Data Protection and Privacy Laws in India
India’s privacy framework now rests on a mix of constitutional protection, sectoral cyber provisions, and a dedicated personal data law. For Prelims revision, the focus should be on the key legal terms, rights of data principals, duties of data fiduciaries, and the main enforcement institutions.
Digital Personal Data Protection Act: Core Structure
The Digital Personal Data Protection Act is the principal law regulating the processing of personal data across public and private sectors. It lays down the framework for consent, lawful processing, data security, and grievance redressal.
- Data Principal: The individual to whom the personal data relates.
- Data Fiduciary: Any entity that independently or jointly determines the purpose and means of processing personal data.
- Data Processor: An intermediary or external agency that processes personal data on behalf of a data fiduciary.
- Consent Manager: A registered single point of contact to help users manage, grant, review, or withdraw consent.
Rights of Data Principals
The Act gives data principals specific rights over their personal data and its use. These rights are central to privacy protection and accountability in digital services.
- Access: The right to seek basic information about personal data processing.
- Correction and erasure: The right to ask for correction or deletion of personal data.
- Grievance redressal: The right to register formal complaints and seek resolution.
Exam fact: The Supreme Court recognised the right to privacy as a fundamental right under Article 21 in the Puttaswamy judgment (2017).
Duties of Data Fiduciaries
Data fiduciaries are responsible for lawful processing and protection of personal data. They must ensure that data is handled only for a legitimate purpose and that security safeguards are in place.
- Technical safeguards: Implement strict security measures to protect personal data.
- Clear notice: Issue notices in clear language, including multiple languages where required.
- Purpose limitation: Delete personal data after the purpose for which it was collected has been fulfilled.
- Children’s data: Processing minor data requires verifiable parental consent.
- Children’s safety: Tracking or behavioural monitoring of children is prohibited.
Information Technology Act: Cyber Offences and Privacy-Related Provisions
Before the dedicated data law, the Information Technology Act provided the main legal basis for cyber offences, unauthorized access, and disclosure of information. These provisions remain important for examination purposes.
- Section 43: Penalises unauthorized downloading of data, system entry, and introduction of malware into networks.
- Section 66: Prescribes imprisonment and fines for intentional hacking and data destruction.
- Section 66C: Punishes identity theft involving passwords, digital signatures, or unique user identifiers.
- Section 72A: Holds corporate service providers liable for disclosing personal information without user consent.
Institutional Oversight and Enforcement
India’s privacy and cyber governance structure includes specialised institutions for breach response, critical infrastructure protection, and enforcement of data protection norms.
| Institution | Core mandate | Administrative function |
| Data Protection Board of India | Adjudication of non-compliance | Imposes monetary penalties and investigates data breach incidents |
| Indian Computer Emergency Response Team | National cyber incident response | Issues security advisories and tracks malware threats |
| National Critical Information Infrastructure Protection Centre | Vital infrastructure protection | Secures strategic networks in power, transport, and finance |
Penalties and Appeal Mechanism
- Data breach penalty: The Data Protection Board of India can levy civil financial penalties of up to Rs 250 crore for failure to prevent data security breaches.
- False complaints: Data principals may face penalties of up to Rs 10,000 for registering false or frivolous complaints.
- Appeals: Orders of the Data Protection Board are appealable before the Telecom Disputes Settlement and Appellate Tribunal.
Key Prelims Takeaways
- Digital Personal Data Protection Act is the core law for personal data processing in India.
- Data Principal means the individual to whom the data belongs.
- Data Fiduciary decides the purpose and means of processing personal data.
- Consent Manager helps in managing, granting, reviewing, or withdrawing consent.
- Children’s data requires verifiable parental consent.
- Tracking or behavioural monitoring of children is prohibited.
- Data Protection Board of India handles non-compliance and breach-related penalties.