India’s digital economy has witnessed extraordinary growth over the last decade. From online banking and e-commerce to social media platforms, health-tech applications, and AI-driven services, personal data has become one of the most valuable assets in the digital age. As millions of Indians increasingly engage with digital platforms, concerns regarding privacy, surveillance, misuse of personal information, and data breaches have also intensified.

India’s journey toward a comprehensive data protection regime has evolved gradually, beginning with provisions under the Information Technology Act, 2000, moving through intermediary and data security rules, and eventually culminating in the enactment of the Digital Personal Data Protection Act, 2023. This transition reflects India’s attempt to balance innovation, economic growth, state interests, and the fundamental right to privacy.

The Early Framework: Information Technology Act, 2000

India’s first major legislation dealing with cyberspace and electronic governance was the Information Technology Act, 2000. The Act was primarily enacted to provide legal recognition to electronic transactions and digital signatures. However, as internet usage expanded, concerns regarding unauthorized access, hacking, and misuse of personal information led to the inclusion of provisions relating to data protection and cybersecurity.

One of the most significant provisions introduced was Section 43A of the IT Act. This section imposed liability on body corporates handling sensitive personal data if they failed to implement reasonable security practices and procedures, resulting in wrongful loss or wrongful gain to any person.

Additionally, Section 72A of the IT Act criminalized the disclosure of personal information obtained through lawful contracts without the consent of the concerned individual, particularly when such disclosure caused wrongful loss or gain.

Although these provisions represented an important beginning, the IT Act was never designed to function as a comprehensive privacy legislation. It addressed data protection only indirectly and lacked a detailed framework concerning consent, user rights, cross-border data transfers, or obligations of digital platforms.

The Information Technology Rules and Sensitive Personal Data

To operationalize Section 43A, the government introduced the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, commonly referred to as the SPDI Rules.

The SPDI Rules marked India’s first dedicated attempt to regulate the collection and handling of personal data by private entities. These rules defined “Sensitive Personal Data or Information” to include:

  • Passwords
  • Financial information
  • Health conditions
  • Sexual orientation
  • Medical records
  • Biometric information

Under these rules, companies collecting sensitive personal data were required to:

  • Obtain consent before collecting information
  • Publish privacy policies
  • Use data only for lawful purposes
  • Allow users to review and correct information
  • Implement reasonable security practices

While the SPDI Rules were progressive for their time, they suffered from several limitations. Their applicability was restricted primarily to body corporates and did not comprehensively regulate government data processing. Further, the rules lacked strong enforcement mechanisms and did not create an independent data protection authority.

The Rise of Privacy Concerns in India

As smartphones, digital payments, Aadhaar-linked services, and social media usage exploded across India, concerns regarding mass data collection and surveillance became increasingly prominent.

Several incidents highlighted the urgent need for stronger privacy protections:

  • Large-scale data breaches affecting consumers
  • Unauthorized sharing of personal information
  • Concerns regarding Aadhaar data security
  • Increasing profiling and targeted advertising
  • Lack of transparency by digital platforms

At the same time, global developments such as the European Union’s General Data Protection Regulation significantly influenced conversations surrounding privacy and data governance worldwide.

Justice K.S. Puttaswamy Judgment: Privacy as a Fundamental Right

A landmark moment in Indian constitutional history arrived in 2017 with the Supreme Court’s judgment in Justice K.S. Puttaswamy v. Union of India.

In this historic case, a nine-judge bench of the Supreme Court unanimously held that the right to privacy is a fundamental right protected under Article 21 of the Constitution of India.

The judgment transformed privacy discourse in India and established several important principles:

  • Privacy is intrinsic to dignity and liberty
  • Informational privacy deserves constitutional protection
  • The state cannot intrude upon privacy arbitrarily
  • Any invasion of privacy must satisfy legality, necessity, and proportionality

The Puttaswamy judgment became the constitutional foundation for modern Indian data protection law and accelerated efforts toward comprehensive legislation.

The Personal Data Protection Bill Journey

Following the Puttaswamy judgment, the government constituted the Justice B.N. Srikrishna Committee to examine issues relating to data protection.

The committee submitted its report along with a draft Personal Data Protection Bill in 2018. The proposed legislation introduced concepts such as:

  • Data fiduciaries
  • Data principals
  • Consent-based processing
  • Data localization
  • User rights
  • Data protection authority
  • Significant data fiduciaries

Over the next few years, multiple versions of the bill were introduced, debated, revised, and criticized by industry experts, civil society organizations, and privacy advocates. Concerns included excessive government exemptions, compliance burdens, and cross-border data transfer restrictions.

