UPSC CSE 2026 Essay Paper Discussion

The DPDP Act: Does India Finally Have Real Privacy?

A UPSC Mains editorial on the DPDP Act, 2023 and its 2025 Rules — real statutory privacy at last, weighed against state exemptions, Board independence, and the RTI dilution now before the Supreme Court.

Your rights, the fiduciary's duties, and penalties up to ₹250 crore

For eight years India had a fundamental right to privacy and no law to make it work. The Supreme Court declared it on 24 August 2017, a nine-judge bench in the Puttaswamy case holding privacy intrinsic to Article 21, the right to life and personal liberty. And then, nothing operational. Your data sat with banks, telecom firms, hospitals, and the State, and you had a constitutional right you couldn’t actually use against any of them. So when the Digital Personal Data Protection (DPDP) Rules were notified on 13 November 2025, finally switching on the DPDP Act, 2023, the obvious question for an aspirant is the one in the title. Does India finally have real privacy, or just a law that looks like one?

The honest answer is both, and the gap between them is the whole topic. India now has its first in-force, statutory, enforceable data-protection regime. That’s real progress, not spin. But three design choices decide whether the protection is genuine or cosmetic, and all three are contested. So contested, in fact, that as you read this the Supreme Court has issued notice on a constitutional challenge to the very Act. The law that was meant to deliver privacy is itself back in the privacy court.

The Issue, Framed

Let’s settle the vocabulary first, because most confusion about this topic comes from people using these words loosely.

A data principal is you. It’s the individual the personal data is about. A data fiduciary is whoever decides why and how your data gets processed, your bank, a shopping app, a hospital, a State department. The word “fiduciary” is deliberate. It signals that the entity holding your data owes you a duty of trust, not just a transactional relationship. So the basic architecture casts the citizen as principal and the data-holder as a trustee who can be held to account.

The Act applies to digital personal data only, data collected in digital form, or offline data later digitised. Paper records that never touch a server sit outside it. The lawful basis for processing is consent, with a carve-out for specified “legitimate uses” like voluntary sharing, or the State processing data to deliver subsidies, licences, and benefits. So the default is: ask first, with a clear purpose, and stop when that purpose ends.

To make consent workable at India’s scale, the Rules introduce the consent manager, a registered, interoperable platform where you grant, review, and withdraw consent across services from one dashboard, the way a single remote controls many devices. Consent managers must be incorporated in India and meet a minimum net-worth bar reported at ₹2 crore, with registration opening 13 November 2026. The point is informational self-determination, your data moving only where you actively allow it.

Enforcement runs through the Data Protection Board of India, a body the central government establishes to investigate breaches and impose penalties, with appeals going to the Telecom Disputes Settlement and Appellate Tribunal. Note one structural fact early, because it matters later: the Board enforces, but it can’t make regulations or issue binding guidance. It’s a referee, not a rule-maker.

Two more terms close the toolkit. The Act follows a negative-list, or “blacklist,” model for cross-border transfers, meaning your data can flow to any country unless the central government specifically restricts that destination, with no general data-localisation mandate forcing storage inside India. And it sits on a constitutional foundation, the Puttaswamy proportionality test, the rule that any State intrusion into privacy must be lawful, serve a legitimate aim, and be no more restrictive than necessary. Hold that test in mind. It’s the yardstick the whole law gets measured against.

What the Data Says

The numbers tell you this is a real regime with real teeth, and a real delay before those teeth bite.

Start with the penalties, because deterrence is where India’s old framework failed completely. The DPDP schedule caps fines at up to ₹250 crore for failing to put reasonable security safeguards in place and suffering a breach as a result. Below that sit tiers of up to ₹200 crore for breach-notification failures and children’s-data violations, up to ₹150 crore for a significant data fiduciary skipping its extra duties, and up to ₹50 crore as a residual penalty. Read every one as “up to.” They’re statutory caps, not fixed fines, and the Board sets the actual figure by severity and intent. But the scale is the signal. The earlier regime, a thin set of rules under the IT Act, topped out at penalties so small that a serious company treated a breach as a rounding error. ₹250 crore is not a rounding error.

