Published on: 18th August 2026
Authored by: Akshal M
Sathyabama Institute of Science and Technology
ABSTRACT
The Digital Personal Data Protection Act, 2023 (DPDP Act) is a landmark in India’s quest for building a legal framework for protecting digital personal data[cite: 3]. With India undergoing rapid digital transformation through initiatives such as Digital India, expanding internet connectivity, digital transactions, artificial intelligence, cloud computing, and e-commerce, there has been a significant increase in the collection and processing of personal data[cite: 3]. While these developments have accelerated innovation and economic growth, they have also raised serious concerns regarding privacy, cybersecurity, data breaches, and the misuse of personal data[cite: 3]. This paper critically evaluates the implementation of the DPDP Act in the 2025–2026 period, focusing specifically on the notification of the Digital Personal Data Protection Rules, 2025, the operationalization of the Data Protection Board of India, and the practical challenges faced by businesses, government agencies, and Data Principals[cite: 3]. It further provides a critical assessment of constitutional issues surrounding the right to privacy under Article 21, broad government exemptions, cross-border data flows, children’s data protection, and emerging challenges posed by artificial intelligence[cite: 3]. Through a comparative analysis with international standards, particularly the European Union’s General Data Protection Regulation (GDPR), this article examines whether the Indian regime achieves an appropriate balance between technological innovation and individual privacy, concluding with targeted legal and institutional reform proposals[cite: 3].
I. INTRODUCTION
Digital Transformation and the Growing Importance of Personal Data
Driven by the Digital India initiative, rising internet penetration, the Unified Payments Interface (UPI), e-commerce, artificial intelligence (AI), and cloud computing, India’s rapid digital transformation has vastly expanded the collection and processing of personal data[cite: 3]. Individuals routinely share financial, biometric, and behavioral information to access essential digital services[cite: 3]. Consequently, personal data has become a critical economic asset powering innovation, commercial decision-making, and digital trade[cite: 3]. However, this widespread data reliance simultaneously heightens risks related to privacy violations, security breaches, data commercialization, and accountability, underscoring the imperative for a robust regulatory framework[cite: 3].
Evolution of Privacy Law in India
India’s journey toward a dedicated data protection regime has been evolutionary, trailing the rapid pace of national digitalization[cite: 3]. Initially, personal data received limited statutory protection through Section 43A of the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011[cite: 3]. A foundational shift occurred when the Supreme Court of India delivered its landmark ruling in Justice K.S. Puttaswamy (Retd.) v. Union of India,[1] unanimously declaring privacy a fundamental right under Article 21 of the Constitution[cite: 3]. This constitutional anchor, alongside recommendations from the Expert Committee chaired by Justice B.N. Srikrishna, laid the groundwork for India’s contemporary data protection statutory structure[cite: 3].
Scope, Research Problem, and Methodology
This paper evaluates the operationalization of the Digital Personal Data Protection Act, 2023 and the evolution of India’s data protection regime through 2025–2026[cite: 3]. It explores the central research issue of whether the statutory and regulatory framework successfully balances the constitutional right to privacy with the operational demands of a growing digital economy[cite: 3]. Utilizing a doctrinal research methodology, this study critically analyzes statutory provisions, judicial precedents, the Digital Personal Data Protection Rules, 2025, and relevant policy frameworks[cite: 3].
II. LEGAL ANALYSIS
2.1 Objectives and Salient Features of the DPDP Act, 2023
The Digital Personal Data Protection Act, 2023 (DPDP Act) establishes a comprehensive statutory framework for the lawful processing of digital personal data, attempting to reconcile an individual’s right to protect their personal data with the necessity of processing such data for lawful purposes by organizations and the State[cite: 3]. The Act applies to the processing of digital personal data within India, as well as extra-territorially where processing relates to offering goods or services to Data Principals within Indian territory[cite: 3]. Key statutory components include consent-based processing, codified rights for Data Principals, statutory obligations for Data Fiduciaries, the establishment of the Data Protection Board of India, regulated cross-border data transfers, and substantial financial penalties for non-compliance[cite: 3].
2.2 Rights of the Data Principal
To empower individuals over their personal information, the DPDP Act confers several enforceable rights upon Data Principals[cite: 3]:
1. Right to Information: The right to obtain a summary of personal data being processed and the processing activities undertaken by the Data Fiduciary[cite: 3].
2. Right to Correction and Erasure: The right to request the correction, updating, or erasure of personal data that is inaccurate, incomplete, or no longer necessary for the specified purpose[cite: 3].
3. Right to Grievance Redressal: Access to readily available mechanisms provided by Data Fiduciaries and the Data Protection Board to resolve grievances[cite: 3].
4. Right to Nominate: The right to designate another individual to exercise data protection rights on behalf of the Data Principal in the event of death or incapacity[cite: 3].
