Opens in a new tab
Join Anantam IAS Channel on Telegram

Data Protection Act 2023: Key Provisions

Complete guide to the Digital Personal Data Protection Act 2023 — key provisions, Data Protection Board, rights, duties, and UPSC Polity relevance.

Digital Personal Data Protection Act, 2023: key provisions.

Data Protection Act 2023: Key Provisions

The Digital Personal Data Protection Act, 2023 (DPDP Act) is India’s first comprehensive data protection legislation. Enacted on 11 August 2023 after years of deliberation, it establishes a framework for processing digital personal data while balancing individual privacy rights with legitimate uses by businesses and the government. For UPSC, the DPDP Act is essential — it connects the fundamental right to privacy (Puttaswamy judgment, 2017), Directive Principles, and governance of the digital economy.

Background and Evolution

The journey toward data protection legislation in India has been long:

YearDevelopment
2017Supreme Court in K.S. Puttaswamy v. Union of India declares privacy a fundamental right under Article 21
2017Justice B.N. Srikrishna Committee constituted to draft data protection law
2018Srikrishna Committee submits draft Personal Data Protection Bill
2019Personal Data Protection Bill introduced in Parliament; referred to Joint Parliamentary Committee
2021JPC submits report with 81 amendments and 12 recommendations
2022Personal Data Protection Bill, 2019 withdrawn; fresh draft prepared
2023Digital Personal Data Protection Bill, 2023 introduced and passed (August)
2023DPDP Act receives Presidential assent on 11 August

The 2019 Bill was withdrawn because it had become unwieldy with amendments. The 2023 Act takes a simpler, principles-based approach.

Key Concepts and Definitions

TermDefinition
Data PrincipalThe individual whose personal data is being processed (equivalent to “data subject” in GDPR)
Data FiduciaryAny entity (person, company, government body) that determines the purpose and means of processing personal data
Significant Data FiduciaryA data fiduciary designated by the government based on volume, sensitivity of data, risk to rights, etc.
Data ProcessorAn entity that processes data on behalf of the data fiduciary
Personal DataAny data about an identifiable individual (digital or digitised)
Consent ManagerA registered entity that enables data principals to manage consent through a single platform

Key Provisions of the DPDP Act

1. Consent-Based Processing

The Act makes consent the cornerstone of data processing. Consent must be:

  • Free — not coerced or manipulated
  • Specific — for a clear, stated purpose
  • Informed — given after clear explanation
  • Unconditional — not bundled with unrelated services
  • Unambiguous — through a clear affirmative action

Data principals can withdraw consent at any time, and the process must be as easy as giving consent.

2. Legitimate Uses (Without Consent)

The Act allows processing without consent in specific situations:

Legitimate UseExample
Specified PurposeWhere an individual voluntarily provides data for a stated purpose
State FunctionsGovernment processing for subsidies, benefits, services, licences
Legal ObligationsCourt orders, legal requirements
Medical EmergencyWhen consent cannot be obtained due to emergency
EmploymentEmployer processing employee data for employment purposes
Public InterestAggregated, anonymised data for research and statistics
Situations where personal data can be processed without consent under the DPDP Act.

3. Rights of Data Principals

RightDescription
Right to InformationKnow what data is collected, for what purpose, and with whom it’s shared
Right to Correction and ErasureRequest correction of inaccurate data or deletion of data no longer needed
Right to Grievance RedressalAccess to complaint mechanism with the data fiduciary
Right of NominationNominate a person to exercise rights in case of death or incapacity
Right to Withdraw ConsentWithdraw consent at any time; withdrawal must be as easy as giving consent

4. Duties of Data Principals

This is a distinctive feature of the Act — it imposes duties on individuals, not just rights:

  • Don’t file false or frivolous complaints
  • Don’t furnish false information or suppress material information
  • Don’t impersonate another person while providing data
  • Penalty for breach: up to Rs 10,000

5. Obligations of Data Fiduciaries

ObligationDetail
Purpose LimitationProcess data only for the purpose for which consent was obtained
Data MinimisationCollect only data necessary for the stated purpose
AccuracyEnsure data is accurate and up-to-date
Storage LimitationDelete data once the purpose is fulfilled (unless legally required to retain)
Security SafeguardsImplement reasonable security measures to prevent data breaches
Breach NotificationNotify the Data Protection Board and affected individuals in case of a breach
Grievance OfficerAppoint a grievance officer for data principal complaints

6. Significant Data Fiduciaries

Entities classified as Significant Data Fiduciaries (based on volume of data, sensitivity, risk to data principals, etc.) face additional obligations:

  • Appoint a Data Protection Officer (based in India)
  • Appoint an independent data auditor
  • Conduct periodic Data Protection Impact Assessments
  • Additional government-specified compliance measures

7. Children’s Data

Special provisions apply to processing data of individuals below 18 years:

  • Verifiable parental consent required before processing
  • Prohibition on tracking, behavioural monitoring, and targeted advertising directed at children
  • Government can designate certain data fiduciaries as “safe” for children (exempting them from some restrictions — e.g., educational platforms)

8. Cross-Border Data Transfer

The Act permits transfer of personal data outside India to any country except those specifically restricted by the Central Government. This is a “blacklist” approach — all countries are allowed unless notified otherwise.

ApproachDPDP Act 2023GDPR (EU)
DefaultTransfer allowed everywhereTransfer restricted by default
Restriction MethodGovernment notifies restricted countries (blacklist)Adequacy decisions whitelist countries
FlexibilityHigh — broad government discretionStructured — adequacy assessments required

Data Protection Board of India

The Data Protection Board of India: features, powers and penalties.

