Published On: August 20, 2026
Authored By: Solihah Rashid
University of Kashmir
1. Introduction
The rapid growth of India’s digital economy has fundamentally changed how personal data is managed, bringing questions about informational privacy, commercial misuse, and state surveillance to the forefront of contemporary constitutional law. This shift reached a decisive turning point with the Supreme Court’s landmark ruling in Justice K.S. Puttaswamy v. Union of India, which firmly established the right to privacy as a fundamental right under Part III of the Constitution and called for a robust statutory architecture to govern data usage.[1] While the legislature subsequently passed the Digital Personal Data Protection Act (DPDPA) in 2023, the statutory mechanism remained largely dormant, lacking the operational mechanics required for administrative enforcement.[2]
This statutory inertia ended when the Ministry of Electronics and Information Technology (MeitY) notified the complete and detailed operational Rules in November 2025.[3] By establishing systems such as Consent Managers and activating the powers of the Data Protection Board of India (DPBI), these Rules finally provide the long-awaited procedural backbone governing data collection, processing, and long-term storage.[4]
The real-world operationalisation of these Rules through 2026 has exposed significant friction between regulatory intent and practical implementation. For businesses, navigating strict compliance timelines and localised storage requirements presents serious challenges. More notably, the framework has invited fresh judicial scrutiny over its constitutional validity. Critics argue that the broad exemptions granted to state agencies create opportunities for unchecked government surveillance, thereby undermining the core principles established in the Puttaswamy judgment.[5] As a result, this period represents a pivotal chapter in India’s legal history, testing the judiciary’s ability to balance the commercial needs of a booming digital economy against the fundamental civil liberties of its citizens.
2. Legal Analysis
The notification of the Digital Personal Data Protection (DPDP) Rules in November 2025 marks a significant institutional shift, transforming India from a historically unregulated data landscape — governed by the vague “reasonable security practices” standard under Section 43A of the Information Technology Act, 2000 — into a highly prescriptive, compliance-heavy regulatory ecosystem.[6][7] This development operationalises the clarificatory principles of the DPDP Act into a functional, enforceable system that sets strict responsibility standards for data fiduciaries while establishing the DPBI as the primary adjudicatory authority.[6]
The 2025 Rules substantially reimagine user autonomy by replacing traditional, bundled, or ambiguous consent forms with granular, standalone privacy notices.[6][8] Data fiduciaries must now map every individual category of collected personal data to a distinct processing purpose, with an increasing expectation to support multiple regional languages to ensure genuine accessibility across India’s diverse demographic landscape.[6] To reduce user data fatigue under this highly detailed regime, the Rules formalise a novel digital intermediary architecture known as the Consent Manager ecosystem.[6] Regulated under mandatory technical, operational, and financial eligibility standards designed to avoid conflicts of interest, Consent Managers operate integrated, interoperable digital dashboards that allow data principals to review, grant, or withdraw consent seamlessly.
Beyond consent collection, the operational Rules impose substantial, ongoing backend responsibilities on organisations that manage data. Fiduciaries must implement clear technical safeguards — including robust encryption, tokenisation, and comprehensive access logging — while adhering to mandatory notification timelines to both the DPBI and affected data principals immediately upon detecting a personal data breach.[6][9] The framework also enforces strict lifecycle limitations on data through mandatory erasure clauses: fiduciaries are legally required to permanently delete personal information once its specific processing purpose is completed, unless retention is directly required by statutory compliance.[6] This creates targeted deletion obligations, specifically requiring commercial platforms and service entities to purge their databases following designated periods of user inactivity.
Regulatory burden increases significantly for large-scale data processors designated as Significant Data Fiduciaries (SDFs), based on the high volume or sensitive nature of the information they manage.[6] These entities face heightened administrative and operational obligations, including the statutory requirement to appoint a localised Data Protection Officer (DPO), conduct thorough annual Data Protection Impact Assessments (DPIAs), and undergo independent external compliance audits.[6] Significantly, SDFs are also required to carry out rigorous algorithmic due diligence to proactively verify that their automated processing and machine learning systems do not produce discriminatory or biased outcomes.[6][10]
Recognising the substantial infrastructural overhaul required to meet these technical, legal, and operational obligations, the DPDP Rules, 2025 provide a structured, phased implementation timeline.[6] This transition window gives domestic and international enterprises the time needed to overhaul legacy software architectures, re-engineer user interfaces, and systematically align their organisational data workflows with India’s newly established standards of digital transparency and state-enforced accountability.
3. Emerging Constitutional Challenges
While the 2025 Rules clarify business obligations, they face several legal challenges concerning fundamental rights under the Indian Constitution.
A. The Proportionality Test and State Exemptions
The first constitutional weakness lies in the state’s broad power to exempt its own agencies from the core requirements of the Act, a power amplified by the procedural provisions in the Rules.[11] In Justice K.S. Puttaswamy v. Union of India (2017), the Supreme Court recognised the right to informational privacy as a fundamental right under Article 21, establishing a rigorous three-pronged proportionality test for state infringement: legality, a legitimate goal, and a rational nexus ensuring proportional means.[1]
Critics argue that the framework fails this proportionality standard by placing only narrow constraints on government surveillance. State data collection for law enforcement or welfare distribution evades the strict consent, itemisation, and erasure mandates imposed on private entities. By insulating state data processing from independent oversight by the DPBI, the structure risks enabling unverified state surveillance without the safeguard of traditional judicial warrants.
