Author: Devalay Dey
College: Maharishi University of Information and Technology, Noida
To the Point
The rapid expansion of digital technology has transformed the way personal information is collected, processed, stored, and shared. Every online transaction, mobile application, banking service, healthcare platform, and government portal relies heavily on the processing of personal data. While digitization has improved efficiency and accessibility, it has simultaneously increased the risks of data breaches, identity theft, cyber fraud, unauthorized surveillance, and misuse of personal information.
Recognizing these concerns, Parliament enacted the Digital Personal Data Protection Act, 2023 (DPDP Act), which came into force to establish a comprehensive legal framework governing the processing of digital personal data in India. The Act seeks to balance two competing objectives: protecting the fundamental right to privacy of individuals while enabling lawful processing of personal data for legitimate governmental and commercial purposes.
The enactment of the DPDP Act represents one of the most significant legislative developments in Indian cyber law since the Information Technology Act, 2000. It operationalizes the constitutional principles laid down by the Supreme Court in Justice K.S. Puttaswamy (Retd.) v. Union of India (2017), wherein the Court unequivocally recognized privacy as an intrinsic part of Article 21 of the Constitution.
The Act establishes rights for individuals known as Data Principals, imposes statutory obligations upon organizations known as Data Fiduciaries, creates mechanisms for obtaining valid consent, prescribes penalties for non-compliance, and provides for the establishment of the Data Protection Board of India for enforcement and adjudication.
Despite these progressive features, the legislation has generated considerable legal debate. Questions have arisen regarding government exemptions, cross-border transfer of personal data, enforcement mechanisms, proportionality of restrictions, children’s privacy, algorithmic decision-making, and the independence of the regulatory authority.
Two years after its enactment, the DPDP Act continues to shape India’s digital governance landscape while raising important constitutional questions concerning privacy, accountability, transparency, and fundamental rights.
Use of Legal Jargon
The DPDP Act introduces a specialized legal vocabulary that reflects internationally accepted principles of data protection jurisprudence while adapting them to India’s constitutional framework.
The Act recognizes every individual as a Data Principal, who possesses statutory rights over personal information processed in digital form. The entity determining the purpose and means of processing such data is designated as the Data Fiduciary, whereas any entity processing data on behalf of the fiduciary functions as a Data Processor.
The cornerstone of lawful processing under the Act is free, specific, informed, unconditional, and unambiguous consent, thereby reinforcing the doctrine of informational self-determination. Consent obtained through coercion, ambiguity, or deception is legally invalid.
The legislation also incorporates the principles of purpose limitation, data minimization, storage limitation, accuracy of data, accountability, and reasonable security safeguards, which are globally recognized standards under modern privacy law.
From a constitutional perspective, the validityof restrictions imposed upon privacy rights is examined through the Doctrine of Proportionality, as articulated by the Supreme Court in Justice KS. Putta Swamy (2017). Under this doctrine, any infringement upon the right to privacy must satisfy four essential requirements:
1. Legality through valid legislation;
2. Legitimate State aim;
3. Rational nexus between the objective and the measure adopted; and
4. Necessity and proportionality of the restriction.
The DPDP Act also incorporates the concept of legitimate uses, permitting processing without explicit consent in specified situations, including compliance with legal obligations, medical emergencies, disaster management, employment purposes, and certain governmental functions.
One of the most debated provisions concerns the discretionary power granted to the Central Government to exempt specified instrumentalities of the State from certain obligations under the Act on grounds such as sovereignty, national security, public order, and prevention of offences. While national security constitutes a recognized constitutional ground for restricting rights, such exemptions remain subject to judicial review to ensure compliance with Articles 14, 19, and 21 of the Constitution.
The Act further empowers the Data Protection Board of India to investigate complaints, impose administrative monetary penalties, direct compliance, and adjudicate violations. Civil penalties under the Act may extend to several hundred crorerupees depending upon the nature and gravity of the contravention, thereby reflecting the legislature’s intention to promote robust compliance rather than criminal punishment.
Thus, the DPDP Act represents a significant shift from fragmented sector-specific regulation toward a comprehensive rights-based legal framework governing digital privacy.
The Proof
The Digital Personal Data Protection Act stems from India’s commitment to protect the privacy and dignity of individuals in a digital world. Before this law was passed, India did not have a clear legal framework focused on personal data processing. The main protections against data misuse came from the Information Technology Act of 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules of 2011. Both were seen as insufficient to meet the challenges posed by modern technology, such as artificial intelligence, big data analysis, cloud computing, and international data transfers.
The Act is grounded in the landmark ruling of Justice KS Putaswamy (Retd) v. Union of India (2017). In this case, a nine-judge Constitution Bench unanimously concluded that the Right to Privacy is a fundamental right under Article 21. It is a vital part of the freedoms guaranteed in Part III of the Constitution. The Court highlighted that informational privacy is a key aspect of personal freedom and stressed the State’s duty to create a robust data protection system.
The purpose of the DPDP Act aligns with widely recognized privacy principles, such as the OECD Privacy Guidelines, the General Data Protection Regulation in the European Union, and the APEC Privacy Framework. These frameworks emphasize transparency, accountability, lawful processing, and individual control over personal information as crucial parts of data governance.
The Act gives Data Principals enforceable rights. These include the right to access information about data processing, the right to correct and delete personal data, the right to seek redress for grievances, and the right to nominate someone to exercise these rights in the event of death or incapacity. At the same time, Data Fiduciaries must implement reasonable security measures, inform users of data breaches, erase data when it is no longer needed, and process data according to the Act.
However, legal experts have raised concerns about provisions that allow the Central Government to exempt certain state entities from the Act under specific conditions. Critics argue that broad exemptions without necessary procedural safeguards could face constitutional challenges under Articles 14 and 21. Supporters claim these exemptions are necessary for national security, public order, and essential state functions.
