Skip to content Skip to left sidebar Skip to right sidebar Skip to footer

Comparative Study of the Digital Personal Data Protection Act, 2023 (India) and the General Data Protection Regulation (EU)

I. Introduction

The emergence of the digital economy has revolutionized the way personal data is collected, stored, and processed. With vast quantities of information being generated online, the protection of individual privacy has become a central legal concern worldwide. Responding to these concerns, India enacted the Digital Personal Data Protection Act, 2023 (“DPDP Act”), a dedicated statute aimed at regulating the digital use of personal data and safeguarding individual privacy. On the global front, the General Data Protection Regulation (GDPR) enacted by the European Union in 2016 (effective from 25 May 2018) stands as a pioneering and comprehensive data protection framework.

Though the DPDP Act draws inspiration from GDPR, there are fundamental differences in their philosophical underpinnings, regulatory structures, scope, and operational mechanisms. This article provides an in-depth comparative analysis between the two legislative frameworks with references to statutory provisions and relevant case laws.

II. The Digital Personal Data Protection Act, 2023 (India)

1. Enactment and Applicability

The DPDP Act, 2023 was enacted on 11 August 2023 and received presidential assent on 12 August 2023. It is yet to be fully enforced, as the Central Government is empowered under Section 1(2) to notify different provisions on different dates.

The Act applies to:

  • The processing of digital personal data within India.
  • Data processing outside India, if such processing is in connection with any offering of goods or services to individuals within India.

2. Key Definitions (Section 2)

  • Data Principal: Refers to the individual to whom the personal data relates.
  • Data Fiduciary: The entity or individual who determines the purpose and means of processing.
  • Consent Manager: An entity registered with the Data Protection Board to act on behalf of data principals in managing consent.
  • Processing: Includes collection, storage, use, and transmission of data.

3. Consent Framework (Section 6)

Consent is the cornerstone of the DPDP Act and must be:

  • Free, informed, specific, unambiguous, and affirmative.
  • Preceded by a notice that describes the nature and purpose of data collection.
  • Data principals also have the right to withdraw consent at any time.

However, the Act allows “legitimate uses” under Section 7, where consent may not be required, including for state functions and emergencies.

4. Rights of Data Principals (Sections 11 to 13)

  • Right to Information (Section 11): To know what data is being processed and why.
  • Right to Correction and Erasure (Section 12): To correct inaccurate data or request erasure.
  • Right to Grievance Redressal (Section 13): To approach the data fiduciary or the Data Protection Board.

Unlike the GDPR, the DPDP Act does not expressly provide the right to data portability or the right to object to processing.

5. Data Protection Board (Section 18)

The Act establishes the Data Protection Board of India, a quasi-judicial body responsible for:

  • Adjudicating disputes
  • Enforcing penalties
  • Investigating non-compliance

However, concerns have been raised regarding the independence of the Board due to its appointment structure and governmental oversight.

6. Cross-border Data Transfers (Section 16)

The Act permits data transfer to countries that the Central Government may notify. Unlike GDPR’s adequacy mechanism, the criteria for such notification remain opaque, raising potential concerns over arbitrary designations.

7. Penalties (Schedule Part A)

Heavy financial penalties are prescribed:

  • Up to ₹250 crore for significant breaches.
  • ₹200 crore for failure to protect children’s data.
  • ₹50 crore for failure to notify data breaches.

These penalties are discretionary and depend on the gravity, frequency, and nature of the breach.

III. General Data Protection Regulation (EU)

1. Enactment and Scope

The GDPR was adopted on 27 April 2016 and came into force on 25 May 2018, replacing the outdated Data Protection Directive (1995). It has extraterritorial applicability, applying to:

  • All organizations within the EU.
  • Non-EU entities processing data of EU residents in connection with offering goods or services.

2. Foundational Principles (Articles 5–11)

The GDPR is underpinned by seven core principles:

  • Lawfulness, fairness, and transparency
  • Purpose limitation
  • Data minimization
  • Accuracy
  • Storage limitation
  • Integrity and confidentiality
  • Accountability

These principles establish a robust and ethical foundation for all data processing activities.

