Data Privacy and Protection for Companies in India

Introduction

For nearly two decades, India’s data protection regime rested on the thin scaffolding of the Information Technology Act, 2000[1] and its subordinate rules, widely seen as inadequate for a modern data economy. The turning point came in August 2017, when a nine-judge Constitution Bench of the Supreme Court, in Justice K.S. Puttaswamy (Retd.) v. Union of India[2], unanimously declared the right to privacy a fundamental right under Article 21 and Part III of the Constitution. That verdict triggered a legislative process, anchored in the Srikrishna Committee’s recommendations[3], culminating in the Digital Personal Data Protection Act, 2023.[4] The Ministry of Electronics and Information Technology (MeitY) notified the implementing DPDP Rules, 2025 on 13 November 2025, setting a phased timeline with full compliance by 13 May 2027.

Historical Evolution of Data Protection Law in India

The IT Act, 2000 and the SPDI Rules, 2011

Section 43A of the IT Act imposed civil liability on corporate bodies that negligently handled ‘sensitive personal data or information’ (SPDI), while Section 72A created criminal liability for disclosing personal information in breach of a lawful contract.[5]  The regime, however, applied only to ‘bodies corporate,’ lacked an independent supervisory authority, imposed no mandatory breach notification, and gave individuals no rights beyond consent withdrawal.

The Srikrishna Committee and the Path to the DPDP Act

After Puttaswamy, the Government constituted the Committee of Experts on Data Protection chaired by retired Justice B.N. Srikrishna.[6] Its 2018 report and draft Bill introduced a consent-centric framework, recognised special categories of sensitive data, and proposed an independent Data Protection Authority. Successive versions — the 2019 Bill (referred to a Joint Parliamentary Committee) and the 2022 draft — drew criticism over broad government exemptions and weak regulatory independence, before the final version received Presidential assent on 11 August 2023 as the DPDP Act, 2023.

The DPDP Act, 2023: Key Provisions

The DPDP Act governs processing of ‘digital personal data’ within India, whether collected digitally or digitised later, and reaches extra-territorially where processing outside India relates to offering goods or services to Data Principals[7] within India. It creates a binary framework: a ‘Data Fiduciary’[8] determines the purpose and means of processing; a ‘Data Processor’ processes data on the Fiduciary’s behalf under contract

The Act adopts consent as the primary lawful ground for processing,[9] requiring it to be free, specific, informed, unconditional, and unambiguous, given through a clear affirmative act.[10]  Beyond consent, ‘legitimate uses’ permit processing without explicit consent — including voluntary sharing, compliance with court orders, employment-related processing, and medical emergencies.

Section 8 imposes absolute, non-delegable obligations on Data Fiduciaries, who remain vicariously liable for their Processors and cannot contractually exclude this liability. On a breach, the Fiduciary must notify both the Board and affected Data Principals without delay,[11] and the DPDP Rules, 2025 require a detailed breach report within seventy-two hours of becoming aware, regardless of magnitude or risk of harm.[12]

Section 17 exempts consent and notice requirements for processing by courts and tribunals, enforcement of legal rights, state security and public order, and research and archiving.[13] Penalties are graduated: up to ₹250 crore for failing to implement reasonable security safeguards; ₹200 crore for failing to notify a breach; ₹150 crore for breaching SDF obligations; and ₹50 crore for other contraventions.[14]

Judicial Landscape: Case Laws Shaping Data Privacy

Puttaswamy v. Union of India (2017) — The Right to Privacy Judgment

The foundational case is Justice K.S. Puttaswamy (Retd.) v. Union of India[15], where a nine-judge Bench unanimously held privacy fundamental under Articles 14, 19, and 21, overruling M.P. Sharma v. Satish Chandra (1954) and Kharak Singh v. State of Uttar Pradesh (1963). Justice D.Y. Chandrachud held that informational privacy is inseparable from this right, and any infringement must satisfy legality, legitimate aim, and proportionality

The Aadhaar Litigation and Restrictions on Private Entities

The Aadhaar-II judgment (2018)[16] upheld the Aadhaar Act’s constitutionality but struck down provisions compelling private companies — banks and telecom providers — to mandatorily link services to Aadhaar, as disproportionately infringing privacy without adequate statutory backing. It remains relevant to companies processing government identification data, establishing that private entities cannot compel Aadhaar biometric collection absent express legislative authority.

The Right to Be Forgotten: Evolving High Court Jurisprudence

India has no codified right to be forgotten (RTBF), but High Court jurisprudence recognises it as emanating from Article 21. In 2016, the Kerala High Court directed Indian Kanoon to remove a judgment disclosing a rape survivor’s identity, finding no legitimate public interest in perpetuating it,[17] while the Karnataka High Court in Sri Vasunathan v. Registrar General (2017)[18] ordered redaction of a petitioner’s daughter’s name from court records, acknowledging RTBF as an evolving principle. The Delhi High Court in Zulfiqar Ahman Khan v. Quintillion Business Media (2019)[19] further held that RTBF and the ‘right to be let alone’ are enforceable even against private actors, including media organisations.

