Site icon Lawful Legal

FROM VOTER TO DATA SUBJECT: CAN POLITICAL PARTIES BE TREATED AS DATA FIDUCIARIES UNDER INDIA’S DPDP REGIME?

Voter Profiling, Political Targeting and the Constitutional Right to Privacy in Indian Elections

Author: Mahima Mittal
College: Asian law college, ccsu

I. TO THE POINT

1. Indian elections are increasingly fought through digital databases, voter segmentation, targeted messaging and analysis of individual and group characteristics, rather than through rallies and door to door canvassing alone.

2. This raises a question that Indian data protection law has not yet answered directly. When a political party decides why and how a voter’s personal data is collected, analysed or used for campaigning, can that party be treated as a Data Fiduciary under the Digital Personal Data Protection Act, 2023.

3. The Act defines a Data Fiduciary as any person who, alone or with others, determines the purpose and means of processing personal data. It does not carve out an express exemption for political parties merely because their activity is electoral or political in nature. However, it is important to state clearly that not all of the Act’s provisions are currently operative. The Ministry of Electronics and Information Technology notified the Digital Personal Data Protection Rules, 2025 on 13 November 2025, and the Act and Rules now follow a staggered commencement, with certain procedural and institutional provisions taking effect immediately, a further set scheduled to commence approximately one year later, in November 2026, and the remaining substantive compliance obligations scheduled to commence roughly eighteen months later, in May 2027. This article’s analysis is therefore prospective and interpretative in significant part, and should not be read as suggesting that the entire substantive DPDP regime is presently enforceable against political parties or anyone else.

4. Electoral data also occupies a distinctive legal space. Electoral rolls are maintained within a separate statutory framework administered by the Election Commission of India, while political parties may independently collect additional information through surveys, membership drives, canvassing and third party sources.

5. This article therefore distinguishes between official electoral roll information, personal data independently collected by parties, inferred political preferences, data obtained from third parties, and data processed for targeted political communication, and argues that political status should not, by itself, immunise an organisation from data protection obligations once those obligations become fully operative.

II. USE OF LEGAL JARGON

A. Data Principal, the individual to whom personal data relates. In this context, the voter can potentially occupy this position.

B. Data Fiduciary, the person who determines the purpose and means of processing personal data, the central classification examined in this article.

C. Processing, a deliberately broad statutory concept covering collection, storage, analysis, sharing and use of digital personal data, within which political profiling and segmentation may fall.

D. Consent, one recognised legal basis for processing under the Act, raising practical questions in the political context about whether consent obtained for one purpose, such as party membership, can support a different purpose, such as targeted political communication.

E. Certain legitimate uses, the specified situations set out in the Act where personal data may be processed without relying on ordinary consent, none of which appears designed with political campaigning specifically in mind.

F. Purpose limitation, the principle that data collected for one purpose should not be repurposed without an appropriate legal basis.

G. Data minimisation and security, obligations concerning the volume of data collected and the safeguards applied to it, relevant given the scale of voter databases maintained by parties.

H. Informational privacy, the constitutional dimension flowing from Article 21, as recognised by the Supreme Court in its privacy jurisprudence, distinct from any statutory classification of data types under the Act itself.

III. THE PROOF

1. The constitutional foundation of privacy. The starting point is Justice K.S. Puttaswamy and Another v. Union of India and Others, (2017) 10 SCC 1, in which a nine-judge Bench of the Supreme Court recognised privacy as a right protected under Article 21. Political opinions, affiliations and voting behaviour are personal data capable of revealing highly sensitive aspects of an individual’s identity, beliefs or associations, even though the DPDP Act does not itself create a separate statutory category of sensitive personal data as some earlier draft legislation had proposed. The constitutional question that follows is whether political campaigning can justify collection and profiling of such information without meaningful informational control resting with the voter. The Digital Personal Data Protection Act, once its substantive provisions come fully into force, will operate against this constitutional background.

2. Electoral data is not simply public data. The presence of a voter’s name in a legally accessible electoral roll does not, without more, mean that every subsequent use of that information is unrestricted. The Election Commission of India maintains the electoral roll system and a public search facility, but administrative accessibility for electoral purposes is different from unrestricted commercial or political exploitation of the same information for profiling. Whether such reuse is lawful requires a separate examination of the legal basis and purpose of the subsequent processing, rather than an assumption that public availability for one purpose automatically authorises use for another.

