For most of India's digital history, data protection was governed by a single, thin provision — Section 43A of the Information Technology Act, 2000, and the rules made under it — designed for an internet that barely resembled today's. That gap has now been substantially closed, at least on paper, by the Digital Personal Data Protection Act, 2023 (DPDPA).
Why a Dedicated Law Became Necessary
The constitutional foundation was laid in *Justice K.S. Puttaswamy v. Union of India* (2017), where the Supreme Court recognised privacy as a fundamental right under Article 21. That judgment did not itself create a data protection framework, but it made clear that any government data-collection scheme, and by extension any private data-processing activity, had to satisfy a test of legality, necessity, and proportionality. Legislation followed years of committee reports and draft bills, eventually converging into the DPDPA.
What the DPDPA Actually Does
The Act applies to the processing of digital personal data within India, and to processing outside India if it relates to offering goods or services to individuals in India. Its core structure will feel familiar to anyone who has studied the GDPR, though the mechanics differ in important ways:
**Consent as the primary basis.** Processing personal data generally requires informed, specific consent, with defined exceptions ("legitimate uses") such as for medical emergencies, employment purposes, or compliance with law.
**Data Fiduciaries and Data Principals.** The entity that decides the purpose and means of processing (the "Data Fiduciary") owes obligations to the individual (the "Data Principal") — the DPDPA's terminology substitutes for the GDPR's "controller" and "data subject."
**Significant Data Fiduciaries.** Entities crossing certain thresholds of data volume or sensitivity can be designated as Significant Data Fiduciaries, attracting heavier obligations such as data protection impact assessments and independent audits.
**Children's data.** Processing of a child's data requires verifiable parental consent, and targeted advertising directed at children is restricted.
**Cross-border transfer.** Unlike some earlier drafts that proposed strict data localisation, the DPDPA takes a blacklist approach — transfers are permitted to any country except those the government specifically restricts.
**The Data Protection Board.** Enforcement runs through a dedicated Board with the power to impose significant financial penalties for non-compliance, rather than through the ordinary courts in the first instance.
Where Practice Meets the Statute
For corporate counsel and in-house teams, the practical work has shifted from "should we comply" to "how do we operationalise compliance": rewriting consent notices in clear language, building consent-withdrawal mechanisms, mapping data flows to identify cross-border transfers, and preparing breach-notification protocols. Much of this mirrors the compliance build-out that followed the GDPR in Europe, but Indian companies are working against a compressed timeline and a still-developing body of subordinate rules and Board precedent.
Open Questions Worth Tracking
A few areas remain genuinely unsettled and are worth following closely:
1. **The "legitimate uses" exceptions** are broadly worded, and how narrowly or expansively the Data Protection Board interprets them will shape how much real friction consent requirements create for ordinary business. 2. **Government processing carve-outs.** The Act permits broad exemptions for processing by government instrumentalities in the interest of sovereignty, security, and public order — an area likely to draw the same proportionality scrutiny that Puttaswamy applied to Aadhaar. 3. **Interplay with sector-specific regulation.** Financial data (RBI), health data, and telecom data already sit under sector regulators with their own rules; reconciling those regimes with the DPDPA's general framework is an unresolved drafting and interpretive challenge.
A Note for Students
Data privacy law now sits at the intersection of constitutional law, contract law, and regulatory compliance — making it one of the more interdisciplinary areas to specialise in early. Reading the DPDPA alongside Puttaswamy, rather than as a standalone statute, is the fastest way to understand not just what the law requires, but why it is drafted the way it is.

