The DPDP Act, 2023: Most urgent policy intervention in India
August 31, 2026
  • Read Ecopy
  • Circulation
  • Advertise
  • Careers
  • About Us
  • Contact Us
Android AppiPhone AppArattai
Organiser
  • ‌
  • Bharat
    • Assam
    • Bihar
    • Chhattisgarh
    • Jharkhand
    • Maharashtra
    • View All States
  • World
    • Asia
    • Europe
    • North America
    • South America
    • Africa
    • Australia
  • Editorial
  • International
  • Opinion
  • RSS @ 100
  • More
    • Op Sindoor
    • Analysis
    • Sports
    • Defence
    • Politics
    • Business
    • Economy
    • Culture
    • Special Report
    • Sci & Tech
    • Entertainment
    • G20
    • Azadi Ka Amrit Mahotsav
    • Vocal4Local
    • Web Stories
    • Education
    • Employment
    • Books
    • Interviews
    • Travel
    • Law
    • Health
    • Obituary
  • Subscribe
    • Subscribe Print Edition
    • Subscribe Ecopy
    • Read Ecopy
  • ‌
  • Bharat
    • Assam
    • Bihar
    • Chhattisgarh
    • Jharkhand
    • Maharashtra
    • View All States
  • World
    • Asia
    • Europe
    • North America
    • South America
    • Africa
    • Australia
  • Editorial
  • International
  • Opinion
  • RSS @ 100
  • More
    • Op Sindoor
    • Analysis
    • Sports
    • Defence
    • Politics
    • Business
    • Economy
    • Culture
    • Special Report
    • Sci & Tech
    • Entertainment
    • G20
    • Azadi Ka Amrit Mahotsav
    • Vocal4Local
    • Web Stories
    • Education
    • Employment
    • Books
    • Interviews
    • Travel
    • Law
    • Health
    • Obituary
  • Subscribe
    • Subscribe Print Edition
    • Subscribe Ecopy
    • Read Ecopy
Organiser
  • Home
  • Bharat
  • World
  • Operation Sindoor
  • Editorial
  • Analysis
  • Opinion
  • Culture
  • Defence
  • International Edition
  • RSS @ 100
  • Magazine
  • Read Ecopy
Home Bharat

The Digital Personal Data Protection Act, 2023: Most urgent policy intervention in India

DPDP is a foundational pillar of India’s digital state, strengthening trust, reducing systemic risk and ensuring that the next billion Indians come online with rights and adequate safety nets, but not vulnerabilities

Shashwat ShekharBabu Sandeep S MShashwat ShekharandBabu Sandeep S M
Nov 30, 2025, 04:00 pm IST
inBharat, Analysis, Law, Sci & Tech
Follow on Google News
The Digital Personal Data Protection Act, 2023

The Digital Personal Data Protection Act, 2023

Facebook
Twitter
WhatsAppTelegramEmail

India today is home to over 800 million active internet users, one of the world’s largest digital identity systems (Aadhaar) and a rapidly scaling fintech and e-commerce economy. Yet, until August 2023, this
digital expansion was happening on top of legal infrastructure built in 2000, a time when smart phones
did not exist and cyber attacks were rare. The consequences were systemic and not merely episodic.

  • 2018-Aadhaar data leak: Personal details of millions, including Aadhaar numbers, were reportedly available for as little as ₹500
  • 2021-Domino’s India breach: 180 million order records leaked, exposing home addresses and GPS coordinates
  • 2022-AIIMS Delhi ransom ware attack: 40 million patient records compromised; the hospital switched to paper for weeks

These were not isolated “technical glitches”. They revealed 4 structural gaps in India’s governance
framework

  1. No uniform rules on what data can be collected, for what purpose or for how long
  2. No clear accountability for securing personal data
  3. No enforceable rights for individuals.
  4. No dedicated regulator to investigate breaches
  5. Low citizen awareness fewer than 20 per cent of Indians report understanding how their data is used
  6. Rapid digitisation without parallel security investment India’s cyber security workforce gap is
    over 40 per cent, according to NASSCOM

As Justice B.N. Srikrishna had warned in 2018, India had created “a goldmine of data without guardrails”. The Digital Personal Data Protection Act (DPDP), 2023, is meant to fill this vacuum.

