UPSC CSE 2026 Essay Paper Discussion
GS Paper 3 10 marks · 150w 9 min Easy

Describe the context and salient features of the Digital Personal Data Protection Act, 2023.

Subtopic: Science & Technology · Data Protection & Privacy

Model answer outline

How to structure your answer

Introduction → context of the law → Puttaswamy and Srikrishna Committee → salient features → obligations and rights → Data Protection Board → Conclusion
Full model answer

Detailed model answer

224 words · target 150 words · 9 min

The Digital Personal Data Protection (DPDP) Act, 2023 is India's first standalone data-privacy law. It governs the processing of digital personal data while seeking to balance an individual's right to protect their data against the need for lawful processing in a digital economy.

Context

  • The Supreme Court in K.S. Puttaswamy (2017) held privacy to be a fundamental right under Article 21, making a data-protection framework a constitutional necessity.
  • The B.N. Srikrishna Committee (2018) and successive draft bills, refined after wide consultation, culminated in this enacted law amid a surge in digitisation and data-driven services.

Salient features

  • Applies to digital personal data processed within India and to processing abroad that is connected with offering goods or services to people in India.
  • Processing rests on consent, with defined 'legitimate uses' as exceptions; notice to the individual must be clear and itemised.
  • Data Fiduciaries must ensure accuracy, adopt security safeguards and notify breaches; Significant Data Fiduciaries face additional duties such as audits and Data Protection Impact Assessments.
  • Data Principals enjoy rights to access, correction, erasure, nomination and grievance redress, with verifiable parental consent required for children's data.
  • It sets up a Data Protection Board of India to adjudicate breaches and impose penalties up to Rs 250 crore.

The Act marks a decisive shift toward accountable, rights-respecting data governance, though its real effectiveness will hinge on the subordinate rules and the Board's independence.

Key points

What an examiner expects to see

  • First dedicated Indian law on digital personal data protection, enacted August 2023.
  • Rooted in the Puttaswamy (2017) right-to-privacy verdict and the Srikrishna Committee report.
  • Applies to digital personal data in India and to overseas processing linked to Indian users.
  • Consent-centric with defined 'legitimate uses' exceptions; clear, itemised notice required.
  • Data Fiduciary duties: purpose limitation, security safeguards, breach reporting; extra duties for Significant Data Fiduciaries.
  • Data Principal rights: access, correction, erasure, nomination and grievance redressal.
  • Data Protection Board of India adjudicates breaches; penalties up to Rs 250 crore.
Examples to use

Concrete cases, schemes and judgments

  • Justice K.S. Puttaswamy v. Union of India (2017) recognising privacy under Article 21.
  • B.N. Srikrishna Committee report (2018) 'A Free and Fair Digital Economy'.
  • Data Protection Board of India as the adjudicatory body.
  • Verifiable parental consent requirement for processing children's data.
Keywords / terms

Terminology to weave into the answer

Data FiduciaryData Principalconsent-based processingData Protection Boardright to privacy

Share this answer