Site icon Lawful Legal

DIGITAL PERSONAL DATA PROTECTION RULES, 2025

We are surrounded by data and it keeps generating virtually in everything we do. Data is of two types, one is that we may have to share by our consent and the second type is the data which created every time as soon as we do something virtually- whether it be ordering food, use transportation or booking tickets online. Undoubtedly, this data is of great value and some Companies even tries paying for it. Indeed, in this era of unlimited and free access internet, data is the new currency. With the advancement of technology, almost every document, even the personal ones can be accessed online by the use of Govt. based apps such as Digilocker and MyAadhar. 

Data, being a beneficial tool can sometimes result in huge problems when leaked. Data privacy is a major cause of concern in today’s world. According to survey conducted by the Data Security Council of India (DSCI), almost 87% of Indian consumers are concerned about their data privacy. Mobiles phones are the most common source of data privacy concerns as it has been proved by a survey conducted in the year 2021 that there are over 642 Million mobile users in India making it a potential source of data-stealing apps.

Earlier, there was no dedicated law regarding the data privacy in India. Then, in 2025, the The Ministry of Electronics and Information Technology (MeitY), Government of India, came up with the Digital Personal Data Protection Rules, 2025, to operationalize the 2023 Digital Personal Data Protection Act (the Act) which received the assent of the Hon’ble President of India on 11th August, 2023 and ensure proper protection and personal privacy in the Digital Reality. The notification of the same was released to the public on 3rd January, 2025 which states as follows:-

”Draft of rules proposed to be made by the Central Government in exercise of the powers conferred by sub-sections (1) and (2) of section 40 of the Digital Personal Data Protection Act, 2023 (22 of 2023), on or after the date of coming into force of the Act, are hereby published for the information of all persons likely to be affected thereby; and notice is hereby given that the said draft rules shall be taken into consideration after 18th February, 2025 “

The Digital Personal Data Protection (DPDP) Rules simply provides us with the procedures and obligations important for implementing the Act.

The primary role of this act is to enact the Digital Private Data protection Act, 2023 and to ensure vigorous protection and privacy of personal data in the digital world. The most significant provisions of the Draft Rules are shown below.

While, this was a much needed law for the country for the protection of right to privacy of citizens rather than allowing the companies and the government to collect and use the personal data of citizens in any way they like. However, the draft rules, just like the Act have attracted criticism for their lack of transparency and clarity on user rights, breach of data and parental consent. One of the most highlighted issues with the DPDP Rules is the failure to clarify critical aspects of the DPDP Act. Some Advocates and industry research experts also argue that the government’s opaque consultation process doesn’t contain public participation. This act, thus raises several concerns that are discussed below as follows.

As shown in the above noted points, The Digital Personal Data Protection Rules, 2025 has received a lot of criticism. But it is of no doubt that the DPDP Act has marked a significant advancement in data protection in India. It creates a detailed framework and marks the importance of individual rights and also helps them in claiming them if they are violated. This Act enhances the legal aspect of data protection and helps in matching India with global standard. This alignment can help in attracting international business as it may help in ending their concern over data privacy.

Moving forward, it is also correct to say that the effectiveness of The DPDP Act will stand upon the way it is implemented and how the organizations and individuals adhere to the rules prescribed to uphold the principles.

Frequently asked question (FAQs)

Q. Does this act give the Data Principal the right to access their personal data?

A. Yes, a Data Principal has the right to receive a summary regarding their personal data being used, to whom it is being shared and other information from the Data Fiduciary to whom they have shared their data.

Q. What are the rights provided to a Data Principal regarding the correction and deletion of personal data?

A. Data Principals are given the right to get an inaccurate or misleading data corrected, complete incomplete data, update their data, and request deletion with subject to legal compliance.

Q. What is the minimum timeframe within which a Data Fiduciary must respond to grievances?

A. The Data Fiduciary must respond to the grievance within the time period prescribed by the Central Government which depends upon the complexity of the grievance.

Q. What are the necessary duties of a Data Principal under the DPDP Rule, 2025?

A. Data Principal is expected to comply with the related laws of this Act, avoid impersonation, not hide required information, refrain from registering fake grievances, and provide authentic information for data correction or erasure.

Author:-Syed Ahmed Husain, 5th Semester, 3rd Year Law Student of IME Law College, Ghaziabad

Exit mobile version