Abstract
The digital revolution has fundamentally reordered the relationship between individuals, corporations, and the State. In no domain is this more acutely felt than in the protection of personal data and the preservation of informational privacy.
India, home to the world's largest internet, using democracy, has for long operated in a legislative vacuum on these questions; a vacuum that the Digital Personal Data Protection Act, 2023 DPDPA now partially fills.
This article examines India's data-protection and cybersecurity framework from its constitutional foundations to its present statutory design. It compares the DPDPA with the GDPR, studies the cybersecurity architecture under the Information Technology Act, 2000, and identifies tensions among state surveillance, individual liberty and regulatory independence.
The paper argues that while the DPDPA represents a watershed moment, it is shot through with ambiguities and executive exemptions that threaten to hollow out its promise.
Keywords
Keywords: Digital Personal Data Protection Act, right to privacy, cybersecurity, state surveillance and regulatory governance.
Introduction
There is something almost paradoxical about the Indian State's relationship with personal data. On one hand, India was among the earliest democracies to judicially recognise privacy as a fundamental right, a recognition that arrived not through legislative design but through the Supreme Court's landmark nine-judge verdict in Justice K. S. Puttaswamy (Retd.) v. Union of India. On the other hand, for nearly six years after that judgment, India continued to process the personal data of over hundreds of millions of internet users without a dedicated data protection statute, relying instead on skeletal provisions in the IT Act and subordinate rules that were plainly inadequate to the task.
The enactment of the Digital Personal Data Protection Act, 2023 ended that particular embarrassment. But the law's arrival has not quieted the concerns of civil libertarians, technologists, or legal scholars. If anything, it has sharpened them.
The DPDPA is a document of considerable ambition and considerable silence, it speaks eloquently of consent and purpose limitation, but whispers when it comes to State accountability, and goes entirely mute on non-personal data and surveillance reform.
What follows is an attempt to hold the Act against the standard it implicitly sets for itself. The right to privacy, as the Supreme Court recognised in Puttaswamy, is not a privilege to be granted by statute, it is a constitutional guarantee that legislation must honour, not merely invoke.
Measured against that baseline, the DPDPA offers a foundation, but not yet a framework. Whether it matures into one will depend less on the text already enacted than on the rules yet to be drafted, the Board yet to be constituted, and the political will that remains, as yet, undemonstrated.
Constitutional Foundations: Privacy as a Fundamental Right
The long road to Puttaswamy
The Indian Constitution does not mention Privacy explicitly. For decades, the Supreme Court equivocated. In M. P. Sharma v. Satish Chandra, an eight-judge bench in 1954 held that no fundamental right to privacy existed. Three years later, a six-judge bench in Kharak Singh v. State of U. P. reached a conflicted conclusion, with the majority denying an independent privacy right even as the minority recognised one. This jurisprudential ambivalence persisted for fifty years.
Privacy protection came in fragmentary judicial gestures, a right against unlawful police surveillance in Gobind v. State of Madhya Pradesh, a right to reputation and informational privacy against the press in R. Rajagopal v. State of Tamil Nadu, and a recognition of telephone tapping as violating Article 21 in People's Union for Civil Liberties v. Union of India It was the Aadhaar biometric identification project that finally forced the constitutional question.
When the government sought to link Aadhaar with bank accounts, mobile phones, and social welfare, essentially making a single biometric identifier the fulcrum of civic existence, few petitioners challenged it. The challenge required the Court to settle, once and for all, whether privacy was a fundamental right.
The Puttaswamy Judgment: Architecture and Significanc e
The nine-judge bench's unanimous verdict in Puttaswamy (2017) is constitutionally transformative. All nine judges agreed that privacy is a fundamental right, intrinsic to Articles 19 and 21 of the Constitution. But the judgment's significance lies not merely in its conclusion but in its reasoning.
Justice D. Y. Chandrachud's concurring opinion, arguably the most intellectually rigorous, located privacy within the concept of human dignity, holding that it protects the individual's "autonomy over the development and growth of his or her own personality."
Crucially, the Court articulated a three-part test for any State infringement of privacy:
legality: the infringement must be sanctioned by law;
legitimate aim: it must serve a legitimate State purpose;
and (iii) proportionality: the means employed must be the least restrictive necessary to achieve the aim.
