Published On: July 21st 2026
Authored By: Tanzila Nisar Shaikh
AKK New Law Academy,
Savitribai Phule Pune University
Abstract
Data and information have always been sensitive and critical matters, as they shape the happenings and non-happenings of various events in a society as a whole, or for an individual alone. In this age, where digital means are evolving rapidly, the scope of data being created, shared, and used has widened significantly, and this has also increased the possibility of its misuse. Data is a matter of a person’s privacy and personal life, where sharing it should be a consented choice, and its protection is of national importance.
I. Introduction
With the landmark judgment of Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1,[1] we can evaluate the importance of privacy, as it was recognised as a “fundamental right.” Prior to the introduction of a dedicated data protection law, matters relating to personal data were regulated through the Information Technology Act, 2000 and various judicial decisions. However, a more comprehensive framework came into existence with the enactment of the Digital Personal Data Protection Act, 2023.[2] This Act identifies the key actors involved, their roles, rights, and obligations; the extent of how and what data can be collected, subject to proper prior notice; the penalties for breaches; and the establishment of the Data Protection Board of India.
In January 2025, the Draft Digital Personal Data Protection Rules were issued for public review and feedback. Subsequently, the DPDP Rules, 2025 were notified and operationalised. However, according to their commencement provisions, certain rules are to come into force one year later, while others are to come into force after eighteen months. Therefore, the complete implementation of the framework is expected to take place in phases.
The DPDP Rules, 2025 are significant because they provide practical implementation to the DPDP Act, 2023. While the Act lays down the legal framework, the Rules explain how such provisions are to be implemented and complied with by the concerned entities. They provide greater clarity regarding consent, data retention, grievance redressal, obligations of Data Fiduciaries, and enforcement mechanisms. In this manner, the Rules attempt to convert the concept of privacy from merely a legal right into an enforceable framework.
This article aims to legally analyse the DPDP Rules, 2025, their significance, the framework they establish, and the challenges that may arise in their implementation.
II. Legal Analysis
The DPDP Rules strengthen the DPDP Act by providing a proper framework for implementation. The Rules include sections, sub-sections, and schedules that can be understood through an overview of their key provisions.
The Rules begin with provisions relating to the short title, commencement, and definitions. They are followed by provisions explaining notice requirements, the consent framework and its management, verification of and access to the personal data of children, and exemptions from certain obligations. The Rules provide various obligations of Data Fiduciaries, including their duties, limitations, extent of liability, and their role in safeguarding the data of Data Principals. They also impose a duty of intimation in cases of personal data breaches.
The Rules further provide for the retention of records and information even after the completion of the purpose for which data was collected. They elaborate upon the consent and management of personal data of persons with disabilities and the verification of their lawful guardians. Additional obligations are prescribed for Significant Data Fiduciaries, given the larger volume and sensitivity of data they process.
The Rules also recognise various rights of the Data Principal and establish mechanisms for grievance redressal. Such provisions are intended to give individuals greater control over their personal data and a platform to seek remedies in case of misuse or violations. The Rules further address matters relating to the international transfer of data and the conditions under which such transfers may take place.
Another important aspect of the Rules is the exemption provided for personal data processed for lawful research, statistical, or archival purposes. Such exemptions recognise the need to balance privacy protection with legitimate public and academic interests; however, they must still operate within the broader objective of preventing misuse of personal data.
The Rules also contain provisions regarding the appointment of the Chairperson and Members of the Data Protection Board of India, including their salaries, allowances, terms, and conditions of service. The Board is designed to function largely through digital means, reflecting the technological nature of the subject matter. The Rules also regulate the meetings and functioning of the Board and provide for the appointment of officers and employees. In case a person is aggrieved by a decision of the Board, an appeal may be preferred before the designated appellate authority upon payment of the prescribed fee; the appellate body is likewise expected to function digitally and to maintain its own procedures for regulation and functioning.
Lastly, the Rules empower the Central Government to require a Data Fiduciary or intermediary to furnish information where matters concerning the sovereignty, integrity, or security of India are involved. Such provisions seek to balance privacy concerns with larger national interests.
The significance of the DPDP Rules lies in the fact that they move beyond merely recognising privacy rights and attempt to provide a practical mechanism for their enforcement. Rights without implementation often remain theoretical. Through the Rules, India has attempted to create a structured system where rights, obligations, liabilities, and remedies are clearly identified.
The Rules also bring greater accountability upon entities that collect and process personal data. Data Fiduciaries are now expected to maintain reasonable security safeguards, report breaches, and ensure that personal data is handled responsibly. This becomes particularly important in a digital economy where large amounts of information are collected daily by businesses, social media platforms, financial institutions, and government agencies.
