EconReads
Donate

Digital Government in India

India's Data Protection Law

What the Digital Personal Data Protection Act, 2023 requires of companies and government, the rights it gives citizens, and the debates about exemptions.

As more of life goes online, personal data becomes valuable, and risky. India passed the Digital Personal Data Protection Act in August 2023.

Key features

  • Consent: organisations (called data fiduciaries) must generally get clear consent before processing personal data.
  • Purpose limitation: data should be used only for stated purposes.
  • Rights for individuals (data principals): to access, correct and erase their data, and to raise grievances.
  • Children’s data: stricter rules, including parental consent.
  • Data breaches must be reported.
  • Penalties of up to 250 crore rupees per instance for serious failures.
  • A Data Protection Board to enforce the law.

The government notified detailed rules in 2025, with phased implementation.

Exemptions and debates

Critics argued the law:

  • Gives the government broad powers to exempt its own agencies, for reasons such as national security.
  • Weakens the Right to Information Act regarding personal information of officials.
  • Lacks an independent regulator, since the Board is appointed by the government.

Supporters say it balances privacy with innovation and state needs.

Economic effects

  • Compliance costs for businesses.
  • Trust in digital services.
  • Potential data localisation requirements for some data.

Comparison

The EU’s GDPR (2018) is stricter in some respects and has an independent regulator.

The app permissions

A shopping app asks for access to a user's contacts and location. Under the DPDP Act, it must explain why and get clear consent, and the user can later withdraw consent and ask for data deletion.

Thinking the law restricts only companies

It applies to government too, though it allows broad exemptions for government agencies.

Key takeaways
  • The DPDP Act was passed in August 2023, with rules notified in 2025.
  • It requires consent, purpose limitation and breach reporting.
  • Penalties reach up to 250 crore rupees per instance.
  • Critics question government exemptions and the Board's independence.
3 min read

No recording for this one yet - EconReader can read it aloud for you.

Welcome to EconReads

This site is made for visually impaired learners, so our read-aloud reader is already switched on to help you explore hands-free.

You're in control - turn it off any time using the Reader button at the top of the page.

EconReader Ready