This proportionality standard, borrowed consciously from German constitutional law and the jurisprudence of the European Court of Human Rights, has since become the touchstone for evaluating data protection and surveillance legislation in India.
What Puttaswamy did not do, and this is its great unfinished work, was legislate. The Court created the constitutional compulsion for a data protection law but left the architecture to Parliament.
The seven years that followed were a story of drafts delayed, committees constituted, and political calculations made.
The Digital Personal Data Protection Act, 2023: Promise and Pathology
The Long Legislative Journey
India's data protection law has a peculiar history. The first formal effort was the Justice Srikrishna Committee report of 2018, which produced a draft Personal Data Protection Bill of 2018-a document of considerable sophistication, modelled heavily on the GDPR while attempting to account for Indian conditions.
The Bill was introduced in Parliament in 2019, referred to a Joint Parliamentary Committee, and after numerous rounds of public consultation, the Committee submitted a revised draft in December 2021. That draft, containing ninety-nine clauses and an annexed Data Protection Authority, was subsequently withdrawn by the government in August 2022, ostensibly to produce a 'comprehensive legal framework.' The DPDPA emerged from this exercise in November 2023. The shift from the 2019 Bill to the 2023 Act is instructive.
The 2019 Bill was detailed, imposing significant obligations on the State, creating categories of sensitive personal data, requiring data localisation for critical personal data, and establishing an independent Data Protection Authority with genuine structural autonomy. The 2023 Act is leaner, more permissive toward government, and significantly more trusting of executive discretion. Whether this represents pragmatic calibration or dangerous dilution is the central question the DPDPA's critics ask.
Core Obligations and Rights
The DPDPA introduces the concept of a 'Data Principal' (the individual whose data is processed) and a 'Data Fiduciary' (the entity processing data). It imposes a purpose-limitation principle which means data may be collected only for a specific, lawful purpose and processed only to the extent necessary. Consent must be free, specific, informed, and unambiguous, and the Data Fiduciary must provide a clear notice before seeking consent. Data Principals are granted rights to access information about processing, to correction and erasure, and to grievance redressal.
These are sound principles. They align broadly with the GDPR's foundational architecture.
However, the manner of their implementation reveals differences. The DPDPA does not create explicit categories of 'sensitive personal data', health records, financial data, biometrics, with heightened protections, unlike the GDPR's Article 9. It collapses these distinctions, leaving the question of differentiated protection to future rules that the central government may or may not frame. This is a legislative abdication dressed as regulatory flexibility.
The Digital Personal Data Protection Rules, 2025, notified following the public consultation process, provide greater procedural detail regarding notice requirements, consent management, and the obligations of Significant Data Fiduciaries. However, they continue to leave several substantive issues-including the scope of differentiated protection and the criteria for certain regulatory classifications-to executive notification and future implementation. Consequently, while the Rules operationalise many provisions of the DPDPA, they do not fully address the structural concerns identified above regarding legislative delegation and executive discretion.
Consent Architecture: Structural Weaknesses
The consent mechanism deserves closer scrutiny. The Act envisions 'deemed consent', processing without explicit consent, in a broad range of situations, including functions of the State, compliance with law, medical emergencies, employment relationships, and 'legitimate uses' to be prescribed by the government. The 'legitimate uses' is particularly expansive and vague.
Commentators examining the Act's early implementation have reached a similar conclusion, observing that terms such as "public interest," "national security," "reasonable purpose," and "significant data fiduciary" remain undefined and open to interpretation - an ambiguity that the Digital Personal Data Protection Rules, 2025, have only partially addressed.
In the GDPR's equivalent provision, the 'legitimate interests' basis in Article 6(1)(f), there is at least a requirement that such interests be balanced against the data subject's fundamental rights. The DPDPA contains no such balancing requirement. The government's power to add to the list of legitimate uses by notification further concentrates discretion in the executive.
It is also worth noting that the Act does not create a right to data portability, a key entitlement under the GDPR and the California Consumer Privacy Act, except in a weakened form subject to central government notification.
For a country aspiring to be a digital economy leader, the absence of robust portability rights is both a consumer rights failure and a competition policy failure.