III. Challenges
Although the Rules have been carefully and elaborately formulated with the aim of ensuring data protection, several concerns continue to exist.
1. The Limits of Consent: One major concern relates to the concept of consent itself. The framework is largely consent-based and assumes that individuals are making informed decisions while sharing their data. In reality, however, many users accept privacy policies and terms and conditions without reading or understanding them, so consent may sometimes become more formal than informed.
2. Digital Literacy: A large section of the population may not possess adequate knowledge regarding how personal data is collected, processed, shared, or stored. Even where rights are available, individuals may not know how to exercise them effectively. Legal protection alone may therefore be insufficient unless accompanied by awareness and education.
3. Scope of Exemptions: The exemptions provided under the Rules may also raise concerns. While exemptions for research, archival, and certain governmental purposes may be justified, excessive or broad application of such exemptions may weaken privacy protections. The challenge lies in ensuring that these exemptions remain proportionate and are not misused.
4. Compliance Burden: The Rules broaden the scope of compliance obligations. While this promotes accountability, it may also create administrative and financial burdens for businesses and smaller entities, given the substantial costs associated with cybersecurity measures, data governance systems, and compliance requirements.
5. Enforcement: The success of any legislation ultimately depends upon its implementation. The effectiveness of the Data Protection Board, the consistency of enforcement actions, and the efficiency of grievance redressal mechanisms will play a crucial role in determining whether the objectives of the framework are achieved.
6. Persistent Cybercrime Risk: Data breaches, identity theft, phishing attacks, online fraud, and unauthorised access to information remain common. Legal regulation alone cannot completely eliminate privacy risks; effective technological safeguards, public awareness, and responsible digital behaviour are equally important.
IV. Supporting Authority
The constitutional basis of data protection in India can be traced to Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1,[1] where the Supreme Court recognised privacy as a fundamental right under Article 21 of the Constitution. The judgment highlighted the importance of informational privacy and laid the foundation for future developments relating to personal data protection.
Further guidance can be found in K.S. Puttaswamy (Aadhaar-5J.) v. Union of India, (2019) 1 SCC 1,[3] where the Court discussed issues relating to data collection, proportionality, and the safeguards necessary for the protection of individual privacy.
The primary statutory authority governing this field is the Digital Personal Data Protection Act, 2023,[2] which establishes the legal framework for the processing of digital personal data. The Act identifies the rights of Data Principals, obligations of Data Fiduciaries, penalties for non-compliance, and the establishment of the Data Protection Board of India.
The Digital Personal Data Protection Rules, 2025[4] supplement the Act by providing the procedural and operational mechanisms necessary for implementation. Together, the Act and the Rules represent India’s most comprehensive attempt to regulate personal data protection in the digital era.
The Information Technology Act, 2000[5] also continues to remain relevant in matters concerning electronic records, cybersecurity, and digital governance. Although the DPDP framework specifically addresses personal data protection, the IT Act continues to operate alongside it in matters involving cyber offences and electronic transactions.
V. Conclusion
The DPDP Rules, 2025 mark an important step in strengthening India’s data protection framework. They provide greater clarity regarding consent, obligations of Data Fiduciaries, grievance redressal mechanisms, data retention, and enforcement procedures. Through these Rules, the framework established by the DPDP Act, 2023 moves closer towards practical implementation.
At the same time, several challenges remain. Issues relating to digital literacy, cyber frauds, compliance burdens, exemptions, and enforcement continue to raise concerns regarding the effectiveness of the framework. The success of the Rules will depend not only upon their existence but also upon their proper implementation and enforcement.
Yet, privacy may still remain a myth due to the lack of proper digital literacy, the increasing number of cyber scams, and the fact that many individuals accept terms and conditions without actually analysing or reading them. Therefore, while the DPDP Rules, 2025 represent a significant legal development in India’s data protection regime, their long-term success will depend upon creating greater awareness, stronger compliance, and meaningful protection of privacy in practice.
References
[1] Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1.
[2] Digital Personal Data Protection Act, 2023, No. 22, Acts of Parliament, 2023 (India).
[3] K.S. Puttaswamy (Aadhaar-5J.) v. Union of India, (2019) 1 SCC 1.
[4] Digital Personal Data Protection Rules, 2025 (Ministry of Electronics & Information Technology, India).
[5] Information Technology Act, 2000, No. 21, Acts of Parliament, 2000 (India).




