Data Protection Act 2023: Key Provisions
The Digital Personal Data Protection Act, 2023 (DPDP Act) is India’s first comprehensive data protection legislation. Enacted on 11 August 2023 after years of deliberation, it establishes a framework for processing digital personal data while balancing individual privacy rights with legitimate uses by businesses and the government. For UPSC, the DPDP Act is essential — it connects the fundamental right to privacy (Puttaswamy judgment, 2017), Directive Principles, and governance of the digital economy.
Background and Evolution
The journey toward data protection legislation in India has been long:
| Year | Development |
|---|---|
| 2017 | Supreme Court in K.S. Puttaswamy v. Union of India declares privacy a fundamental right under Article 21 |
| 2017 | Justice B.N. Srikrishna Committee constituted to draft data protection law |
| 2018 | Srikrishna Committee submits draft Personal Data Protection Bill |
| 2019 | Personal Data Protection Bill introduced in Parliament; referred to Joint Parliamentary Committee |
| 2021 | JPC submits report with 81 amendments and 12 recommendations |
| 2022 | Personal Data Protection Bill, 2019 withdrawn; fresh draft prepared |
| 2023 | Digital Personal Data Protection Bill, 2023 introduced and passed (August) |
| 2023 | DPDP Act receives Presidential assent on 11 August |
The 2019 Bill was withdrawn because it had become unwieldy with amendments. The 2023 Act takes a simpler, principles-based approach.
Key Concepts and Definitions
| Term | Definition |
|---|---|
| Data Principal | The individual whose personal data is being processed (equivalent to “data subject” in GDPR) |
| Data Fiduciary | Any entity (person, company, government body) that determines the purpose and means of processing personal data |
| Significant Data Fiduciary | A data fiduciary designated by the government based on volume, sensitivity of data, risk to rights, etc. |
| Data Processor | An entity that processes data on behalf of the data fiduciary |
| Personal Data | Any data about an identifiable individual (digital or digitised) |
| Consent Manager | A registered entity that enables data principals to manage consent through a single platform |
Key Provisions of the DPDP Act
1. Consent-Based Processing
The Act makes consent the cornerstone of data processing. Consent must be:
- Free — not coerced or manipulated
- Specific — for a clear, stated purpose
- Informed — given after clear explanation
- Unconditional — not bundled with unrelated services
- Unambiguous — through a clear affirmative action
Data principals can withdraw consent at any time, and the process must be as easy as giving consent.
2. Legitimate Uses (Without Consent)
The Act allows processing without consent in specific situations:
| Legitimate Use | Example |
|---|---|
| Specified Purpose | Where an individual voluntarily provides data for a stated purpose |
| State Functions | Government processing for subsidies, benefits, services, licences |
| Legal Obligations | Court orders, legal requirements |
| Medical Emergency | When consent cannot be obtained due to emergency |
| Employment | Employer processing employee data for employment purposes |
| Public Interest | Aggregated, anonymised data for research and statistics |

3. Rights of Data Principals
| Right | Description |
|---|---|
| Right to Information | Know what data is collected, for what purpose, and with whom it’s shared |
| Right to Correction and Erasure | Request correction of inaccurate data or deletion of data no longer needed |
| Right to Grievance Redressal | Access to complaint mechanism with the data fiduciary |
| Right of Nomination | Nominate a person to exercise rights in case of death or incapacity |
| Right to Withdraw Consent | Withdraw consent at any time; withdrawal must be as easy as giving consent |
4. Duties of Data Principals
This is a distinctive feature of the Act — it imposes duties on individuals, not just rights:
- Don’t file false or frivolous complaints
- Don’t furnish false information or suppress material information
- Don’t impersonate another person while providing data
- Penalty for breach: up to Rs 10,000
5. Obligations of Data Fiduciaries
| Obligation | Detail |
|---|---|
| Purpose Limitation | Process data only for the purpose for which consent was obtained |
| Data Minimisation | Collect only data necessary for the stated purpose |
| Accuracy | Ensure data is accurate and up-to-date |
| Storage Limitation | Delete data once the purpose is fulfilled (unless legally required to retain) |
| Security Safeguards | Implement reasonable security measures to prevent data breaches |
| Breach Notification | Notify the Data Protection Board and affected individuals in case of a breach |
| Grievance Officer | Appoint a grievance officer for data principal complaints |
6. Significant Data Fiduciaries
Entities classified as Significant Data Fiduciaries (based on volume of data, sensitivity, risk to data principals, etc.) face additional obligations:
- Appoint a Data Protection Officer (based in India)
- Appoint an independent data auditor
- Conduct periodic Data Protection Impact Assessments
- Additional government-specified compliance measures
7. Children’s Data
Special provisions apply to processing data of individuals below 18 years:
- Verifiable parental consent required before processing
- Prohibition on tracking, behavioural monitoring, and targeted advertising directed at children
- Government can designate certain data fiduciaries as “safe” for children (exempting them from some restrictions — e.g., educational platforms)
8. Cross-Border Data Transfer
The Act permits transfer of personal data outside India to any country except those specifically restricted by the Central Government. This is a “blacklist” approach — all countries are allowed unless notified otherwise.
| Approach | DPDP Act 2023 | GDPR (EU) |
|---|---|---|
| Default | Transfer allowed everywhere | Transfer restricted by default |
| Restriction Method | Government notifies restricted countries (blacklist) | Adequacy decisions whitelist countries |
| Flexibility | High — broad government discretion | Structured — adequacy assessments required |
Data Protection Board of India

The Act establishes the Data Protection Board of India (DPBI) as the adjudicatory body.
