Subject: Current Affairs | Published: 25 November 2025
India's DPDP Act 2023: A New Digital Charter or a Tool for State Control?
Recommended UPSC Book List
Access the curated list of standard books and resources used by top aspirants for all subjects.
In August 2023, India enacted a landmark piece of legislation, the Digital Personal Data Protection Act, 2023 (DPDP Act), culminating a near-decade-long and often tumultuous journey towards creating a comprehensive legal framework for data privacy. This Act represents India’s definitive response to the global conversation on data governance, seeking to balance the privacy rights of individuals with the processing needs of the burgeoning digital economy and the security imperatives of the state. Born from the constitutional crucible of the Justice K.S. Puttaswamy (Retd.) v. Union of India (2017) judgment, which unanimously and unequivocally enshrined the Right to Privacy as a fundamental right under Article 21 of the Constitution, the DPDP Act aims to regulate the entire ecosystem of personal data processing within India. However, its passage has ignited a fierce and polarized debate, particularly concerning its far-reaching implications for media freedom, journalistic practices, state surveillance, and the foundational principles of transparency enshrined in the Right to Information (RTI) Act, 2005.
While celebrated by industry stakeholders as a crucial step towards digital citizenship and a more stable, predictable business environment, critics and civil society advocates argue that its broad exemptions for the state and its dilution of transparency mechanisms could dangerously reshape the relationship between the citizen, the press, and the government. The Act’s implementation, which has been phased in through 2024 and early 2025 with the notification of its rules, is now revealing the practical contours of this new data regime, forcing news organizations, civil society, and government bodies to navigate a complex, uncertain, and highly contested legal landscape. This article provides a comprehensive, analytical deep-dive into the DPDP Act, 2023, focusing on its core principles, its transformative impact on media and journalism, the controversial amendment to the RTI Act, and the broader questions it raises about privacy, accountability, and governance in the world’s largest democracy.
The genesis of the DPDP Act is intrinsically linked to the Supreme Court’s unanimous declaration in the Puttaswamy case that privacy is an intrinsic part of the right to life and personal liberty. This verdict created a constitutional mandate for a robust data protection law, establishing that any infringement on privacy must satisfy a three-part test: it must be based on a law (legality), pursue a legitimate state aim (necessity), and be proportionate to the objective being sought (proportionality). The government’s first attempt to meet this mandate, the Personal Data Protection Bill, 2019, which emerged from the recommendations of the Justice B.N. Srikrishna Committee, was a comprehensive but complex draft. It introduced concepts heavily influenced by the European Union’s General Data Protection Regulation (GDPR), such as data localization requirements, the classification of sensitive personal data, and a more powerful, structurally independent Data Protection Authority.
However, after an extensive review by a Joint Parliamentary Committee (JPC), which proposed 81 amendments and 12 recommendations, the 2019 bill was withdrawn in August 2022. The government’s stated rationale was the need for a simpler, more agile, and business-friendly law that would not stifle innovation in India’s rapidly growing tech sector. The JPC’s report had, in fact, suggested expanding the scope of the law to cover non-personal data and further strengthening government exemptions, which drew significant criticism and likely contributed to the decision to redraft the legislation entirely. The result is the DPDP Act, 2023—a legislation that is notably less prescriptive and significantly more streamlined than its predecessor and the GDPR. It is built on a set of core principles rather than rigid, detailed rules, granting significant rule-making power to the central government. This flexibility, while intended to foster agility and adapt to technological changes, has also become a primary source of profound concern. The ultimate strength, fairness, and efficacy of India’s data protection regime will depend heavily on the subordinate legislation and rules framed by the executive branch. As seen in the rules notified in early 2025, this approach has concentrated immense power in the hands of the central government to define the scope of exemptions, prescribe procedures for the Data Protection Board, and determine what constitutes “legitimate uses,” making the executive both a key player and the primary referee in the data ecosystem.
Core Pillars and Key Definitions of the DPDP Act
Understanding the DPDP Act requires a deep familiarity with its foundational concepts, which define the rights and obligations of all participants in the digital ecosystem. The Act revolves around the triangular relationship between the individual whose data is being processed, the entity that determines the purpose and means of processing, and the state.
