This is an archive article published on March 19, 2025
Premium

India’s Data Protection Law: Simple, consent-driven and business-friendly

The key challenge of data protection law lies in effective implementation. India’s Data Protection Board must demonstrate real independence and hold both government agencies and corporations accountable

data protection lawIndia’s Data Protection Board must demonstrate real independence and hold both government agencies and corporations accountable, while enhancing user rights. (Representative/Canva)
6 min readMar 19, 2025 01:34 PM IST First published on: Mar 19, 2025 at 01:34 PM IST

The origin of the Digital Personal Data Protection Act (DPDPA), 2023, considered to be India’s first comprehensive data protection law, lies in the Supreme Court’s landmark judgment in Justice K S Puttaswamy vs Union of India (2017), that recognised the right to privacy as a fundamental right under Article 21 of the Constitution. In 2017, the union government constituted an expert committee, chaired by Justice B N Srikrishna, to draft a data protection framework, leading to the introduction of the Personal Data Protection Bill in 2018. A revised version was subsequently tabled in the Parliament in 2019. Addressing various concerns, the Bill was withdrawn in August 2022, followed by an introduction of the DPDP bill, 2023, which was passed by Parliament and received presidential assent on August 11, 2023, formally enacting the DPDPA. To operationalise the Act, the government released the corresponding draft rules in January 2025, setting the stage for its implementation.

However, to place this policy in a global context, it is essential to draw comparisons between the DPDPA and the European Union (EU)’s General Data Protection Regulation (GDPR). Such comparisons would help understand how India’s framework aligns with or diverges from international standards in data protection as both regulations seek to protect individuals’ personal data rights.

Latest Comment
Post Comment
Read Comments