Indian Laws and Policies on Data Protection
Introduction
India’s data protection framework combines privacy rights with digital governance needs. It covers how personal data is collected, processed, stored and shared, while also fixing responsibilities for private entities and public institutions.
The legal architecture rests on the Digital Personal Data Protection Act, provisions of the Information Technology Act, constitutional privacy jurisprudence, and sector-specific rules issued by regulators such as the RBI and SEBI.
Digital Personal Data Protection Act
- Comprehensive framework: The Act provides a legal basis for processing digital personal data within India.
- Extraterritorial reach: It also applies to processing outside India if the data relates to offering goods or services to individuals in India.
- Key parties: A data principal is the individual to whom the personal data relates, while a data fiduciary determines the purpose and means of processing.
- Consent requirement: Processing generally requires explicit, free, unconditional and unambiguous consent, either directly from the individual or through a registered consent manager.
- Purpose limitation: Data must be used only for the stated and lawful purpose for which consent was taken.
Information Technology Act Provisions
- Section 43A: Corporate entities handling sensitive personal data must implement reasonable security practices and procedures.
- Civil liability: If failure to maintain adequate security causes wrongful loss or wrongful gain, the organisation can be liable for damages and penalties.
- Section 72A: This provision prescribes criminal punishment for intentional disclosure of personal information obtained under a lawful contract without consent.
- Penalty under Section 72A: Imprisonment up to three years, or a fine up to five lakh rupees, or both.
Right to Privacy and Constitutional Basis
- Fundamental right: In the Puttaswamy judgment, a nine-judge bench of the Supreme Court unanimously recognised the right to privacy as a fundamental right.
- Article 21: Privacy is protected as an intrinsic part of the right to life and personal liberty.
- Judicial test: Any intrusion into privacy must satisfy the requirements of legality, proportionality and a legitimate state aim.
Exam fact: The Puttaswamy judgment is the constitutional foundation of privacy protection in India.
Rights and Duties of Data Principals
- Right to information: Individuals can seek a summary of personal data processed and the identities of entities with whom it has been shared.
- Right to correction: Data principals may ask for correction of inaccurate data and updating of incomplete records.
- Right to erasure: They can seek deletion once the purpose of processing has been fulfilled, subject to legal requirements.
- Nomination provision: An individual may nominate a representative to exercise rights in the event of death or incapacity.
- Statutory duties: Data principals must not file false grievances, impersonate others or suppress material information.
Obligations of Data Fiduciaries
- Privacy notice: Fiduciaries must issue clear and itemised notices explaining what data is collected and why it is processed.
- Security safeguards: Technical and organisational measures are mandatory to prevent personal data breaches.
- Breach disclosure: Data breaches must be reported to the regulatory board and affected individuals without delay.
- Children’s data: Processing data relating to children requires verifiable parental consent.
- Restrictions for minors: Behavioural tracking, targeted advertising and detrimental profiling of children are prohibited.
- Shared responsibility: Compliance with lawful processing and security norms remains central to fiduciary accountability.
Significant Data Fiduciaries and Enforcement
- Classification: The central government may notify certain entities as Significant Data Fiduciaries based on the volume and sensitivity of data processed.
- Additional compliance: Such entities must appoint an India-based data protection officer.
- Impact assessment: Periodic data protection impact assessments are required.
- Independent audit: Significant Data Fiduciaries must also undertake independent data audits.
- Adjudicatory body: The Data Protection Board of India assesses non-compliance and imposes penalties.
- Appeal forum: Appeals against Board orders lie before the Telecom Disputes Settlement and Appellate Tribunal.
| Violation category | Statutory basis | Prescribed consequence |
| Failure to prevent data breach | Digital Personal Data Protection Act | Financial penalty up to two hundred fifty crore rupees |
| Non-compliance with children’s data rules | Digital Personal Data Protection Act | Financial penalty up to two hundred crore rupees |
| Breach of fiduciary obligations | Digital Personal Data Protection Act | Financial penalty up to fifty crore rupees |
| Breach of user duties | Digital Personal Data Protection Act | Financial penalty up to ten thousand rupees |
| Unauthorized disclosure under contract | Section 72A, Information Technology Act | Imprisonment up to three years or fine up to five lakh rupees |
Sectoral and Special Regimes
- RBI and SEBI: Sectoral regulators such as the Reserve Bank of India and the Securities and Exchange Board of India enforce specialised data localisation and storage norms for financial transactions.
- Aadhaar Act: It regulates the collection, authentication and vault storage of biometric identifiers.
- Targeted delivery: The Aadhaar framework is used for the targeted delivery of subsidies and public services.
Key Prelims Takeaways
- DPDP Act: The main statute governing digital personal data protection in India.
- Extraterritorial application: It can cover processing outside India if goods or services are offered to individuals in India.
- Consent manager: Consent may be obtained through a registered consent manager.
- Privacy right: Recognised as a fundamental right in the Puttaswamy judgment under Article 21.
- Data Protection Board of India: The statutory body that adjudicates violations and imposes penalties.
- Children’s data: Verifiable parental consent is required, with restrictions on tracking and targeted advertising.
- Section 72A: Covers intentional disclosure of personal information obtained under a lawful contract.
Originally written on
June 5, 2026
and last modified on
September 6, 2026.