At the heart of the Act is the Data Principal, who is the individual to whom the personal data relates. The law grants them a set of specific rights designed to give them control over their digital footprint, but also, for the first time in Indian law, imposes duties upon them. The entity that, alone or in conjunction with others, determines the purpose and means of processing personal data is termed the Data Fiduciary. This can be any entity, from a large social media corporation or a small news website to a government department or a local municipal body. The Act places the primary responsibility for lawful data processing squarely on the Data Fiduciary. In many cases, Data Fiduciaries use other entities to process data on their behalf; these are known as Data Processors, who are contractually bound to follow the Fiduciary’s instructions.
The cornerstone of the Act’s framework is consent. The guiding principle is that personal data can only be processed for a lawful purpose after obtaining the free, specific, informed, and unambiguous consent of the Data Principal. This consent must be sought through a clear, plain-language notice that explains precisely what data is being collected and for what specific purpose. However, the Act carves out a significant and highly controversial exception to this rule through the concept of “deemed consent.” This provision, detailed under Section 7, allows Data Fiduciaries to process personal data without explicit, itemized consent in a wide range of situations. These include:
- Where the Data Principal “voluntarily” provides data for a specified purpose.
- For the performance of any function under law by the State and its instrumentalities.
- To comply with any legal judgment or order.
- For responding to a medical emergency or a public health crisis.
- For disaster management.
- For employment-related purposes, including preventing corporate espionage.
The breadth of “deemed consent,” especially the catch-all provision for state functions and the ambiguity of “voluntary” provision, has been flagged by privacy advocates as a gaping loophole. It could systematically undermine the consent-based architecture of the law, effectively making consent the exception rather than the rule when dealing with the state and even in certain private sector contexts like employment.
To operationalize this framework, the Act establishes the Data Protection Board of India (DPBI). This body is tasked with adjudicating disputes, investigating data breaches upon being directed by the government or on receipt of a complaint, and imposing penalties for non-compliance. A major point of contention is the Board’s structure and independence. The chairperson and members of the DPBI are to be appointed by the central government for two-year terms and are eligible for re-appointment. This contrasts sharply with the Srikrishna Committee’s recommendation for a judicially-led, independent authority with a fixed, non-renewable tenure to ensure autonomy. Critics argue that this direct control by the executive, which is itself the country’s largest Data Fiduciary, creates an inherent conflict of interest and compromises the Board’s ability to act as an impartial regulator against government agencies. The penalties for non-compliance are substantial, with fines extending up to ₹250 crore (approximately $30 million) for a significant data breach, signaling a strong intent to enforce the law, though the Board’s willingness to penalize government entities remains a critical open question.
Fun Fact: The amount of data created globally each day is staggering. By early 2025, it was estimated that over 400 exabytes of data were generated daily. An exabyte is one quintillion bytes, equivalent to the information in hundreds of thousands of the world’s largest libraries. The DPDP Act is India’s attempt to govern its small but rapidly growing slice of this global data explosion.
The rights granted to Data Principals are a critical component of the Act. These include the right to access information about their personal data being processed, the right to correction and erasure of their data, and the right to grievance redressal. The Act also introduces the concept of a Consent Manager, a new type of entity registered with the Board that will act as a single point of contact to enable a Data Principal to give, manage, review, and withdraw their consent through an accessible, transparent, and interoperable platform. However, the Act also imposes duties on Data Principals, such as the duty not to file false or frivolous complaints and to provide accurate information, with a penalty of up to ₹10,000 for non-compliance. This unique feature has been criticized for potentially discouraging citizens from reporting genuine data breaches or privacy violations for fear of being penalized.
To remember the key rights of a Data Principal under the DPDP Act, one can use the following mnemonic:
Mnemonic: G-CARE
- Grievance Redressal: The right to have complaints addressed by the Data Fiduciary and the Board.
- Correction & Erasure: The right to correct inaccurate data and request the erasure of data that is no longer necessary.
- Access Information: The right to obtain a summary of personal data being processed and the processing activities.
- Representative Nomination: The right to nominate another person to exercise rights in case of death or incapacity.
- Easy Withdrawal: The right to withdraw consent at any time with ease.
The Sweeping Exemptions for the State
One of the most contentious provisions of the DPDP Act is Section 17(2), which grants the central government the power to exempt any “instrumentality of the State” from the Act’s provisions. The government can issue a notification to grant such an exemption on broad and vaguely defined grounds, including:
- The sovereignty and integrity of India
- Security of the State
- Friendly relations with foreign states
- Maintenance of public order
- Preventing incitement to any cognizable offence
This provision effectively gives the government a carte blanche to exclude any of its agencies—from law enforcement and intelligence bodies to public sector undertakings—from the purview of the data protection law. This is a significant departure from the Puttaswamy judgment, which held that any infringement on privacy must be proportionate. By allowing for blanket exemptions rather than purpose-limited ones, the Act fails to embed the proportionality test into its core fabric. Privacy advocates argue that this creates a framework for a surveillance state, where government agencies can collect, process, and retain citizen data without any of the safeguards, obligations, or accountability mechanisms that apply to private entities. This stands in stark contrast to the GDPR, where exemptions for national security are more narrowly tailored and subject to oversight by independent data protection authorities and courts.