B. Free Speech and Algorithmic Arbitrariness
The requirement for SDFs to ensure algorithmic transparency and prevent “user harm” risks conflicting with Article 19(1)(a) (Freedom of Speech and Expression).[11] Because “harm” remains open to interpretation, intermediaries may over-censor content to avoid the severe financial penalties prescribed under the Act (up to ₹250 crore).[6][8] Following the doctrine laid down in Shreya Singhal v. Union of India (2015), vague and overbroad statutory provisions that chill legitimate speech are unconstitutional.[12] Vague rules on automated profiling risk becoming, in effect, indirect state tools for content moderation.
C. Executive Overreach and Institutional Independence
The Data Protection Board of India (DPBI) functions as the central adjudicatory body for data breaches and non-compliance.[6] Even so, its institutional architecture raises separation-of-powers concerns.[11] The central government controls the appointment, terms, and regulatory resources allocated to the DPBI.[6][11] Under settled Indian constitutional jurisprudence — notably the Madras Bar Association line of cases — tribunals exercising judicial functions must maintain institutional independence from the executive.[13] Because the state is India’s largest data collector, permitting the executive to retain significant control over the body that adjudicates state infractions creates an inherent conflict of interest within the framework.
4. Supporting Authority
The operational Rules must be read together with established statutes and precedents. Section 43A of the Information Technology Act, 2000, which served as an early framework for “reasonable security practices,” has been superseded by prescriptive standards such as mandatory encryption and masking, alongside rapid reporting requirements under the DPDP Rules.[7] The K.S. Puttaswamy (2017) judgment establishes the right to privacy under Article 21, requiring that any state processing of data strictly follow the three-fold proportionality standard.[1] Furthermore, the Anuradha Bhasin (2020) ruling mandated proactive disclosure and transparency in state actions.[14] In the context of the 2025 Rules, this precedent challenges the state’s blanket exemptions from publishing data-processing registers.
Read alongside these legal milestones, it becomes clear that the DPDP framework cannot operate in isolation; it must continuously reconcile private corporate obligations with existing constitutional limits on state surveillance and executive power. These foundational authorities jointly underscore that while data security standards are modernising, state actions remain — and must remain — bound by transparency and fundamental rights.
5. Conclusion
The Digital Personal Data Protection (DPDP) Rules mark a turning point in India’s legal landscape, transforming the DPDP Act into an actionable, enforceable blueprint for digital governance. By establishing procedural transparency, the Rules place compliance accountability squarely on data fiduciaries. Even so, the framework’s asymmetric structure creates a distinct constitutional unevenness: it imposes strict, granular procedural rules on the private sector while granting broad, sweeping exemptions to state agencies.
For India’s emerging data protection regime to withstand impending constitutional challenges before the Supreme Court, its operational application must be aligned with the foundational privacy principles established in the Puttaswamy judgment. The true impact of this framework will depend on addressing significant concerns regarding government exemptions, ensuring regulatory independence, and building robust enforcement capacity. A secure data regime requires a uniform standard of accountability that applies equally to commercial entities and the state alike.
The period from 2025 to 2026 represents an early stage in India’s data protection journey. The future of digital rights will rely on striking a balance between individual privacy, corporate transparency, and legitimate state interests. As technologies such as AI and big data analytics advance rapidly, the legal framework must continuously evolve to address emerging systemic challenges. Ultimately, how India navigates these structural asymmetries and legal obstacles today will significantly shape the trajectory of constitutional rights and democratic governance in the years to come.
References
[1] Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1.
[2] Digital Personal Data Protection Act, No. 22 of 2023, Gazette of India (Extraordinary, Part II, Section 1, Aug. 11, 2023).
[3] DLA Piper, Navigating the Operational Switch: India Notifies Finalized Guidelines Under the DPDP Act, DLA Piper Global Data Protection Insights (2025).
[4] Nagashree, S., Activating the Administrative Spine: Consent Managers and the DPBI Under the 2025 Guidelines, 18(1) Journal of Indian Corporate Law 45–61 (2026).
[5] Maurya, R., & Saxena, A., Shifting Boundaries of State Surveillance: A Constitutional Critique of Exemptions Under the DPDP Framework, 14(2) Indian Constitutional Law Review 145–168 (2025).
[6] Christopher, J., Ahmed, S., & Yadav, V., From Bundle to Baseline: The Operationalized Compliance Framework of India’s Data Protection Board, 9(3) Technology and Law Policy Journal 89–112 (2025).
[7] Information Technology Act, No. 21 of 2000, § 43A.
[8] Yadav, V., Granular Consent and Demographic Realities Under the DPDP Rules (LexIndia Publications, 2026).
[9] Jaggi, S., Data Breach Response Mechanisms Under the Newly Notified DPDP Rules, 11(4) International Data Privacy Law Review 202–215 (2025).
[10] Chail, A., India’s DPDP Act and Draft DPDP Rules: Operational Considerations for Algorithmic Due Diligence, 23(1) Journal of Data Rights and Governance 12–28 (2025).
[11] Law, S., Executive Dominance or Regulatory Autonomy? Structuring the Data Protection Board of India, 4(2) Supreme Court Journal (Opinion) 77–92 (2025).
[12] Shreya Singhal v. Union of India, (2015) 5 SCC 1.
[13] Madras Bar Association v. Union of India, (2014) 10 SCC 1.
[14] Anuradha Bhasin v. Union of India, (2020) 3 SCC 637.