Key Features of DPBI
| Feature | Detail |
|---|---|
| Nature | Quasi-judicial body; not a regulator in the traditional sense |
| Appointment | Chairperson and members appointed by Central Government |
| Tenure | 2 years; eligible for re-appointment |
| Functions | Adjudicate complaints, investigate breaches, impose penalties |
| Proceedings | Digital by default |
| Appeal | Orders can be appealed to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) |
Penalties
| Violation | Maximum Penalty |
|---|---|
| Non-fulfilment of obligations for children’s data | Rs 200 crore |
| Failure to take security safeguards (resulting in breach) | Rs 250 crore |
| Non-compliance with provisions of the Act | Rs 50 crore |
| Breach of additional obligations by Significant Data Fiduciaries | Rs 150 crore |
| Data Principal filing false/frivolous complaints | Rs 10,000 |
Government Exemptions
The Act grants broad exemptions to the Central Government. Processing for the following purposes is exempt from most provisions:
- National security
- Public order
- Prevention and investigation of offences
- Enforcement of legal rights or claims
The government can also exempt any government instrumentality from any provision of the Act by notification.
Criticism of Exemptions
| Concern | Detail |
|---|---|
| Broad government exemption | National security and public order exemptions lack judicial oversight |
| No independent regulator | DPBI members appointed by government; perceived lack of independence |
| RTI Amendment | Section 44(3) amends the RTI Act — personal information cannot be disclosed even if disclosure serves public interest |
| Surveillance concerns | Government processing exempted without proportionality test |
DPDP Act vs GDPR: Key Differences
| Feature | DPDP Act 2023 (India) | GDPR (EU) |
|---|---|---|
| Scope | Digital personal data (including digitised) | All personal data (digital and manual) |
| Sensitive Data | No separate category | Special categories with stricter rules |
| Data Principal Duties | Yes — penalties for false complaints | No duties imposed on data subjects |
| Cross-Border Transfer | Blacklist approach (allowed unless restricted) | Whitelist approach (restricted unless adequate) |
| Government Exemptions | Broad — national security, public order | Narrow — subject to proportionality |
| Regulator Independence | DPBI appointed by government | Data Protection Authorities independent |
| Maximum Penalty | Rs 250 crore (~$30M) | 4% of global annual turnover or €20M |
| Right to Data Portability | Not explicitly provided | Explicit right |
| Automated Decision-Making | Not specifically addressed | Right to contest automated decisions |
Significance for UPSC
The DPDP Act connects several constitutional and governance themes:
- Article 21 — Right to Privacy (Puttaswamy, 2017) forms the constitutional foundation
- Article 19(1)(a) — Informational privacy as an aspect of free speech
- Reasonable Restrictions (Article 19(2)) — Government exemptions must satisfy this test
- RTI Impact — Section 44(3) amends RTI Act, potentially limiting transparency
- Digital India Governance — Regulatory framework for India’s expanding digital economy
- International Comparisons — Understanding data governance models (EU GDPR, US sectoral approach, China PIPL)
Right to Privacy Fundamental Rights
Frequently Asked Questions
What is the DPDP Act 2023?
The Digital Personal Data Protection Act, 2023 is India’s first comprehensive data protection law. It regulates the processing of digital personal data by establishing consent requirements, data principal rights, fiduciary obligations, and a Data Protection Board for adjudication. It applies to data processed within India and to processing of Indian residents’ data abroad.
Who is a Data Principal and Data Fiduciary?
A Data Principal is the individual whose personal data is being processed — equivalent to a u0022data subjectu0022 in GDPR terminology. A Data Fiduciary is any entity (company, government body, or individual) that determines the purpose and means of processing personal data. A Significant Data Fiduciary faces additional compliance requirements.
How does the DPDP Act handle cross-border data transfer?
The Act uses a u0022blacklistu0022 approach — personal data can be transferred to any country unless the Central Government specifically restricts transfer to that country through notification. This is simpler and more permissive than the EU’s GDPR approach, which restricts transfers by default and requires adequacy determinations for each destination.
What are the main criticisms of the DPDP Act?
Key criticisms include broad government exemptions from data protection obligations, lack of an independent data protection regulator (DPBI members are government-appointed), amendment of the RTI Act limiting access to personal information, absence of a separate category for sensitive personal data, and no explicit right to data portability.
What penalties does the DPDP Act prescribe?
The maximum penalty is Rs 250 crore for failure to take reasonable security safeguards resulting in a data breach. Processing children’s data in violation of the Act attracts up to Rs 200 crore. General non-compliance carries a penalty of up to Rs 50 crore. Data principals filing false or frivolous complaints can be fined up to Rs 10,000.
Tell Google you want more of this.
Add Anantam IAS as a preferred sourceOne tap, and this site shows up more often in your own Top Stories, AI Overviews and AI Mode. Remove it any time.