Privacy, Data Protection and the Digital Personal Data Protection Act, 2023: Author: Hussein Burhanpurwala

The rapid digitization of everyday life has incredibly transformed India into a powerhouse of digital innovation, bridging the gap between rural and urban populations through instant payment methods (UPI), accessible online governance, and the rapid internet connectivity.This article explores the constitutional foundation of the DPDP Act, its implication on privacy, the need for data protection, and moreover highlights both features and drawback of the DPDP Act, 2023.

Hussein Burhanpurwala

9/9/2026

Introduction

The rapid digitization of everyday life has incredibly transformed India into a powerhouse of digital innovation, bridging the gap between rural and urban populations through instant payment methods (UPI), accessible online governance, and the rapid internet connectivity. While it is well known that such amenities enable efficiency and innovation, it also raises concern regarding security, regulations and potential misuse. Until recently, India lacked a comprehensive law to protect data, however the Digital Personal Data Protection Act, 2023 (DPDP Act) finally fills that gap. This article explores the constitutional foundation of the DPDP Act, its implication on privacy, the need for data protection, and moreover highlights both features and drawback of the DPDP Act, 2023.

The Journey of Privacy in India

In India, privacy was not always treated as a fundamental right. For decades, courts struggled with its scope. Early cases like M.P Sharma (1954) denied a general right to privacy. Later decisions slowly started recognizing aspects of it, such as protection against tapping of phone. The turning point came in 2017 with the Supreme Court’s landmark judgment in Justice K.S. Puttaswamy v. Union of India. A nine-judge bench unitedly held that the right to privacy is intrinsic to the right to life and personal liberty under Article 21 of the Constitution. Moreover, the right to control one’s personal data was expressly recognized as informational privacy.

The Puttaswamy judgement made it clear that the state and private establishment could no longer treat personal data casually. Yet, for years after Puttaswamy, India continued to rely on a limited constitutional framework under the Information Technology Act, 2000 and the Sensitive Personal Data Rules of 2011. Both of them only covered a certain category of “sensitive” data and lacked strong enforcement by law. It is important to note that despite IT Act of 2000, cases of data breaches, unauthorized sharing of personal data, and no consent of usage of data remained common.

Why Data Protection Matters

In today’s digital economy, personal data is valuable resource. How well it is utilized by digital platform is an interesting case, platforms use data to target youth by feeding algorithm from their online searches, banks use financial data of users to score credits, customer feedback is used as data and a pattern is generated to help businesses modify their digital tools, goods, and services to fit market demand. While its positive aspect is that it creates convenience and bring economic value, it also creates risk of identity theft, discrimination and loss of autonomy. Without laying down clear data protection rules, individuals would have little control over how their data is collected, used, shared, or retained.

The introduction of DPDP Act seeks to restore that control. The Act typically rely on principals of consent, minimization of data, limited data storage, rectifying purpose, and most importantly security of personal data. Worldwide, the European Union’s GDPR is often held up as the gold standard. The DPDP Act has drawn strong inspiration from foreign models but has also ensured that local realities are met coordinately, by emphasizing simplicity, innovation, and the dual need to protect individuals while allowing lawful processing.

Key Features of the DPDP Act, 2023

The DPDP Act received Presidential sanction on August 11 2023. It applies to the processing of digital personal data within India and to processing of foreign data if it relates to offering goods or services to individuals in India. The Act however, do not cover purely personal or domestic processing, or data that the individual has made publicly available by his/her consent.

The law has introduced clear rules that Data Principal is the individual whose data is being processed, whereas The Data Fiduciary is the establishment that would decide the purpose and means of processing. There also exist Significant Data Fiduciary who faces additional obligations based on volume, sensitivity, and risk of data. Fiduciaries are acted upon by Data Processors under a signed contract. Moreover, a new role of Consent Manager is appointed, that helps individuals manage and withdraw consent through integrated platforms.

