Data Privacy & Protection is a legal and conceptual framework that governs the collection, storage, and use of personal information in the digital age. Data privacy defines an individual's right to control who can access their information, while data protection refers to the security measures and policies used to prevent unauthorized access.
The foundation for this concept in India was laid by the Supreme Court's landmark judgment in Justice K.S. Puttaswamy (Retd.) & Anr. vs. Union of India & Ors. in 2017. The nine-judge bench unanimously held that the right to privacy is protected as a fundamental right under Article 21 of the Constitution of India. This judgment addressed the problem of a fragmented legal regime, which previously relied on provisions like Section 43A of the Information Technology Act, 2000, introduced in 2008.
The current comprehensive legal framework is the Digital Personal Data Protection Act, 2023 (DPDP Act), an Act that applies to the processing of digital personal data within India. The Act works by establishing the Data Fiduciary (the entity processing the data) as accountable for adhering to principles like lawful, fair, and transparent usage, and purpose limitation. It grants the Data Principal (the individual) rights, including the right to access and the right to request deletion of their personal data. A key mechanism is the imposition of a maximum financial penalty of INR 250 Crores on a Data Fiduciary for failing to take reasonable security safeguards to prevent a personal data breach.
The DPDP Act, 2023, is a major recent change, replacing the former patchwork of laws, including Section 43A of the Information Technology Act, 2000, and the IT Rules, 2011. However, the IT Act and Rules will continue to govern the privacy regime until the core operational provisions of the DPDP Act are fully effective, which is expected to be in a phased manner by May 2027. The constitutional guarantee of the right to privacy under Article 21 remains the bedrock of the entire framework.