Why in the news
The Centre floated the Draft Digital Personal Data Protection Rules, 2025, to make the DPDP Act, 2023 workable by setting out procedures, compliance duties and enforcement.
Background
- The Supreme Court in Justice K.S. Puttaswamy vs Union of India (2017) declared the Right to Privacy a Fundamental Right.
- The DPDP Act was enacted in 2023 to regulate personal data processing; the 2025 draft rules are subordinate legislation adding operational detail.
- Objectives: define procedures and duties, enable compliance by Data Fiduciaries and Processors, detail the working of the Data Protection Board of India (DPBI), and give Data Principals ways to enforce rights.
Scope
- Covers digital personal data in India, and outside India when goods or services are offered to people in India; data digitised later is also covered.
- Five actors: the Board, Data Principals (individuals), Data Fiduciaries, Consent Managers and Data Processors.
Key provisions
| Topic | Provision |
|---|
| Notice and consent | Standard privacy notice; consent free, informed, specific, unambiguous and withdrawable; multiple languages |
| Data Principal rights | Access, correction, erasure, grievance redressal, nomination; complaints to DPBI |
| Fiduciary duties | Data minimisation, purpose limitation, security safeguards (encryption, access control, breach response), processing records |
| Significant Data Fiduciary | Judged on turnover, data volume and risk to sovereignty; must appoint a DPO, run DPIAs and get independent audits |
| Cross-border transfer | Allowed unless the Central Government restricts it |
| Children (under 18) | Verifiable parental consent; no behavioural tracking or targeted ads |
| Grievances | Resolution in 30 days, then escalation to the Board |
| Breach notice | To DPBI and users within 72 hours, stating data type, impact and remedy |
Role of the DPBI
- A quasi-judicial central regulator: inquires into breaches, investigates complaints and imposes penalties.
- Also adjudicates disputes, issues guidelines and advisory opinions, and oversees grievance redressal.
- Appeals against its orders lie before the Telecom Disputes Settlement and Appellate Tribunal (TDSAT).
Penalties (maximum)
| Violation | Up to |
|---|
| Delayed breach notification | ₹50 crore |
| Unlawful processing or non-erasure | ₹150 crore |
| Children’s data not protected | ₹200 crore |
| Breach with no safeguards in place | ₹250 crore |
Sectoral and global view
- Startups and SMEs: light-touch compliance and Consent Managers to help.
- Health and finance: strong encryption, anonymisation and regular DPIAs.
| Feature | India DPDP Rules | EU GDPR | US CPRA |
|---|
| Reach | Global if targeting Indians | Extra-territorial | California residents only |
| Children | Parental consent under 18 | Under 16 | Under 13 |
| Top penalty | ₹250 crore | €20 million or 4% of turnover | $7,500 per violation |
Concerns
- Vague terms such as “public interest” and “significant harm”.
- Section 17 gives wide exemptions to government bodies.
- The DPBI is still being set up; low digital literacy may blunt consent; unclear rules on restricted countries for data transfer.
Way forward
- Finalise after consultation, give the DPBI real autonomy, run awareness drives and work with industry.
Exam angle
- Key terms: Data Principal, Data Fiduciary, Consent Manager, SDF, DPO, DPIA.
- Appellate forum: TDSAT; breach window: 72 hours; top penalty ₹250 crore.