3. Legal Grounds for Processing (Article 6)

The GDPR allows processing based on six lawful grounds:

  1. Consent
  2. Contractual necessity
  3. Legal obligation
  4. Vital interests
  5. Public interest
  6. Legitimate interest

This provides greater flexibility than the DPDP Act.

4. Data Subject Rights (Articles 12–23)

The GDPR empowers individuals with extensive rights, including:

  • Right of Access (Art. 15)
  • Right to Rectification (Art. 16)
  • Right to Erasure (‘Right to be Forgotten’, Art. 17)
  • Right to Data Portability (Art. 20)
  • Right to Object (Art. 21)

These rights are enforceable against data controllers, and data subjects can approach independent supervisory authorities for redress.

5. Data Protection Officer (Article 37)

Appointment of a Data Protection Officer (DPO) is mandatory for:

  • Public bodies
  • Entities processing sensitive data on a large scale
  • Monitoring behavior of data subjects

The DPO must operate independently and report directly to the highest level of management.

6. Cross-border Data Transfers (Chapter V)

Transfers are restricted to:

  • Countries deemed to provide adequate protection by the European Commission
  • Organizations implementing Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs)

7. Penalties (Articles 83–84)

GDPR enforces strict penalties:

  • Up to €20 million or 4% of global annual turnover, whichever is higher.
  • Penalties are proportionate to the nature, gravity, and duration of the infringement.

IV. Judicial Developments and Case Laws

A. Indian Context

1. Justice K.S. Puttaswamy (Retd.) v. Union of India

Citation: (2017) 10 SCC 1
Significance:

  • Unanimous nine-judge bench held that right to privacy is a fundamental right under Article 21.
  • This judgment catalyzed the framing of India’s data protection law.

2. Internet Freedom Foundation v. Union of India (2023)

Status: Pending
Concerns:

  • The PIL challenges the surveillance exemptions under Section 17(2), which allow government agencies to bypass the Act for reasons of national interest, raising issues of unchecked executive power.

B. European Context

1. Google Spain SL v. AEPD (C-131/12, 2014)

Facts: Individual sought removal of outdated links from Google search.
Held: Court recognized the right to be forgotten and enforced obligations on search engines to delist irrelevant data.

2. Schrems I (C-362/14, 2015)

Facts: Challenged the EU-US Safe Harbor arrangement.
Held: The Court of Justice of the EU struck down Safe Harbor, stating it did not provide adequate protection against US surveillance.

3. Schrems II (C-311/18, 2020)

Held: The Privacy Shield was invalidated, but SCCs were upheld subject to additional safeguards. This reshaped global data transfer regimes and highlighted the supremacy of EU privacy rights.

V. Key Comparative Chart

FeatureDPDP Act, 2023 (India)GDPR (EU)
Nature of LegislationDomestic statuteEU-wide regulation
ScopeDigital personal data onlyAll personal data (digital and non-digital)
ConsentPrimary basisOne among several bases
Data Subject RightsLimited (No portability/objection)Extensive (includes portability, objection, etc.)
Regulatory BodyData Protection Board of IndiaIndependent national Data Protection Authorities
Cross-border TransfersTo notified countriesTo adequate jurisdictions or with legal safeguards
PenaltiesUp to ₹250 croreUp to €20 million or 4% of global turnover
DPO AppointmentNot mandatory for allMandatory for specific entities
Surveillance ExemptionsBroad government exemption (Section 17(2))Subject to proportionality and legal safeguards

VI. Conclusion

Both the Digital Personal Data Protection Act, 2023 and the General Data Protection Regulation mark significant legislative milestones in the protection of personal data and privacy. While the GDPR is more expansive and rights-based, the DPDP Act is still evolving, with its implementation framework under development.

The GDPR reflects a comprehensive and rights-centric model, setting the global standard with its rigorous accountability mechanisms and robust individual rights. In contrast, the DPDP Act, though promising, suffers from ambiguities in its enforcement, lack of clarity on cross-border transfer mechanisms, and executive control over the Data Protection Board.

Moving forward, India’s challenge will be to ensure that the law is implemented with adequate transparency, autonomy of the Board, and genuine respect for individual rights, thereby harmonizing its regulatory approach with international best practices.


0 Comments

There are no comments yet

Leave a comment

Your email address will not be published. Required fields are marked *