National Data Governance, Data Protection Laws and Policies in India
India’s digital ecosystem operates through a legislative and policy framework designed to regulate data processing, safeguard citizen privacy, secure cyberspace, and govern non-personal data sharing across public and private sectors.
Legal and Legislative Framework for Data Protection
Digital Personal Data Protection Act
- Enacted in 2023, the Digital Personal Data Protection Act serves as the primary legislation governing the processing of digital personal data in India.
- It mandates that data fiduciaries obtain explicit, free, unconditional, and informed consent from data principals before processing personal information.
- It establishes rights for data principals to access information about their data processing, request correction or erasure, and register grievances.
- It imposes statutory financial penalties up to two thousand crore rupees for data breaches and failure to implement adequate security safeguards.
Information Technology Act and Rules
- The Information Technology Act of 2000 provides the foundational legal architecture for electronic commerce, digital signatures, and cybercrime prosecution.
- Section 43A of the Act mandates corporate entities handling sensitive personal data to implement reasonable security practices and procedures.
- The Information Technology Rules of 2021 regulate intermediaries, social media platforms, and digital news publishers, enforcing grievance redressal mechanisms.
- The Cyber Security Directions issued by the Indian Computer Emergency Response Team mandate mandatory incident reporting within six hours of detecting cyber security events.
National Data Governance and Non-Personal Data Policies
National Data Governance Framework Policy
- Formulated by the Ministry of Electronics and Information Technology to maximize the access, sharing, and utilization of non-personal and anonymized government data.
- It establishes the India Data Management Office under the Digital India Corporation to streamline data governance standards across ministries.
- It standardizes open government data platforms and establishes protocols for sharing non-personal datasets with startups and research institutions.
- It prioritizes data security, privacy standards, and sovereign control over national datasets.
CERT-In and Cyber Security Architecture
- The Indian Computer Emergency Response Team operates as the national nodal agency for responding to cybersecurity incidents and analyzing threat vectors.
- It issues vulnerability advisories, coordinates national cyber drills, and assists law enforcement agencies during critical infrastructure attacks.
- Sectoral computer emergency response teams operate across critical sectors such as power, finance, and telecommunications to ensure specialized domain defense.
Institutional Regulators and Compliance Bodies
Data Protection Board of India
- Established as an independent statutory adjudicatory body under the Digital Personal Data Protection Act of 2023.
- It monitors compliance with data protection provisions, investigates personal data breaches, and imposes statutory penalties for violations.
- It functions through a digital-by-design model, conducting hearings and inquiries through electronic workflows.
Telecom Regulatory Authority of India and sectoral bodies
- The Telecom Regulatory Authority of India formulates regulatory frameworks for data privacy, consumer consent management, and telemarketing restrictions.
- The Reserve Bank of India mandates localized data storage requirements for payment system operators to ensure financial data sovereignty.
- The Competition Commission of India examines data concentration issues and anti-competitive practices involving large technology platforms.
Comparative Overview of Data Laws and Policies
| Regulation or Policy Name | Enacting Year | Primary Regulatory Authority | Core Mandate |
| Information Technology Act | 2000 | Ministry of Electronics and Information Technology | Cybercrime prosecution and digital commerce governance |
| IT Intermediary Guidelines | 2021 | Ministry of Electronics and Information Technology | Social media compliance and grievance redressal |
| DPDP Act | 2023 | Data Protection Board of India | Personal data privacy and processing consent |
| National Data Governance Policy | 2022 | India Data Management Office | Non-personal data sharing and open government access |
- The Justice B. N. Srikrishna Committee submitted a comprehensive white paper and draft personal data protection bill in July 2018.
- The Supreme Court of India recognized the right to privacy as a fundamental right under Article 21 in the landmark K. S. Puttaswamy judgment of 2017.
- India signed the Budapest Convention on Cybercrime as an observer, enhancing international cooperation against cross-border digital offenses.
- The Personal Data Protection Bill underwent multiple revisions through a Joint Parliamentary Committee before culminating in the Digital Personal Data Protection Act of 2023.
- The Ministry of Electronics and Information Technology serves as the central administrative nodal ministry for formulation of national cyberspace and IT policies.
Originally written on
December 15, 2015
and last modified on
August 14, 2026.
Tags: Assam