The Act establishes the Data Protection Board of India (DPBI) as the adjudicatory body.

Key Features of DPBI

FeatureDetail
NatureQuasi-judicial body; not a regulator in the traditional sense
AppointmentChairperson and members appointed by Central Government
Tenure2 years; eligible for re-appointment
FunctionsAdjudicate complaints, investigate breaches, impose penalties
ProceedingsDigital by default
AppealOrders can be appealed to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT)

Penalties

ViolationMaximum Penalty
Non-fulfilment of obligations for children’s dataRs 200 crore
Failure to take security safeguards (resulting in breach)Rs 250 crore
Non-compliance with provisions of the ActRs 50 crore
Breach of additional obligations by Significant Data FiduciariesRs 150 crore
Data Principal filing false/frivolous complaintsRs 10,000

Government Exemptions

The Act grants broad exemptions to the Central Government. Processing for the following purposes is exempt from most provisions:

  • National security
  • Public order
  • Prevention and investigation of offences
  • Enforcement of legal rights or claims

The government can also exempt any government instrumentality from any provision of the Act by notification.

Criticism of Exemptions

ConcernDetail
Broad government exemptionNational security and public order exemptions lack judicial oversight
No independent regulatorDPBI members appointed by government; perceived lack of independence
RTI AmendmentSection 44(3) amends the RTI Act — personal information cannot be disclosed even if disclosure serves public interest
Surveillance concernsGovernment processing exempted without proportionality test

DPDP Act vs GDPR: Key Differences

FeatureDPDP Act 2023 (India)GDPR (EU)
ScopeDigital personal data (including digitised)All personal data (digital and manual)
Sensitive DataNo separate categorySpecial categories with stricter rules
Data Principal DutiesYes — penalties for false complaintsNo duties imposed on data subjects
Cross-Border TransferBlacklist approach (allowed unless restricted)Whitelist approach (restricted unless adequate)
Government ExemptionsBroad — national security, public orderNarrow — subject to proportionality
Regulator IndependenceDPBI appointed by governmentData Protection Authorities independent
Maximum PenaltyRs 250 crore (~$30M)4% of global annual turnover or €20M
Right to Data PortabilityNot explicitly providedExplicit right
Automated Decision-MakingNot specifically addressedRight to contest automated decisions

Significance for UPSC

The DPDP Act connects several constitutional and governance themes:

  • Article 21 — Right to Privacy (Puttaswamy, 2017) forms the constitutional foundation
  • Article 19(1)(a) — Informational privacy as an aspect of free speech
  • Reasonable Restrictions (Article 19(2)) — Government exemptions must satisfy this test
  • RTI Impact — Section 44(3) amends RTI Act, potentially limiting transparency
  • Digital India Governance — Regulatory framework for India’s expanding digital economy
  • International Comparisons — Understanding data governance models (EU GDPR, US sectoral approach, China PIPL)

Right to Privacy Fundamental Rights

Frequently Asked Questions

What is the DPDP Act 2023?

The Digital Personal Data Protection Act, 2023 is India’s first comprehensive data protection law. It regulates the processing of digital personal data by establishing consent requirements, data principal rights, fiduciary obligations, and a Data Protection Board for adjudication. It applies to data processed within India and to processing of Indian residents’ data abroad.

Who is a Data Principal and Data Fiduciary?

A Data Principal is the individual whose personal data is being processed — equivalent to a u0022data subjectu0022 in GDPR terminology. A Data Fiduciary is any entity (company, government body, or individual) that determines the purpose and means of processing personal data. A Significant Data Fiduciary faces additional compliance requirements.

How does the DPDP Act handle cross-border data transfer?

The Act uses a u0022blacklistu0022 approach — personal data can be transferred to any country unless the Central Government specifically restricts transfer to that country through notification. This is simpler and more permissive than the EU’s GDPR approach, which restricts transfers by default and requires adequacy determinations for each destination.

What are the main criticisms of the DPDP Act?

Key criticisms include broad government exemptions from data protection obligations, lack of an independent data protection regulator (DPBI members are government-appointed), amendment of the RTI Act limiting access to personal information, absence of a separate category for sensitive personal data, and no explicit right to data portability.

What penalties does the DPDP Act prescribe?

The maximum penalty is Rs 250 crore for failure to take reasonable security safeguards resulting in a data breach. Processing children’s data in violation of the Act attracts up to Rs 200 crore. General non-compliance carries a penalty of up to Rs 50 crore. Data principals filing false or frivolous complaints can be fined up to Rs 10,000.

Tell Google you want more of this.

Add Anantam IAS as a preferred source

One tap, and this site shows up more often in your own Top Stories, AI Overviews and AI Mode. Remove it any time.

Share this

PDF

Written by

Rahul Puri Sir

Director & Mentor · Anantam IAS

Rahul Puri is the Director & Mentor at Anantam IAS. He leads the institution's teaching philosophy — focused not on syllabus completion but on the thinking, clarity and consistency that actually crack UPSC. A long-time mentor to hundreds of civil services aspirants and interview toppers (including AIR 28, 48, 56, 73, 96, 106, 116, 143 in CSE 2025), he anchors Anantam's flagship Interview Guidance Programme.

Specialises in · Institutional leadership, mentoring and programme design Experience · 10+ years Visit website ↗

Preparing for UPSC CSE 2026? Sit in a free demo class.

No sales call. No brochure. Watch a real Monday-morning GS session taught by ex-Rau's IAS faculty.