Policy Data Protection

THE REIGN OF THE DIGITAL POLICEMAN BEGINS

Designer 3 1

The Digital Personal Data Protection Act is a much needed step forward to protect people from misuse of personal data in an interconnected world. But, given the sweeping powers of censorship that this law confers on the State, the government needs to ensure that this law is not abused by public servants with vested interests to curtail freedom of expression

From pesky calls from real estate agents trying to sell the next luxury apartment to reputed companies sending an unending stream of spam SMSs to emails getting bombarded with junk mail — these are all too familiar experiences for everyone in this digitally connected world. It’s proof, if ever needed, that a person’s digital profile and critical personal data have become a common commodity available in every nook and cranny of cyberspace. The tussle between privacy and proliferation of personal data is as old as the internet. But now governments around the world are waking up to the need to protect a person’s digital footprint from those who want to churn the bits and bytes of data into money without the consent of that person. In India, this need has led to the enactment of the Digital Personal Data Protection Act, 2023 (DPDPA) — albeit a few years late. It’s expected that the DPDPA rules will be notified in the near future, making the law operational.

This Act, a landmark step forward in India’s digital journey, is a significant piece of legislation aimed at protecting the digital privacy of over a billion citizens. Passed in August 2023, it emerged from years of deliberation, drafting, redrafting, public consultation, legal scrutiny, and parliamentary debate. Yet, its roots go back Photo: AI GENERATED even further, to 2017, when the Supreme Court of India ruled in the historic Justice K.S. Puttaswamy case that the right to privacy is a fundamental right under the Constitution. That ruling not only galvanised public discourse but also compelled the government to codify a robust data protection regime.
The DPDPA establishes a legal framework that governs how personal data is collected, processed, stored, and transferred. At its heart lies a simple but powerful premise: the individual, or the “data principal” as described in the law, owns their personal data. Entities that collect or process this data are termed “data fiduciaries” and are bound by a duty to ensure that data is handled in a lawful, fair, and transparent manner. Unlike earlier legislation such as the Information Technology Act, 2000 — which contained only scattered provisions on data security — the DPDPA is a comprehensive law. It mandates that data fiduciaries must seek informed consent from users before collecting their data, explicitly state the purpose of data collection, and ensure the data is used only for that purpose. There are provisions for withdrawal of consent, correction of data, and even for grievance redressal. The law also introduces the concept of Significant Data Fiduciaries, who handle large volumes of 

sensitive data and are subject to stricter compliance requirements, such as data protection impact assessments and audits. The Act attempts to balance individual rights with the needs of the state and business. It permits the government to exempt certain agencies from the purview of the law for reasons related to national security, public order, or law enforcement. This aspect has drawn criticism from privacy advocates, who argue that such exemptions could be misused, creating potential loopholes. Still, proponents of the Act suggest that this flexibility is crucial for addressing real world challenges, especially in a country as vast and complex as India. The DPDPA also establishes a Data Protection Board of India, an independent body tasked with enforcing the law, investigating complaints, and imposing penalties for non compliance. The Board is empowered to levy  significant fines — up to Rs 250 crore — for breaches, signalling the seriousness with which the government intends to implement data  protection norms. Yet, critics argue that the appointment process for Board members, which is
 controlled by the government, could compromise its independence.

A Global Comparison
Looking beyond India, the DPDPA becomes even more interesting in comparison with global data protection laws.
 Perhaps the most widely recognised is the European Union’s General Data Protection Regulation (GDPR), enacted in 2018. The GDPR is often considered the gold standard of data protection worldwide. It was one of the first comprehensive laws to articulate a rights-based approach to personal data, emphasising consent, transparency, and accountability. The GDPR has several features that the DPDPA mirrors, such as the right to access and correct data, the right to be forgotten,
 and the requirement for Data Protection Officers in certain cases. However, the GDPR goes further in many respects. For instance, it mandates data minimisation and storage limitation, requiring that only necessary data be collected and retained for
 no longer than needed. The DPDPA, while comprehensive, is somewhat more flexible in this regard, perhaps reflecting India’s need to foster innovation and support its burgeoning digital economy.Another key difference lies in territorial scope. The GDPR applies to any entity, regardless of location, that processes the data of EU residents. The DPDPA adopts a similar stance but places a stronger emphasis on localisation, particularly when it comes to sensitive personal data. However, it has relaxed earlier proposals that would have required all data to be stored in India, adopting a more pragmatic approach that
 allows cross-border transfers to notified jurisdictions.

Unlike earlier legislation such as the Information Technology Act, 2000, the DPDPA is a comprehensive law. It mandates that data fiduciaries must seek informed consent from users before collecting their data, explicitly state the purpose of data collection, and
ensure the data is used only for that purpose

Looking beyond India, the DPDPA becomes even more interesting in comparison with global data protection laws. Perhaps the most widely recognised is the European Union’s General Data Protection Regulation (GDPR), enacted in 2018. The GDPR is often considered the gold standard of data protection worldwide

