SupremeToday Landscape Ad

DIGITAL PERSONAL DATA PROTECTION ACT, 2023

Read full Act
Pre. [Act No. 22 of 2023]

[11th August, 2023]

PREAMBLE

An Act to provide for the processing of digital personal data in a manner that recognises both the right of individuals to protect their personal data and the need to process such personal data for lawful purposes and for matters connected therewith or incidental thereto.

Be it enacted by Parliament in the Seventy-fourth Year of the Republic of India as follows:--



Legal Commentary on Section: Preliminary of the DIGITAL PERSONAL DATA PROTECTION ACT, 2023

Introduction

The Preliminary section of the Digital Personal Data Protection Act, 2023 (DPDP Act) sets the foundational framework for the legislation, defining key terms, scope, and the overarching purpose of the Act. It establishes the legal context within which subsequent provisions operate, emphasizing the protection of individual privacy and regulation of data processing activities.

What does Section Says

The Preliminary section introduces the title, commencement, definitions, and scope of the Act. It clarifies that the Act applies to the processing of digital personal data within India, and lays down the basic principles guiding data processing, including the recognition of individuals' rights and the responsibilities of data fiduciaries.

Essential Ingredients

  • Short Title and Commencement: Specifies the name and effective date of the Act.
  • Definitions: Clarifies key terms such as "personal data," "data fiduciary," and "processing."
  • Scope of Application: Defines the territorial and substantive limits of the Act, including the types of data and entities covered.
  • Purpose: To regulate processing activities, protect individual privacy, and establish accountability.

Scope of Section

The section broadly delineates the geographical and functional scope, applying to all digital personal data processed within India, regardless of where the data was collected. It also sets the stage for defining obligations and rights in subsequent chapters.

Punishment for Section

As a preliminary section, it does not prescribe penalties directly. However, violations related to definitions, scope, or procedural missteps can attract penalties under the later provisions of the Act, which include hefty fines for non-compliance.

Legal Comments

  • "Scope" - The section establishes that the Act applies to digital personal data processed within India, emphasizing territorial jurisdiction [Source: "India: Digital Personal Data Protection Act, 2023 part one – Scope"].
  • "Definitions" - Clear definitions are crucial for legal certainty, ensuring that terms like "personal data" and "data fiduciary" are precisely understood [Source: "Chapter I. PRELIMINARY. CLAUSES. 2. Definitions"].
  • "Purpose" - The primary aim is to protect individual privacy rights while enabling lawful data processing, balancing rights and responsibilities [Source: "An Act to provide for the processing of digital personal data..."].
  • "Application" - The Act applies to both online and offline data that is digitized, broadening its reach to all digital data within Indian jurisdiction [Source: "The Bill will apply to the processing of digital personal data within India"].
  • "Penalties" - Although the preliminary section does not specify penalties, non-compliance with definitions or scope can lead to significant sanctions under later sections [Source: "Penalties for non-compliance under DPDP Act 2023"].
  • "Regulatory Framework" - The section hints at the establishment of an independent Data Protection Board to oversee compliance and adjudication [Source: "Data Protection Board of India (DPBI)"].
  • "Rights of Individuals" - Recognizes the right of individuals to protect their personal data, forming the basis for rights-based provisions in subsequent chapters [Source: "An Act to provide for the processing of digital personal data..."].
  • "Obligations of Data Fiduciaries" - Sets the groundwork for defining the responsibilities of entities processing personal data [Source: "Chapter II. OBLIGATIONS OF DATA FIDUCIARY"].
  • "Legal Certainty" - Precise scope and definitions aim to reduce ambiguity, facilitating enforcement and compliance [Source: "Commentary on The Digital Personal Data Protection Act, 2023"].
  • "Inclusivity" - The Act adopts an inclusive approach, covering data processed both online and offline but digitized [Source: "The Bill will apply to the processing of digital personal data within India"].
  • "Balance of Interests" - Strives to balance individual privacy rights with the needs of lawful data processing for societal and economic benefits [Source: "Salient Features of the Digital Personal Data Protection Act, 2023"].
  • "Legal Certainty for Stakeholders" - Clear scope and definitions provide legal certainty for data fiduciaries, data principals, and regulators [Source: "Digital Personal Data Protection Act, 2023 – An Overview"].
  • "Framework for Compliance" - The preliminary provisions set the stage for detailed obligations, rights, and penalties in subsequent sections [Source: "Penalties for non-compliance under DPDP Act 2023"].
  • "Operational Readiness" - The section underscores the importance of establishing clear legal boundaries to facilitate compliance and enforcement [Source: "Readiness of India Inc. for the Digital Personal Data Protection Act"].
  • "Legal Robustness" - The comprehensive scope and detailed definitions aim to create a robust legal framework for data protection in India [Source: "Digital Personal Data Protection Act of India (DPDP) - usecure Blog"].

This concise legal commentary synthesizes the key aspects of the Preliminary section of the Digital Personal Data Protection Act, 2023, drawing from multiple sources to provide a comprehensive analysis.

S.1 Short title and commencement

(1) This Act may be called the Digital Personal Data Protection Act, 2023.

