Why in news?
The Ministry of Electronics and IT (MeitY) has notified the Digital Personal Data Protection (DPDP) Rules, 2025, paving the way for India’s first functional privacy law, eight years after the Supreme Court declared privacy a fundamental right.
UPSC Relevance
Prelims, GS2 – Important legislations are often asked, GS3 – Role of Media and Social Networking Sites in Internal Security Challenges, Basics of Cyber Security
PYQ
2024 – GS2 – What are the aims and objectives of recently passed and enforced, The Public Examination (Prevention of Unfair Means) Act, 2024? Whether University/State Education Board examinations, too, are covered under the Act?
2024 – GS3 – Describe the context and salient features of the Digital Personal Data Protection Act, 2023.
DPDP Act, 2023
- The Act directly is the statutory fulfillment of the constitutional mandate laid down in the Justice K.S. Puttaswamy (Retd.) v. Union of India (2017) Supreme Court judgment, which unanimously declared privacy as a fundamental right inherent in Article 21 (Right to Life and Personal Liberty) of the Constitution.
- New Rights: It empowers individuals, referred to as Data Principals, with rights that reflect constitutional values, such as:
- The Right to Access information about their personal data.
- The Right to Correction and Erasure of their data.
- The requirement of specific, informed consent for data processing.
- Cybersecurity and Accountability – The Act imposes strict obligations and heavy penalties on entities, known as Data Fiduciaries, forcing a paradigm shift in how digital personal data is handled and secured.
Features of DPDP Act, 2023
- Objective: To recognise both the individual’s right to protect their personal data and the need to process such data for lawful purposes.
- Scope: Applies to the processing of digital personal data within the territory of India. It also applies to processing outside India if it is related to offering goods or services to Data Principals within India.
- Grounds for Processing: Processing of personal data must be for a lawful purpose and based on either the Data Principal’s consent or for “certain legitimate uses” (as defined in the Act).
- Data Principal Rights: Includes the right to access information about their personal data and the right to correction and erasure of their personal data.
- Data Fiduciary Obligations: Imposes obligations on Data Fiduciaries to ensure data security, provide notice, and erase data when no longer needed
- Supremacy of the Act: The provisions of the Act are in addition to and not in derogation of any other law, but in the event of a conflict, the DPDP Act shall have an overriding effect.
Definitions under DPDP Act, 2023
- Data Principal: The individual to whom the personal data relates. This includes a parent or lawful guardian in the case of a child (an individual under eighteen years of age) or a person with disability.
- Data Fiduciary (DF): Any person who determines the purpose and means of processing personal data.
- Data Processor: Any person who processes personal data on behalf of a Data Fiduciary.
- Personal Data: Any data about an individual who is identifiable by or in relation to such data.
- Personal Data Breach: Any unauthorised processing or accidental loss of personal data that compromises its confidentiality, integrity, or availability.
- Consent Manager: A person registered with the Board, acting as a single point of contact for the Data Principal to give, manage, review, and withdraw consent via an accessible, transparent, and interoperable platform.
DPDP Rules, 2025
- The notification of the rules comes over two years after the DPDP Act received the President’s assent in August 2023.
- The law is now operational, but only parts are currently in force.
- Most important protections will take longer—between 12 to 18 months—to be fully implemented.
- Commencement after One Year (November 2026): The rules regarding the Registration and obligations of Consent Manager (Rule 4) will come into force
- The following provisions will only become operational after18 months:
- Data Fiduciary Notice requirements (Rule 3)
- Reasonable Security Safeguards (Rule 6)
- Personal Data Breach Notification (Rule 7)
- Processing of Children’s Personal Data (Rule 10)
- Additional obligations for Significant Data Fiduciaries (Rule 13)
The Rules
- Notice and Informed Consent: The Data Fiduciary’s notice must be presented clearly, in simple language, and independently of other information. It must detail the items of personal data and the specific purpose for processing to enable the Data Principal to give informed consent.
- Data Erasure: A Data Fiduciary must erase personal data when the specified purpose is no longer being served, unless retention is necessary for compliance with any law or for a corresponding period specified in the rules.
- Child Data Processing: Data Fiduciaries must adopt appropriate measures to obtain verifiable consent from the parent or guardian before processing a child’s personal data.