Ultimately, the earlier bill was withdrawn, and a revised framework emerged as the Digital Personal Data Protection Act, 2023.

The Digital Personal Data Protection Act, 2023

The Digital Personal Data Protection Act, 2023 represents India’s first comprehensive standalone legislation dedicated specifically to personal data protection.

The Act applies to digital personal data processed within India as well as outside India when goods or services are offered to individuals in India.

The law introduces several important concepts.

Data Principal

The individual to whom the personal data relates is called the “Data Principal.” In the case of children or persons with disabilities, parents or lawful guardians may exercise rights on their behalf.

Data Fiduciary

Entities determining the purpose and means of processing personal data are termed “Data Fiduciaries.” These may include companies, platforms, startups, or government bodies.

Consent-Centric Framework

The DPDP Act adopts a consent-based framework requiring consent to be:

  • Free
  • Specific
  • Informed
  • Unconditional
  • Unambiguous

Consent notices must clearly specify the purpose for which data is being collected.

Rights of Individuals

The Act grants several rights to individuals, including:

  • Right to access information
  • Right to correction and erasure
  • Right to grievance redressal
  • Right to nominate another person to exercise rights upon death or incapacity

Obligations of Data Fiduciaries

Data fiduciaries must:

  • Ensure accuracy of data
  • Implement reasonable security safeguards
  • Notify authorities and users regarding breaches
  • Erase data when no longer necessary

Children’s Data Protection

The Act contains specific obligations relating to children’s data and prohibits tracking, behavioral monitoring, or targeted advertising directed toward children.

Data Breaches and Penalties

One of the strongest features of the DPDP Act is its penalty framework. The legislation imposes significant financial penalties for non-compliance, including failures to prevent data breaches or implement adequate safeguards.

Penalties may extend to several hundred crores depending on the nature and severity of violations.

This reflects India’s intention to create stronger accountability for digital platforms and businesses handling personal information.

Government Exemptions and Criticism

Despite being a major legislative development, the DPDP Act has also attracted criticism.

One major concern relates to exemptions granted to the government and certain state instrumentalities. Critics argue that broad exemptions may weaken privacy protections and create risks of surveillance.

Other concerns include:

  • Lack of complete independence of the Data Protection Board
  • Ambiguity regarding cross-border data transfers
  • Limited user remedies
  • Potential impact on journalistic and research activities

Privacy advocates continue to debate whether the Act sufficiently balances state interests and individual freedoms.

Impact on Businesses and Startups

The DPDP Act has substantial implications for businesses operating in India.

Companies must now focus on:

  • Consent management systems
  • Privacy notices
  • Data minimization
  • Cybersecurity frameworks
  • Vendor compliance
  • Data retention policies
  • Employee training

Startups, fintech companies, health-tech platforms, ed-tech companies, and digital marketing agencies will need to align operations with the new legal framework.

Data protection compliance is increasingly becoming not just a legal requirement but also a competitive business advantage.

The Future of Data Protection in India

India’s data governance journey is still evolving. With rapid advances in artificial intelligence, facial recognition, digital payments, cloud computing, and cross-border data flows, new legal challenges continue to emerge.

Future discussions are likely to focus on:

  • AI governance and algorithmic accountability
  • Non-personal data regulation
  • Surveillance reform
  • Cross-border data transfer mechanisms
  • Cybersecurity obligations
  • Platform accountability

As India moves toward becoming one of the world’s largest digital economies, the effectiveness of its data protection framework will significantly influence public trust, innovation, and international digital trade.

Conclusion

India’s evolution from the limited protections under the IT Act and SPDI Rules to the comprehensive framework under the Digital Personal Data Protection Act represents a major transformation in the country’s legal approach toward privacy and digital governance.

The DPDP Act marks a significant step toward recognizing the importance of informational privacy in the digital era. However, its true effectiveness will depend upon implementation, regulatory oversight, judicial interpretation, and the ability to balance innovation with civil liberties.

As personal data increasingly becomes the foundation of economic and technological power, data protection law will continue to play a central role in shaping India’s digital future.


Discover more from Law School Uncensored

Subscribe to get the latest posts sent to your email.

Leave a Reply

I’m Aishwarya Sandeep

Adv. Aishwarya Sandeep is a Media and IPR Lawyer, TEDx speaker, and founder of Law School Uncensored, committed to making legal knowledge practical, accessible, and career-oriented for the next generation of lawyers.

Let’s connect

Discover more from Law School Uncensored

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from Law School Uncensored

Subscribe now to keep reading and get access to the full archive.

Continue reading