Digital Personal Data Protection Act, 2023: New Challenges
Introduction
In the digital era, personal data has become the new currency. With rising concerns over privacy breaches, data misuse, and surveillance, the Indian Parliament enacted the Digital Personal Data Protection Act, 2023 (hereinafter “DPDP Act”). This law aims to protect individuals’ personal data and regulate its processing in a manner that respects privacy while enabling the growth of the digital economy. However, the implementation of the Act comes with several challenges, including regulatory enforcement, interplay with other laws, cross-border data transfer, and ensuring technological neutrality.
Definition and Objective of the DPDP Act, 2023
The DPDP Act, 2023 is a comprehensive legislation enacted to provide for the processing of digital personal data in a manner that recognizes both the right of individuals to protect their personal data and the need to process such data for lawful purposes. It came into force on 11 August 2023 and aligns with the spirit of the Supreme Court’s judgment in Justice K.S. Puttaswamy v. Union of India (2017), where privacy was recognized as a fundamental right under Article 21.
Objectives
- Safeguard personal data of individuals.
- Establish obligations for data fiduciaries and data processors.
- Provide a grievance redressal mechanism.
- Establish a Data Protection Board of India.
- Ensure digital trust and accountability in the digital ecosystem.
Key Definitions and Provisions
1. Personal Data
Defined under Section 2(s), it refers to “any data about an individual who is identifiable by or in relation to such data.”
2. Data Fiduciary
As per Section 2(i), it means any person who alone or in conjunction with others determines the purpose and means of processing personal data.
3. Consent
Under Section 6, personal data can be processed only with the free, informed, specific, unconditional, and unambiguous consent of the data principal.
4. Legitimate Uses (Section 7)
Includes scenarios where data can be processed without consent, such as in the interest of sovereignty, legal obligations, or employment-related matters.
5. Rights of the Data Principal
- Right to access information (Section 11)
- Right to correction and erasure (Section 12)
- Right to grievance redressal (Section 13)
6. Duties of the Data Principal (Section 15)
These include not registering false or frivolous complaints, and not impersonating others.
7. Cross-Border Data Transfer (Section 16)
The government may notify countries where data may be transferred, implying that cross-border transfers are permissible unless restricted.
8. Data Protection Board (Section 18)
A quasi-judicial body established to ensure compliance and impose penalties.
New Challenges under the DPDP Act
1. Ambiguity in Government’s Exemptions
Section 17 grants the Central Government wide discretionary powers to exempt any instrumentality of the state from the application of the Act for reasons such as national security or public order. This raises constitutional concerns regarding potential surveillance and violation of privacy.
Case Law:
- K.S. Puttaswamy v. Union of India (2017) – The Supreme Court upheld the right to privacy as a fundamental right, which must be protected from arbitrary state actions.
2. Weak Regulatory Oversight
Unlike GDPR’s independent data protection authorities, the Data Protection Board of India is appointed and controlled by the government, raising questions about autonomy and potential conflict of interest.
3. Limited Applicability to Offline Data and Non-Digital Processing
The Act is only applicable to digital personal data or data that is digitized later. This leaves a regulatory gap in the protection of offline data records, making the framework less comprehensive.
4. Consent Fatigue and Complex Language
Although the Act mandates consent, in practice, most individuals do not read or understand long privacy policies. This leads to ‘consent fatigue’, thereby undermining the very purpose of informed consent.
Case Law:
- Google India Pvt. Ltd. v. Visaka Industries (2020) – Highlighted the duty of intermediaries and digital platforms to inform users transparently.
5. Inadequate Provisions on Children’s Data
The Act defines a child as an individual under 18 and prohibits tracking or behavioral advertising targeting children. However, it lacks clarity on how companies will verify age or obtain verifiable parental consent, leading to implementation issues.
6. Absence of Data Localization Mandate
Unlike earlier drafts, the DPDP Act does not mandate data localization. This may compromise national security, especially when sensitive data is stored in jurisdictions with weak privacy laws.
Comparative Insight:
- Under China’s Personal Information Protection Law (PIPL) and EU GDPR, strict cross-border transfer rules are imposed, including adequacy assessments.
7. Sectoral Overlap and Conflict with Existing Laws
There is no clear harmonization between the DPDP Act and other legislations such as:
- The Information Technology Act, 2000
- The Indian Telegraph Act, 1885
- The Consumer Protection Act, 2019
This creates confusion and potential litigation due to overlapping provisions.
8. Penalty vs. Compensation
The Act provides for penalties under Schedule 1, but does not provide a civil remedy for compensation to affected individuals in cases of data breaches or misuse.
Significant Case Laws Related to Data Protection
1. Justice K.S. Puttaswamy v. Union of India (2017)
- Declared the right to privacy as a part of Article 21 of the Constitution.
- Laid the foundation for the DPDP Act.
2. Anuradha Bhasin v. Union of India (2020)
- Emphasized the necessity of proportional restrictions on fundamental rights, including online expression and access to information.
3. Internet and Mobile Association of India v. RBI (2020)
- Struck down the RBI’s circular banning cryptocurrency transactions, reaffirming the importance of a procedurally fair and proportionate regulatory regime.
4. WhatsApp LLC v. Competition Commission of India (2021)
- Raised concerns about data sharing with Facebook, triggering investigation into abuse of dominant position and non-consensual data processing.
Conclusion
The Digital Personal Data Protection Act, 2023 marks a landmark development in India’s journey towards safeguarding individual privacy in the digital age. It codifies the principles of purpose limitation, consent, accountability, and data minimization, offering a structured framework for personal data governance. However, despite its progressive outlook, the Act faces substantial challenges in implementation, particularly around government overreach, lack of independent oversight, ambiguities in enforcement, and absence of explicit compensation mechanisms for data breaches.
The absence of strict data localization norms, the government’s wide exemption powers under Section 17, and the limited independence of the Data Protection Board of India present serious concerns that need to be addressed through amendments, rules, or judicial interpretation. As digital ecosystems evolve rapidly, it is imperative for the legal framework to be technologically neutral, rights-centric, and adaptive.
To ensure that the DPDP Act achieves its intended goals, the Indian government must engage in continuous stakeholder consultation, promote digital literacy, and align the Act with international standards like the EU GDPR. Further, judicial oversight and civil society engagement will play a crucial role in checking executive discretion and upholding constitutional values.
0 Comments