Digital Personal Data Protection Act, 2023: What Individuals and Businesses Should Know

Understanding India’s new framework for protecting personal data in an increasingly digital world

Every day, people share their personal information with businesses and online platforms, often without giving much thought to what happens to that information afterwards. From ordering food and shopping online to making digital payments, booking travel, using social media and signing up for mobile applications, personal data has become an integral part of everyday life.

For businesses, personal data has also become an important part of operations. Companies collect information about customers, employees, vendors and users for a variety of purposes. With the rapid growth of India’s digital economy, the need for a clear legal framework governing such information has become increasingly important.

The Digital Personal Data Protection Act, 2023, commonly referred to as the DPDP Act, is India’s principal legislation dealing with the processing of digital personal data. The Act seeks to balance an individual’s right to protect personal data with the need to process such data for lawful purposes.

The law is therefore relevant not only to large technology companies, but also to businesses and individuals who interact with the digital ecosystem in their everyday lives.

What does the DPDP Act cover?

The Act applies to the processing of digital personal data in India where the personal data is collected in digital form, or where it is collected in non digital form and subsequently digitised.

It can also apply to processing outside India where the processing is connected with offering goods or services to individuals in India.

At the same time, the Act excludes certain situations, including personal or domestic use and certain personal data that has been made publicly available by the individual or by a person who is legally required to make it publicly available.

This makes the legislation relevant to a wide range of activities involving digital information.

Who is a Data Principal?

The DPDP Act uses the term “Data Principal” for the individual to whom the personal data relates.

In simple terms, if a company has your name, telephone number, email address or other personal information, you are the Data Principal in relation to that information.

The organisation determining the purpose and means of processing personal data is referred to as the “Data Fiduciary”. An organisation that processes personal data on behalf of a Data Fiduciary is called a “Data Processor”.

The Act also provides for a category known as a Significant Data Fiduciary, which may include organisations whose activities involve larger volumes or more sensitive categories of personal data or may have a greater impact on individuals or public interests.

Consent is an important part of the framework

One of the important principles under the Act is that personal data must be processed for a lawful purpose.

Where processing is based on consent, the Act requires consent to be free, specific, informed and unambiguous. It must involve a clear affirmative action by the individual and should be limited to the personal data necessary for the specified purpose.

The ability to withdraw consent is also recognised. An individual can withdraw consent at any time, and withdrawing consent should be as easy as giving it.

For individuals, this means that consent is not intended to be an unlimited permission for the use of personal information. For businesses, it means that the way consent is obtained and managed becomes an important part of compliance.

Individuals have specific rights

The DPDP Act gives individuals a number of rights in relation to their personal data.

A Data Principal has the right to obtain information about the personal data being processed and certain information relating to its processing.

The Act also provides rights relating to the correction, completion and updating of personal data and, subject to the applicable requirements, erasure of personal data.

These rights are important because personal information may not always remain accurate or relevant. A person may change their address, telephone number or other details, or may wish to understand what information an organisation continues to hold about them.

The law therefore gives individuals a more active role in relation to their personal information.

What if your personal data rights are violated?

The DPDP Act provides individuals with a clear mechanism to seek redressal when they believe their personal data rights have been violated.

A Data Principal can first raise a grievance with the Data Fiduciary or Consent Manager through the grievance redressal mechanism made available by them. If the grievance remains unresolved, the matter may be taken before the Data Protection Board of India, whose orders can be challenged before the Appellate Tribunal.

The Act also provides for mediation and voluntary undertakings as additional mechanisms for resolving or addressing certain matters.

The existence of a grievance mechanism is significant because data protection is not limited to setting out rights on paper. It also provides individuals with a framework through which concerns can be raised.

Children receive additional protection

Children’s use of digital platforms has increased considerably, making the protection of children’s personal information an important concern.

The DPDP Act provides additional safeguards for the processing of children’s personal data. It requires verifiable parental or guardian consent and places restrictions on certain activities, including tracking or behavioural monitoring of children and targeted advertising directed at children, subject to the exceptions provided under the law.