2.3 Obligations of the Data Fiduciary
Data Fiduciaries must obtain free, specific, informed, unconditional, and unambiguous consent prior to processing personal data, accompanied or preceded by a clear notice detailing the specific purpose and categories of data collected[cite: 3]. Fiduciaries are required to implement reasonable security safeguards to prevent data breaches and must notify both the Data Protection Board and affected Data Principals without undue delay in the event of a breach[cite: 3]. Additionally, Fiduciaries must maintain data accuracy and adhere to data minimization and storage limitation mandates, erasing personal data once the specified purpose is fulfilled or consent is withdrawn, subject to statutory retention exceptions[cite: 3].
2.4 Data Protection Board of India
The Data Protection Board of India (DPBI) is structured as a digital-first adjudicatory body responsible for investigating data breaches, receiving complaints, directing remedial measures, and imposing financial penalties[cite: 3]. Operating with civil court powers, the DPBI is authorized to levy penalties of up to ₹250 crore for severe statutory contraventions[cite: 3]. Decisions and orders of the DPBI are appealable before the Telecom Disputes Settlement and Appellate Tribunal (TDSAT)[cite: 3].
III. IMPLEMENTATION OF THE DPDP ACT (2025–2026)
3.1 DPDP Rules, 2025 and Regulatory Developments
Following extensive public consultation on draft regulations initiated by the Ministry of Electronics and Information Technology (MeitY)—which received 6,915 inputs across diverse stakeholder groups—the final Digital Personal Data Protection Rules, 2025 were officially notified on 13 November 2025[cite: 3]. The notification introduced a phased, three-stage implementation roadmap[cite: 3]:
Phase One (Immediate): Focuses on administrative and procedural setup, including the formal constitution and operationalization of the Data Protection Board[cite: 3].
Phase Two (13 November 2026): Enforces the regulatory framework governing Consent Managers[cite: 3].
Phase Three (13 May 2027): Brings into force substantive obligations regarding notice, consent architecture, security safeguards, breach reporting timelines, and Data Principal rights exercise, affording Fiduciaries an 18-month compliance runway[cite: 3].
3.2 Compliance Challenges for Businesses
The phased rollout has generated variable compliance pressures across different commercial sectors[cite: 3]. Startups and Micro, Small, and Medium Enterprises (MSMEs) face significant compliance costs in re-engineering consent user interfaces, appointing Data Protection Officers (DPOs), and establishing Data Protection Impact Assessments (DPIAs)[cite: 3]. Sector-specific rules under the Third Schedule impose additional mandates on banks, fintech platforms, and e-commerce entities that handle large volumes of sensitive financial and behavioral data, including strict data retention and erasure schedules[cite: 3]. Healthcare providers encounter operational hurdles in adapting traditional medical recordkeeping to statutory consent workflows[cite: 3]. Across industries, managing third-party data processors remains a challenge, as Data Fiduciaries retain vicarious liability for processor non-compliance[cite: 3].
3.3 Public Sector and Administrative Challenges
Implementation within government departments presents significant administrative challenges due to massive citizen databases operating on legacy IT systems without dedicated privacy infrastructure[cite: 3]. Broad statutory exemptions granted to State instrumentalities for reasons of national security, public order, and sovereign functions create asymmetrical accountability between public and private actors[cite: 3]. Building modern data governance architecture across ministries and training public officials in privacy compliance remain ongoing efforts[cite: 3]. Without commensurate institutional capacity within state organs, the framework risks creating a two-tiered compliance ecosystem that could undermine public trust in state-held data[cite: 3].
3.4 Public Awareness and Digital Literacy
The practical utility of the DPDP Act depends on informed Data Principals; however, widespread “consent fatigue” caused by frequent online notices often hinders meaningful choice[cite: 3]. Digital literacy gaps remain, particularly in rural regions where understanding privacy notices, exercising erasure rights, or interacting with the DPBI’s digital portal poses challenges[cite: 3]. Empirical surveys consistently reflect limited public awareness of statutory privacy rights, even within urban demographics[cite: 3]. Addressing this requires sustained public education campaigns, multilingual notices, and offline grievance channels alongside digital interfaces[cite: 3].
IV. CRITICAL LEGAL ANALYSIS OF THE EMERGING FRAMEWORK
4.1 Constitutional Perspective: Privacy and Article 21
Under the constitutional standard established in Justice K.S. Puttaswamy (Retd.) v. Union of India,[2] any state interference with informational privacy under Article 21 must satisfy the three-fold test of proportionality: legality, necessity, and legitimate aim[cite: 3]. Further amplified in Anuradha Bhasin v. Union of India,[3] restrictions on digital rights must be narrowly tailored[cite: 3]. Critics argue that the broad exemptions granted to state instrumentalities under Section 17 of the DPDP Act bypass essential requirements of notice, purpose limitation, and judicial oversight via executive notification, potentially conflicting with established constitutional proportionality standards[cite: 3].