3. The statutory question under the DPDP Act. The Act introduces the vocabulary of Data Principal, Data Fiduciary, processing, consent, certain legitimate uses, security safeguards and the rights and obligations attaching to each. As noted above, the Rules and the corresponding provisions of the Act commence in three phases, and any assessment of a political party’s current obligations must be read against the specific commencement date applicable at the relevant time, rather than assumed to already apply in full.

4. Locating political parties within the statutory definition. A party’s data related activities can be broken down into a chain, namely outreach, surveys, collection of contact details, demographic segmentation, inference of political preference, and targeted messaging. Not every link in that chain necessarily rests on the same legal basis. Where a party itself decides what information to collect, why it is collected, how it is analysed, with whom it is shared, and how it is used for political communication, there is a credible textual argument for examining that party through the Data Fiduciary framework. This is presented here as this article’s central unresolved legal question and a matter of statutory interpretation, not as settled law. No Supreme Court judgment has yet conclusively held that political parties are Data Fiduciaries under the DPDP Act, and the more accurate formulation is that the Act creates a credible statutory basis for treating a political party as a Data Fiduciary when it independently determines the purpose and means of processing voters’ personal data, once the relevant provisions are in force.

5. The democratic counterweight, the voter’s own right to information. Privacy cannot be assessed in isolation from electoral transparency. The Supreme Court’s jurisprudence recognises that voters possess a right to information about candidates under Article 19(1)(a), necessary for casting an informed vote. Separately, the Court’s more recent electoral jurisprudence shows that even in matters of maximal transparency, such as verification of how votes are recorded and counted, the electoral architecture itself continues to protect the individual voter’s own informational privacy. This produces an important asymmetry, discussed further below, between the voter’s right to know about the candidate and the very different question of what a party may know about the voter.

IV. ABSTRACT

This article examines whether political parties can be treated as Data Fiduciaries under the Digital Personal Data Protection Act, 2023 when they collect, analyse or use voters’ personal data for campaigning, profiling and targeted political communication. It situates the statutory definition of Data Fiduciary against the constitutional right to privacy recognised in the Puttaswamy line of cases and against the Supreme Court’s electoral jurisprudence on the voter’s right to information and on the secrecy of the ballot. It distinguishes official electoral roll data from data independently collected or inferred by political parties, and argues that political status should not automatically place a party outside data protection obligations, while acknowledging both that no court has yet conclusively determined this specific question and that substantial parts of the DPDP regime are still in the process of staggered commencement. The article proposes that a political party should attract Data Fiduciary obligations to the extent it independently determines the purpose and means of processing personal data, subject always to the Act’s exemptions, lawful bases and commencement timeline.

V. CASE LAWS

1. Justice K.S. Puttaswamy and Another v. Union of India and Others 
Citation: (2017) 10 SCC 1, Supreme Court of India, nine judge Bench, decided 24 August 2017. 
Relevance and reference of judgment: The Court held that the right to privacy is protected as an intrinsic part of the right to life and personal liberty guaranteed under Article 21, and recognised informational privacy and individual autonomy over personal data as central components of that right. The judgment supplies the constitutional foundation for this article’s central claim, namely that a voter’s political opinions and behavioural data attract heightened constitutional protection, so that any statutory scheme permitting their collection or profiling, including by a political party, must be examined against Article 21 rather than treated as a purely commercial or regulatory matter.

2. People’s Union for Civil Liberties v. Union of India 
Citation: (2003) 4 SCC 399, Supreme Court of India. 
Relevance and reference of judgment: The Court held that the right of voters to know relevant information about candidates, including criminal antecedents and assets, flows from the freedom of speech and expression under Article 19(1)(a), reasoning that an informed citizenry is essential for meaningful participation in a democracy. This case supplies the core voter right to information proposition relied upon in this article, namely that transparency obligations in Indian election law run from the candidate toward the voter.