In summary, the DPDP Act marks a significant step forward in Indian privacy law by trying to balance technological progress with constitutional rights. Its long-term success will depend on transparent enforcement, independent regulatory oversight, judicial interpretation, and strict adherence to constitutional values.
Abstract
The Digital Personal Data Protection Act, 2023 is India’s first law that regulates the processing of digital personal data. It was created to enforce the constitutional right to privacy recognized in Justice K.S. Puttaswamy (Retd) v. Union of India (2017). The Act sets up a framework that balances individual privacy with the valid interests of the government and businesses.
This law introduces important concepts like Data Principal, Data Fiduciary, lawful processing with valid consent, acceptable uses of personal data, data breach notification, grievance handling, and administrative enforcement by the Data Protection Board of India. It also imposes significant fines for violations and requires organizations to keep reasonable security measures and handle personal data only for legal reasons. Even with its forward-thinking framework, the Act has sparked debates over issues like government exemptions, the independence of the enforcement body, data transfers across borders, protecting children’s data, accountability for algorithms, and how the State can interfere with personal privacy.
The success of this legislation will depend not only on its legal text but also on how courts interpret it, how effectively it is enforced, public understanding, and how accountableinstitutions are. As India’s digital economy grows, the DPDP Act could become a key part of privacy law while promoting responsible innovation and building public trust in digital governance.
Case Laws
1. Justice K.S. Puttaswamy (Retd.) v. Union of India (2017)
This landmark judgment is regarded as the constitutional foundation of data protection law in India. A nine-judge Constitution Bench of the Supreme Court unanimously held that the Right to Privacy is a fundamental right protected under Article 21 and forms an inseparable part of the freedoms guaranteed by Part III of the Constitution. The Court recognized informational privacy as an essential aspect of personal liberty and observed that individuals possess the right to exercise control over the collection, storage, and dissemination of their personal information. The judgment further introduced the Doctrine of Proportionality, requiring every State action affecting privacy to satisfy the tests of legality, legitimate State purpose, necessity, and proportionality. The Digital Personal Data Protection Act, 2023, derives its constitutional legitimacy from the principles established in this decision.
2. Shreya Singhal v. Union of India (2015)
Although primarily concerned with freedom of speech underArticle 19(1)(a), this case significantly influenced India’s digital rights jurisprudence. The Supreme Court declared Section 66A of the Information Technology Act, 2000 unconstitutional on the ground that its vague and overbroad language violated the fundamental right to freedom of expression. The Court emphasized that restrictions on constitutional rights must be precise, reasonable, and proportionate. The judgment established that laws regulating digital platforms cannot confer arbitrary powers upon public authorities. These principles continue to guide the interpretation of digital governance legislation, including the DPDP Act, particularly in balancing privacy with constitutional freedoms.
3. Anuradha Bhasin v. Union of India (2020) 3 SCC 637
This case arose from the suspension of internet services in Jammu and Kashmir following the constitutional changes relating to Article 370. The Supreme Court held that access to the internet has become an important medium for exercising the freedoms guaranteed under Articles 19(1)(a) and 19(1)(g). The Court ruled that restrictions imposed by the State must satisfy the tests of necessity, proportionality, transparency, and periodic judicial review. Although the judgment dealt with internet shutdowns, its reasoning has broader implications for digital privacy and State regulation of technology. It reinforces the principle that governmental powers affecting digital rights cannot be exercised arbitrarily.
4. People’s Union for Civil Liberties (PUCL) v. Union of India (1997) 1 SCC 301
In this landmark telephone tapping case, the Supreme Court recognized that unauthorized interception of private communications constitutes an infringement of the constitutional right to privacy. The Court directed that surveillance measures must be accompanied by procedural safeguards, accountability, and periodic review to prevent arbitrary abuse of executive power. The principles laid down in PUCL continue to influence contemporary debates concerning digital surveillance, lawful interception, and protection of personal data. They remain relevant while assessing the constitutional validity of governmental exemptions and surveillance powers under the DPDP Act.
5. District Registrar and Collector v. Canara Bank (2005) 1 SCC 496
The Supreme Court held that privacy extends beyond the physical person and includes protection against unreasonable intrusion into personal documents and confidential information. The Court observed that an individual’s personal records cannot be accessed indiscriminately by public authorities without following due process established by law. This judgment strengthened the concept of informational privacy and laid an important doctrinal foundation that was later expanded by the Constitution Bench in Justice K.S. Puttaswamy. The decision continues to support the principle that personal data deserves constitutional protection against arbitrary State action.
Conclusion
The Digital Personal Data Protection Act, 2023 is a major milestone in India’s digital legal framework. It sets up a complete system for protecting personal data while allowing for responsible innovation and economic growth. This law reflects the constitutional values highlighted by the Supreme Court in Justice K.S. Puttaswamy. It recognizes privacy as a vital part of human dignity and personal freedom under Article 21.
However, the Act needs to meet constitutional tests to make sure its implementation does not weaken fundamental rights due to too much government power or weak institutional protections. The long-term success of this law will depend on effective enforcement by the Data Protection Board of India, clear regulatory practices, judicial oversight, and responsible compliance by Data Fiduciaries.
As India moves quickly towards becoming a global digital economy, protecting personal data is not just a legal requirement but a constitutional must. The DPDP Act, if carried out fairly, transparently, and accountably, could boost citizens’ trust in digital governance, encourage innovation, and position India as a leader in data protection law. Thus, it stands as both a legislative reform and a significant step toward fulfilling the constitutional promise of privacy, dignity, and individual freedom in the digital era.


