India’s Data Governance and Protection Policies
India’s digital governance framework combines privacy law, cyber security regulation and data-sharing policy. For Prelims, the focus is on the key Acts, institutions, consent norms, enforcement bodies and the distinction between personal and non-personal data.
Legal and legislative framework
The core law governing digital personal data is the Digital Personal Data Protection Act, 2023. It applies to the processing of digital personal data and requires explicit, free, unconditional and informed consent from data principals before processing personal information.
- Rights of data principals: access information on data processing, seek correction or erasure, and file grievances.
- Obligations of data fiduciaries: ensure lawful processing and implement adequate security safeguards.
- Penalty framework: statutory financial penalties can go up to rupees two thousand crore for data breaches and related non-compliance.
The Information Technology Act, 2000 provides the foundational legal architecture for electronic commerce, digital signatures and cybercrime prosecution. It remains central to India’s wider digital legal system.
- Section 43A: mandates corporate entities handling sensitive personal data to adopt reasonable security practices and procedures.
- IT Rules, 2021: regulate intermediaries, social media platforms and digital news publishers, including grievance redressal requirements.
- CERT-In Directions: require mandatory reporting of cyber security incidents within six hours of detection.
Data governance and non-personal data policy
India’s data governance approach also covers non-personal and anonymized government data. The National Data Governance Framework Policy was formulated by the Ministry of Electronics and Information Technology to improve access, sharing and use of such data.
- Objective: maximize the utility of non-personal and anonymized government datasets.
- Institutional mechanism: it establishes the India Data Management Office under the Digital India Corporation.
- Platform standardization: it supports open government data platforms and common sharing protocols.
- Access for innovation: non-personal datasets can be shared with startups and research institutions.
- Policy emphasis: data security, privacy standards and sovereign control over national datasets.
This framework is important for understanding the growing separation between rules for personal data and policy support for responsible use of non-personal data.
Cyber security architecture and CERT-In
The Indian Computer Emergency Response Team (CERT-In) is the national nodal agency for responding to cyber security incidents and analysing threat vectors. It plays a key role in incident response and coordination across the digital ecosystem.
- Functions: issues vulnerability advisories and coordinates national cyber drills.
- Law enforcement support: assists agencies during attacks on critical infrastructure.
- Sectoral response: sector-specific CERTs operate in areas such as power, finance and telecommunications.
Prelims note: CERT-In incident reporting is mandatory within six hours of detecting a cyber security event.
Institutional regulators and compliance bodies
Data protection in India is enforced through a set of specialised regulators and sectoral bodies. These institutions address breaches, compliance, privacy concerns and data concentration issues.
- Data Protection Board of India: an independent statutory adjudicatory body under the DPDP Act, 2023.
- Functions of the Board: monitors compliance, investigates personal data breaches and imposes penalties for violations.
- Digital-by-design model: hearings and inquiries are conducted through electronic workflows.
- Telecom Regulatory Authority of India (TRAI): frames regulatory norms for data privacy, consent management and telemarketing restrictions.
- Reserve Bank of India (RBI): mandates localized data storage requirements for payment system operators.
- Competition Commission of India (CCI): examines data concentration and anti-competitive practices involving large technology platforms.
Important milestones and legal background
India’s data protection journey has evolved through constitutional, legislative and committee-based developments. Some of the most important milestones are:
- K. S. Puttaswamy judgment, 2017: the Supreme Court recognised the right to privacy as a fundamental right under Article 21.
- Justice B. N. Srikrishna Committee: submitted a white paper and draft personal data protection bill in July 2018.
- Personal Data Protection Bill: underwent multiple revisions through a Joint Parliamentary Committee before becoming the DPDP Act, 2023.
- Budapest Convention on Cybercrime: India signed it as an observer, supporting cross-border cybercrime cooperation.
- MeitY: the Ministry of Electronics and Information Technology is the central nodal ministry for national cyberspace and IT policy.
| Regulation or Policy | Year | Primary Authority | Core Mandate |
| Information Technology Act | 2000 | Ministry of Electronics and Information Technology | Cybercrime prosecution and digital commerce governance |
| IT Intermediary Guidelines | 2021 | Ministry of Electronics and Information Technology | Social media compliance and grievance redressal |
| DPDP Act | 2023 | Data Protection Board of India | Personal data privacy and processing consent |
| National Data Governance Policy | 2022 | India Data Management Office | Non-personal data sharing and open government access |
Key Prelims Takeaways
- DPDP Act, 2023 is the principal law for digital personal data protection in India.
- Consent under the DPDP framework must be explicit, free, unconditional and informed.
- Data principals can seek access, correction, erasure and grievance redressal.
- Section 43A of the IT Act deals with reasonable security practices for sensitive personal data.
- IT Rules, 2021 focus on intermediaries, social media and digital news compliance.
- CERT-In is the national nodal agency for cyber incident response, with a six-hour reporting norm.
- National Data Governance Framework Policy supports non-personal and anonymized government data sharing.