy of an individual against unreasonable state interference was in the Constituent Assembly
· Mr. Kazi Syed Karimuddin moved an amendment to protect individuals from unreasonable search-and-seizures under Article 20 of constitution, on the lines of the American and Irish Constitution
· There was strong opposition to those proposals. BN Rau (Advisor to the Constituent Assembly) and Alladi Krishnaswamy Ayyar, a constituent Assembly member, disagreed with the inclusion of the right to privacy within fundamental rights.
· However, the right to privacy was not placed explicitly in the Constitution.
2. 1954 – MP Sharma v. Satish Chandra
· Case related to search and seizure of documents of Dalmia group companies.
· The District Magistrate issued warrants, and searches were consequently conducted after FIR was registered.
· In writ petitions before the Supreme Court, the constitutional validity of searches was challenged on the grounds that it violated their fundamental rights under Article 19(1)(f) and 20(3) – The Right to protection against self - incrimination.
· The Supreme Court’s eight-judge bench ruled that the power of search and seizure was not intended to be constrained by a fundamental right to privacy.
· They started that the constitution does not contain language that is comparable to the Fourth Amendment of the idea of a fundamental right to privacy in search-and-seizure procedures through what they referred to as a “strained construction.”
3. 1962 – Kharak Singh v. State of Uttar Pradesh
· Kharak Singh was detained on suspicion of dacoity but later released for a lack of proof.
· Police placed him under surveillance by Uttar Pradesh Police, under Chapter XX of the Uttar Pradesh Police Regulations, which was contested using the right to privacy.
· Kharak Singh then argued that Article 19(1)(d) (Right to Freedom of Movement) and Article 21 (Right to Life and Liberty) were infringed by Chapter XX and the authority it granted to police officials (protection of life and personal liberty).
· The majority opinion of the six-judge bench ruled that overnight house visits were illegal but supported the rest of the Regulations.
· More significantly, the bench decided that the Constitution does not guarantee the right to privacy.
4. 2017 – Justice K.S. Puttaswamy v. Union of India
· On August 24th 2017, a 9 Judge Bench of the Supreme Court delivered a unanimous verdict in Justice K.S. Puttaswamy v. Union of India.
· It was held that the constitution of India guarantees to each individual a fundamental right to privacy.
· Verdict had 6 separate concurring decisions.
· In 2012, Justice K.S Puttaswamy, a retired judge of the High Court, filed a writ petition in the Supreme Court challenging the constitutional validity of the Aadhar scheme introduced by the UPA Government.
· This matter was first placed before a Five Judge Bench headed by the then Chief Justice Khehar.
· Subsequently, the matter was referred to a Nine Judge Bench on July 18th 2017.
· August 24th 2017, the Bench unanimously recognized right to privacy as fundamental right of every individual guaranteed by the Constitution, within Article 21.
· The decision in M.P. Sharma and Kharak Singh cases were overruled.
· The approach in Kharak Singh was referred to as the “silos” approach borrowed from A.K. Gopalan by Justice D.Y. Chandrachud.
· The Court observed that this approach of viewing fundamental rights in water tight compartments was abrogated after Maneka Gandhi.
· Court held that right to privacy was “not an elitist construct”
· Court also rejected the argument of the authority general that the right to privacy must be forsaken in the interest of welfare entitlements provided by the state.
· But at the same time, it was held that right to privacy was not absolute in nature.
Digital Personal Data Protection Act, 2023
The Digital Personal Data Protection Act, 2023 is the legal framework for regulating the processing of digital personal data in india. Its objective is to provide norms for the processing of personal data and to acknowledge the right of the data principle and obligations of the data processor.
Journey towards the DPDP Act, 2023
Below is the timeline of the DPDP Act, outlining its release and the key milestones in its implementation
· August 2017: The Honorable Supreme Court of India declared the Right to Privacy as a fundamental right in K.S. Puttaswamy judgment.