The Act also gives the Central Government the power to provide exemptions in certain circumstances where the prescribed conditions are met.

These provisions recognise that children may require a higher level of protection in the digital environment.

Businesses have responsibilities too

The DPDP Act is not only about giving rights to individuals. It also places responsibilities on organisations that process personal data.

Businesses need to understand what personal data they collect, why they collect it, how it is processed and who has access to it.

They also need to consider the security measures used to protect personal data and the procedures followed when a data breach occurs.

For organisations, data protection is therefore not simply an information technology issue. It can involve legal agreements, internal policies, employee practices, technology systems and business processes.

A company dealing with personal data should be able to identify what information it holds and the purpose for which it is being processed.

Significant Data Fiduciaries

The Act recognises that some organisations may present greater risks because of the nature or scale of the personal data they process.

The Central Government may notify an organisation as a Significant Data Fiduciary after considering factors such as the volume and sensitivity of personal data, risks to the rights of individuals and potential implications for India’s sovereignty, security and other public interests.

Significant Data Fiduciaries have additional responsibilities. These include appointing a Data Protection Officer in India, appointing an independent data auditor and undertaking periodic data protection impact assessments and audits.

What happens in the event of a data breach?

A data breach can have serious consequences for both individuals and businesses.

Personal information exposed through a breach may be misused and can also cause financial, reputational and other harm.

The DPDP framework therefore places importance on reasonable security safeguards and obligations relating to personal data breaches.

The Act provides for substantial financial penalties for certain breaches. The Schedule to the Act provides for a maximum penalty of up to ₹250 crore for failure to take reasonable security safeguards to prevent a personal data breach. Certain other breaches can attract penalties of up to ₹200 crore or ₹150 crore, depending upon the obligation involved.

The significant financial consequences indicate the seriousness with which data protection is intended to be treated.

Individuals also have certain duties

The relationship created by the DPDP Act is not entirely one sided.

Along with rights, the Act also places certain duties on Data Principals.

These include complying with applicable laws, not impersonating another person, not suppressing material information when providing information for specified purposes and not making false or frivolous complaints.

Individuals are therefore also expected to use the rights provided by the law responsibly.

What should individuals know?

For an ordinary internet user, understanding the DPDP Act does not require becoming familiar with every provision of the legislation.

However, individuals should be aware that they have rights concerning their personal data.

Before providing personal information to an organisation, it is useful to understand why the information is being requested and how it is intended to be used.

Individuals should also know that they may have the right to obtain information about the processing of their personal data, seek correction or updating of inaccurate information and exercise other rights provided under the law.

Most importantly, individuals should know where to raise a grievance if they believe their rights have not been respected.

What should companies do?

For businesses, the first step should be understanding the personal data they collect and process.

A company should consider what information it collects, the purpose for which it is collected, the basis on which it is processed, who has access to it and how it is protected.

Businesses should also review their contracts, privacy notices, internal processes and data security practices in light of the requirements applicable to them.

Data protection should ideally become part of the ordinary functioning of a business rather than something considered only after a complaint or data breach.

A changing digital environment

The importance of the DPDP Act can ultimately be understood by looking at how much of everyday life now depends upon digital information.

A person may provide personal data to a bank, an online retailer, an employer, a hospital, a social media platform or a mobile application, often within the same day.

At the same time, businesses increasingly rely on personal data to provide services, understand customers and operate their digital platforms.

The DPDP Act seeks to create a framework in which this processing can take place while recognising the rights of individuals and placing corresponding responsibilities on organisations.

As India’s digital economy continues to grow, awareness of data protection will become increasingly important. Individuals need to understand the rights available to them, while businesses need to understand the responsibilities that come with collecting and processing personal data. The DPDP Act is therefore not simply a law for technology companies. It is a law that touches the relationship between individuals, information and the businesses that increasingly depend upon that information.

Share it :