BREAKING
Revolutionary climate technology breakthrough announced • Championship finals draw record 150M+ viewers • Global markets surge following policy changes • New discovery in quantum computing promises faster processors
Business

India Notifies Key Provisions of Data Protection Law, Begins Major Overhaul of Digital Privacy Framework

The Union government on Friday activated significant portions of the Digital Personal Data Protection (DPDP) Act, 2023, marking a crucial moment in India’s long-delayed effort...

Nov 14
4 min read
India Notifies Key Provisions of Data Protection Law, Begins Major Overhaul of Digital Privacy Framework

The Union government on Friday activated significant portions of the Digital Personal Data Protection (DPDP) Act, 2023, marking a crucial moment in India’s long-delayed effort to build a modern privacy and data governance regime. The move brings the country a step closer to fulfilling the Supreme Court’s landmark K.S. Puttaswamy (2017) judgement, which recognised privacy as a fundamental right and directed the creation of comprehensive data protection legislation.

Alongside the Act’s partial rollout, the government formally notified the DPDP Rules, 2025, ending months of consultations on how the law will be implemented.


What the Newly Enforced Provisions Mean

The DPDP Act, passed in August 2023, establishes clear obligations for companies that collect and process digital data belonging to Indian citizens. These entities—legally termed “data fiduciaries”—must ensure security, limit misuse, and follow stringent consent norms.

However, the Act also includes broad exemptions for the government and its agencies, allowing them to process personal data for reasons such as national security, public order, and law enforcement. These carve-outs have been a point of continuous debate among privacy advocates.

One particularly controversial change takes effect immediately: amendments that dilute the Right to Information (RTI) Act, 2005. Government departments are no longer required to disclose personal information even when a strong public interest argument exists. Transparency groups argue that this weakens India’s premier accountability law by shielding officials from scrutiny.


Compliance Timeline: Companies Get Staggered Deadlines

While some provisions take effect immediately, the government has given businesses a phased schedule to meet full compliance:

By November 2026

  • Companies must publish contact information of their Designated Data Protection Officer (DPO).

  • The Consent Manager Framework goes live, enabling users (“data principals”) to correct or delete their data through trusted intermediaries.

By May 2027

  • Large technology platforms and major data processors, classified as “significant data fiduciaries,” must comply with the Act in its entirety.

  • These firms may face additional obligations, such as independent audits, risk assessments, and increased reporting requirements.

This extended timeline aims to prevent major disruptions while allowing companies—particularly smaller firms—to update their systems and practices.


Data Protection Board of India: Structure Announced

A separate notification issued on Friday established the structure of the Data Protection Board of India (DPBI), the regulatory body responsible for evaluating complaints and imposing penalties for violations.

  • The DPBI will consist of four members.

  • Members will be appointed by the Ministry of Electronics and Information Technology (MeitY).

  • The board will have quasi-judicial powers to hold inquiries and direct penalties for data breaches or misuse.

However, no appointments have been announced yet, raising questions about when enforcement will begin in practice.


A Law Years in the Making

The road to India’s data protection law has been long and contentious:

  • 2018 Draft: Proposed stringent provisions such as mandatory data localisation, requiring companies to store copies of personal data within India. Many global tech firms strongly opposed these requirements.

  • 2021 Draft: Introduced broader exemptions for the government, drawing criticism from civil society groups.

  • 2023 Act: Removed several controversial clauses from earlier versions, including strict localisation rules, and adopted a more business-friendly approach.

The 2023 version has received a more measured response from Indian and global tech companies, though concerns about oversight, government access, and weakened transparency remain.


Why This Matters

India is home to the world’s largest population of internet users, generating enormous volumes of personal data daily. Yet, until now, the country lacked a modern framework aligned with global norms such as Europe’s GDPR.

The DPDP Act:

  • Sets the foundation for a rights-based privacy framework.

  • Raises the bar on data accountability for private firms.

  • Creates a central enforcement authority for breach investigations.

  • Aligns India with the global push for stronger privacy protections.

However, critics warn that the wide exemptions for government agencies could undermine the balance between individual rights and state power.