§Legal Chronicle
Editorial · Perspective

Why Personal Data Protection Needs Teeth, Not Just Text

The Digital Personal Data Protection Act gives India its first comprehensive data law. Whether it changes anything depends on an enforcement body that doesn't exist yet.

Aditi Rao1 July 20266 min read2 sources
Stance
Opinion: the author argues enforcement infrastructure, not statutory language, will determine whether the DPDP Act succeeds.
Editorial · Perspective

The Digital Personal Data Protection Act, 2023, was, on the day it passed, treated as a milestone — India's first dedicated data protection statute, arriving after years of committee reports, draft bills and a Supreme Court judgment that had already declared privacy a fundamental right. That framing is not wrong. It is also not the part that will matter most.

This is an opinion piece, not a case report: everything that follows is the author's argument, not a neutral summary of settled law.

A statute is a promise, not a mechanism

The Act's core architecture is sound on paper. It requires consent for processing personal data, gives individuals rights to access and correct their data, creates a category of 'significant data fiduciaries' subject to heavier obligations, and sets out penalties that can run into hundreds of crores of rupees for serious breaches. None of that does anything by itself. A right to correct your data is only as real as the body you can complain to when a company ignores your correction request.

The Data Protection Board is the whole ballgame

That body is the Data Protection Board of India, an adjudicatory authority the Act itself creates. Its design choices — how it's staffed, how independent it is from the government whose own agencies are frequently exempted from parts of the Act, how quickly it can move on a complaint — will do more to determine whether Indian data protection is real than any clause in the statute itself. A board that is slow, under-resourced, or reluctant to rule against large or state-linked processors turns a strong law into a strong-looking law.

Enforcement infrastructure is not an implementation detail. For a statute like this, it is the statute.

The government-exemption problem

The Act also carries broad exemptions for processing carried out by the state in the interest of sovereignty, security and public order — categories broad enough to cover a great deal, if applied loosely. A law that regulates private companies tightly while leaving the largest data processor in the country, the state itself, subject to looser scrutiny is not neutral between citizen and government. It is a choice, and one worth naming plainly rather than treating as a technical footnote.

What would actually count as success

Not the number of consent pop-ups Indian users now see. Not the existence of a grievance officer email address on every app's privacy policy. Success looks like a Data Protection Board that rules against powerful processors often enough that compliance becomes cheaper than violation — for private companies and government bodies alike. Until that track record exists, the right assessment of the DPDP Act is 'promising framework, unproven enforcement', not 'India has solved data protection'.

References

  1. [1]Digital Personal Data Protection Act, 2023 — Statute.
  2. [2]K.S. Puttaswamy v. Union of India, (2017) 10 SCC 1 — Supreme Court of India — constitutional basis for the right to privacy.
Written by
AR
Aditi Rao

Aditi studies law with a focus on how courts are adapting constitutional doctrine to digital-age questions. She founded Legal Chronicle to give student legal writing a more rigorous, research-first home.