What the DPDP act attempts to fix

Passed in August 2023, DPDP aims to align India with global frameworks like the EU’s GDPR while balancing privacy with innovation. As IT Minister Ashwini Vaishnaw put it, the law seeks to “protect rights without slowing down digital growth”. But comparing it with GDPR reveals its unique design choices, particularly broader government exemptions and simplicity-first architecture intended to ease compliance for India’s diverse business ecosystem.

Core Features

  • Establish the Data Protection Board (DPB) for breach adjudication
  • Consent-Centric Processing: No more vague, open ended permissions. Consent must be specific
    and informed
  • User Rights: Access, correction, erasure, and the right to withdraw consent.
  • Fiduciary Obligations: Encryption, access controls, audits, and “reasonable security safeguards.”
  • Mandatory Breach Reporting: To both the affected user and the Data Protection Board (DPB).
  • Cross Border Transfers: Permitted except to blacklisted jurisdictions.
  • Penalties: Up to ₹250 crore for failure to prevent breaches or notify users.

Why a two year gap before enforcement?

The delayed enforcement was not accidental; it reflects the government’s attempt to avoid the failures of previous draft laws that collapsed under compliance complexity.

Three factors explain the long runway:

  1. Administrative Complexity: The Act required drafting 30+ rules: consent architecture, breach
    reporting timelines, DPB procedures, cross-border transfer criteria, exemptions and fiduciary
    classifications.
  2. Building the DPB from scratch: Appointing adjudicating officers, setting up digital infrastructure
    and defining processes for hearings and appeals.
  3. Preparing industry: Micro and small enterprises needed time to adjust to consent flows, data
    minimization and breach reporting norms.
  4. Harmonising with CERT-In: After the 2022 CERT-In directive mandating 6-hour breach reporting,
    the government needed to avoid contradictory timelines.

This transition period mirrors global experience GDPR itself had a two-year preparatory window.

Evidence & data: Why DPDP became urgent

The AIIMS cyberattack was a turning point. As one senior doctor said, “It felt like the entire hospital was held hostage.”

The broader picture is more alarming:

  • CERT-In recorded 1.39 million cyber security incidents in 2022.
  • India is the 2nd most targeted country in Asia (IBM Security).
  • The average cost of a breach in India reached ₹17.7 crore in 2023.
  • 52 per cent of Indian companies were hit by ransom ware in the past year (Sophos)
  • India’s cyber insurance market grew 60 per cent YoY a sign of rising perceived risk

As Nandan Nilekani observed, “When digital economies scale without data protection, vulnerabilities scale faster”. DPDP uses institutional accountability not just technical mandates to reduce systemic risk.

Will DPDP reduce cyber attacks? A realistic view

Where it strengthens India’s posture

  • Security gets teeth

“Reasonable safeguards” may sound vague, but for the first time, there is a financial cost for negligence. Earlier, many breaches went unreported because the IT Act penalties were minuscule.

  • Breach visibility improves

Timely reporting ensures faster containment. As CERT-In’s former chief Gulshan Rai noted, “Half the battle knows a breach has occurred”.

  • Impact assessments for high-risk sectors

Fintech, telecom, health and large social platforms prime targets must now conduct Data Protection Impact Assessments (DPIAs).

  • Centralised enforcement

A unified DPB means companies aren’t navigating fragmented regulators.

But major gaps persist:

  • Security standards lack specificity

Terms like “reasonable” leave room for interpretation. Unlike GDPR or NIST-based laws, DPDP avoids prescriptive frameworks.

  • DPB independence remains unclear

Appointments and removals rest with the executive raising concerns about bias, especially if government agencies are involved in a breach.

  • Broad government exemptions

Consent can be bypassed for national security, public order or “any other purpose notified.” This raises another critical question: What happens if the government refuses to comply with a DPB order?
Legally, DPB orders apply to “data fiduciaries,” including state bodies, but enforcement ultimately depends on political will. There is no explicit mechanism for penalising non-compliant government departments, a gap that civil society has flagged repeatedly.