The Impact on Media, Journalism, and the Freedom of Expression
The relationship between data protection and journalism is inherently complex and often fraught with tension. While journalists require access to information—often sensitive personal information—to hold power to account and inform the public, they also handle this data and have a responsibility to protect their sources and subjects. The DPDP Act attempts to navigate this delicate balance by providing a specific, albeit conditional, exemption for journalistic work. Section 17(1)(c) of the Act states that the provisions of most chapters (including the need for consent-based processing, purpose limitation, and most obligations of Data Fiduciaries) shall not apply to the processing of personal data “if it is necessary for a journalistic purpose.”
However, this exemption is far from a blanket protection for the press. It is contingent on the processing being “necessary” for the purpose and, crucially, is subject to any rules that the central government may prescribe. The ambiguity surrounding what constitutes “necessary” processing for a “journalistic purpose” creates a significant gray area and a potential tool for administrative overreach. This could empower the Data Protection Board or the courts to second-guess editorial judgments on what information is vital for a news story. For instance, could an investigative story that exposes corruption by using personal data obtained without consent be challenged as not “necessary,” thereby subjecting the journalist and their organization to the Act’s punitive measures? This legal uncertainty may lead to a significant “chilling effect” on investigative journalism, as media organizations, particularly smaller, independent ones, might become overly cautious to avoid costly litigation and hefty penalties.
Furthermore, the exemption does not absolve media organizations from their responsibilities as Data Fiduciaries in other contexts. A news website that collects user data for subscriptions, newsletters, comments, or targeted advertising is fully bound by the Act’s provisions. They must obtain explicit consent, provide clear privacy notices, implement robust data security measures to protect user information, and respond to Data Principal rights requests. The recent enforcement actions initiated by the DPBI in late 2024 against several e-commerce and media platforms for non-compliant cookie consent banners and opaque privacy policies underscore the seriousness of these obligations. This creates a dual compliance burden for media houses: navigating the ambiguities of the journalistic exemption for their editorial content while ensuring strict, technical adherence to the law for their commercial and user-engagement activities.
Analogy: The role of a Data Fiduciary is like that of a trustee for a valuable asset. If you entrust your money to a bank (the fiduciary), you expect them to protect it, use it only for purposes you’ve agreed to, and be transparent about how it’s managed. Similarly, a Data Fiduciary holds your personal data “in trust” and is legally obligated to handle it responsibly and in your best interest, with severe penalties for any breach of that trust.
The RTI Amendment: A Decisive Blow to Transparency?
Perhaps the most fiercely debated and consequential aspect of the DPDP Act is its amendment to the Right to Information Act, 2005. The RTI Act has been a transformative tool for transparency and accountability in India, empowering citizens and journalists to question public authorities and access information about government functioning, thereby acting as a vital check on arbitrary power. The DPDP Act amends Section 8(1)(j) of the RTI Act, a provision that dealt with the exemption of personal information.
The original Section 8(1)(j) exempted the disclosure of personal information that had no relationship to any public activity or interest, or which would cause an unwarranted invasion of the privacy of the individual, unless the Central Public Information Officer (CPIO) or the appellate authority was satisfied that the larger public interest justified the disclosure. This public interest override was the soul of the provision; it allowed journalists and activists to access information about public officials—such as their educational qualifications, asset declarations, details of actions taken in their official capacity, or records of foreign tours—by arguing that transparency in their functioning served a larger public interest that outweighed their personal privacy.
