Privacy & Trust

What does DPDPA - India's new Privacy Law mean for you?

Breakdown of India's new Privacy Law, Digital Personal Data Protection Act 2023 and its implications on individuals and businesses.

Hardik Katyarmal
27 JAN 2025 · 7 MIN READ

Understanding Digital Privacy

In an increasingly digital world, the concept of privacy has evolved to encompass the protection of personal data in the online realm. Digital privacy refers to an individual's right to control how their personal information is collected, used, shared, and stored. Recognizing the critical role of data privacy, countries worldwide have adopted various regulations to safeguard individuals' rights. As shown on the map, a majority of nations now have comprehensive legislation or draft policies in place to address the growing challenges of data security and privacy. Most of these regulations, such as the EU's GDPR, US's CCPA, India's DPDPA, and others, have gained momentum in the last 10 years to establish frameworks for responsible data handling, ensuring transparency, accountability, and consent-driven practices.

Global data privacy law coverage map
Global data privacy law coverage map

Setting the Stage

Did you know Right to Privacy wasn't always recognized as a fundamental right in India? The Right to Privacy wasn't included in India's original Constitution. Even early arguments in cases from 1954, 1962 against state surveillance, search & seizure failed to establish it as a fundamental right. Indian Courts dismissed these as non-violations of individual rights.

Key Milestones

  1. 1975: The Court acknowledged privacy as an implied right through Articles 19 and 21, linking it to life, liberty, and freedom of movement. However, it wasn't absolute; exceptions were allowed for security.
  1. 2017: The Supreme Court unanimously upheld Privacy as a fundamental right in the Aadhar case, extending the Right's scope to body, mind, choices, and information for the first time.
  1. 2018: Srikrishna Committee proposed a robust framework for digital data protection, setting the stage for proactive legislative measures like the DPDPA
  1. 2019: First draft of the Personal Data Protection Bill was introduced in the Indian Parliament and passed on to Joint Parliamentary Committee for further deliberation
  1. 2023: Digital Personal Data Protection Act was passed establishing a framework for consent as well as responsibilities of data custodians, processors followed up by draft rules in 2025
India's privacy law timeline
India's privacy law timeline

Scope of the DPDPA

Digital Data

As the name suggests, the act applies specifically to Digital Personal Data - any data that can directly or indirectly identify a particular individual captured in a digital form or captured offline and digitized later. Unlike GDPR, the act does not apply to offline data.

Sensitive Data

DPDPA does away with the concept of Sensitive data/ Critical data that was defined under SPDI Rules (2011) and IT Act (2000). It suggests application of all data security measures equally across all personal data.

Geography

All data collected, stored or processed in India is subject to DPDPA compliance. In addition, organizations outside India that process data related to Indian citizens also need to follow the same guidelines.

Key Concepts

Actors

  1. Data principal: Individual whose data is being collected, processed or shared. Should be treated as the owner of the data that holds rights over data generated about them.
  1. Data fiduciary: Entity that collects and defines usage of data collected. Can be referred as the Data Custodian/ Guardian holding and protecting data on behalf of the principal.
  1. Data processor: Entity that undertakes responsibility of processing data on behalf of the fiduciary as an outsourcing partner. All vendors that touch customer data fall in this bucket.
  1. Consent manager: User-facing intermediary employed by data fiduciaries to capture and manage consent from data principals regarding processing and/ or sharing of personal data while remaining blind on its contents. Eg: Account Aggregators
DPDPA key actors diagram
DPDPA key actors diagram

Significant Data Fiduciaries

Some organizations are further tagged by the government as Significant Data Fiduciaries (SDFs) basis volume, sensitivity of data and risk to data principals' rights, national security concerns. Large scale organizations such as Social Media companies, eCommerce marketplaces, Tech giants are likely to fall under this category.

Being tagged as an SFD by the government brings additional responsibilities like:

Consent

Agreement between Data principals and Fiduciaries to capture, store, process and/or share personal data given it is:

Reasonable Security Standards

Draft rules for DPDPA 2025 suggest certain best practices as reasonable security safeguards that Data Fiduciaries need to apply on their systems as well as enforce on data processors they may have employed to outsource certain parts of data processing:

Rights of the Data Principal

Implications for Businesses

Conclusion

DPDPA is a pivotal step in India's journey toward a digital ecosystem that values both empowerment and privacy. By defining clear responsibilities for businesses and empowering individuals with comprehensive rights, the Act sets a framework for trust in the digital age.

For individuals, it ensures greater control and transparency over personal data, creating an environment where data protection becomes a shared priority. For businesses, DPDPA challenges them to adopt a privacy-first approach, emphasizing compliance, security, and user-centric practices. As India positions itself as a global leader in data protection, the DPDPA reflects the nation's commitment to balancing technological growth with individual privacy rights.

Author: Hardik Katyarmal

Hardik Katyarmal
Writes on data strategy, privacy-preserving tech, and ecosystem intelligence at LattIQ.

Get ecosystem intelligence on your data.

30 minutes. Your live use case. A back-test you can run in your stack. No commitment.

Talk to our team