Comparative Analysis: GDPR and CCPA
The GDPR, enacted in 2016 and operative since 2018, is the world's most comprehensive data protection instrument. It applies to all entities processing data of EU residents, regardless of where the entity is located. It creates independent data protection authorities in each member state, coordinated through the European Data Protection Board. It imposes fines of up to four percent of global annual turnover for the most serious violations. It creates explicit protections for sensitive data categories, requires data protection impact assessments for high-risk processing, and mandates privacy-by-design.
The GDPR's 'right to be forgotten', a contested but significant entitlement, has no real counterpart in the DPDPA.
The California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, takes a somewhat different approach, centering on consumer rights to know, delete, and opt-out of the spread of personal data. It creates a dedicated California Privacy Protection Agency with enforcement powers. While less comprehensive than the GDPR in some respects, it is notable for its explicit extension to business-to-business data and its whistleblower protections.
Against these benchmarks, the DPDPA appears considerably more State-friendly and enforcement-light. Its penalties, while nominally significant (up to Rs. 250 crore per breach), are assessed by the Data Protection Board, an executive body, not an independent regulatory authority, and are not calibrated as a percentage of global turnover, a significant gap for regulating multinational data fiduciaries.
The Cybersecurity Architecture: It Act and Its Discontents
The IT Act, 2000: A Framework Outpaced by Technology
The Information Technology Act, 2000 was India's foundational legislation for the digital space. Enacted before social media, cloud computing, the smartphone revolution, or large-scale data breaches were imaginable as everyday phenomena, it has been repeatedly amended and stretched to accommodate realities its drafters could not have foreseen. It remains the primary source of cybercrime liability, intermediary regulation, and State powers of interception.
Section 43A of the IT Act, introduced by the 2008 amendment, imposes liability on corporate bodies handling sensitive personal data for negligent security practices causing wrongful loss. The IT (Reasonable Security Practices) Rules, 2011 operationalise this requirement. However, the standard of 'reasonable security practices' has never been authoritatively defined by courts, and the civil remedy framework has been largely ineffective, there is hardly any reported judgment in which a data breach victim has successfully recovered compensation under Section 43A. Section 66C criminalises identity theft, and Section 66D criminalises cheating by impersonation using computer resources.
These provisions serve important functions but are complaint-driven, underenforced, and inadequate to the scale of cyberfraud in contemporary India. The Indian Cyber Crime Coordination Centre (I4C) was established in 2020 to coordinate responses, but institutional capacity remains a persistent challenge.
CERT-In and the 2022 Directions
The Computer Emergency Response Team of India (CERT-In) functions under Section 70B of the IT Act as the national nodal agency for cybersecurity incident response. In April 2022, CERT-In issued directions requiring service providers, intermediaries, and data centres to mandatorily report cybersecurity incidents within six hours of detection, one of the shortest mandatory reporting windows globally. The directions also required the maintenance of logs for 180 days and the synchronisation of clocks to Indian Standard Time. VPN providers were required to maintain customer records for five years, a requirement that caused several major VPN services to shut down their Indian servers.
These directions are significant both for what they do and what they reveal. The six-hour reporting window is operationally challenging for large organisations dealing with complex breaches. The VPN requirement, ostensibly justified by national security, is difficult to reconcile with the privacy rights of journalists, activists, and whistleblowers who rely on VPNs for secure communication. The directions were issued without prior public consultation, raising procedural legitimacy concerns.
Intermediary Liability: The Section 79 Framework
Section 79 of the IT Act provides a safe harbour to intermediaries, platforms like social media companies, search engines, and messaging services, for third-party content, subject to compliance with due diligence requirements.
The IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 significantly expanded these requirements, mandating the appointment of compliance officers, grievance redressal mechanisms, monthly transparency reports, and, most controversially, 'traceability' obligations for significant social media intermediaries.
The traceability requirement compels messaging platforms to identify the 'first originator' of messages flagged as threatening national security or public order. The technology implementation of this requirement necessarily requires breaking end-to-end encryption, a fact acknowledged by technologists but fiercely disputed by the government. The constitutional challenge to this requirement remains pending before the Supreme Court.
The tension is fundamental: traceability and end-to-end encryption are mutually incompatible, and the Court's resolution of this question will have profound consequences for digital rights in India.
