Author: Aaditya Mittal, B.B.A. LL.B. (Hons.), Fairfield Institute of Management and Technology, GGSIPU
Introduction
The Digital Personal Data Protection Act, 2023 got Presidential assent on 11 August 2023. That’s the short version. The longer version runs through Justice K.S. Puttaswamy v. Union of India, the Srikrishna Committee’s 2018 report, two Bills that were withdrawn in 2019 and 2021, and a 2022 draft that finally stuck. What we got at the end of all that is India’s first standalone data protection law – and a much slimmer one than anyone expected a few years ago. Just 44 sections, built on broad principles ratherthan the kind of granular detail the earlier drafts had. In this piece I want to walk through how the Act is put together, weigh its consent and exemption framework against the constitutional right to privacy that Puttaswamy set out, and point to the bitsmost likely to end up in front of a court once the Act is actually switched on.
Scope and Key Definitions
Start with Section 3. It applies to digital personal data collected in India, whether that data was born digital or got digitised later, and it also reaches outside India wherever the processing is tied to offering goods or services to people here. If that sounds like the GDPR’s Article 3, it should – the extraterritorial logic is borrowed almost directly, minus the GDPR’s more elaborate ‘establishment’ test.
Here’s the catch, though: this Act only cares about digital data. Paper records are outside its scope, full stop, unless someone eventually digitises them. Section 3(c) adds two more carve-outs – purely personal or domestic processing, and data a person has voluntarily made public, or that someone else is legally required to make public. That second one is illustrated in the Act by the now-familiar ‘blogger’ example, and it’s written loosely enough to potentially cover large-scale scraping of information nobodyever meant for commercial reuse. The Act doesn’t really grapple with that problem.
On terminology, the Act sets up a Fiduciary/Processor structure that mirrors the GDPR’s Controller/Processor split under Sections 2(i) and 2(k). What it adds on top is the Consent Manager, defined in Section 2(g) – a registered intermediary through which someone can give, manage, review, or withdraw consent. This part is genuinely new. It draws on the Account Aggregator model already working in India’s financial sector, and honestly, whether it delivers on that promise comes down entirely to the technical standards and registration conditions still waiting to be written.
The Consent and ‘Legitimate Uses’ Framework
Section 4 keeps things narrow: processing is lawful only with consent under Section 6, or under one of the seven ‘certain legitimate uses’ in Section 7. Consent has to be free, specific, informed, unconditional, unambiguous, and given through a clear affirmative act. If part of that consent breaches the Act, that part alone is severable and void – which is, in effect, the EU’s anti-bundling rule showing up in Indian law.
Section 7 goes a good deal further than the GDPR’s Article 6 legitimate-interest test. It covers voluntary data-sharing for a specified purpose, State delivery of subsidies and benefits, compliance with judgments and legal obligations, medical emergencies, disaster response, and one that stands out – employment-related processing under Section 7(i). That ground stretches to cover anything ‘related to safeguarding the employer from loss or liability,’ which in practice hands employers a lot of room to process employee data without asking, subject only to the general duties in Chapter II.
Rights and Duties of the Data Principal
Chapter III is where the rights sit. A right to a summary of processed data and to know who it’s been shared with (Section 11), a right to correction and erasure (Section 12), a right to grievance redressal that has to be exhausted before anyone reaches the Board (Section 13), and one that’s a bit unusual – a right to nominate someone to act on your behalf if you die or become incapacitated (Section 14). No direct GDPR equivalent for that last one. It’s a local addition.
What’s missing matters too, maybe more. No standalone right to data portability. No general right to object to processing. Both exist under the GDPR; neither made it into this Act. And then Section 15 turns the tables a little by imposing duties on Data Principals themselves – don’t impersonate someone, don’t withhold material information, don’t file frivolous complaints. It’s an unusual bit of symmetry for a privacy statute, and I wouldn’t be surprised if Fiduciaries end up leaning on it to push back against genuine grievances.
Obligations of Data Fiduciaries and the Significant Data Fiduciary Category
Section 8 sets the baseline: keep the data accurate, put reasonable security safeguards in place, notify the Board and affected individuals if there’s a breach, and erase data once it’s served its purpose. One thing that stands out is what’s missing – unlike the GDPR’s 72-hour breach-notification rule, the DPDP Act doesn’t fix a timeline at all. It’s left to be ‘prescribed’ later. That turns out to be a pattern running through the whole statute; more than twenty separate matters, including what even counts as ‘reasonable’ security, have been handed off to rules under Section 40 that don’t exist yet.
Section 10 then creates the Significant Data Fiduciary category, for entities the Central Government notifies based on data volume, sensitivity, risk to electoral democracy, and public order. These entities carry extra weight – an India-based Data Protection Officer, an independent auditor, and periodic Data Protection Impact Assessments. Similar idea to the GDPR’s DPIA regime, just triggered by government notification instead of the entity’s own risk assessment.
The Data Protection Board of India: Structure and Independence Concerns
Chapter V sets up the Data Protection Board of India as the Act’s main enforcement body, and it looks nothing like what the Srikrishna Committee had originally imagined – an independent regulator with both rule-making and broad supervisory powers. As passed, the Board’s composition, tenure, and terms of service are all decided by the Central Government under Sections 19 and 20. Add to that the fact that the Government is itself a major processor of personal data with wide exemptions under Section 17(2), and that the Board’s actual job is adjudicatory rather than regulatory – real rule-making power under Section 40 sits with the Central Government, not the Board.
Unsurprisingly, this has drawn a fair amount of criticism from privacy scholars and practitioners. A body appointed by, and answerable to, the executive isn’t obviously well placed to hear complaints against the executive’s own agencies. Section 28’s requirement that the Board function ‘as far as practicable’ as a digital office is a sensible efficiency measure. It just doesn’t touch this deeper independence problem at all.