The rights are concrete too. As a data principal you get the right to access your data and know who it’s been shared with, the right to correction and erasure, the right to grievance redressal, and the right to nominate someone to exercise these rights if you can’t. These aren’t aspirations in a preamble. They’re statutory entitlements you can take to the Board.

Now the catch, and it’s a big one. The rollout is phased across roughly 18 months. Board-establishment provisions and definitions came alive immediately on 13 November 2025. Consent-manager registration opens 13 November 2026. And the substantive duties, the notice-and-consent regime, security safeguards, breach notification, data retention and erasure, and the data-principal rights themselves, only become enforceable from 13 May 2027. So the part of the law that actually protects you is more than a year away as of mid-2026.

One contrast frames the ambition gap. The European Union’s General Data Protection Regulation, the GDPR, lets a harmed individual sue for compensation under its Article 82. India’s DPDP Act has no such route. Penalties flow to the State, not to the victim. So if your data leaks and you suffer real harm, the Board may fine the company, but you personally collect nothing. A compensation clause existed in the 2019 draft Bill, and it didn’t survive into the final law.

And the law is missing tools that other regimes treat as standard. No right to data portability, the ability to take your data and move it to a competitor. No explicit right to be forgotten. No carve-out for journalism. None of these is fatal on its own. Together they tell you this is a first-generation law, deliberately lighter than the GDPR, not a finished one.

Your rights, the fiduciary's duties, and penalties up to ₹250 crore
Your rights, the fiduciary’s duties, and penalties up to ₹250 crore.
What the DPDP Act gets right, and what's still contested
What the DPDP Act gets right, and what’s still contested.

The Case For

The case that India has, at last, taken privacy seriously is strong, and a good answer states it at full strength before poking holes.

It’s a real law, in force, after a very long wait. Puttaswamy in 2017 effectively told Parliament to build a data-protection framework, and for eight years there wasn’t one. The 2025 Rules close that gap. So the foundational criticism, that India recognised the right but never operationalised it, no longer holds. The framework exists, it’s notified, and the clock on compliance is running.

The rights are enforceable, not decorative. Access, correction, erasure, grievance redressal, and nomination are written into statute and routed through a dedicated Board. Before this, your remedy for misused data was a vague, slow, expensive civil suit. Now there’s a specialist forum whose job is exactly this. That’s a structural upgrade.

The penalties give the regime weight. Up to ₹250 crore for a security-failure breach is a number that changes how a board of directors thinks about data security. Compliance stops being optional once the downside is measured in hundreds of crores. So the deterrent that India’s IT-Act patchwork never had is finally on the books.

The consent architecture is genuinely ambitious. A purpose-bound, withdrawable consent model, plus interoperable consent managers, tries to make informational self-determination work for a billion-plus people, not just for the lawyered-up few. Whether it works in practice is an open question. But the design intent, putting the citizen in the driver’s seat of their own data, is the right one.

And it’s deliberately business-friendly without being toothless. A single national standard replaces a tangle of sectoral rules, smaller firms get a lighter compliance load, and the negative-list transfer model with no blanket localisation mandate lets data flow across borders, which matters for a services economy that runs on global data. Heightened duties fall on the significant data fiduciaries, the largest, highest-risk processors who must appoint an India-based data protection officer, commission independent audits, and run data protection impact assessments. So the heavy obligations land where the risk concentrates, and children’s data gets its own dedicated protections. That’s proportionate regulation, not a one-size hammer.

The Case Against

Here’s what the progress story walks past. A privacy law is only as real as the limits it places on the most powerful data-collector in the country, which is the State itself. On that test, the gaps are serious, and they’re exactly the questions now in court.

The state exemptions are wide open. Under Section 17, the central government can exempt its own agencies from the Act’s obligations on grounds of sovereignty, security of the State, public order, and prevention of offences. PRS Legislative Research itself flags the risk that this lets the State collect and retain data “beyond what is necessary”. Critics put it more bluntly: the State has written itself a door out of the privacy framework it just enacted. And that runs straight into the Puttaswamy proportionality test, which says State intrusion must be necessary and narrowly tailored, not open-ended.