· July 2018: The committee formed under the chairmanship of Justice Sri krishna submitted report along with a draft of PDP Act, 2018.
· December 2019: The PDP Act, 2019 introduced in the Lok Sabha and was referred to the Joint Parliamentary Committee (JPC).
· December 2021: JCP released its report and a new version of the Act as the Data Protection Act (DPA).
· November 2022: The Ministry of Electronics and Informational Technology (MeitY) released a draft on Digital Personal Data Protection Bill (DPDPB) for public consultation.
· July 2023: The Union Cabinet approved the draft DPDP Bill, 2023.
· August 2023: The President of India assented to the Bill to make a Digital Personal Data Protection (DPDP) an Act.
· January 2025: The Draft DPDP Rules, 2025, were published for public consultation.
· November 2025: MeitY has officially notified the final DPDP Rules, 2025.
Applicability of the Act
Processing of Digital and Digitalized Personal Data
· Processing of personal data within the territory of India and outside the India.
· Data that is in digital format or in non-digital form and digitalized subsequently
· Activity related to offering goods and services to Data Principals within India.
Exemptions to the Act
· Processing personal data necessary for research, archiving, or statistical purposes is exempted, provided it means the standards specified in Second Schedule of DPDP Rules, 2025
· Certain instrumentalities, of the Government of India are exempted from compliance when processing is in the interest of sovereignty, security, public order, or national integrity, as notified by the governments.
Children’s Data
The Data Fiduciary shall adopt appropriate technical and organizational measures to ensure that verifiable consent of the parent is obtained.
Behavioral monitoring of children or targeted advertising directed at children is prohibited.
Rights of Individuals under the DPDP Act
· The Right to Access Information: The right to know what personal data is being processed and with whom the data has been shared.
· The Right to Correction and Erasure: The right to correct any inaccurate or incomplete data subjects to any legal requirements.
· The Right to Grievance Redressal: The right to complain about inappropriate processing of personal data.
· The Right to Nomination: The right to nominate an individuals to act on one’s behalf in the case that one is deceased or incapacitated.
How Well Are These Rights Protected in Practice?
Although the DPDP Act provides some legal rights their practical protection is determined by a degree to which individuals and organizations utilize and employ such provisions. The fact that many people may not understand privacy notices or the extent to which their personal information is gathered or processed may result in limitations to practical protection. Moreover, the issues of data breaches, abuse and a lack of implementation of legally mandated privacy rights. Thus, although the mere recognition of such rights is a significant step towards better data protection, their effective employment remain a key priority.
Challenges and Gaps:
While the DPDP Act provides legal protection to personal data, there are still some issues and gap that hinder the process, such as
· Lack of awareness
· Misunderstanding of consent
· Data breaches
· Exercise of privacy rights
Thus, appropriate implementation, awareness and enforcement of the law are necessary to ensure that the rights are well exercised.
Conclusion:
Data privacy has indeed become a critical legal and social issue in India’s digital ecosystem. The facts that the government has acknowledged the right to privacy as well as introduced laws such as the Digital Personal Data Protection Act, 2023 reflects positively on the country’s progressive stance on data protection. However, having appropriate data privacy laws is just one part of the solution. Public awareness, ethical data handling and poor enforcement of the existing laws are equally important. Individuals must be aware of their rights, and businesses must process personal data ethically and securely, and such measures must be taken to ensure that data privacy laws are enforced effectively for better individual privacy protection.
References
1. Ministry of Electronics and information technology, Digital Personal Data Protection Act, 2023.
2. Justice K.S. Puttaswamy (Retd.) v. Union of India (2017) – Right to Privacy judgment.
3. Constitution of India, Article 21.
4. Universal Declaration of Human Rights, Article 12.
5. M.P Sharma v. State of Uttar Pradesh, AIR 1963 SC 1295.
6. Kharak Singh v. State of Uttar Pradesh, AIR 1963 SC 1295.
7. Govind v. State of Madhya Pradesh & Anr., (1975) 2SCC 148.