The Supreme Court's own jurisprudence provides relevant guidance. In Shreya Singhal v. Union of India, the Court struck down Section 66A of the IT Act, which criminalised online speech causing annoyance or inconvenience, as unconstitutionally vague and an unjustifiable restriction on free expression. The Shreya Singhal principle, that content restrictions online must meet the same constitutional standards as offline speech restrictions, applies with equal force to surveillance and traceability mandates.
Cross Cutting Themes: Aadhar and Data Localisation
AADHAR: The Biometric State
No discussion of Indian data protection is complete without confronting Aadhaar. Established under the Aadhaar Act, 2016, the system has enrolled over 1.3 billion individuals, collecting biometric identifiers, fingerprints, iris scans, alongside demographic data. Its integration into welfare delivery, banking, taxation, and telecommunications has made it the world's most extensive civilian biometric database.
The second Puttaswamy judgment of 2019, the Aadhaar judgment, upheld the constitutional validity of the Aadhaar Act in a fractured 4:1 verdict, while striking down its mandatory private sector linkage. Justice D. Y. Chandrachud's dissent is, however, the more intellectually compelling opinion. He characterised Aadhaar as creating a 'surveillance state,' noting that the aggregation of data across databases transforms mundane information into a profile capable of tracking an individual's movements, transactions, and social interactions. This aggregation problem, the privacy harm that arises not from any single data point but from the combination of multiple datasets, is one the DPDPA barely addresses.
The Aadhaar example illustrates a deeper structural problem in Indian data governance: the State demands data from citizens as a condition of access to rights and services, simultaneously positioning itself as both the largest data collector and the legislator determining the rules of collection. This conflict of interest is constitutionally troubling and practically dangerous.
B. Cross-Border Data Flows and Data Localisation
The question of where data is stored is not merely technical, it determines which jurisdiction's laws govern access, breach liability, and law enforcement requests.
The 2019 Bill proposed mandatory localisation of 'critical personal data' on Indian servers and mirroring of 'sensitive personal data.' The DPDPA marks a decisive departure from this framework, vesting in the Central Government the power to notify permissible transfer destinations, substituting the rigidity of mandatory localisation with the administrative flexibility of a whitelist regime.
This is actually a more sophisticated approach, consistent with the adequacy decision mechanism under the GDPR. However, the criteria for notifying countries as permissible transfer destinations are not specified in the statute, they are left to executive discretion.
The Schrems II saga in Europe illustrates the dangers of data transfer frameworks that lack genuine independence and enforceability. The Court of Justice of the European Union invalidated the EU-US Privacy Shield precisely because US surveillance law did not provide adequate protection for EU data subjects.
India's transfer framework requires equivalent rigour in its criteria and institutional oversight.
The Data Protection Board: Independence and Institutional Adequacy
The DPDPA establishes a Data Protection Board as its enforcement mechanism. On paper, the Board has adjudicatory powers, it can impose significant penalties, direct the erasure of data, and hear complaints. In practice, its structural design raises serious questions about independence. Board members are appointed by the central government, their service conditions are determined by the central government, and they may be removed by the central government. The statute contains no provisions analogous to the security of tenure protections that characterise genuinely independent regulatory bodies like the Election Commission of India or the Comptroller and Auditor General.
This matters enormously when the State is itself a major data fiduciary, through Aadhaar, tax databases, health records, and welfare systems. A Board whose existence depends on executive goodwill cannot be expected to robustly adjudicate complaints against the government that created it.
The contrast with the GDPR model, where supervisory authorities must have 'complete independence' and members must be subject to fixed, non-renewable terms, is stark. India's choice to create an executive-controlled adjudicatory body rather than a genuinely independent regulator represents perhaps the DPDPA's most fundamental structural failure.
The Srikrishna Committee's 2018 report had proposed a Data Protection Authority with genuine independence, modelled partly on the Information Commission under the Right to Information Act, 2005. The abandonment of that model in favour of executive control is a political choice, not a technical necessity, and it deserves critical attention.