3. Association for Democratic Reforms v. Election Commission of India 
Citation: 2024 INSC 341, Supreme Court of India, decided 26 April 2024. 
Relevance and reference of judgment: This case did not concern candidate disclosure. It arose from a challenge to the adequacy of the Voter Verified Paper Audit Trail system and sought either a return to paper ballots or one hundred percent cross verification of votes. The Court declined that relief and, in doing so, described the design of the VVPAT printer’s window as tinted specifically to maintain secrecy, allowing only the individual voter a seven second view of their own slip. The judgment is used in this article not for the candidate disclosure proposition, which is drawn instead from People’s Union for Civil Liberties, but to illustrate a genuine constitutional tension in Indian election law between electoral transparency and the individual voter’s own informational privacy. Even where the Court insists on verifiability and transparency of the electoral process as a whole, it simultaneously preserves the secrecy of each individual voter’s choice from disclosure to others, including the state’s own counting machinery. This supports, by analogy, the article’s broader argument that transparency values in the electoral sphere do not translate into an unrestricted right of any actor, including a political party, to acquire or expose voter specific information.

VI. CONCLUSION

The better legal position is neither that every political party is automatically a Data Fiduciary, nor that political parties fall outside data protection law simply because they operate in the electoral sphere. The more defensible position is functional and, at present, interpretative rather than settled. Where a political party independently determines the purpose and means of processing personal data, the statutory definition of Data Fiduciary provides a substantial basis for applying the Digital Personal Data Protection Act, subject to its exemptions, lawful bases and the staggered commencement timeline that governs the Act and the 2025 Rules through 2026 and 2027. The constitutional position reinforces this reading. Puttaswamy establishes informational privacy as part of Article 21, People’s Union for Civil Liberties establishes that voters require information about candidates to participate meaningfully in democracy, and the VVPAT judgment shows that Indian election law itself preserves the secrecy of the individual voter’s choice even while pursuing maximal transparency of the process as a whole. These strands are not in conflict, since the voter’s constitutional interest in transparency runs toward knowing about the candidate and the process, not toward exposing the voter’s own data to others. The central proposition of this article is that political participation may require information about voters, but political power should not automatically confer unrestricted control over voter information.

VII. FAQ

Q1. Does the DPDP Act expressly declare political parties to be Data Fiduciaries?
A1. No. The Act does not name political parties as a distinct category. The position must be worked out through the general statutory definition based on who determines the purpose and means of processing, and this remains an open question of interpretation.

Q2. Is the entire DPDP Act already in force?
A2. No. The Act and the 2025 Rules commence in stages. Certain provisions took effect on notification in November 2025, a further set is scheduled for November 2026, and the remaining substantive obligations are scheduled for May 2027. Any statement about a party’s current obligations must account for this timeline.

Q3. Is electoral roll information automatically outside data protection law because it is publicly accessible?
A3. Not necessarily. Accessibility for electoral purposes does not automatically authorise unrestricted secondary use of the same information for a different purpose, such as political profiling. The legal basis and purpose of the subsequent use must be examined separately.

Q4. Can political parties lawfully collect voters’ phone numbers?
A4. This depends on how the data was obtained, the legal basis relied upon, the purpose of processing, and which provisions of the Act and Rules are in force at the relevant time.

Q5. Can political parties profile voters based on inferred preferences?
A5. This is precisely the unresolved question examined in this article. Profiling of this kind is capable of amounting to processing of personal data and therefore raises questions of purpose, lawful basis, transparency and security that have not yet been judicially settled.

Q6. Has the Supreme Court already decided whether political parties are Data Fiduciaries?
A6. No. The Supreme Court has developed strong jurisprudence on privacy, on the voter’s right to information about candidates, and on the secrecy of the ballot, but the specific question of whether a political party is a Data Fiduciary under the DPDP Act when profiling voters has not been conclusively decided.

VIII. REFERENCE

1. Justice K.S. Puttaswamy and Another v. Union of India and Others, (2017) 10 SCC 1.

2. People’s Union for Civil Liberties v. Union of India, (2003) 4 SCC 399.

3. Association for Democratic Reforms v. Election Commission of India, 2024 INSC 341.

4. The Digital Personal Data Protection Act, 2023, Ministry of Electronics and Information Technology.

5. The Digital Personal Data Protection Rules, 2025, notified 13 November 2025, Ministry of Electronics and Information Technology, staggered commencement through November 2026 and May 2027.

6. Election Commission of India, Electoral Roll portal and Privacy Policy, official website.

Exit mobile version