The DPDP Act, 2023, replaces this nuanced, balanced provision with a blanket, absolute exemption. The new Section 8(1)(j) simply exempts “information which relates to personal information.” It completely removes the public interest override and the test of nexus with public activity. The immediate and stark consequence is that any information that can be categorized as “personal” can now be withheld by a public authority, regardless of its relevance to public interest, accountability, or the exposure of corruption.
| Feature | RTI Section 8(1)(j) - Before DPDP Act (2005-2023) | RTI Section 8(1)(j) - After DPDP Act (2023) |
|---|---|---|
| Exemption Basis | Personal information with no relation to public activity/interest, or causing unwarranted invasion of privacy. | All information which relates to personal information. |
| Public Interest Test | Present. Disclosure was allowed if the larger public interest justified it. | Removed. There is no provision for a public interest override. |
| Balancing Act | Balanced the right to privacy against the public interest in transparency. | Prioritizes personal privacy (of officials) absolutely over public interest. |
| Impact on Journalism | Enabled access to data on officials’ performance, assets, and qualifications for accountability reporting. | Severely restricts access to such data, hampering investigative journalism and anti-corruption efforts. |
| Example | A journalist could obtain details of a minister’s foreign travel expenses by arguing public interest. | The same request can now be denied outright as it pertains to “personal information.” |
This change fundamentally alters the balance between privacy and transparency that was at the core of the RTI Act, tilting it overwhelmingly in favor of secrecy for public officials. Critics, including numerous former Information Commissioners, legal scholars, and transparency advocates, have argued that this amendment effectively neuters the RTI Act and will severely hamper anti-corruption efforts and accountability journalism. The government’s defense is that this change was necessary to bring the RTI Act in line with the new data privacy law. However, this argument is widely seen as flawed, as the DPDP Act itself contains provisions for processing data for legitimate state functions, and the RTI Act was already equipped with a mechanism to balance these competing rights.
Critical Policy Appraisal
| Challenges / Criticisms | Opportunities / Successes / Way Forward |
|---|---|
| Overbroad State Exemptions: Section 17(2) allows the government to exempt any of its agencies, undermining the Act’s core purpose and creating a risk of unchecked state surveillance. | Legal Certainty for Business: Provides a clear, unified legal framework for data processing, boosting the digital economy and ease of doing business. |
| Dilution of RTI Act: The amendment to Section 8(1)(j) of the RTI Act creates a major setback for transparency and government accountability. | Baseline Privacy Rights: Establishes a foundational set of rights for citizens (Data Principals), including the right to access, correct, and erase their data. |
| Weak Data Protection Board (DPBI): The Board’s appointment process and structure raise serious concerns about its independence from the executive, creating a conflict of interest. | Focus on Digital Economy: The Act’s business-friendly approach, including a blacklist-based mechanism for cross-border data transfer, can attract foreign investment. |
| Ambiguous Journalistic Exemption: The lack of clarity on what constitutes “journalistic purpose” could lead to a chilling effect on investigative reporting. | Way Forward: Judicial Review: The constitutional validity of the broad exemptions and the RTI amendment is likely to be challenged in the Supreme Court, which could read down the problematic provisions. |
| Concept of “Deemed Consent”: The wide grounds for deemed consent, especially for state functions, significantly weaken the consent-based framework of the Act. | Way Forward: Strong Rule-Making & Oversight: Civil society and the judiciary must closely monitor the rules framed under the Act and the functioning of the DPBI to ensure they operate in the public interest. |
Analytical Lens: UPSC Focus (Mains & Prelims)
Conceptual Basis
The legal and constitutional backbone of the DPDP Act, 2023, is Article 21 of the Indian Constitution, which guarantees the Right to Life and Personal Liberty. The Supreme Court, in its landmark Justice K.S. Puttaswamy (Retd.) v. Union of India (2017) judgment, interpreted this article to include the Right to Privacy as a fundamental right. The court mandated that any intrusion into this right must be based on law, serve a legitimate state purpose, and be proportionate. The DPDP Act is the legislative instrument enacted to give statutory effect to this fundamental right.
UPSC Integration: Connecting the Dots
- Polity & Governance (GS Paper 2): This topic is central to Fundamental Rights (Article 21), the separation of powers (concerns about the executive-controlled DPBI), the functioning of statutory and regulatory bodies, and the critical theme of transparency vs. state security. The amendment to the RTI Act directly impacts the chapter on accountability and governance.
- Economy (GS Paper 3): The Act is a cornerstone of India’s digital economy policy. It directly relates to the ease of doing business, foreign investment in the tech sector, the growth of startups, and the overall architecture of India’s $1 trillion digital economy goal.
- Internal Security (GS Paper 3): The broad exemptions for state agencies under Section 17(2) connect directly to the syllabus topic of the role of external state and non-state actors in creating challenges to internal security, and the debate on security versus individual liberty. It raises questions about state surveillance capabilities.
- Ethics (GS Paper 4): The Act touches upon information ethics, the ethical responsibilities of corporations (Data Fiduciaries) and governments in handling citizen data, and the ethical dilemmas of balancing privacy with public interest and security.