Exemptions: The Most Contested Provision
If one provision in this Act is going to keep courts busy, it’s Section 17. Section 17(1) exempts things like enforcement of legal rights, court and tribunal processing, and offence investigation from most of Chapters II and III. The bigger issue is Section 17(2)(a), which lets the Central Government exempt any ‘instrumentality of the State’ from the entire Act by mere notification, on grounds as broad as sovereignty, security of the State, public order, and friendly relations with foreign States. None of the safeguards Puttaswamy read into privacy restrictions – necessity, proportionality, judicial oversight – show up here.
Compare that to the GDPR, which ties similar derogations to specific, narrowly defined national-security exemptions subject to constitutional review at the member-state level. The DPDP Act doesn’t do any of that. The proportionality question is left entirely to executive discretion, and there’s no requirement that a notification be time-bound, reasoned, or independently reviewed, beyond the fairly thin requirement in Section 41 that it simply be laid before Parliament. Given how much personal data the Indian State itself handles – Aadhaar-linked welfare systems, policing, surveillance – it makes sense that this exemption has drawn the sharpest constitutional criticism of the whole Act. I wouldn’t be shocked to see a challenge built on the Puttaswamy and Aadhaar proportionality standard once this provision actually gets used.
Penalties and Enforcement
The Schedule sets out fairly steep monetary penalties – up to ₹250 crore for failing to maintain reasonable security safeguards, up to ₹200 crore for breach-notification failures or violations involving children’s data, and up to ₹150 crore for non-compliance by a Significant Data Fiduciary. Numbers big enough to sting large platforms. What the Act stops short of, though, is criminal liability, which is a real departure from several sectoral Indian statutes and from how some GDPR member states enforce their own laws. Worth noting too that penalties go to the Consolidated Fund of India rather than to the people actually affected, and there’s no private right of action or compensation built in. Anyone chasing a remedy for real harm has to fall back on tort or consumer protection law instead.
Concluding Observations
On the whole, the DPDP Act reads like a pragmatic, business-friendly middle ground between the GDPR’s rights-heavy model and the practical limits of Indian governance and enforcement capacity. Its consent framework, breach-notification duties, and Significant Data Fiduciary obligations do move India’s private-sector data practices closer to global norms. But the broad, government-controlled exemption powers under Section 17(2), the lack of a genuinely independent regulator, and just how much of the Act’s substance has been handed off to rules that haven’t been written yet – all of this means its real character, protective or permissive, won’t be obvious until those rules are notified and the Board is actually up and running. Until then, I’d treat this as a framework statute. Its real impact on the right to privacy under Puttaswamy is, in large part, still unwritten.
Frequently Asked Questions
Does the DPDP Act cover paper records, or only digital data?
Just digital data. Section 3 keeps the Act’s scope limited to digital personal data – anything that exists purely on paper stays outside it, until someone digitises it, at which point the Act applies.
Is consent the only lawful basis for processing personal data?
There’s a second route. Section 4 lets Fiduciaries rely either on consent under Section 6, or on one of the seven ‘certain legitimate uses’ in Section 7 – things like State delivery of subsidies, compliance with legal obligations, medical emergencies, and employment-related processing.
What exactly is a Consent Manager?
A registered intermediary, defined under Section 2(g), that lets a person give, review, manage, or withdraw consent across different Data Fiduciaries in one place. Borrowed loosely from India’s existing Account Aggregator framework for financial data.
Does the Act give a right to data portability or a right to object to processing?
It doesn’t, and it’s a fairly noticeable gap. Chapter III covers access, correction, erasure, grievance redressal, and nomination, but there’s no standalone portability right and no general right to object – both of which the GDPR provides.
What makes an entity a Significant Data Fiduciary?
A government notification under Section 10, based on factors like the volume and sensitivity of the data being processed, risk to electoral democracy, and public order. Once notified, the entity has to appoint an India-based Data Protection Officer and an independent auditor, and run periodic Data Protection Impact Assessments.
Is the Data Protection Board actually independent of the Government?
Not structurally. Its composition, tenure, and service conditions are all decided by the Central Government under Sections 19 and 20, and its function is mostly adjudicatory – the actual power to frame rules sits with the Central Government under Section 40. Probably the most consistent criticism privacy scholars have raised about the Act.
Can the Government exempt itself or its own agencies from the Act?
Yes. Arguably the most contested feature of the whole statute. Section 17(2)(a) allows the Central Government to exempt any ‘instrumentality of the State’ from the entire Act through a simple notification, on grounds as broad as sovereignty, security of the State, and public order, with no requirement that the exemption be time-bound, reasoned, or independently reviewed.
Does the Act carry any criminal liability for non-compliance?
No. It’s limited to monetary penalties, going up to ₹250 croredepending on what’s violated – a deliberate departure from several sectoral Indian statutes that do carry criminal consequences.
If a Data Fiduciary mishandles my data, can I claim compensation directly?
Not through this Act. Penalties go to the Consolidated Fund of India rather than to the person affected, and there’s no private right of action written into the statute. Actual harm would need to be pursued under general tort or consumer protection law instead.
Has the DPDP Act actually come into force yet?
It has Presidential assent, but a lot of how it works in practice depends on subordinate rules under Section 40 that haven’t been notified yet – breach-notification timelines, how the Board is actually composed, and more. Until those rules show up, large parts of this Act are, in a very real sense, still unwritten.
(The author is a fourth-year B.B.A. LL.B. (Hons.) student and Executive Member of the Moot Court Society at Fairfield Institute of Management and Technology, GGSIPU, Delhi. Views expressed are personal.)



