Digital Personal Data Protection Act 2023 Enshrines Consent-Based Data Processing and Establishes Data Protection Board

India’s Parliament has enacted the Digital Personal Data Protection Act, 2023, a landmark legislation that introduces a comprehensive legal framework for the processing of digital personal data. The Act, which received the President’s assent on August 11, 2023, aims to balance the right of individuals to protect their personal data with the need to process such data for lawful purposes.

The Act establishes a clear regulatory architecture, defining key roles such as Data Fiduciary, Data Principal, and Data Processor, and sets out obligations for consent, notice, and data security. It also creates the Data Protection Board of India to enforce compliance and impose penalties for breaches.

The Architecture of Consent and Notice

At the heart of the Act is the requirement for a Data Fiduciary to obtain free, specific, informed, unconditional, and unambiguous consent from the Data Principal before processing personal data. Section 6(1) states: “The consent given by the Data Principal shall be free, specific, informed, unconditional and unambiguous with a clear affirmative action.” Every request for consent must be accompanied by a notice detailing the personal data to be processed, the purpose, and the mechanism for exercising rights.

The Act also recognizes "certain legitimate uses" under Section 7, allowing data processing without consent for purposes such as responding to medical emergencies, complying with legal obligations, or providing government benefits. This dual approach—consent and legitimate use—creates a flexible yet controlled environment for data processing.

Duties of Data Fiduciaries and Data Principals

Data Fiduciaries bear significant responsibilities. Section 8 mandates reasonable security safeguards to prevent personal data breaches, and in the event of a breach, the Board and affected Data Principals must be notified. Section 8(5) requires the fiduciary to “protect personal data in its possession or under its control… by taking reasonable security safeguards to prevent personal data breach.” Data must be erased when consent is withdrawn or the specified purpose is no longer served.

Data Principals, in turn, have duties under Section 15, including not impersonating others, not suppressing material information, and not filing frivolous complaints. They are also granted rights to access information about their processed data, request correction and erasure, and seek grievance redressal.

The Data Protection Board of India

A key institutional innovation is the Data Protection Board of India, established under Section 18 as a body corporate. The Board will operate as a digital office, handling complaints, personal data breach intimation, and enforcement. It has powers akin to a civil court for summoning, evidence, and document production. Penalties are substantial: up to ₹250 crore for breach of security safeguards, and up to ₹200 crore for breaching obligations related to children’s data or failing to notify a breach.

Significant Data Fiduciaries and Additional Obligations

The Act empowers the Central Government to designate certain entities as Significant Data Fiduciaries based on factors like data volume, sensitivity, and risk to electoral democracy or national security. These fiduciaries must appoint a Data Protection Officer based in India, conduct periodic Data Protection Impact Assessments, and undergo independent data audits.

Critical Perspectives: The Gaps in the Framework

While the Act represents a major step forward, experts have pointed to critical gaps. An analysis of the legislation and the broader digital economy highlights that the Act does not explicitly recognize a right to data portability, which would allow individuals to transfer their data between services. This absence can lead to data lock-in, stifling competition and consumer choice. Additionally, the Act lacks a dedicated framework for profiling and automated decision-making. Where algorithms use data to infer sensitive characteristics—such as creditworthiness or health status—the data subject may not have consciously provided that information, and the current right to correction only applies to inaccurate data, not inaccurate inferences.

The Data Empowerment and Protection Architecture (DEPA) introduced by NITI Aayog provides a technological infrastructure for data mobility, but without a legally enforceable right to portability, its impact remains limited. As data brokerage becomes a multi-billion-dollar market, the Act’s focus on the moment of collection may be insufficient to regulate the subsequent use of data for prediction and influence.

Implications and Way Forward

The Digital Personal Data Protection Act, 2023, lays a strong foundation for India’s data governance regime. It empowers individuals with rights and establishes institutional oversight. However, as the digital economy evolves, the Act may need amendments to address data portability and automated decision-making to keep pace with the invisible market of data brokerage. For now, businesses must urgently comply with the new consent, notice, and security requirements, while individuals can expect greater transparency and control over their personal data.