Aadhaar Enrolement Biswarup Ganguly Wiki Commons 1

similar stance but places a stronger emphaOn August 24, 2017, the Supreme Court ruled that the citizens of India have a right to privacy and it’s a fundamental right under the Constitution 

binary 5137356 1 1

In the United States, the situation is quite different. The country does not have a single, unified data protection law akin to the GDPR or DPDPA. Instead, it relies on a patchwork of sector-specific laws such as the Health Insurance Portability and Accountability Act (HIPAA) for health data, and the Children’s Online Privacy Protection Act (COPPA) for children’s data. Some states, like California, have taken the lead in enacting comprehensive laws — the California Consumer Privacy Act (CCPA) and its successor, the California Privacy Rights Act (CPRA), being prime examples.
The CCPA, like the DPDPA, gives consumers rights over their data, including the right to know what data is collected, the right to delete it, and the right to opt out of its sale. However, US laws tend to prioritise consumer choice and market-driven solutions, rather than enshrining data protection as a fundamental right. India’s approach, rooted in constitutional principles, arguably offers stronger foundational protections, though implementation remains a concern. China’s Personal Information Protection Law (PIPL), enacted in 2021, offers another point of contrast. While it bears similarities to the GDPR in terms of user consent and data rights, it is also aligned with China’s broader policy goals. It allows extensive state access to data, and its enforcement is deeply intertwined with national security considerations. The DPDPA, while also offering exemptions for state functions, still preserves a distinct boundary between state surveillance and individual privacy — at least on paper. In many ways, India’s law attempts to chart a middle path. It is neither as stringent as the GDPR nor as fragmented as the US approach. It recognises the importance of individual rights but tempers them with practicalities of governance and economic growth. For a country that has leapfrogged into the digital era, often without adequate legal safeguards in place, the DPDPA represents a long-overdue course correction.
However, it remains to be seen how informed consent pans out on the ground, given that digital literacy in urban and rural India is still extremely poor.
The journey of data protection in India is just beginning. There will be challenges ahead — legal, technological, and bureaucratic. But the Digital Personal Data Protection Act has laid the foundation for a future where citizens are not mere data points in a vast algorithm, but individuals with rights, agency, and dignity in the digital world. And in that sense, it is more than just legislation; it is a quiet, powerful reaffirmation of the right to be human in the age of machines. 

The Digital Personal Data Protection Act, 2023, has been the subject of considerable debate, especially regarding its impact on the Right to Information Act, 2005 (RTI Act) — a law widely credited with promoting transparency and accountability in governance. Critics argue that the DPDPA dilutes key provisions of the RTI Act, particularly in how it handles access to personal information held by public authorities. A closer look reveals how that dilution happens.

Amendment to Section 8(1 (j) of the RTI Act
One of the most significant changes brought in by the DPDPA is the amendment to Section 8(1)(j) of the RTI Act. Under the original RTI Act, this section exempted personal information from disclosure only if it had no relationship to any public activity or interest, or if it would cause unwarranted invasion of the individual’s privacy unless the Central or State Public information Officer was satisfied that the  larger public interest justified its disclosure.
The DPDPA removes the public interest override from this clause.

Before Amendment
“Information which relates to personal information, the disclosure of which has no relationship to any public activity or interest, or which would cause unwarranted invasion of the privacy of the individual unless the public authority is satisfied that the larger public interest justifies the disclosure of such information.”
After Amendment (via DPDPA)
“Information which relates to personal information.” This small but powerful change removes the discretion of Public Information Officers (PIOs) in weighing public interest against privacy concerns — effectively making all personal information exempt from disclosure, even if it’s about public officials or matters of public importance.
Shift in Balance from Transparency to Privacy
The original RTI Act balanced privacy and transparency by allowing for disclosure when larger public interest was at stake. Journalists, activists, and citizens could access important personal data of public servants (like property declarations, assets, service records, etc.) if it was relevant to exposing corruption, conflicts of interest, or abuse of power.
Now, with the DPDPA overriding this mechanism, even personal information of public officials that may reveal corruption or misuse of public office could be withheld simply on the grounds of it being  personal”.
This shifts the balance of power toward privacy and away from transparency, which many fear could create an environment of opacity in governance.
Potential Chilling Effect on Whistleblowing and Investigative Journalism
The dilution of Section 8(1 (j) could have a chilling effect on the use of RTI for exposing wrongdoing. For example:
✹ Investigations into assets disproportionate to income of public servants may now hit a wall, since such data may be withheld as “personal”.
✹ Information about misuse of official perks, recruitment processes, or disciplinary actions against government officials could be denied, curbing public oversight.
✹ Journalists trying to track government contracts or land allotments may find it harder to trace personal links and conflicts of interest involving public servants.

Weakened Role of the Central and State Information Commissions

The RTI Act gave quasi judicial bodies — the Central and State Information Commissions — the power to weigh public interest against personal privacy in appeals and complaints. With the DPDPA’s stricter approach to personal data and blanket exemption from disclosure, these commissions may now find themselves powerless in cases where transparency is needed but involves personal data.

Ambiguity in Definitions and Implementation

The DPDPA uses terms like “personal data” and “consent” liberally, but lacks clarity on
 how these would be interpreted in RTI cases. For example: Is a public servant’s attendance record personal? Are educational qualifications of a public official protected under personal data? Can citizens seek details of travel or expense reimbursements of public servants? Without  clarity or defined boundaries, PIOs may err on the side of caution and deny more RTI requests to avoid penalties or legal risks under the DPDPA regime.

Clash of Rights

At the heart of this issue is a clash between two fundamental rights: the Right to Privacy, recognised by the Supreme Court as a part of the Right to Life under Article 21, and the Right to Information, which empowers citizens to hold the state accountable and is rooted in the Right to Freedom of Speech and Expression Article 19(1)(a).
The DPDPA prioritises privacy but, critics argue, at the cost of weakening democratic transparency. In a country where RTI has been instrumental in uncovering scams, misgovernance, and corruption, the concern is that the DPDPA’s blanket protections could shield public officials from scrutiny, reducing the RTI Act’s effectiveness as a tool of accountability. As India navigates this complex digital landscape, the real challenge will be finding legal and moral equilibrium — one that protects both citizen privacy and the public’s right to know. 

Adhar DSCN4539 1

Any entity that collects personal data becomes a data fiduciary and will be governed by the provisions of DPDPA for storage and usage

MAIN PICTURE Data Economy Photo Gerd Altmann Pixabay 1 1