  • The Aadhaar puzzle: Does DPDP apply?

Legally, yes, Aadhaar data is personal data. But in practice, the Aadhaar Act (2016) overrides DPDP for core functions, and government exemptions further complicate enforcement. This creates a regulatory blind spot around one of India’s most frequently breached datasets.

The Data Protection Board (DPB)

The DPB serves as a centralized adjudicator designed to address a longstanding lacuna where breach
enforcement was fragmented across CERT-In, sectoral regulators and police cyber cells with limited
expertise.

But how effectively can the DPB handle complaints?

This question has gained urgency as India officially notified the DPDP Rules in November 2025, more
than two years after the Act was passed.

But is DPB equipped to handle complaints?

As of 2025:

  • DPB is expected to begin with 80 – 120 officers, including tech specialists.
  • The government has allocated a ₹110 crore setup budget (PIB, 2025).
  • MeitY projects that over 50,000 complaints annually may reach the Board.

However, capacity challenges remain:

  • India has no historical precedent for privacy adjudication.
  • Digital literacy among complainants varies widely.
  • The Board must coordinate with CERT-In and sectoral regulators.

Realistically, DPB will take 2- 3 years to reach full operational maturity.

What happens if the government refuses to comply with a DPB Order?

This is one of the most contested grey zones. DPDP allows broad exemptions for government departments. If a dispute arises:  DPB can issue directions and penalties. However, enforcement against government agencies may face:

  • delays,
  • appeals to High Courts,
  • National security exemptions.

In effect:

The government sits both as a regulated entity and regulator. This creates a potential accountability
vacuum.

Learning from other regulators

India has seen similar challenges before:

  • SEBI and TRAI both struggled with early enforcement because of limited staff and technical expertise.
  • CERT-In’s 2022 directive triggered widespread compliance confusion because of unrealistic timelines.

These precedents show that capacity, not drafting, determines regulatory success.

How DPDP can become more effective

  1. Define clear cyber security baselines (NIST Zero Trust, ISO/IEC 27001, ENISA benchmarks).
  2. Enhance DPB autonomy through multi-stakeholder appointments, clear tenure protections, judicial oversight of exemptions
  3. Create a single breach reporting portal routing submissions to DPB, CERT-In, RBI, IRDAI. Similar to the EU’s “One-Stop Shop” model.
  4. Narrow government exemptions with judicial or parliamentary review.
  5. Run a national digital rights awareness program, because rights unused are rights lost.

The law is passed. Now comes the hard part

DPDP is not flawless, but it closes a 20-year gap in India’s legal architecture. As Justice D.Y. Chandrachud
said, “Privacy is the right to control one’s information”. In that sense, DPDP is India’s first systemic attempt to shift power away from institutions and back to citizens.

Also Read: Safeguarding Digital Dignity: India updating framework to combat non-consensual intimate imagery

Successful implementation will depend on four pillars:

  • A technically capable, independent and empowered DPB
  • Clear & consistent security standards
  • Limited and accountable state exemptions
  • Citizens who understand and exercise their rights
  • Industry wide compliance maturity
  • Inter regulatory coordination (CERT-In, RBI, IRDAI, UIDAI)

If these fall into place, DPDP can become a foundational pillar of India’s digital state, strengthening trust,
reducing systemic risk and ensuring that the next billion Indians come online with rights and adequate safety nets, not vulnerabilities.

Topics: Cyber SecurityDigital IndiaAadharDigital Personal Data Protection ActDPDP Act
Share
Tweet
SendShareSend
✮ Subscribe Organiser YouTube Channel. ✮
✮ Join Organiser's WhatsApp channel for Nationalist views beyond the news. ✮
Previous News

EC appoints retired IAS officer Subrata Gupta as special observer for SIR in West Bengal amid escalating TMC-EC clash

Next News

Red Fort Terror Blast: How quick police response in first 10 minutes saved dozens of lives

Related News

Bharat’s decolonization is reshaping laws, education and culture while reclaiming its civilisational identity (This image is generated by AI)

