MENU
15 Jun 2026

What India's New Data Protection Law Gets Right and Wrong, Big Ideas Ep 74

Smriti Parsheera explores India's new data protection framework, examining how the 2023 Digital Personal Data Protection Act compares to global standards and what the creation of the Data Protection Board means for regulatory governance.

VIDEO BY
Smriti Parsheera

Smriti is a lawyer and public policy researcher. Her primary research interest lies in the study of digital technologies and their interaction with law and society, across areas such as digital access, privacy, data governance, digital public infrastructure, and artificial intelligence.

Abstract

India has finally enacted comprehensive data protection legislation after years of deliberation, but the final law differs significantly from both earlier drafts and international standards. The Digital Personal Data Protection Act of 2023, along with recently notified rules and the creation of the Data Protection Board, represents a milestone in Indian privacy regulation—yet one that prioritizes state and industry interests over individual protections.

Parsheera traces the law's origins to concerns around the Aadhaar project and the Supreme Court's Puttaswamy judgment recognizing privacy as a fundamental right. However, the enacted version represents a substantial departure from initial proposals, featuring limited scope (covering only digital data), fewer individual rights, and a notably weak regulatory structure. The transition from a proposed "Data Protection Authority" to a "Data Protection Board" exemplifies this shift, creating an agency with minimal independence and no rule-making powers.

Despite these limitations, Parsheera argues this marks only the dawn of data protection regulation in India, with potential for evolution through judicial intervention, legislative amendments, and the board's own choices in exercising its limited mandate.

Citation

Parsheera, Smriti, and Nevin George. "What India's New Data Protection Law Gets Right and Wrong." Episode 74 of Big Ideas. XKDR Forum, June 15, 2026. Video, 0:15:45. https://www.xkdr.org/viewpoints/what-indias-new-data-protection-law-gets-right-and-wrong-big-ideas-ep-74

Key Insights

  • India's data protection law emerged from two key pressures: privacy concerns around the Aadhaar biometric identity project and the IT services industry's need to demonstrate credibility in handling outsourced data
  • The Supreme Court's Puttaswamy judgment established both negative and positive obligations for privacy rights—not only preventing government interference but requiring legal frameworks to prevent others from violating privacy
  • The final 2023 law differs substantially from earlier drafts, covering only digital personal data rather than all personal data, excluding physical records and analog information
  • Key individual rights found in international standards are missing, including the right to be forgotten and data portability rights that allow automatic transfer between service providers
  • The law adopts a "blacklisting approach" to cross-border data transfers, permitting all transfers unless specifically restricted by government order, rather than requiring positive safeguards
  • The shift from "Data Protection Authority" to "Data Protection Board" represents a significant weakening of regulatory independence, despite the nomenclature not being consistently meaningful across Indian law
  • Analogy: The original proposal envisioned the regulator as "a mini state" with regulation-making, enforcement, and adjudication functions, but the final board lacks rule-making powers entirely
  • The Data Protection Board lacks standard markers of regulatory independence: no financial autonomy, no power to appoint employees without government approval, and complete dependence on government grants
  • The board is legally required to function as a "digital office," adopting techno-legal measures for hearings, complaints, and penalties, potentially enhancing transparency
  • Regulatory agencies in India often evolve through judicial intervention and legislative amendments, as seen with the Competition Commission and Telecom Regulatory Authority, suggesting potential future strengthening

Notes

The long road from Aadhaar to data protection

India's data protection journey began not with abstract privacy concerns but with very concrete fears about government surveillance. When the Aadhaar biometric identification project launched in 2009-2010, it immediately triggered debates about collecting sensitive biometric data without any privacy framework in place. This created the first serious push for data protection legislation through the Justice AP Shah Committee.

Simultaneously, India's booming IT services industry faced its own pressures. As companies handled increasing volumes of outsourced data from international clients, they needed the government to demonstrate credibility in data management. The industry itself began advocating for data protection regulation to reassure foreign partners about India's commitment to secure data handling.

Smriti explains the dual motivation:

"The need was being felt by the industry itself that the government needs to have data protection regulation to show credibility to the outside world about the fact that we are serious about how we manage your data that comes into our country."

These parallel concerns set the stage for what would become a decades-long policy development process, though the first phase of deliberations didn't immediately materialize into law.