The Board may not be independent enough to bite the hand that appoints it. The Chairperson and Members are appointed by the executive, serve renewable two-year terms, and the body sits under the Ministry of Electronics and IT. The Software Freedom Law Centre warns this gives “unchecked powers to the Executives to appoint the chairperson and members,” diluting the Board’s independence. The Internet Freedom Foundation argues it “deepens executive control”. So the problem is structural: a watchdog whose tenure depends on the executive’s goodwill is poorly placed to police that same executive when the State is the data fiduciary in question.

The RTI Act took a hit, and it took it immediately. This is the sharpest fight. Section 44(3) of the DPDP Act recast Section 8(1)(j) of the Right to Information Act, 2005, turning it into a near-blanket exemption for “information which relates to personal information” and removing the earlier test that balanced privacy against the larger public interest. In plain terms, the old RTI law let you access an official’s assets, a voter list, or land records when the public interest outweighed the privacy intrusion. The amendment strips out that override. So information that exposes corruption or abuse of public office can now be refused as “personal.” The Justice A.P. Shah Committee had warned back in 2012 that a privacy law must not water down the RTI. This one did.

Breach victims get sympathy and no money. Unlike the GDPR’s Article 82 right to compensation, the DPDP Act gives a harmed individual no statutory route to be made whole. Penalties go to the State. So the person whose leaked health record or financial data caused real damage is, in compensation terms, a bystander to their own case.

And the surveillance architecture is untouched. The Act doesn’t reform how the State accesses data. Broad Section 17 exemptions, plus government powers to demand information from data fiduciaries under Section 36 read with Rule 23, leave the Puttaswamy proportionality promise largely unmet where it matters most, against the State. That’s precisely the question the Supreme Court is now examining.

From Puttaswamy to the 2027 rollout, the long road to a data law
From Puttaswamy to the 2027 rollout, the long road to a data law.

The Deeper Structural Read

Step back from the section numbers and the deeper pattern shows up. Every contested provision points the same way: the law is far stronger at disciplining private companies than at disciplining the State. And that’s exactly the inversion Puttaswamy was meant to prevent.

Remember what the 2017 judgment actually held. Privacy is a fundamental right under Article 21, and it binds the State first. The whole reason the case existed was to fence in government intrusion, the Aadhaar-era anxiety about a State that knows too much. So a data-protection law that comes out tough on your shopping app but soft on the agency that can surveil you has, in a sense, solved the smaller problem and left the larger one open. The proportionality test was the constitutional core. A law that exempts the State on open-ended grounds doesn’t apply that test. It suspends it.

The sequencing makes the same point in time. As The Hindu editorial framed it, relayed through Bar & Bench’s coverage, “the rules delay the implementation of practically all key protections to 2027, while implementing the dilution of the (right to information) RTI Act immediately”. Sit with that ordering. The part that constrains officials, the RTI amendment, switched on at once. The part that protects citizens waits until 2027. Whether or not you accept the editorial’s framing, the asymmetry is a fact in the text.

There’s a genuine tension underneath, and a fair answer names it rather than picking a villain. Privacy and transparency are both democratic goods, and they really can conflict, your medical record is “personal information” and should be protected; a minister’s undisclosed assets are also “personal information” and should not be hidden. The old RTI Section 8(1)(j) handled this with a public-interest balance, weighing the two case by case. Section 44(3) didn’t rebalance that scale. It removed it. So the criticism isn’t that privacy was protected. It’s that protecting privacy was used to quietly shrink the right to know, with no balancing test left in between.

And here’s the part a future administrator should sit with. A regulator’s independence isn’t a technicality. The Board will, sooner or later, have to rule on a breach or a data demand involving a government department. If its members serve at the executive’s pleasure on renewable two-year terms, the structural incentive to go easy is built in before a single case is heard. So the design question isn’t whether these particular members are honest. It’s whether the institution is built to stay honest when the powerful party in front of it is the same party that decides its next term.

