Digital Personal Data Protection Rules: What Changes for Citizens
The Act in Brief
The Digital Personal Data Protection Act, 2023 is India's first comprehensive law on personal data. It follows the Supreme Court's recognition of privacy as a fundamental right under Article 21 in K.S. Puttaswamy v. Union of India (2017) and the B.N. Srikrishna Committee's 2018 draft.
- Applies to digital personal data processed within India, and to processing abroad if it relates to offering goods or services in India.
- Introduces 'Data Principals' (individuals), 'Data Fiduciaries' (entities deciding purpose and means) and 'Significant Data Fiduciaries'.
- Penalties of up to ₹250 crore per instance for failure to take reasonable security safeguards.
What the Rules Add
- Notice and consent: fiduciaries must give itemised notices in plain language; consent may be withdrawn as easily as it was given.
- Consent Managers: registered platforms enabling individuals to give, manage and withdraw consent — must be Indian companies with a minimum net worth.
- Children's data: verifiable parental consent for users under 18, with exemptions for health and education providers.
- Breach notification: affected users and the Board must be informed without delay, with a detailed report within 72 hours.
- Data Protection Board: a fully digital adjudicatory body; appeals lie to the TDSAT.
Concerns & Debates
Civil society groups have flagged wide exemptions for government agencies under Section 17, the dilution of the RTI Act, and the absence of an independent, multi-member regulator comparable to the EU's data protection authorities. Industry, in turn, has sought longer transition timelines and clarity on cross-border data flows, which the Rules permit except to countries on a negative list.
Test Yourself
2 graded questions · Prelims format
With reference to the Digital Personal Data Protection Act, 2023, consider the following statements:
- 1.The Act applies only to personal data processed within the territory of India.
- 2.Appeals against orders of the Data Protection Board of India lie with the TDSAT.
- 3.The Act follows a 'blacklist' model for cross-border transfer of personal data.
Frequently Asked Questions
Previous Year Questions on this topic
Consider the following: 1. Battery storage 2. Biomass generators 3. Fuel cells 4. Rooftop solar photovoltaic units. How many of the above are considered 'Distributed Energy Resources'?
Consider the following actions: 1. Detection of car crash/collision which results in the deployment of airbags almost instantaneously. 2. Detection of accidental free fall of a laptop towards the ground which results in the immediate turning off of the hard drive. 3. Detection of the tilt of the smartphone which results in the rotation of display between portrait and landscape mode. In how many of the above actions is the function of accelerometer required?
Related Reading
Picked by shared GS paper & subject tags
The Waqf (Amendment) Act: Governance of Religious Endowments
Amendments to the management of Waqf properties raise questions of transparency, digitisation, the role of Waqf tribunals and the constitutional boundaries of State regulation of religious institutions.
Algorithms in the Secretariat: Ethics of AI in Public Administration
From welfare targeting to predictive policing, AI now shapes administrative decisions. What ethical guardrails should a civil servant apply when the machine recommends and the officer signs?
Heatwaves as Disasters: Are India's Heat Action Plans Working?
With April temperatures crossing 45°C across the Indo-Gangetic plain, the debate on notifying heatwaves as a 'disaster' under the Disaster Management Act has returned, alongside questions on the quality of Heat Action Plans.
