Enshrines Consent-Based Data Processing and Establishes Data Protection Board
has enacted the , a landmark legislation that introduces a comprehensive legal framework for the processing of digital personal data. The Act, which received the President’s assent on , aims to balance the right of individuals to protect their personal data with the need to process such data for lawful purposes.
The Act establishes a clear regulatory architecture, defining key roles such as , , and , and sets out obligations for consent, notice, and data security. It also creates the to enforce compliance and impose penalties for breaches.
The Architecture of Consent and Notice
At the heart of the Act is the requirement for a to obtain free, specific, informed, unconditional, and unambiguous consent from the before processing personal data. states: “The consent given by the shall be with a clear affirmative action.” Every request for consent must be accompanied by a notice detailing the personal data to be processed, the purpose, and the mechanism for exercising rights.
The Act also recognizes "" under , allowing data processing without consent for purposes such as responding to medical emergencies, complying with legal obligations, or providing government benefits. This dual approach—consent and legitimate use—creates a flexible yet controlled environment for data processing.
Duties of Data Fiduciaries and Data Principals
Data Fiduciaries bear significant responsibilities. mandates to prevent personal data breaches, and in the event of a breach, the Board and affected Data Principals must be notified. (5) requires the fiduciary to “protect personal data in its possession or under its control… by taking to prevent .” Data must be erased when consent is withdrawn or the specified purpose is no longer served.
Data Principals, in turn, have duties under , including not impersonating others, not suppressing material information, and not filing . They are also granted rights to access information about their processed data, request correction and erasure, and seek grievance redressal.
The
A key institutional innovation is the , established under as a . The Board will operate as a digital office, handling complaints, intimation, and enforcement. It has powers akin to a civil court for summoning, evidence, and document production. Penalties are substantial: up to ₹250 crore for breach of security safeguards, and up to ₹200 crore for breaching obligations related to children’s data or failing to notify a breach.
and Additional Obligations
The Act empowers the to designate certain entities as based on factors like data volume, sensitivity, and risk to electoral democracy or national security. These fiduciaries must appoint a based in India, conduct periodic , and undergo independent .
Critical Perspectives: The Gaps in the Framework
While the Act represents a major step forward, experts have pointed to critical gaps. An analysis of the legislation and the broader digital economy highlights that the Act does not explicitly recognize a , which would allow individuals to transfer their data between services. This absence can lead to , stifling competition and consumer choice. Additionally, the Act lacks a dedicated framework for and . Where algorithms use data to infer sensitive characteristics—such as creditworthiness or health status—the data subject may not have consciously provided that information, and the current only applies to inaccurate data, not .
The introduced by provides a technological infrastructure for data mobility, but without a legally enforceable right to portability, its impact remains limited. As becomes a multi-billion-dollar market, the Act’s focus on the moment of collection may be insufficient to regulate the subsequent use of data for prediction and influence.
Implications and Way Forward
The , lays a strong foundation for India’s data governance regime. It empowers individuals with rights and establishes institutional oversight. However, as the digital economy evolves, the Act may need amendments to address data portability and to keep pace with the invisible market of . For now, businesses must urgently comply with the new consent, notice, and security requirements, while individuals can expect greater transparency and control over their personal data.