Introduction
In an era where smartphones, social media platforms, and cloud services pervade daily life, personal data has become both a vital resource and a potential vulnerability. The Indian legal landscape now rests on two pillars: the Supreme Court’s affirmation that privacy is a fundamental right under Article 21 of the Constitution and the enactment of the Digital Personal Data Protection Act, 2023 (DPDPA), supplemented by the draft Digital Personal Data Protection Rules, 2025. Together, these frameworks aim to regulate state surveillance, ensure corporate accountability, and empower individuals to control their digital footprints.
Constitutional Foundations and Judicial Doctrines
The watershed moment in India’s privacy jurisprudence was the Supreme Court’s judgment in Justice K.S. Puttaswamy v. Union of India (2017), which unanimously recognized privacy as an essential facet of “life and personal liberty” guaranteed by Article 21. The five-judge bench formulated a three-fold test—legality, necessity, and proportionality—to evaluate any state interference with privacy. Under this test, legislation must clearly authorize intrusion, pursue a legitimate state aim (such as national security or public health), and employ the least intrusive means available. Crucially, Puttaswamy rejected the third-party doctrine: data held by private entities (telecom operators, cloud providers) cannot be accessed by the government without due process and judicial oversight similar to a search warrant.
Subsequent rulings have extended these principles to the digital realm. In matters of metadata and location tracking, courts have signaled that retrospective acquisition of communication records demands prior judicial sanction. Bulk surveillance initiatives—exemplified by the Aadhaar ecosystem—face heightened scrutiny to ensure minimal impairment to privacy. The Court’s insistence on judicial warrants for digital searches echoes the U.S. Supreme Court’s approach in Carpenter v. United States (2018), where warrantless access to cell-site location information was deemed unconstitutional despite carriers’ role as third-party data custodians.
The Digital Personal Data Protection Act, 2023
To translate constitutional mandates into operational rules, Parliament enacted the DPDPA. The Act applies to any “digital personal data” collected or processed in India and extends extraterritorially to entities offering goods or services to Indian residents. It establishes a set of rights for “data principals” (individuals) and obligations for “data fiduciaries” (entities that determine the purpose and means of processing).
Data principals may exercise the following rights:
- Access and Correction: Individuals can obtain confirmation of whether their data is processed and rectify inaccuracies.
- Erasure (“Right to be Forgotten”): Upon withdrawal of consent or completion of processing purposes, fiduciaries must delete personal data.
- Consent Withdrawal: Principals can revoke consent at any time, compelling fiduciaries to cease processing.
- Nomination: Individuals may appoint a nominee to exercise rights in cases of incapacity or death.
- Grievance Redressal: Principals can lodge complaints with the Data Protection Board of India, which must resolve disputes within ninety days.
Data fiduciaries must adhere to the principles of lawful, fair, and transparent processing, collect only data necessary for specified purposes, ensure accuracy, implement reasonable security measures, and notify the Board and affected principals of breaches within seventy-two hours. Privacy notices must detail the categories of data collected, processing purposes, and data principal rights in one of India’s official languages. The Act prescribes penalties up to ₹50 crore for non-compliance, underscoring the government’s commitment to enforcement.
However, certain exemptions have sparked debate. State processing for national security, public order, or crime prevention lies outside the Board’s jurisdiction, potentially diluting the proportionality requirement when agencies invoke broad “public interest” grounds. Additionally, by covering only data that is initially digital, the Act leaves ambiguity over records digitized retrospectively, and it omits an explicit data portability right, limiting individuals’ ability to transfer data across service providers.
Draft Digital Personal Data Protection Rules, 2025
To operationalize the DPDPA, the Ministry of Electronics and Information Technology released draft Rules in January 2025. These Rules classify “Significant Data Fiduciaries” based on data volume, sensitivity, and impact, requiring them to conduct annual Data Protection Impact Assessments and appoint a Data Protection Officer. Rules specify verifiable parental consent mechanisms for processing minors’ data, retention limits, and deletion of inactive data after three years, with 48-hour advance notice. They also mandate that consent managers be Indian-incorporated entities with certified interoperable platforms, ensuring local control over consent infrastructure. Cross-border transfers must comply with government-issued guidelines, reflecting a cautious approach to data sovereignty. Exemptions for healthcare, education, and childcare data recognize sector-specific necessities while maintaining principles of purpose limitation and security.
Impact of the Pegasus and Aadhaar Controversies
High-profile surveillance allegations have tested India’s privacy safeguards. Amnesty International’s investigation revealed targeted deployment of Pegasus spyware—capable of exfiltrating messages, calls, and location—against journalists and activists without judicial oversight. In response, the Supreme Court appointed a technical committee to examine suspected devices, raising urgent questions about surveillance oversight, state accountability, and redress mechanisms.
The Aadhaar ecosystem’s mandatory biometric identification for welfare schemes prompted intense litigation culminating in the 2018 judgment on the Aadhaar Act. The Court upheld the Act’s constitutional validity but struck down provisions allowing private entities to demand Aadhaar for KYC authentication and curtailed storage of transaction metadata beyond six months. It reaffirmed that any expansion of state access must satisfy proportionality and purpose tests, underscoring the need for robust data protection mechanisms before further extension of biometric identification systems.
Practical Takeaways and Compliance Roadmap
Organizations processing personal data in India must integrate “privacy by design” across their operations. From initial product development, consent flows should be granular and revocable, and purposes for data collection strictly defined. High-risk processing—such as profiling or minors’ data—must undergo impact assessments, and Data Protection Officers should manage regulatory submissions and breach responses. Privacy notices must be comprehensible and localized, while staff training and quarterly audits can sustain a culture of data governance. Meanwhile, individuals should remain vigilant: exercise access, correction, and erasure rights; monitor privacy notices; and utilize grievance redressal mechanisms.
Conclusion
India’s digital privacy regime now stands on a robust constitutional foundation and a tailored statutory framework. Courts demand judicial warrants for state intrusions and insist on proportionality, while the DPDPA and draft Rules articulate statutory rights and duties that reflect global best practices. As the digital ecosystem evolves—with AI, Internet of Things, and cross-border data flows—ongoing review, rulemaking, and judicial vigilance are essential to ensure that privacy rights keep pace with technological advances.
