Articles / By Kurian K Jose
The legal landscape of digital personal data protection in India is governed by The Digital Personal Data Protection Act, 2023 (“Act”) and the recently enacted Digital Personal Data Protection Rules, 2025 (“Rules”). The Act and Rules try to balance the rights of individuals to protect their digital personal data while recognising the need to process such personal data for lawful purposes. Two key terms that one needs to understand before delving into the provisions of the Act and Rules are PERSONAL DATA and PROCESSING OF DATA.
WHAT IS PERSONAL DATA?
According to Sec. 2(t) of the Act, personal data means any data about an individual who is identifiable by or in relation to such data. To put it in other words personal data means i) any data about an individual who is identifiable by such data and ii) any data about an individual who is identifiable in relation to such data. The first part is pretty straight forward any data about an individual who is identifiable by such data means, the data itself is sufficient to single out the person. E.g.- Name and Residential Address; Official IDs such as Aadhaar Card, Passport, PAN Card, Voter ID Card, Employee ID. The second part, any data about an individual who is identifiable in relation to such data, means a data when used in relation to other data, allows an individual to be identified. In other words the data when combined with other data held by the entity or data publicly available, allows a person to be identified. This is a very broad scope designed to protect against various methods of tracking or profiling. E.g.- Location data, IP Address, Device ID, Date of Birth, Gender, Marital Status, Photograph, Bank Account details, Credit Card Details or Medical Records. Basically these data alone are not enough to identify an individual but when combined with other data, a person could be identified. Thus, to sum it up the scope of personal data as per the Act is very wide. It includes any data which by itself or when combined with other data is capable of identifying a person.
WHAT IS MEANT BY PROCESSING OF DATA?
According to Sec. 2 (x) of the Act, “processing” in relation to personal data, means a wholly or partly automated operation or set of operations performed on digital personal data, and includes operations such as collection, recording, organisation, structuring, storage, adaptation, retrieval, use, alignment or combination, indexing, sharing, disclosure by transmission, dissemination or otherwise making available, restriction, erasure or destruction; This definition is extremely broad and is intended to cover every single action that can be performed on digital personal data, from the moment it is collected until it is finally destroyed. As aforesaid, mere collection or storage of digital personal data by itself would fall under the definition of data processing as per the Act.
APPLICABILITY OF THE ACT
As per section 3 of the Act, it applies to the processing of digital personal data within India and also to the processing of digital personal data outside the territory of India, if such processing is in connection with any activity related to offering of goods or services to individuals in India. Exemptions- However the Act shall not apply to
i) personal data processed by an individual for any personal or domestic purpose (E.g.- personal contact list, emailing friends, or taking family photos) and;
ii) personal data that is made or caused to be made publicly available by the individual himself (E.g.- data posted in social media publicly) or by any other person who is under an obligation under any law for the time being in force in India to make such personal data publicly available.
iii) Research, archiving or statistical purposes if it is carried on in accordance with the standards specified in the second schedule of the Rules (Rule 16 of the Rules)
iv) Partly exempted for state and its instrumentalities for certain purposes.
OBLIGATIONS OF DATA FIDUCIARY
Before going further, the following terms should be understood:
Data Fiduciary- A Data Fiduciary is the one who determines the purposes and means of processing personal data. In other words, the Data Fiduciary decides the how and why of a data processing operation (Sec. 2(i) of the Act). A Data Fiduciary can be a legal person, it could be an individual, a company, a firm, an association of persons or the State. The Data Fiduciary makes material decisions relating to the processing of personal data, such as determining the purposes for which personal data is collected, stored, used, altered and disclosed.
Data principal - means the individual to whom the personal data relates and where such individual is— (i) a child, includes the parents or lawful guardian of such a child; (ii) a person with disability, includes her lawful guardian, acting on her behalf (Sec. 2(j) of the Act).
Data Processor- means any person who processes personal data on behalf of a Data Fiduciary (Sec. 2(k) of the Act). A Data Processor is the individual or the legal person/company/firm that carries out processing activities, on behalf of and in accordance with the Data Fiduciary’s instructions. In other words, the Data Fiduciary can provide personal data to the Data Processor to carry out such processing activities on its behalf. A Data Fiduciary does not need the consent of data subjects to engage a processor. Arrangements between the Data Fiduciary and Data Processor are governed by a legal agreement. Any queries an individual may have regarding the role of the processor ought to be directed back to the Data Fiduciary who engaged the processor in the first place. (E.g.- When a business (Data Fiduciary) outsources the calculation and disbursement of employee salaries, taxes, and benefits to a specialized IT company, such company is a Data Processor, When a bank (Data Fiduciary) contracts a third-party IT company to manage, maintain, or update its customer database and core systems, such IT company is a Data Processor.