Enforcement Architecture and Prevailing Trends

The DPDP Act establishes the Data Protection Board of India[20] as the primary enforcement authority, a digital-by-design institution where complaints are filed online, and appeals lie to TDSAT.[21] The Board monitors compliance, investigates breaches, and may recommend blocking persistently non-compliant Fiduciaries, though its independence remains a concern since members are appointed and removable by the Central Government, unlike the GDPR’s independent supervisory authorities.

The IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021[22] add obligations such as appointing a Grievance Officer, publishing privacy policies, and removing privacy-invasive content — together forming a multi-layered compliance framework for Indian businesses.

Conclusion

India’s data protection framework has evolved from the IT Act, 2000 and the Puttaswamy judgment to the consent-centric DPDP Act and Rules, shifting companies from negligence-based liability to comprehensive fiduciary accountability across the data lifecycle.

Questions remain on the validity of broad government exemptions, the Board’s independence, and the pending RTBF ruling. Companies will be best placed by treating privacy as a core organisational value rather than merely a legal obligation.


[1]Information Technology Act, No. 21 of 2000, India Code (2000).

[2]Justice K.S. Puttaswamy (Retd.) & Anr. v. Union of India & Ors., (2017) 10 SCC 1 (India).

[3]Ministry of Electronics and Information Technology, Report of the Committee of Experts on a Data Protection Framework for India (Justice B.N. Srikrishna, Chair, 2018).

[4]Digital Personal Data Protection Act, No. 22 of 2023, India Code (2023) [hereinafter DPDP Act].

[5]Information Technology Act, No. 21 of 2000, § 43A (India); id. § 72A (providing punishment for disclosure of information in breach of lawful contract).

[6]Ministry of Electronics and Information Technology, Government of India, Report of the Committee of Experts on a Data Protection Framework for India (Justice B.N. Srikrishna, Chair, 2018).

[7]DPDP Act, supra note 4, § 2(j) (defining ‘Data Principal’ as ‘the individual to whom the personal data relates’).

[8]DPDP Act, supra note 4, § 2(i) (defining ‘Data Fiduciary’ as ‘any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data’).

[9]DPDP Act, supra note 4, §§ 4–6.

[10]DPDP Act, supra note 4, § 6(1) (consent must be ‘free, specific, informed, unconditional and unambiguous with a clear affirmative action’).

[11]DPDP Act, supra note 4, § 8(6) (requiring intimation to the Board and affected Data Principals upon a personal data breach).

[12]Digital Personal Data Protection Rules, 2025, Ministry of Electronics and Information Technology, G.S.R. 846(E) (Nov. 13, 2025) [hereinafter DPDP Rules], r. 7.

[13]DPDP Act, supra note 4, § 17 (exempting processing necessary for enforcement of legal rights and claims, courts and tribunals, state security, research, and archiving).

[14]DPDP Act, supra note 4, Schedule (imposing a penalty of up to ₹250 crore for failure to implement reasonable security safeguards; ₹200 crore for failure to report a breach; ₹150 crore for breach of Significant Data Fiduciary obligations; and ₹50 crore for other contraventions).

[15]Justice K.S. Puttaswamy (Retd.) v. Union of India, supra note 2.

[16]Justice K.S. Puttaswamy (Retd.) v. Union of India, (2018) 1 SCC 809 (India) (Aadhaar-II judgment, upholding constitutionality of Aadhaar but restricting mandatory linking by private entities).

[17]Kerala High Court, W.P. (C) No. 9478 of 2016 (directing Indian Kanoon to remove a judgment revealing the identity of a rape victim on right to privacy grounds).

[18]Sri Vasunathan v. The Registrar General, High Court of Karnataka & Ors., W.P. No. 62038 of 2016 (Karn. 2017) (acknowledging the right to be forgotten as an evolving principle).

[19]Zulfiqar Ahman Khan v. Quintillion Business Media Pvt. Ltd. & Ors., 2019 SCC OnLine Del 8494 (Delhi HC 2019).

[20]DPDP Act, supra note 4, §§ 27–30; DPDP Rules, supra note 12, rr. 14–20 (establishing the Data Protection Board of India, its composition, functions and powers).

[21]DPDP Act, supra note 4, § 29 (appeals from Board decisions lie to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT)).

[22]Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, Ministry of Electronics and Information Technology, G.S.R. 139(E) (Feb. 25, 2021).

Written by:

Sakshi
Legal Intern (1st April 2026-1st May 2026)
3rd-year B.A. LL.B. Student
Army Institute of Law, Sector 68, Mohali, Punjab

Related articles