- Data Localization and International Transfers
- The Centre will specify the kind of personal data that “significant data fiduciaries” can process, subject to the restriction that such data is not transferred outside the territory of India.
- This is effectively a data localization requirement, which the industry has previously resisted.
- A committee will be formed by the government to determine this.
- Processing Children’s Personal Data
- Tech companies are required to implement a mechanism for collecting “verifiable” parental consent before processing the personal data of children.
- The government refrained from prescribing a specific mechanism, giving companies the flexibility to adopt a system of their choice.
- Behavioural tracking and targeted advertising to children are generally prohibited, though limited processing is allowed to prevent harmful content and ads.
- Government Processing: Personal data processing by the State or its instrumentalities for providing a subsidy, benefit, or service must adhere to the standards specified in the Second Schedule of the Rules.
- The Act also permits exemptions for government processing on grounds such as ‘national security’, ‘friendly relations with other states’, and ‘public order’.
- Breach Reporting: In case of a Personal Data Breach, the Data Fiduciary must inform the affected Data Principal and the Board ‘without delay’. A detailed report must be submitted to the Board within seventy-two hours of awareness.
Types of Data Fiduciaries
- Data Fiduciary (DF): The standard category of entity processing personal data.
- Significant Data Fiduciary (SDF): A class of Data Fiduciaries notified by the Central Government based on the volume and sensitivity of personal data processed, risk to the Data Principal, and factors like the potential impact on India’s sovereignty, security of the State, and public order.(e.g., Meta, Google, Apple, Microsoft, Amazon).
- Additional Obligations: SDFs must appoint a Data Protection Officer who must be based in India and conduct a Data Protection Impact Assessment and an audit once every twelve months.
Penalties
- The Act specifies significant monetary penalties for non-compliance, ranging from ₹ 10,000 to ₹250 Cr, including:
- Breach of the obligation to take reasonable security safeguards: May extend up to ₹250 crore.
- Breach in observing obligations in relation to children: May extend up to ₹200 crore.
- Breach in observing additional obligations of a Significant Data Fiduciary: May extend up to ₹150 crore.
DPDP Board
- The Data Protection Board of India (DPB) has been established by the Central Government via notification on November 13, 2025.
- It will be a subordinate office of MeitY with total 4 members.
- Head Office: The DPB’s head office shall be located in the National Capital Region of India.
- Comprises a Chairperson and 3 Members appointed by the Central Government.
- Role: The Board acts as the key adjudicatory body to exercise powers and perform functions assigned under the Act.
- Functions as an independent body and digital office, with powers to inquire into breaches, impose penalties, and issue directions.
- No civil court has jurisdiction over matters for which the Board is empowered
Three Tier Dispute Resolution
- Grievance Redressal: A Data Principal must first address grievances to the Data Fiduciary or Consent Manager, who must respond within a prescribed period.
- Complaint to Board: A Data Principal may make a complaint to the Data Protection Board of India.
- Appeals: Appeals against the orders of the Data Protection Board will lie with the Telecom Disputes Settlement and Appellate Tribunal (TDSAT).
Controversies around DPDP Act 2023
- A controversial provision that amends the Right to Information (RTI) Act is now in force.
- This provision disallows disclosure of personal information about public officials, even when justified in larger public interest.
- The DPDP Act has faced scrutiny for granting wide-ranging exemptions to the government or its agencies while processing citizens’ personal data on grounds such as ‘national security’, ‘friendly relations with other states’, and ‘public order’.
- The Act and Rules are criticized for potentially hindering investigative journalism. The earlier draft had an exemption for journalistic work, which was later removed. Experts suggest that journalists may find it harder to identify or even mention individuals involved in wrongdoing without their express permission, risking high penalties and thus restricting free speech and investigative reporting.
- The provision, which effectively acts as a data localisation requirement, is expected to face pushback from large international tech companies and could complicate cross-border data flows for the industry.
- While the administrative rules and the Data Protection Board (DPB) are effective immediately, most of the core compliance requirements for entities (like seeking informed consent, breach notification to users, etc.) are deferred for an 18-month transition window. Critics have urged for shorter and clearer implementation timelines.
Tell Google you want more of this.
Add Anantam IAS as a preferred sourceOne tap, and this site shows up more often in your own Top Stories, AI Overviews and AI Mode. Remove it any time.