The Surveillance Problem: the Elephant in the Room
Lawful Interception Under the IT Act and Telegraph Act
Perhaps the most glaring gap in India's data protection framework is the near-complete absence of meaningful legal regulation of State surveillance. Section 69 of the IT Act empowers the government to intercept, monitor, or decrypt any information for reasons including national security, public order and sovereignty- terms of capacious breadth. The Temporary Suspension of Telecom Services (Public Emergency or Public Safety) Rules, 2017 and the Indian Telegraph Act, 1885 provide parallel interception powers.
The procedural safeguards are minimal and entirely executive in nature, there is no requirement for judicial authorisation before interception is ordered. This stands in stark contrast to the United States where the Foreign Intelligence Surveillance Court, for all its limitations, provides some judicial oversight, Germany where the Federal Constitutional Court has insisted on independent judicial review of surveillance orders, and the European Court of Human Rights' Strasbourg jurisprudence, which requires prior judicial control as a general rule.
The Puttaswamy proportionality test, which should apply to surveillance, has not been tested against Section 69 in the Supreme Court. The Pegasus spyware controversy of 2021, which involved alleged targeted surveillance of journalists, activists, and opposition politicians using Israeli NSO Group software, brought these questions into sharp public relief.
The Supreme Court constituted a Technical Expert Committee to investigate, but its findings were not made public in their entirety. This episode underscores how the absence of a robust legal framework for surveillance enables State overreach without accountability.
The DPDPA's Exemptions: A State Carve-Out
The DPDPA contains a broad exemption for the State and its instrumentalities from most of the Act's obligations when processing data for national security, public order, or law enforcement purposes. This exemption is unlimited in scope and entirely self-assessed, the government determines when the exemption applies, without independent review. As commentators have noted, this carve-out effectively creates a two-track system- robust if imperfect protections for data processed by private entities, and near-total absence of statutory protection against government data processing.
The irony is that the State, which collects the most personal data, through the most coercive means, with the least reciprocal accountability, is the entity least constrained by the law.
This is not an unfamiliar structural pathology in Indian law. The RTI Act's exemption for intelligence agencies and security organisations has similarly been criticised for creating a zone of unaccountability. But the data protection context is more acute, because the digital State's capacity for mass surveillance, through Aadhaar linkages, NATGRID, the proposed Criminal Procedure (Identification) Act, and CERT-In's logging requirements, far exceeds anything contemplated when the RTI exemptions were drafted.
Emerging Frontiers: AI, Children's Data, and the Competition Interface
Artificial Intelligence and Automated Decision-Making
The DPDPA is almost entirely silent on artificial intelligence and automated decision-making, a significant lacuna given India's ambitions in the AI sector. The GDPR's Article 22 grants data subjects a right not to be subject to solely automated decisions with significant effects, and requires explainability. The DPDPA contains no equivalent provision. As AI-driven systems increasingly determine creditworthiness, insurance eligibility, hiring decisions, and judicial risk assessments, the absence of a right to explanation or contestation is not merely a regulatory gap but a due process problem.
This gap is compounded by the DPDPA's exclusion of "publicly available personal data" from its scope under Section 3(c)(ii), a carve-out increasingly scrutinised for the uncertainty it creates around AI systems trained on datasets scraped from the open web.
The government's National Strategy on Artificial Intelligence (2018) and the more recent IndiaAI Mission have focused primarily on the opportunity dimensions of AI, with insufficient attention to rights and accountability. A data protection framework that does not address the outputs of the systems processing personal data is fundamentally incomplete.
Children's Data
The DPDPA's provisions on children's data are both notable and problematic. Section 9 prohibits the processing of children's data without verifiable parental consent and prohibits 'tracking, behavioural monitoring or targeted advertising' directed at children. These are meaningful protections.
However, the Act defines a child as a person below eighteen years, and the age verification mechanism is left entirely to future rules. Digital age verification is technically difficult, expensive, and creates its own privacy risks, the very act of verifying age online may require sharing more personal data than the underlying service would have processed.
Some industry participants favour a risk-based approach, with lower age thresholds for services that present limited harm. The GDPR permits member states to set the age of digital consent between thirteen and sixteen. The DPDPA instead adopts an absolute threshold that may prove difficult to enforce without creating an intrusive verification system or widespread non-compliance.