That’s why this is now a constitutional case and not just a policy debate. On 16 February 2026 the Court issued notice in The Reporters’ Collective Trust’s petition, referring the RTI-amendment question towards a larger bench. On 12 March 2026 a three-judge bench led by Chief Justice Surya Kant issued notice on the broader challenge to Section 36 read with Rule 23, tagging it with allied petitions, and the bench reportedly observed that data is “the real, true wealth”. The law meant to make privacy real is itself being tested against the right it was built to serve.

What Should Be Done

So what closes the gap between a law that exists and privacy that’s real? Not a vague plea for “balance,” but a short, concrete reform agenda, none of which weakens the genuine progress already on the books.

  1. Narrow Section 17 to the proportionality test. Replace open-ended executive exemptions with carve-outs that are purpose-limited, time-bound, and subject to independent oversight, so State access has to clear the same necessity-and-proportionality bar Puttaswamy set for every other intrusion. The fix isn’t to deny the State its security needs. It’s to make those needs pass a test instead of skipping it. The deeper logic here connects to how India handles all of its data-driven governance, the subject I take up in India’s Digital Public Infrastructure.
  2. Make the Data Protection Board genuinely independent. Broaden the selection committee to include a judicial member and independent experts, the way the Justice Patel and Competition Act models do, secure longer fixed tenures, and insulate service conditions from the executive. A watchdog that can’t be fired by the party it watches is the minimum a credible regime needs.
  3. Restore the RTI public-interest balance. Reinstate the larger-public-interest override in Section 8(1)(j), or add a clear public-interest and journalistic exemption, so transparency and privacy coexist instead of one cannibalising the other. Protect the citizen’s medical record. Don’t protect the official’s hidden assets. The old test did both. Bring it back.
  4. Give breach victims a real remedy. Operationalise timely breach notification and restore a statutory compensation route for harmed data principals, on the GDPR Article 82 model that India’s own 2019 draft once contained. A right with no remedy for the person actually harmed is half a right.
  5. Pair the data law with surveillance reform. The DPDP Act regulates data fiduciaries; it doesn’t touch how the State intercepts and demands data. Add statutory, judicially-overseen surveillance safeguards so State access meets the proportionality standard. This is the same governance question that runs through AI governance in India, where the State is simultaneously regulator, user, and the largest data-holder of all.

Every one of these strengthens the law rather than gutting it. A privacy regime that disciplines the State as firmly as it disciplines a startup is the one that finally makes the Puttaswamy right mean something in daily life.

For Your Mains Answer

This is a rare topic that pays off in both GS2 and GS3, and a strong answer shows the examiner you can move between the two.

GS paper mapping: GS2: Fundamental Rights (Article 21 privacy), independence of regulatory and statutory bodies, RTI and transparency, the citizen-State relationship in e-governance. GS3: cyber-security and data security, the digital economy and ease of doing business, technology regulation, and the internal-security dimension of State data access.

Likely question frames:

  • The DPDP Act, 2023 operationalises the right to privacy recognised in Puttaswamy, yet critics argue it leaves the State largely outside its own framework. Critically examine.
  • A data-protection law and the Right to Information Act can pull in opposite directions. Discuss in the light of Section 44(3) of the DPDP Act.
  • The strength of a data-protection regime lies in the independence of its enforcer. Evaluate with reference to the Data Protection Board of India.

Quotable data points:

  • Puttaswamy (24 Aug 2017): nine-judge bench unanimously holds privacy a fundamental right under Article 21, subject to a proportionality test.
  • DPDP Act assented 11 Aug 2023; covers digital personal data only.
  • DPDP Rules notified 13 Nov 2025; phased over ~18 months, with most substantive duties live only from 13 May 2027 and consent-manager registration from 13 Nov 2026.
  • Penalties up to ₹250 crore for a security-failure breach (a statutory cap, not a fixed fine).
  • No statutory compensation for breach victims, unlike GDPR Article 82; penalties go to the State.
  • Section 44(3) recast RTI Section 8(1)(j) into a near-blanket personal-information exemption, dropping the larger-public-interest override (IFF / Bar & Bench).
  • Supreme Court issued notice on the constitutional challenge (16 Feb 2026 and 12 Mar 2026); the case is live, not decided.

