GS Paper 3 10 marks · 150w 9 min Easy
Describe the context and salient features of the Digital Personal Data Protection Act, 2023.
Subtopic: Science & Technology · Data Protection & Privacy
How to structure your answer
Introduction → context of the law → Puttaswamy and Srikrishna Committee → salient features → obligations and rights → Data Protection Board → Conclusion
Detailed model answer
224 words · target 150 words · 9 min
The Digital Personal Data Protection (DPDP) Act, 2023 is India's first standalone data-privacy law. It governs the processing of digital personal data while seeking to balance an individual's right to protect their data against the need for lawful processing in a digital economy.
Context
- The Supreme Court in K.S. Puttaswamy (2017) held privacy to be a fundamental right under Article 21, making a data-protection framework a constitutional necessity.
- The B.N. Srikrishna Committee (2018) and successive draft bills, refined after wide consultation, culminated in this enacted law amid a surge in digitisation and data-driven services.
Salient features
- Applies to digital personal data processed within India and to processing abroad that is connected with offering goods or services to people in India.
- Processing rests on consent, with defined 'legitimate uses' as exceptions; notice to the individual must be clear and itemised.
- Data Fiduciaries must ensure accuracy, adopt security safeguards and notify breaches; Significant Data Fiduciaries face additional duties such as audits and Data Protection Impact Assessments.
- Data Principals enjoy rights to access, correction, erasure, nomination and grievance redress, with verifiable parental consent required for children's data.
- It sets up a Data Protection Board of India to adjudicate breaches and impose penalties up to Rs 250 crore.
The Act marks a decisive shift toward accountable, rights-respecting data governance, though its real effectiveness will hinge on the subordinate rules and the Board's independence.
What an examiner expects to see
- First dedicated Indian law on digital personal data protection, enacted August 2023.
- Rooted in the Puttaswamy (2017) right-to-privacy verdict and the Srikrishna Committee report.
- Applies to digital personal data in India and to overseas processing linked to Indian users.
- Consent-centric with defined 'legitimate uses' exceptions; clear, itemised notice required.
- Data Fiduciary duties: purpose limitation, security safeguards, breach reporting; extra duties for Significant Data Fiduciaries.
- Data Principal rights: access, correction, erasure, nomination and grievance redressal.
- Data Protection Board of India adjudicates breaches; penalties up to Rs 250 crore.
Concrete cases, schemes and judgments
- Justice K.S. Puttaswamy v. Union of India (2017) recognising privacy under Article 21.
- B.N. Srikrishna Committee report (2018) 'A Free and Fair Digital Economy'.
- Data Protection Board of India as the adjudicatory body.
- Verifiable parental consent requirement for processing children's data.
Terminology to weave into the answer
Data FiduciaryData Principalconsent-based processingData Protection Boardright to privacy