Decolonising Bharat: How legal, educational and cultural reforms are reclaiming India’s indigenous identity

Representative Image

WhatsApp’s Big India Update: Why Age Verification Is Here, What the DPDP Act Means, Meta Under Pressure

AI Generated Image

BHASHINI–PNB Pact: Destined to take multilingual AI-powered banking to every Indian

The MHA has proposed recruitment rules for CEO and Additional CEO posts at I4C, inviting stakeholder feedback till August 14

MHA proposes recruitment rules for CEO, additional CEO posts at I4C; seeks stakeholder feedback till August 14

A representative image

Samriddh Gram wins WSIS prize 2026: How BharatNet is driving rural digital transformation across Bharat

A representative image

From villages to national markets: How eSaras is empowering 8.99 crore SHG members through rural digital commerce

Load More

Latest News

Students at the Gautam Buddha University, Greater Noida

Mann Ki Baat: PM Modi praises GBU’s mission ShakthiSAT, says dreams of daughters are now taking flight to space

Dutch TikTokker Angelo Bryson, known as Superhuman Unchained, at a pro-Palestine protest.

Dutch TikTokker recently converted to Islam livestreams stabbing three in Amsterdam; Watch video

From Kanchipuram to Kalamkari, India’s traditional textiles reflect its rich regional cultures and centuries-old craftsmanship

From Kanchipuram to Kalamkari: Exploring India’s rich traditional textiles and regional clothing heritage

Punjabi Influencer Abducted, Burnt Alive Near Morinda

Punjab Law and order crisis: Influencer Manjeet Kaur abducted, burnt alive after attack near Morinda

‘Dimagi Naxals’ romanticising Mao, Stalin and Pol Pot

The Swadeshi movement turned Indian enterprise into a powerful force for economic self-reliance, national pride and the struggle for Swaraj

Building Economic Swaraj: How Indian enterprises fought foreign rule and reclaimed national pride

Prime Minsiter Narendra Modi and Uzbekistan President Shavkat Mirziyoyev

India-Uzbekistan Herald New Chapter: Uranium deal, 30-day visa-free entry to Indians & $5bn trade propel bilateral ties

The new FCRA rules seek to curb unchecked foreign funding, strengthen financial accountability, and protect Bharat’s national security

Stopping Unchecked Foreign Money: How new FCRA rules protect Bharat’s security and financial sovereignty

Keralam CM VD Satheeshan, DCC member Chembil Anil (Left to Right)

Keralam Congress infighting surfaces in CM VD Satheeshan’s vehicle blockade; DCC member Chembil Anil arrested, remanded

Indian Logistics Data Bank tracks ten crore containers, transforming freight visibility and strengthening the nation’s logistics network

From Lothal Dockyard to Ten Crore Containers: India’s Logistics Data Bank transforms EXIM freight tracking

Load More
  • Privacy
  • Terms
  • Cookie Policy
  • Refund and Cancellation
  • Delivery and Shipping

© Bharat Prakashan (Delhi) Limited.
Tech-enabled by Ananthapuri Technologies

  • Home
  • Search Organiser
  • Bharat
    • Assam
    • Bihar
    • Chhattisgarh
    • Jharkhand
    • Maharashtra
    • View All States
  • World
    • Asia
    • Africa
    • North America
    • South America
    • Europe
    • Australia
  • Editorial
  • Operation Sindoor
  • Opinion
  • Analysis
  • Defence
  • Culture
  • Sports
  • Business
  • RSS @ 100
  • Entertainment
  • More ..
    • Sci & Tech
    • Vocal4Local
    • Special Report
    • Education
    • Employment
    • Books
    • Interviews
    • Travel
    • Health
    • Politics
    • Law
    • Economy
    • Obituary
  • Subscribe Magazine
  • Read Ecopy
  • Advertise
  • Circulation
  • Careers
  • About Us
  • Contact Us
  • Policies & Terms
    • Privacy Policy
    • Cookie Policy
    • Refund and Cancellation
    • Terms of Use

© Bharat Prakashan (Delhi) Limited.
Tech-enabled by Ananthapuri Technologies