4.2 Strengths of the DPDP Framework
Despite these concerns, the DPDP Act represents a significant structural advancement[cite: 3]. It consolidates enforceable rights of access, correction, erasure, and grievance redressal within a single primary statute, replacing the fragmented framework of Section 43A of the IT Act, 2000[cite: 3]. By establishing statutory obligations regarding consent and breach reporting, it enhances corporate data governance[cite: 3]. Furthermore, the simplified, principle-based drafting, phased implementation timelines, and a digital-first adjudicatory Board reflect an approach intended to balance compliance with ease of doing business[cite: 3].
4.3 Key Challenges and Criticisms
Several structural and procedural criticisms persist within the emerging framework[cite: 3]:
1. Executive Exemptions: Broad government exemption powers under Section 17 raise concerns regarding state surveillance authority[cite: 3].
2. Board Independence: Members of the Data Protection Board are appointed directly by the Central Government without judicial tenure protections, raising questions about adjudicatory independence in disputes involving the State[cite: 3].
3. Appellate Jurisdiction: Channeling appeals exclusively through the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) limits specialized judicial oversight over complex privacy matters[cite: 3].
4. Cross-Border Data Flows: The adoption of a “negative list” approach—permitting international data transfers to all jurisdictions except those explicitly restricted—departs from earlier strict data localization proposals, which some argue reduces data protection safeguards[cite: 3].
5. Children’s Data Safeguards: Mandating verifiable parental consent for processing children’s data remains technically complex to operationalize without establishing intrusive age-verification systems[cite: 3].
6. Regulatory Uncertainty: The absence of tailored sector-specific regulations for healthcare and finance, combined with the full implementation date extending to May 2027, creates a prolonged period of compliance uncertainty[cite: 3].
4.4 Comparative Analysis
Compared internationally, India’s DPDP framework adopts a lighter operational compliance model than the European Union’s General Data Protection Regulation (GDPR)[cite: 3]. The GDPR enforces strict legal bases for processing, mandatory Data Protection Impact Assessments, and independent supervisory authorities like the UK’s Information Commissioner’s Office (ICO)[cite: 3]. While Singapore’s Personal Data Protection Act (PDPA) relies on a consent-plus-legitimate-interest model with escalating penalties, India’s regime concentrates rulemaking power within the Executive, enforces significant monetary penalties without criminal sanctions, and grants somewhat narrower data-subject rights than the GDPR, reflecting a policy choice geared toward fostering digital innovation[cite: 3].
4.5 Emerging Technologies and Artificial Intelligence
The DPDP Act currently lacks explicit provisions addressing automated profiling, algorithmic accountability, or automated decision-making[cite: 3]. As artificial intelligence, machine learning, facial recognition, and generative AI systems (including deepfakes) become integrated into the digital economy, future regulatory updates will likely need to incorporate algorithmic explainability standards, statutory audit requirements, and protections against synthetic media misuse[cite: 3].
V. CONCLUSION
The Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 mark a significant milestone in India’s digital governance landscape[cite: 3]. The phased implementation roadmap—with the Data Protection Board operationalized, Consent Manager provisions scheduled for November 2026, and primary substantive compliance mandates taking effect in May 2027—provides structured transition timelines for Fiduciaries[cite: 3]. However, addressing ongoing institutional concerns, including the scope of executive exemptions, the adjudicatory independence of the Board, judicial oversight mechanisms, and public digital literacy, will be critical to achieving the statute’s objectives[cite: 3]. Ensuring long-term effectiveness will require balanced administrative enforcement, clear sector-specific guidelines, and adaptive regulatory frameworks capable of addressing emerging technologies such as artificial intelligence[cite: 3].
REFERENCES
[1] Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1 (India)[cite: 3].
[2] Id. at 112[cite: 3].
[3] Anuradha Bhasin v. Union of India, (2020) 3 SCC 637 (India)[cite: 3].
[4] Internet and Mobile Association of India v. Reserve Bank of India, (2020) 10 SCC 274 (India)[cite: 3].
[5] Digital Personal Data Protection Act, No. 22 of 2023, INDIA CODE (2023)[cite: 3].
[6] Digital Personal Data Protection Rules, 2025, Gazette of India, Extraordinary, Part II, Section 3(i) (Nov. 13, 2025)[cite: 3].
[7] Information Technology Act, No. 21 of 2000, § 43A, INDIA CODE (2000)[cite: 3].
[8] Council Regulation 2016/679, General Data Protection Regulation, 2016 O.J. (L 119) 1 (EU)[cite: 3].
[9] Data Protection Act 2018, c. 12 (UK)[cite: 3].
[10] Personal Data Protection Act 2012, No. 26 of 2012 (Singapore)[cite: 3].




