Modi File Research, records, achievements and public life Saturday, October 3, 2026

Man of Determined Intentions

Narendra Modi, his political journey, governance record, and India transformation story.

Judiciary, Law & Institutions

Data Protection Law: Understanding India’s DPDP Act

Data Protection Law: Understanding India’s DPDP Act

India passed its first comprehensive data protection law in 2023, establishing rules for how companies and government bodies can collect and use citizens’ personal data. This article explains the law’s core provisions, why its actual implementation took over two additional years, and a specific, less-discussed consequence for India’s separate right-to-information framework.

The Law’s Constitutional Foundation

The Digital Personal Data Protection Act, passed in 2023, traces its explicit constitutional basis to the Supreme Court’s 2017 Puttaswamy judgment, covered in more detail in our earlier article, which established privacy as a fundamental right, with the DPDP Act functioning as the legislative framework translating that judicially recognised right into specific, enforceable statutory rules governing personal data collection, use, and protection across both private companies and government bodies.

The Core Provisions

The Act establishes a consent-based framework requiring organisations, referred to in the law as “data fiduciaries,” to obtain clear consent before collecting and processing an individual’s personal data, with specific obligations around data security, breach notification, and limits on how long collected data can be retained. The law establishes financial penalties for data breaches and non-compliance, and creates a dedicated Data Protection Board specifically responsible for enforcing the Act’s provisions and adjudicating complaints and violations.

Read this next: POCSO Act Strengthening: How Child Protection Laws Were Tightened

The Long Delay Before Implementation

Despite the law’s 2023 passage, its actual implementing rules, the detailed procedural framework needed to make the Act’s provisions operationally enforceable, were not notified for over two additional years. According to a Press Information Bureau release, the Digital Personal Data Protection Rules, 2025 were finally notified in mid-November 2025, with a phased compliance rollout extending into 2026 and 2027 for different categories of obligated organisations, according to compliance timelines compiled by industry trackers including TCSA and Scrut.io, an unusually long implementation gap for a major piece of legislation that mirrors the similarly extended delay documented in our earlier article on the Citizenship Amendment Act’s own implementing rules.

The Government Exemption Concern

A specific and sustained criticism of the DPDP Act’s actual provisions, rather than merely its delayed implementation, involves the scope of exemptions the law grants to government agencies themselves. Critics have argued the Act’s exemption provisions allow government bodies considerably more latitude to process personal data for various stated purposes, including national security and law enforcement, than the law’s private-sector data fiduciary obligations permit for private companies, raising concerns about an uneven regulatory standard where the government’s own data-handling practices face less stringent oversight than the private-sector practices the law was primarily designed to regulate.

The RTI Act Amendment Consequence

Perhaps the most concrete and actively litigated criticism of the DPDP Act involves its consequential amendment to a separate law entirely: the Right to Information Act. The DPDP Act amended Section 8(1)(j) of the RTI Act, the specific provision that had previously allowed personal information to be disclosed under an RTI request when doing so served a broader public interest that outweighed the individual’s privacy concern, effectively removing that public-interest balancing test and instead exempting personal information from RTI disclosure more broadly, a change transparency advocates have argued substantially weakens the RTI Act’s practical effectiveness for uncovering information about public officials’ conduct, since much of the information RTI activists have historically used to expose corruption or misconduct involves personal information about specific officials that this amended provision could now more easily shield from disclosure. This specific consequence of the DPDP Act is now itself before the Supreme Court, according to legal tracking of the ongoing challenge.

If you like this, you must read: CBI and ED: Understanding the Debate Over Their Use

The Industry and Business Response

The organised business and technology industry’s response to the DPDP Act has generally been more favourable than the RTI-related civil society criticism, with industry bodies broadly welcoming the law as providing much-needed regulatory clarity around data handling obligations that companies operating in India had previously lacked, even as specific compliance requirements, particularly around data localisation and breach notification timelines, have drawn more targeted industry feedback during the extended rules-drafting process that preceded the Rules’ eventual November 2025 notification.

Why the Implementation Delay Itself Drew Scrutiny

The more-than-two-year gap between the DPDP Act’s 2023 passage and its November 2025 Rules notification drew its own separate criticism independent of the substantive provisions themselves, with data protection advocates arguing that a law establishing citizens’ data rights provided little practical protection while its enforcement mechanism, including the Data Protection Board, remained without the operational rules needed to actually process complaints, meaning individuals technically covered by the Act’s protections had no functioning avenue to exercise them for the entire multi-year gap between passage and implementation.

Bottom Line

India’s Digital Personal Data Protection Act, passed in 2023 and drawing its constitutional foundation from the 2017 Puttaswamy privacy judgment, establishes consent-based data handling obligations and a dedicated Data Protection Board, but its implementing rules were not notified until November 2025, over two years after the Act’s passage, and the law has drawn sustained criticism both for the breadth of exemptions it grants government agencies and, more concretely, for its amendment weakening the RTI Act’s public-interest disclosure test, a specific consequence now itself before the Supreme Court.

Disclaimer: This article is based on publicly available Ministry of Electronics and Information Technology records and news reports listed below. It is written for general informational purposes and does not represent an official statement from the Government of India.

FAQ

When did India’s DPDP Act’s rules actually take effect?

The Act was passed in 2023, but its implementing rules were not notified until November 2025, with a phased compliance rollout extending into 2026 and 2027.

How did the DPDP Act affect the RTI Act?

It amended Section 8(1)(j) of the RTI Act, removing the public-interest balancing test that had previously allowed personal information disclosure when it served a broader public interest, a change now before the Supreme Court.

What is the Data Protection Board?

A dedicated body established under the DPDP Act specifically responsible for enforcing the law’s provisions and adjudicating complaints and violations. —