KK Associates
KK Associates
Introduction and Constitutional Background (Preamble; Statement of Objects and Reasons)
The Digital Personal Data Protection Act, 2023 marks India’s first comprehensive statutory intervention devoted exclusively to the governance of personal data in digital form. Its enactment must be understood as a constitutional sequel to the Supreme Court’s recognition of privacy as an intrinsic component of the right to life and personal liberty under Article 21 in Justice K.S. Puttaswamy v. Union of India & Ors., (AIR 2017 SC 4161, 2017 SCC OnLine SC 1462). The Act does not merely codify informational privacy; it reflects a legislative choice to recalibrate the relationship between individual autonomy, market activity, and State governance within a data-driven constitutional order.
Unlike rights-maximalist regimes such as the GDPR, the Indian statute adopts a calibrated and interest-balancing approach that permeates its structure. This orientation, evident from the Preamble and operative provisions, treats privacy as a fundamental but non-absolute right, mediated through regulatory supervision rather than adversarial adjudication.
The Act also effects a clear structural break from the earlier regime under section 43A of the Information Technology Act, 2000 and the Information Technology (SPDI) Rules, 2011. That framework was narrow in scope, entity-specific, and compensation-centric. By contrast, the DPDP Act establishes a continuous compliance architecture enforced through a specialised regulator, signalling a shift from ex post liability to ex ante governance.
Scope, Applicability and Territorial Reach (Sections 2, 3, 4)
Section 3 confines the Act’s application to digital personal data, whether collected in digital form or subsequently digitised. The deliberate exclusion of purely offline structured databases marks a conscious legislative narrowing of scope when compared to the GDPR. At the same time, section 3(b) extends the Act extraterritorially to processing outside India where goods or services are offered to data principals within India, significantly expanding its regulatory reach over foreign digital actors.
Section 4 carves out exclusions for personal or domestic processing, voluntarily public data, and disclosures mandated by law. These exclusions prevent the over-constitutionalisation of everyday digital expression and preserve the functioning of transparency and disclosure regimes.
Temporal Architecture of Enforcement and Regulatory Transition (Sections 1(2), 18, 19, 33; DPDP Rules, 2025)
Although enacted in August 2023, section 1(2) expressly empowers the Central Government to bring the Act into force in phases. Exercising this power, the Government notified the DPDP Rules, 2025 on 13 November 2025, rendering the statute legally operative while deferring full compliance obligations.
The first phase operationalised sections 18 and 19 relating to the establishment, composition, and powers of the Data Protection Board of India, alongside delegated rule-making authority. The second phase, scheduled for November 2026, activates the consent-management ecosystem under section 2(g) read with the Rules. The third phase, commencing May 2027, will give full effect to operative provisions governing rights, obligations, safeguards, and penalties under Chapters II to VIII.
This phased architecture creates a constitutionally significant transition window that tempers regulatory shock, supports proportionality, and mitigates claims of frustrated legitimate expectation.
Conceptual Framework: Data Fiduciary and Data Principal (Sections 2(i), 2(j), 5, 6)
The Act is anchored in a fiduciary model of data governance. Section 2(i) defines the Data Fiduciary as the entity determining the purpose and means of processing, while section 2(j) defines the Data Principal. Section 5 establishes consent as the default legal basis for processing, subject to statutorily recognised legitimate uses under section 7.
This structure shifts Indian data protection law away from negligence-based liability towards continuous regulatory responsibility, aligning compliance obligations with control over data processing decisions.
Consent Architecture and Its Legal Rigour (Section 6)
Section 6 prescribes a stringent consent standard: consent must be free, specific, informed, unconditional, unambiguous, and signified through affirmative action. Any consent purporting to waive statutory rights is rendered invalid. Section 6(4) mandates that withdrawal of consent be as easy as its grant, while preserving the legality of prior processing.
The consent-manager framework, contemplated under section 2(g) and operationalised through the Rules, introduces an intermediary accountability mechanism aimed at enhancing transparency and interoperability.
Non-Consensual Processing and Legitimate Uses (Section 7)
Section 7 exhaustively enumerates circumstances permitting non-consensual processing, including welfare delivery, sovereign functions, legal compliance, emergencies, disaster management, public order, and employment-related purposes. The closed-list approach reflects a governance-centric philosophy that prioritises administrative continuity over open-ended balancing tests.
Obligations of Data Fiduciaries (Sections 8, 9, 10)
Sections 8 and 9 impose ongoing obligations of accuracy, security safeguards, breach notification, and storage limitation. Section 10 mandates erasure upon withdrawal of consent or fulfilment of purpose, subject to statutory retention requirements. These obligations must be read in light of phased enforcement under section 1(2), which defers their coercive application until May 2027.
Protection of Children’s Personal Data (Section 9)
Section 9 introduces heightened protections for children’s data, mandating verifiable parental consent and prohibiting behavioural tracking and targeted advertising. The provisos empowering governmental relaxation for specified fiduciaries raise concerns of dilution and executive discretion.
Significant Data Fiduciaries and Enhanced Compliance (Section 10)
Section 10 empowers the Central Government to designate Significant Data Fiduciaries based on volume, sensitivity, and systemic risk. Such entities are subject to enhanced obligations, including appointment of data protection officers, audits, and impact assessments, reinforcing an executive-centric compliance hierarchy.
Rights and Duties of Data Principals (Sections 11–15)
Sections 11 to 14 confer enforceable rights of access, correction, erasure, grievance redressal, and nomination. Section 15 introduces duties on data principals to prevent misuse of rights, embedding reciprocity into the rights framework.
Exemptions and Executive Discretion (Sections 17, 36)
Section 17 provides wide-ranging exemptions for State functions, law enforcement, judicial proceedings, insolvency, and research. Section 36 empowers the Central Government to exempt classes of fiduciaries or suspend provisions, raising constitutional concerns regarding delegation and proportionality.
Data Protection Board of India and Enforcement (Sections 18–28)
Sections 18 to 28 constitute the enforcement architecture, vesting adjudicatory and regulatory powers in the Data Protection Board of India. The Board’s early activation under phased enforcement underscores its initial norm-setting role prior to penalty-driven adjudication.
Appellate Structure and Penalty Regime (Sections 29–33)
Appeals from the Board lie to the Telecom Disputes Settlement and Appellate Tribunal under section 29. Section 33 prescribes administrative penalties up to ₹250 crore, with all amounts credited to the Consolidated Fund of India and no provision for individual compensation.
Interface with Other Laws and Overall Assessment (Sections 38–44)
Sections 38 to 44 provide for overriding effect, repeal of section 43A of the IT Act, amendment of the RTI Act, and exclusion of civil court jurisdiction. Taken together, the Act replaces a reactive regime with a regulator-led governance model that strengthens accountability while consolidating executive discretion, embodying a deliberate constitutional trade-off between informational autonomy and governance efficiency.
Disclaimer: This article is intended for general informational and policy discussion purposes only. It does not constitute legal advice, financial advice, or a formal interpretation of law. The views expressed are based on publicly available information, prevailing statutory provisions, and reported developments as of the date of publication. Readers are advised to seek independent professional advice before taking any action based on the contents of this article. The author assumes no liability for decisions taken in reliance upon this information.