The Digital Personal Data Protection Act, 2023, was, on the day it passed, treated as a milestone — India's first dedicated data protection statute, arriving after years of committee reports, draft bills and a Supreme Court judgment that had already declared privacy a fundamental right. That framing is not wrong. It is also not the part that will matter most.
This is an opinion piece, not a case report: everything that follows is the author's argument, not a neutral summary of settled law.
A statute is a promise, not a mechanism
The Act's core architecture is sound on paper. It requires consent for processing personal data, gives individuals rights to access and correct their data, creates a category of 'significant data fiduciaries' subject to heavier obligations, and sets out penalties that can run into hundreds of crores of rupees for serious breaches. None of that does anything by itself. A right to correct your data is only as real as the body you can complain to when a company ignores your correction request.
The Data Protection Board is the whole ballgame
That body is the Data Protection Board of India, an adjudicatory authority the Act itself creates. Its design choices — how it's staffed, how independent it is from the government whose own agencies are frequently exempted from parts of the Act, how quickly it can move on a complaint — will do more to determine whether Indian data protection is real than any clause in the statute itself. A board that is slow, under-resourced, or reluctant to rule against large or state-linked processors turns a strong law into a strong-looking law.
Enforcement infrastructure is not an implementation detail. For a statute like this, it is the statute.
The government-exemption problem
The Act also carries broad exemptions for processing carried out by the state in the interest of sovereignty, security and public order — categories broad enough to cover a great deal, if applied loosely. A law that regulates private companies tightly while leaving the largest data processor in the country, the state itself, subject to looser scrutiny is not neutral between citizen and government. It is a choice, and one worth naming plainly rather than treating as a technical footnote.
What would actually count as success
Not the number of consent pop-ups Indian users now see. Not the existence of a grievance officer email address on every app's privacy policy. Success looks like a Data Protection Board that rules against powerful processors often enough that compliance becomes cheaper than violation — for private companies and government bodies alike. Until that track record exists, the right assessment of the DPDP Act is 'promising framework, unproven enforcement', not 'India has solved data protection'.
References
- [1]Digital Personal Data Protection Act, 2023 — Statute.
- [2]K.S. Puttaswamy v. Union of India, (2017) 10 SCC 1 — Supreme Court of India — constitutional basis for the right to privacy.
Aditi studies law with a focus on how courts are adapting constitutional doctrine to digital-age questions. She founded Legal Chronicle to give student legal writing a more rigorous, research-first home.