E-Governance and Data Protection Laws in India

E-Governance and Data Protection Laws in India

India’s e-governance ecosystem is built on digital public infrastructure, online service delivery and platform-based governance. At the same time, the legal framework is evolving to protect personal data and regulate online intermediaries in a more structured manner.

Constitutional Foundation and Legislative Background

In Justice K. S. Puttaswamy (Retd.) v. Union of India (2017), a nine-judge bench of the Supreme Court held that the right to privacy is a fundamental right under Article 21 of the Constitution. This judgment created the constitutional basis for a dedicated data protection regime in India.

Before a comprehensive law was enacted, digital personal data regulation mainly depended on Section 43A and Section 72A of the Information Technology (IT) Act, 2000. These provisions were not backed by a central data protection authority, leaving a regulatory gap that was later addressed through specialised rules and the principal data protection law.

The DPDP Act, 2023 and DPDP Rules, 2025

The Digital Personal Data Protection (DPDP) Act, 2023 was enacted on August 11, 2023, to regulate the processing of digital personal data. To operationalise the Act, the Ministry of Electronics and Information Technology (MeitY) notified the DPDP Rules, 2025, on November 13, 2025.

  • Phased implementation: The rules have been brought into force gradually to give organisations time to adapt their systems.
  • Data Protection Board: The provisions relating to the establishment and operational procedures of the Data Protection Board of India (DPBI) took effect immediately on November 13, 2025.
  • Consent Managers: Rule 4, which provides the administrative framework for Consent Managers, takes effect on November 14, 2026.
  • Substantive compliance: Rules 3, 5 to 16, 22 and 23 will take effect on May 14, 2027.
  • Board’s status: As of September 2026, the DPBI remained unstaffed, while MeitY began recruitment for the Chairperson and four Members through a vacancy circular issued on May 6, 2026.

Data Protection Board of India and Appeals

The DPBI is established under Section 18 of the DPDP Act as an independent adjudicating body. It is responsible for examining non-compliance and directing penalties where required.

The Telecom Disputes Settlement and Appellate Tribunal (TDSAT) hears appeals against decisions of the Data Protection Board of India.

The creation of the DPBI marks a shift from general IT law provisions to a specialised framework for data protection enforcement and grievance handling.

Regulating Synthetically Generated Information and Intermediaries

With the rise of artificial intelligence and deepfakes, MeitY notified the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026, which took effect on February 20, 2026. These rules provide a statutory framework for regulating Synthetically Generated Information (SGI).

  • Content takedown: Intermediaries must remove illegal digital content ordered by a court or government authority within 3 hours.
  • Deepfake removal: Non-consensual deepfakes and sexually explicit content must be removed within 2 hours of receiving a complaint.
  • Labeling requirement: Intermediaries must prominently label AI-generated imagery to disclose its synthetic origin.
  • Safe Harbour risk: Non-compliance may lead to the loss of Safe Harbour protection under Section 79 of the IT Act, 2000.

Core E-Governance Infrastructure and Platforms

India’s digital governance model depends on large-scale platforms and delivery networks that connect citizens to public services. These platforms have become central to service access, document storage and last-mile delivery.

Platform or Infrastructure Administrative Authority User Base and Reach Metrics
UMANG Platform National e-Governance Division (NeGD) 2,575 digital government services; 11.66 crore registered users (as of July 31, 2026)
DigiLocker National e-Governance Division (NeGD) Over 72.43 crore registered users (as of July 31, 2026)
Common Service Centres (CSCs) CSC e-Governance Services India Limited 4,07,122 functional CSCs at the Gram Panchayat level (as of June 30, 2026)

Key Prelims Takeaways

  • Right to privacy: Recognised as a fundamental right under Article 21 in the 2017 Puttaswamy judgment.
  • Previous legal basis: Section 43A and Section 72A of the IT Act, 2000 were the main provisions governing digital personal data before the DPDP law.
  • DPDP Act: Enacted on August 11, 2023, to regulate processing of digital personal data.
  • DPDP Rules, 2025: Notified by MeitY on November 13, 2025, with phased implementation.
  • DPBI: Established under Section 18 of the DPDP Act as the adjudicating authority for non-compliance.
  • Appeals: Decisions of the DPBI are appealable before the TDSAT.
  • SGI rules: The IT Amendment Rules, 2026 took effect on February 20, 2026 to regulate synthetically generated information.
  • Takedown timelines: 3 hours for court/government orders and 2 hours for non-consensual deepfakes or sexually explicit content.
  • Safe Harbour: Section 79 of the IT Act, 2000 protects compliant intermediaries from liability for third-party content.
  • UMANG: NeGD’s platform offering 2,575 services to 11.66 crore users as of July 31, 2026.
  • DigiLocker: Crosses 72.43 crore registered users as of July 31, 2026.
  • CSCs: 4,07,122 functional centres operating at the Gram Panchayat level as of June 30, 2026.
Originally written on April 8, 2026 and last modified on September 5, 2026.

Leave a Reply

Your email address will not be published. Required fields are marked *