Keywords to use: data principal, data fiduciary, significant data fiduciary, consent manager, legitimate uses, purpose limitation, data minimisation, proportionality, informational privacy, negative-list cross-border transfer, surveillance reform.

Syllabus linkages: Fundamental Rights and the judiciary, statutory and regulatory bodies and their independence, transparency and accountability (RTI), e-governance, cyber-security, the digital economy.

Balanced conclusion line: India finally has a privacy law, and that’s real progress; whether it delivers real privacy now depends on a single test, whether the State is willing to bind itself as tightly as it binds everyone else.

How to Build the Answer

Open with the eight-year gap, not a definition. The hook is that India recognised privacy as a fundamental right in 2017 and only switched on a law to enforce it in 2025. That one sentence shows you grasp both the constitutional source and the policy delay. The definition of data principal and data fiduciary can follow in the next line.

Bring data in early and ration it. A strong first body paragraph can carry three figures: 24 Aug 2017 for Puttaswamy, 13 May 2027 for the substantive rollout, and ₹250 crore for the top penalty. Then say what they prove, that the rights are real but delayed, and the deterrent is serious. UPSC rewards the move from fact to inference, not the fact alone.

Steelman both sides before you judge. If your stance is that the Act is genuine progress, first concede the state-exemption and RTI critiques honestly. If your stance is critical, first credit the enforceable rights and the ₹250-crore deterrent. An answer that only argues one way reads like a pamphlet.

Group the way forward; don’t scatter it. Cluster the reforms: narrow Section 17, make the Board independent, restore the RTI balance, give victims a remedy, add surveillance safeguards. Tie each to an actor, the legislature, the executive, the Board, the courts.

Close on the syllabus link and on judgment, not summary. The reliable pattern is “the law is real; whether the privacy is real depends on X.” That lets you balance progress against the unresolved constitutional question without sitting on the fence.

Common Mistakes to Avoid

  • Don’t confuse the Act with the rollout. The Act was assented in 2023; the protections largely go live in 2027. Mixing these up signals you only skimmed the news.
  • Don’t call it a copy of the GDPR. It deliberately diverges, no compensation right, no portability, a negative-list transfer model. Name the differences; that’s where the marks are.
  • Don’t treat the SC challenge as decided. It’s live. Write “the Court has issued notice,” not “the Court struck down.”
  • Don’t go one-sided on the State exemptions. The State has genuine security needs. The critique is about open-endedness and the absence of a proportionality check, not about denying security itself.
  • Don’t forget the citizen. Name the RTI activist who can no longer access an asset declaration, or the patient whose leaked record earns them no compensation. Concrete stakes beat abstractions.

A Compact Answer Spine

  1. Introduction: The 2017 right, the 2025 law, the eight-year gap; define data principal and data fiduciary in one line.
  2. Evidence: Two or three attributed data points, each tied to an implication.
  3. Arguments: The case for (in-force law, enforceable rights, ₹250-cr penalties), then the case against (Section 17, Board independence, RTI dilution, no compensation).
  4. Structural diagnosis: The law disciplines private firms harder than the State, inverting the Puttaswamy priority; the proportionality test is the missing yardstick.
  5. Way forward: Four to five grouped reforms, each with a clear actor.
  6. Conclusion: Adapt the balanced line to the exact question wording.

Diagram or Flowchart Idea

For a 15-marker, draw one timeline-plus-logic chain: Puttaswamy 2017 (privacy = fundamental right) → DPDP Act 2023 → Rules 2025 → phased rollout to 2027 → contested provisions (Section 17, Board, Section 44(3)) → SC challenge 2026. The examiner reads the whole arc in seconds.