Processing of personal data is only allowed if the person agrees to it or if it falls under a few special situations the law calls legitimate uses. Consent has to be real and proper. It must be given freely, for a clear purpose, with the person knowing exactly what they’re agreeing to. It can’t be forced or mixed up with other conditions, and the person has to take a clear action to say yes—like clicking a button. Before asking for that consent, the company or establishment must tell the person what data they’re collecting, why they need it, and how the person can use their rights or complain if something goes wrong. The special situations where consent isn’t needed include things like when someone voluntarily gives their data for a specific reason, when the government is giving benefits or services, in a medical emergency, or for employment-related purpose. These rules are meant to stop companies from collecting whatever data they want without people having any real say in it.

People whose data is being used (called Data Principals) get some useful rights under the law. They can find out what information is held about them, ask for corrections or deletion if something is wrong or no longer needed, get help when they have a complaint, and even choose someone to handle these rights for them if they pass away or become unable to act. At the same time, they have a few responsibilities too—like not hiding important facts or making fake complaints just to cause trouble.

The establishment that control the data (Data Fiduciaries) also have clear duties. They can only use the data for the exact purpose it was collected for, must keep it reasonably safe, make sure it stays accurate when it affects decisions about people, and delete it once that purpose is over (unless the law says they have to keep it). If there’s a data breach, they have to quickly tell both the Data Protection Board and the people affected. Children get extra protection. Companies need proper parental consent before using a child’s data, and they’re not allowed to track child’s behavior or show them targeted ads. These rules are real attempt to give ordinary people more control while still treating their information with care.

Drawbacks and Reflection

Even though these strengths build the foundation of data protection in India, the Act itself is not without limitations. The exemptions granted to the State for national security, public order and related purposes are framed in broad terms and it lacks clarity on the basis of allowance. While it is important to address legitimate state interest, the worrying possibility is that privacy protections could be diluted in practice. Another major drawback is that in the DPDP Act, same rules apply across all forms of personal data. Which further indicate that particular intimate information does not receive stronger formal protection.

Moreover, Consent Manager must function in a way that genuinely contribute individuals rather than adding another layer of complexity. Establishment of every size, especially MSMEs who have limited compliance resources, will need time and more importantly support to adapt to the new law. At last, awareness among ordinary citizens will be important as those rights which are unknown by its people loses much of their value.

Conclusion

Overall, the DPDP Act is a solid first step rather than a perfect final law. It takes the big idea of privacy from the Supreme Court and turns it into actual rules that can give ordinary people more control over their data. Whether it really works will depend on proper enforcement, small improvements over time, and ordinary citizens treating personal information with more care. In the end, the law’s true value will show in how it protects real people in everyday life.

Bibliography

Primary Sources

1. Justice K.S. Puttaswamy (Retd.) & Anr. v. Union of India & Ors., (2017) 10 SCC 1 (Supreme Court of

India).

2. The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023). Gazette of India,

Extraordinary, Part II, Section 1, 11 August 2023.

3. Digital Personal Data Protection Rules, 2025, G.S.R. 846(E) (notified on 13 November 2025).

Ministry of Electronics and Information Technology, Government of India.

4. Notification G.S.R. 843(E), dated 13 November 2025 (commencement of various provisions of the

Digital Personal Data Protection Act, 2023). Ministry of Electronics and Information Technology,

Government of India.

Secondary Sources / Useful References

5. Future of Privacy Forum, “The Digital Personal Data Protection Act of India, Explained” (15

August 2023).

6. PRS Legislative Research, Summary of the Digital Personal Data Protection Bill, 2023.

7. Ministry of Electronics and Information Technology (MeitY) / Press Information Bureau releases on

the notification of the DPDP Rules, 2025 (November 2025).

8. Various explanatory notes and analyses from CADP, Mondaq, EY India, and Taxmann on the key

provisions and implementation timeline of the DPDP Act and Rules (2023–2026).