Data Protection and Privacy Laws in India

Data Protection and Privacy Laws in India

India’s privacy framework now rests on a mix of constitutional protection, sectoral cyber provisions, and a dedicated personal data law. For Prelims revision, the focus should be on the key legal terms, rights of data principals, duties of data fiduciaries, and the main enforcement institutions.

Digital Personal Data Protection Act: Core Structure

The Digital Personal Data Protection Act is the principal law regulating the processing of personal data across public and private sectors. It lays down the framework for consent, lawful processing, data security, and grievance redressal.

  • Data Principal: The individual to whom the personal data relates.
  • Data Fiduciary: Any entity that independently or jointly determines the purpose and means of processing personal data.
  • Data Processor: An intermediary or external agency that processes personal data on behalf of a data fiduciary.
  • Consent Manager: A registered single point of contact to help users manage, grant, review, or withdraw consent.

Rights of Data Principals

The Act gives data principals specific rights over their personal data and its use. These rights are central to privacy protection and accountability in digital services.

  • Access: The right to seek basic information about personal data processing.
  • Correction and erasure: The right to ask for correction or deletion of personal data.
  • Grievance redressal: The right to register formal complaints and seek resolution.

Exam fact: The Supreme Court recognised the right to privacy as a fundamental right under Article 21 in the Puttaswamy judgment (2017).

Duties of Data Fiduciaries

Data fiduciaries are responsible for lawful processing and protection of personal data. They must ensure that data is handled only for a legitimate purpose and that security safeguards are in place.

  • Technical safeguards: Implement strict security measures to protect personal data.
  • Clear notice: Issue notices in clear language, including multiple languages where required.
  • Purpose limitation: Delete personal data after the purpose for which it was collected has been fulfilled.
  • Children’s data: Processing minor data requires verifiable parental consent.
  • Children’s safety: Tracking or behavioural monitoring of children is prohibited.

Information Technology Act: Cyber Offences and Privacy-Related Provisions

Before the dedicated data law, the Information Technology Act provided the main legal basis for cyber offences, unauthorized access, and disclosure of information. These provisions remain important for examination purposes.

  • Section 43: Penalises unauthorized downloading of data, system entry, and introduction of malware into networks.
  • Section 66: Prescribes imprisonment and fines for intentional hacking and data destruction.
  • Section 66C: Punishes identity theft involving passwords, digital signatures, or unique user identifiers.
  • Section 72A: Holds corporate service providers liable for disclosing personal information without user consent.

Institutional Oversight and Enforcement

India’s privacy and cyber governance structure includes specialised institutions for breach response, critical infrastructure protection, and enforcement of data protection norms.

Institution Core mandate Administrative function
Data Protection Board of India Adjudication of non-compliance Imposes monetary penalties and investigates data breach incidents
Indian Computer Emergency Response Team National cyber incident response Issues security advisories and tracks malware threats
National Critical Information Infrastructure Protection Centre Vital infrastructure protection Secures strategic networks in power, transport, and finance

Penalties and Appeal Mechanism

  • Data breach penalty: The Data Protection Board of India can levy civil financial penalties of up to Rs 250 crore for failure to prevent data security breaches.
  • False complaints: Data principals may face penalties of up to Rs 10,000 for registering false or frivolous complaints.
  • Appeals: Orders of the Data Protection Board are appealable before the Telecom Disputes Settlement and Appellate Tribunal.

Key Prelims Takeaways

  • Digital Personal Data Protection Act is the core law for personal data processing in India.
  • Data Principal means the individual to whom the data belongs.
  • Data Fiduciary decides the purpose and means of processing personal data.
  • Consent Manager helps in managing, granting, reviewing, or withdrawing consent.
  • Children’s data requires verifiable parental consent.
  • Tracking or behavioural monitoring of children is prohibited.
  • Data Protection Board of India handles non-compliance and breach-related penalties.
Current General Studies comprises current-affairs-based, General Studies-rich study material on policies, laws, institutions, economy, science, environment, governance, international relations, and other varied but important topics for UPSC and State PSC Prelims examinations. Fortnightly PDF compilations: Available here
Originally written on June 12, 2026 and last modified on September 6, 2026.

Leave a Reply

Your email address will not be published. Required fields are marked *