For a 10-marker, skip the timeline and use a two-column table, “Strong (real progress)” against “Contested (is it real?).” It does more work and is faster to grade under time pressure.

Ethics and Governance Angle

Add one ethical line even in a technology answer. The deeper issue is the citizen-State trust relationship, who watches the watchman when the State is both the rule-maker and the largest data-holder. Name the person who bears the cost: the RTI user denied an official’s asset declaration, the breach victim with no compensation.

Then convert the ethics into design. Don’t merely say “protect privacy.” Say how: a proportionality-bound Section 17, an independent Board with secure tenure, a restored RTI public-interest test, a statutory compensation route. That’s the move from moral language to administrative maturity, exactly what the examiner wants on a balance question.

A sentence pattern that travels across topics: “The aim is legitimate; its legitimacy depends on procedure, proportionality, and an independent check.” It accepts the State’s data needs without handing it a blank cheque.

How to Use Data Without Sounding Mechanical

Use fewer numbers than you know. Three well-explained figures beat ten scattered ones. Lead with a date that anchors the constitutional story (24 Aug 2017), use a second for the delay (13 May 2027), and a third for the deterrent (₹250 crore). One foundation, one gap, one tooth.

Never leave a statistic standing alone. Follow it with “this means” or “the implication is.” The ₹250-crore cap means nothing until you add that it changes how a board treats data security. The 2027 date means nothing until you add that the protective half of the law is more than a year away.

Finish by asking one question: can a tired examiner follow this in a single pass? Short introduction, data early, two sides marked cleanly, grouped way forward, judgment at the close. For UPSC, clarity is how depth becomes visible. Cut any line that sounds impressive but does no work, and replace it with a fact, a cause, a consequence, or a reform.

FAQ

What exactly is the difference between a data principal and a data fiduciary?

A data principal is the individual the personal data is about, so for your own data, that’s you. A data fiduciary is whoever decides why and how that data is processed, a bank, an app, a hospital, or a State department. The word “fiduciary” signals a duty of trust: the entity holding your data is treated as a trustee accountable to you, not just a party to a transaction.

Does the DPDP Act give Indians the same protection as Europe’s GDPR?

Not quite, and the differences are deliberate. The DPDP Act is a lighter, first-generation law. It has no individual compensation right (unlike GDPR Article 82, penalties go to the State), no right to data portability, and no explicit right to be forgotten. It does follow a business-friendly negative-list model for cross-border transfers with no blanket localisation mandate. So it’s a genuine statutory regime, but a more limited one than the GDPR.

Why is the DPDP Act being challenged in the Supreme Court?

The core objections are that Section 17 lets the central government exempt its own agencies on broad grounds, that the Data Protection Board is appointed and controlled by the executive, and that Section 44(3) diluted the RTI Act by removing the larger-public-interest override in Section 8(1)(j). The Court issued notice in February and March 2026 and tagged the petitions together. The case is live and undecided, so it should be described as ongoing, not as a verdict.

When do the DPDP protections actually take effect?

In stages. The Rules were notified on 13 November 2025, but only the Board-establishment provisions and definitions came into force then. Consent-manager registration opens around 13 November 2026, and the substantive duties, notice and consent, security safeguards, breach notification, and the data-principal rights, become enforceable from about 13 May 2027. So as of mid-2026, the protective core of the law is still more than a year away.

Tell Google you want more of this.

Add Anantam IAS as a preferred source

One tap, and this site shows up more often in your own Top Stories, AI Overviews and AI Mode. Remove it any time.

Share this

PDF

Written by

Pooja Bhatt Ma'am

Editor — UPSC Content · Anantam IAS

Pooja Bhatt is part of the editorial team at Anantam IAS, writing and editing UPSC prep content across Prelims, Mains and current affairs.

Specialises in · UPSC syllabus content, editing and publishing Experience · 6+ years

Preparing for UPSC CSE 2026? Sit in a free demo class.

No sales call. No brochure. Watch a real Monday-morning GS session taught by ex-Rau's IAS faculty.