From privacy rights to positive obligations

The breakthrough came through constitutional litigation. When Aadhaar faced Supreme Court challenges, the resulting Puttaswamy judgment established privacy as a fundamental right with both negative and positive dimensions. The negative aspect prevents government interference in personal life and improper data handling. But crucially, the positive aspect creates an affirmative obligation for the state to establish legal frameworks preventing others from violating privacy rights.

This positive obligation became the constitutional trigger requiring the government to create a comprehensive data protection law. During court proceedings, government representatives committed to establishing such a framework, transforming what had been policy discussions into constitutional necessity.

The Supreme Court's framework provided the legal foundation, but the path from constitutional principle to enacted legislation proved complex. The law went through five to six different versions over several years, with each iteration reflecting evolving political and economic priorities.

How India diverges from global standards

India's final approach differs markedly from international frameworks like GDPR and even laws in other BRICS countries. The divergences begin with basic scope - India's law covers only digital data, excluding analog records and physical documents that remain common in many sectors.

The rights and protections are notably more limited. Key omissions include the right to be forgotten, which courts are developing separately through case law, and data portability rights that allow users to transfer information between service providers in interoperable formats.

Cross-border data transfers represent perhaps the most significant departure from global norms. Instead of requiring comparable protections in destination countries or specific conditions for transfers, India adopted what Smriti calls a "blacklisting approach." All transfers are permitted unless the government specifically restricts certain countries or imposes conditions through administrative orders.

Smriti notes the broader pattern:

"Many people would agree that the law as finally enacted does both of those things very often at the cost of the protection and the quality of protection that has been given to the end user who is the principal who is supposed to be the ultimate beneficiary of that law."

The framework prioritizes state surveillance capabilities and industry operational flexibility, sometimes at the expense of individual privacy protections.

The Data Protection Board's constrained independence

One of the most significant changes between early drafts and the final law involved transforming the proposed Data Protection Authority into the current Data Protection Board. This shift reflects more than nomenclature—it represents a fundamental restructuring of regulatory power.

Research comparing the Board to other Indian regulators reveals substantial constraints on independence. Unlike bodies such as SEBI or the Competition Commission, the Data Protection Board cannot make its own regulations. All significant policy decisions—from consent mechanisms to cross-border transfer rules—remain with the government through the rule-making process.

The Board also lacks financial autonomy, depending entirely on government grants rather than having independent funding sources. It cannot hire employees or set employment terms without government approval, further limiting operational independence.

Smriti describes the theoretical framework for regulatory authorities:

"A regulatory authority is like a mini state which has slivers of regulation making, enforcement and adjudication functions. And if you try to apply that to the Data Protection Board, you see a whole set is completely missing because it has no power to make regulations."

However, the law does include some positive innovations. The Board must function as a "digital office," using technology for all operations from grievance handling to penalty proceedings. This technological mandate should theoretically enable greater transparency, though actual transparency will depend on the Board's voluntary choices rather than legal requirements.

Signaling progress despite structural limitations

Despite its limitations, the law's enactment represents significant progress after years of regulatory uncertainty. Companies can finally develop compliance strategies around known requirements rather than guessing about future regulations. The phased implementation timeline over 18 months provides additional clarity for business planning.

The regulatory structure, while constrained, could evolve through multiple mechanisms. Indian regulatory bodies have historically undergone significant reforms when initial structures prove inadequate. The Competition Commission faced years of litigation over its structure, while the Telecom Regulatory Authority saw major changes to its adjudicatory powers just years after creation.

Courts could also play a role if the Board's limited powers prove insufficient for protecting privacy rights established in Puttaswamy. Additionally, the Board itself has opportunities to demonstrate effectiveness within its constrained mandate through voluntary transparency and public participation.

Smriti concludes with cautious optimism:

"This is only the starting point. And we know from the history of other authorities in India that very often if there is something remiss in the way an agency is structured or it exercises its powers in a manner which is deemed insufficient, you do have the courts, very often the legislature will step in and make amendments to the law."

The current framework establishes a foundation that, while imperfect, creates space for future evolution toward more robust privacy protections as India's digital economy continues expanding.

Supplementary Resources

The complete transcript file is available to download below.

Access It