
The Digital Personal Data Protection (DPDP) Act, 2023
#GS-2 #Indian Polity & Constitution #Constitution #Governance & Social Justice #Regulatory Bodies #E-Governance #Current Events #National #GS-3 #Science & Technology #Cyber Security #ICT #DPDP Act 2023 #Data Privacy
Key takeaways
- The Centre directed government entities to prepare time-bound implementation plans for the Digital Personal Data Protection (DPDP) Act, 2023.
- Built on the SARAL approach, the law provides statutory backing to the privacy principles set in the landmark Puttaswamy judgement (2017).
- Violations carry severe non-criminal financial penalties, including up to ₹250 crore for security failures and ₹200 crore for child privacy breaches.
- The legislation establishes the Data Protection Board of India (DPBI) as the adjudicatory body with appeals heard by TDSAT.
Why in News
- The central government initiated a major compliance drive for the Digital Personal Data Protection (DPDP) Act, 2023.
- It directed all central ministries, States, and Union Territories to create time-bound implementation plans and appoint nodal officers.
- Under these directives, government Data Fiduciaries must perform comprehensive data audits, improve cybersecurity systems, and integrate privacy-by-design features directly into their digital platforms.
Overview of DPDP Act 2023
- The DPDP Act, 2023 serves as India's primary law for regulating the processing of digital personal data.
- This framework follows the SARAL approach, which stands for Simple, Accessible, Rational, and Actionable.
- The law defines statutory rights for citizens called Data Principals, creates legal duties for data collectors known as Data Fiduciaries, and grants enforcement powers to the Data Protection Board of India (DPBI).
- The main aim of this law is to protect individual privacy while allowing data processing for lawful, legitimate, and national development purposes.
Key Features of the DPDP Act
- The act covers digital personal data processed within India as well as foreign data processing linked to offering goods or services to people in India.
- Data processing requires prior clear notice along with free, explicit, and informed consent.
- Consent is exempted for specific uses like government subsidies, emergency medical care, voluntary data submissions, and employment requirements.
- Citizens receive strong rights including accessing their data processing summary, requesting data correction or erasure, registering grievances, and nominating legal representatives upon death or incapacity.
- To safeguard children, the law bans behavioral tracking, targeted advertising, and harmful data processing, requiring verifiable parental consent before collecting child data.
- The Data Protection Board of India (DPBI) acts as the primary adjudicating authority, with appeals directed to TDSAT.
- Failing to maintain reasonable security safeguards to prevent data breaches carries financial penalties up to ₹250 crore.
- Failing to report data breaches or violating child privacy rules can attract penalties up to ₹200 crore.
- General statutory violations carry fines up to ₹50 crore.
Significance of the Legislation
- The law gives statutory effect to the constitutional privacy principles established in the landmark Puttaswamy judgement (2017).
- It permits cross-border data transfers unless specifically restricted, supporting Indian IT exports, cloud services, and foreign investment in the digital economy.