Data Protection and Competition Law
An underappreciated dimension of data law is its intersection with competition policy. Large technology platforms namely Meta, Google, Amazon, derive competitive advantage precisely from the data they accumulate.
When WhatsApp unilaterally changed its privacy policy in 2021 to mandate data-sharing with Meta's other products, the Competition Commission of India initiated proceedings that resulted in a significant order finding abuse of dominance. This case illustrates how data protection violations can simultaneously constitute competition harms, and how the institutional architecture for addressing these overlapping concerns remains fragmented.
The DPDPA does not create any mechanisms for coordination between the Data Protection Board and the Competition Commission of India. As data becomes the primary input of the digital economy, this institutional fragmentation, with data protection, competition, telecom, and financial sector regulators each holding partial jurisdiction, creates both regulatory gaps and the risk of conflicting mandates.
Critical Synthesis: What Is Missing and Why It Matters
Looking across this landscape, several structural deficits emerge that no amount of rule-making under the DPDPA can fully cure.
First, the accountability deficit- the law creates significant obligations for private data fiduciaries but exempts the State in ways that are both overbroad and insufficiently scrutinised. A data protection law that does not bind the government with the same rigour as it binds private actors is not truly a fundamental rights instrument, it is a consumer protection statute with a constitutional preamble.
Second, the institutional deficit- the Data Protection Board's dependence on the executive for appointment, tenure, and conditions of service makes genuine regulatory independence structurally impossible. India's experience with other regulatory bodies, the CCI, TRAI, SEBI- demonstrates that institutional design matters enormously. The Board needs constitutional or statutory insulation equivalent to that enjoyed by constitutional bodies.
Third, the surveillance deficit- the absence of judicial authorisation requirements for State surveillance, the broadly drafted exemptions in the DPDPA, and the lack of any oversight mechanism for intelligence agency data processing constitute a systemic failure to translate Puttaswamy's constitutional promise into operational reality. The proportionality test the Supreme Court articulated requires legislative embodiment, not merely judicial aspiration.
Fourth, the technology deficit- the Act's silence on AI, automated decision-making, facial recognition technology, and the aggregation of non-personal data means that the framework is already running behind the technological frontier.
The CERT-In directions, the Aadhaar ecosystem, and the proposed National Data Governance Framework will generate legal questions that the DPDPA is not designed to answer.
Conclusion and Recommendations
India stands at a critical juncture. The DPDPA represents genuine legislative progress after two decades of regulatory inadequacy. It creates a consent-based processing framework, establishes individual rights, and imposes obligations on fiduciaries that did not previously exist in statute. This should not be minimised.
But the law as enacted is a beginning, not a destination. The following reforms are necessary to build a data protection regime worthy of a constitutional democracy. Parliament should amend the DPDPA to bind State instrumentalities to the same consent, purpose-limitation, and accountability standards as private actors, with limited and judicially reviewable exceptions for genuine national security imperatives. The Data Protection Board must be reconstituted as a genuinely independent regulatory authority, with members appointed through a collegium process and protected by security of tenure equivalent to that of High Court judges.
Judicial authorisation, not merely executive oversight, should be required before any surveillance order under Section 69 of the IT Act, consistent with the proportionality standard mandated by Puttaswamy.
The DPDPA must be supplemented by rules or dedicated legislation addressing automated decision-making, algorithmic transparency, and AI governance. Cross-border data transfer criteria must be legislatively specified, with independent adequacy assessments and reciprocal privacy rights for Indian data abroad.
The notification of the Digital Personal Data Protection Rules, 2025, has advanced the operational implementation of the DPDPA by prescribing procedural compliance requirements. Nevertheless, many of the constitutional and institutional concerns discussed in this paper-including executive exemptions, regulatory independence, and surveillance oversight-remain matters of legislative design rather than procedural implementation.
The right to privacy that the Supreme Court recognised in Puttaswamy is not a formal entitlement to be satisfied by the enactment of any statute that uses the word 'data.' It is a substantive guarantee of individual autonomy against both private actors and, perhaps especially, against the State. India's data protection framework, in its current form, honours that guarantee incompletely. The work of making it complete remains, urgently, to be done.
Primary materials
Key primary materials: Digital Personal Data Protection Act, 2023 and subordinate legislation; Ministry of Electronics and Information Technology.