Future Impact and Policy Relevance
The long-term impact of the DPDP Act will be profound. For the economy, it provides a much-needed legal foundation for data flows, which is crucial for innovation and investment. However, its success will be judged by its ability to protect citizens’ rights effectively. The Act’s greatest challenge lies in its implementation and the potential for its wide-ranging exemptions to be misused. The future trajectory will likely be shaped by judicial review. The Supreme Court may be called upon to rule on the constitutionality of the sweeping state exemptions and the RTI amendment, potentially reading them down to align with the proportionality test laid down in the Puttaswamy judgment. The functioning of the Data Protection Board will be under intense scrutiny; its ability (or failure) to act independently and penalize powerful state actors will determine whether the law has teeth. For policy, the Act represents a paradigm shift, but the real test will be in the rules that are framed and the precedents that are set in the coming years.
Prelims Practice Question (MCQ)
Question: With reference to the Digital Personal Data Protection Act, 2023, which of the following is NOT a valid ground for “deemed consent” for the processing of personal data? (a) For the performance of any function under any law by the State. (b) For the purpose of employment or for safeguarding the employer from loss or liability. (c) For responding to a medical emergency involving a threat to the life of the Data Principal. (d) For the purpose of targeted advertising by a social media company.
Answer: (d) For the purpose of targeted advertising by a social media company. Explanation: The DPDP Act, 2023, specifies certain “legitimate uses” under Section 7 where consent is deemed to be given. These include processing for state functions (a), employment purposes (b), and medical emergencies (c). However, processing for commercial purposes like targeted advertising is not a ground for deemed consent. For such activities, the Data Fiduciary must obtain free, specific, and unambiguous consent from the Data Principal.
Mains Sample Question
Question (15 Marks): The Digital Personal Data Protection Act, 2023, is hailed as a milestone for India’s digital economy but criticized as a setback for governmental accountability. Critically analyze this statement, with special emphasis on the Act’s provisions regarding state exemptions and its amendment to the RTI Act. (250 words)
Mind Map Outline (Revision Structure)
- Digital Personal Data Protection Act, 2023
- Genesis & Constitutional Basis
- Supreme Court: Justice K.S. Puttaswamy v. Union of India (2017)
- Right to Privacy as a Fundamental Right (Article 21)
- Three-Part Test: Legality, Necessity, Proportionality
- Legislative History
- Justice B.N. Srikrishna Committee
- Withdrawal of Personal Data Protection Bill, 2019
- Shift to a “simpler, business-friendly” framework
- Supreme Court: Justice K.S. Puttaswamy v. Union of India (2017)
- Core Principles & Definitions
- Data Principal: The individual (citizen).
- Rights: G-CARE (Grievance, Correction, Access, Representative, Erasure)
- Duties: Not to file false complaints.
- Data Fiduciary: The entity deciding the purpose of processing (company, govt).
- Consent Framework
- Primary Basis: Free, specific, informed, unambiguous consent.
- Deemed Consent (Section 7): Major exception for state functions, employment, etc.
- Data Principal: The individual (citizen).
- Regulatory Body: Data Protection Board of India (DPBI)
- Composition: Appointed by the Central Government.
- Functions: Adjudication, imposing penalties (up to ₹250 crore).
- Criticism: Lack of independence, potential conflict of interest.
- Major Areas of Impact & Controversy
- State Exemptions (Section 17(2))
- Grounds: Sovereignty, security, public order, etc.
- Criticism: Overbroad, enables surveillance, violates proportionality.
- Impact on Media & Journalism
- Journalistic Purpose Exemption (Section 17(1)(c)).
- Ambiguity of “necessary” processing.
- Potential for “Chilling Effect” on investigative reporting.
- Amendment to RTI Act, 2005
- Target: Section 8(1)(j).
- Change: Removal of the “public interest override.”
- Consequence: Blanket exemption for personal information, weakening transparency.
- State Exemptions (Section 17(2))
- Policy Analysis & Future Outlook
- Critical Appraisal
- Challenges: State control, weak DPBI, RTI dilution.
- Opportunities: Economic growth, legal certainty.
- UPSC Linkages
- GS-2: Fundamental Rights, Governance, Accountability.
- GS-3: Digital Economy, Internal Security.
- GS-4: Information Ethics.
- Way Forward
- Role of Judicial Review.
- Monitoring of rule-making and DPBI’s functioning.
- Critical Appraisal
- Genesis & Constitutional Basis