In order to obtain such consent, the Data Fiduciary is bound to give a request to the Data Principal. In the said request the personal data and the purpose for which the same is processed shall be mentioned (Sec.5 of the Act & Rule 3 of the Rules).
Illustration. - X, an individual, downloads Y, a telemedicine app. Y requests the consent of X for (i) the processing of her personal data for making available telemedicine services, and (ii) accessing her mobile phone contact list, and X signifies her consent to both. Since phone contact list is not necessary for making available telemedicine services, her consent shall be limited to the processing of her personal data for making available telemedicine services.
(i) appropriate data security measures, such as securing of personal data through encryption, obfuscation, masking or the use of virtual tokens mapped to that personal data;
(ii) appropriate measures to control access to the computer, computer system, computer network, data, computer data base or software, used by such Data Fiduciary or such a Data Processor, wherever applicable;
(iii) visibility on the accessing of such personal data, through appropriate logs, monitoring and review, for enabling detection of unauthorised access, its investigation and remediation to prevent recurrence;
(iv) reasonable measures for continued processing in the event of confidentiality, integrity or availability of such personal data being compromised as a result of destruction or loss of access to personal data or otherwise, such as by way of data-backups;
(v) for enabling the detection of unauthorised access, its investigation, remediation to prevent recurrence and continued processing in the event of such a compromise, retain such logs and personal data for a period of one year, unless compliance with any law for the time being in force requires otherwise;
(vi) appropriate provision in the contract entered into between such Data Fiduciary and such a Data Processor, wherever applicable, for taking reasonable security safeguards; and
(vii) appropriate technical and organisational measures to ensure effective observance of security safeguards.
RIGHTS OF DATA PRINCIPAL
DATA PROTECTION BOARD OF INDIA
Data Protection Board of India (“Board”) is the authority which would be established by the Central Government for the implementation and enforcement of the Act. The Board is empowered to adjudicate disputes and non-compliance issues between individuals and entities (Data Fiduciaries) that process personal data. The proceedings of adjudication may be initiated upon receiving a complaint from an affected Data Principal , a reference from the Central Government, or suo motu. The Board can impose significant monetary penalties for non-compliance, as specified in the Schedule of the Act. The Board also has the power to issue binding directions to the concerned person (Data Fiduciary or Data Processor) to ensure compliance of the provisions of the Act. The Board shall, as far as practicable, function as a digital office, handling complaint filings, inquiries, hearings, and decision-making through digital means. The Board also has the power to advise the Central Government to block the website, app, etc., of a Data Fiduciary who repeatedly breaches the provisions of the Act.
PENALTIES UNDER THE ACT
As aforesaid the Data Protection Board can impose significant penalties for the breach of provisions of the Act. Following are the penalties that could be imposed under the Act.
|
Sl No |
Provisions Breached |
Penalty |
|
1 |
Failure to take reasonable security safeguards to prevent a personal data breach by Data Fiduciary. |
Up to Rs. 250 Crore |
|
2 |
Failure to notify the Data Protection Board and affected Data Principals in the case of a personal data breach. |
Up to Rs. 200 Crore |
|
3 |
Breach of obligations in relation to Children's Data |
Up to Rs. 200 Crore |
|
4 |
Breach of additional obligations by a Significant Data Fiduciary |
Up to Rs. 150 Crore |
|
5 |
Breach of duties by Data principal |
Up to Rs. 10,000/- |
|
6 |
Breach of any term of voluntary undertaking accepted by the Board under section 32. |
Up to the extent applicable for the breach in respect of which the proceedings were instituted. |
|
7 |
Breach of any other provision of the Act or Rules. |
Up to Rs. 50 Crore |
Although significant monetary penalties are mentioned in the Act, the said amount goes to the Government of India. There is no provision in the Act which grants compensation to the Data Principal in the event of a personal data breach.
IMPLEMENTATION TIMELINE
The provisions of the Rules are implemented in a phased manner. The Rules relating to the short title, definitions and constitution of the Data Protection Board came into force on November 14th, 2025. The Rule relating to registration and obligations of Consent Managers shall come into force after November 14th, 2026. The Rules shall fully come into force after 14th May, 2027.