UPSC Mains — Previous Year Question
Question
Describe the context and salient features of the Digital Personal Data Protection Act, 2023.
Model Answer
The enactment of the Digital Personal Data Protection (DPDP) Act, 2023 establishes a statutory framework for data privacy in India, balancing the fundamental right to informational privacy under Article 21 with legitimate data processing needs in an expanding digital economy.
Context of the DPDP Act, 2023
- The Puttaswamy Verdict (2017): In Justice K.S. Puttaswamy v. Union of India, a nine-judge Supreme Court bench declared the Right to Privacy an inalienable fundamental right under Article 21, mandating a formal statutory data protection architecture.
- The Justice B.N. Srikrishna Committee Report (2018): Provided the foundational white paper and draft bill outlining data protection principles.
- Rapid Growth of the Digital Economy: With hundreds of millions of internet users and expanding fintech systems, increasing personal data generation highlighted risks of unmonitored data collection, identity theft, and corporate surveillance.
- Alignment with Global Data Privacy Frameworks: International standards like the European Union’s General Data Protection Regulation (GDPR) underscored the need for regulatory frameworks to facilitate secure cross-border trade and data flows.
- Replacing Inadequate Legacy Provisions: Addressed limitations in Section 43A of the Information Technology Act, 2000, which lacked comprehensive user rights and compliance mechanisms.
Salient Features of the DPDP Act, 2023
- Applicability and Scope: Applies to the processing of digital personal data within India, and to processing outside India if connected with offering goods or services to Data Principals in India.
- Core Institutional Roles:
- Data Principal: The individual to whom personal data relates.
- Data Fiduciary: The entity determining the purpose and means of data processing, responsible for statutory compliance.
- Consent Architecture: Data can generally be processed only for a lawful purpose after obtaining explicit, unambiguous, and revocable consent through clear notices, except for specified “legitimate uses” (e.g., state welfare delivery, medical emergencies).
- Rights of the Data Principal: Grants individuals the right to access summaries of their personal data, request correction or erasure, nominate representatives in case of death or incapacity, and access grievance redressal.
- Significant Data Fiduciaries (SDFs): Requires entities handling sensitive volumes of data to appoint a resident Data Protection Officer (DPO), engage independent data auditors, and conduct periodic Data Protection Impact Assessments (DPIAs).
- Protection of Children’s Data: Mandates verifiable parental consent before processing data of minors (under 18 years), prohibiting behavioral tracking, profiling, and targeted advertising directed at children.
- Establishment of the Data Protection Board of India (DPBI): Establishes the DPBI as an adjudicatory authority to investigate data breaches, adjudicate non-compliance, and resolve complaints.
- Substantial Financial Penalties: Replaces criminal imprisonment with civil financial penalties, reaching up to ₹250 crore for severe failures in preventing personal data breaches.
- Cross-Border Data Flows: Permits cross-border transfer of personal data to foreign jurisdictions, except to countries placed on a negative restricted list by the Central Government.
The DPDP Act, 2023 establishes legal protections for personal data within India’s digital ecosystem. Effective implementation will depend on the independent functioning of the Data Protection Board and transparent rules for statutory government exemptions.