(2) It shall come into force on such date as the Central Government may, by notification in the Official Gazette, appoint and different dates may be appointed for different provisions of this Act and any reference in any such provision to the commencement of this Act shall be construed as a reference to the coming into force of that provision.


S.2 Definitions

In this Act, unless the context otherwise requires,--

(a) "Appellate Tribunal" means the Telecom Disputes Settlement and Appellate Tribunal established under Section 14 of the Telecom Regulatory Authority of India Act, 1997 (24 of 1997);

(b) "automated" means any digital process capable of operating automatically in response to instructions given or otherwise for the purpose of processing data;

(c) "Board" means the Data Protection Board of India established by the Central Government under Section 18;

(d) "certain legitimate uses" means the uses referred to in Section 7;

(e) "Chairperson" means the Chairperson of the Board;

(f) "child" means an individual who has not completed the age of eighteen years;

(g) "Consent Manager" means a person registered with the Board, who acts as a single point of contact to enable a

S.3 Application of Act

Subject to the provisions of this Act, it shall--

(a) apply to the processing of digital personal data within the territory of India where the personal data is collected--

(i) in digital form; or

(ii) in non-digital form and digitised subsequently;

(b) also apply to processing of digital personal data outside the territory of India, if such processing is in connection with any activity related to offering of goods or services to Data Principals within the territory of India;

(c) not apply to--

(i) personal data processed by an individual for any personal or domestic purpose; and

(ii) personal data that is made or caused to be made publicly available by--

(A) the Data Principal to whom such personal data relates; or

(B) any other person who is under an obligation under any

S.4 Grounds for processing personal data

(1) A person may process the personal data of a Data Principal only in accordance with the provisions of this Act and for a lawful purpose,--

(a) for which the Data Principal has given her consent; or

(b) for certain legitimate uses.

(2) For the purposes of this section, the expression "lawful purpose" means any purpose which is not expressly forbidden by law.


S.5 Notice

(1) Every request made to a Data Principal under Section 6 for consent shall be accompanied or preceded by a notice given by the Data Fiduciary to the Data Principal, informing her,--

(i) the personal data and the purpose for which the same is proposed to be processed;

(ii) the manner in which she may exercise her rights under Sub-Section (4) of Section 6 and Section 13; and

(iii) the manner in which the Data Principal may make a complaint to the Board, in such manner and as may be prescribed.

(2) Where a Data Principal has given her consent for the processing of her personal data before the date of commencement of this Act,--

(a) the Data Fiduciary shall, as soon as it is reasonably practicable, give to the Data Principal a notice informing her,--

(i) the personal data and the purpose for which the same has been processed;

(1) The consent given by the Data Principal shall be free, specific, informed, unconditional and unambiguous with a clear affirmative action, and shall signify an agreement to the processing of her personal data for the specified purpose and be limited to such personal data as is necessary for such specified purpose.

(2) Any part of consent referred in Sub-Section (1) which constitutes an infringement of the provisions of this Act or the rules made thereunder or any other law for the time being in force shall be invalid to the extent of such infringement.

(3) Every request for consent under the provisions of this Act or the rules made thereunder shall be presented to the Data Principal in a clear and plain language, giving her the option to access such request in English or any language specified in the Eighth Schedule to the Constitution and providing the contact details of a Data Protection Officer, where applicable, or o

S.7 Certain legitimate uses

A Data Fiduciary may process personal data of a Data Principal for any of following uses, namely:--

(a) for the specified purpose for which the Data Principal has voluntarily provided her personal data to the Data Fiduciary, and in respect of which she has not indicated to the Data Fiduciary that she does not consent to the use of her personal data.

(b) for the State and any of its instrumentalities to provide or issue to the Data Principal such subsidy, benefit, service, certificate, licence or permit as may be prescribed, where--

(i) she has previously consented to the processing of her personal data by the State or any of its instrumentalities for any subsidy, benefit, service, certificate, licence or permit; or

(ii) such personal data is available in digital form in, or in non-digital form and digitised subsequently from, any database, register, book or other document which is

S.8 General obligations of Data Fiduciary

(1) A Data Fiduciary shall, irrespective of any agreement to the contrary or failure of a Data Principal to carry out the duties provided under this Act, be responsible for complying with the provisions of this Act and the rules made thereunder in respect of any processing undertaken by it or on its behalf by a Data Processor.

(2) A Data Fiduciary may engage, appoint, use or otherwise involve a Data Processor to process personal data on its behalf for any activity related to offering of goods or services to Data Principals only under a valid contract.

(3) Where personal data processed by a Data Fiduciary is likely to be--

(a) used to make a decision that affects the Data Principal; or

(b) disclosed to another Data Fiduciary,

the Data Fiduciary processing such personal data shall ensure its completeness, accuracy and consistency.

(4) A Da

S.9 Processing of personal data of children

(1) The Data Fiduciary shall, before processing any personal data of a child or a person with disability who has a lawful guardian obtain verifiable consent of the parent of such child or the lawful guardian, as the case may be, in such manner as may be prescribed.

Explanation.--For the purpose of this sub-section, the expression "consent of the parent" includes the consent of lawful guardian, wherever applicable.

(2) A Data Fiduciary shall not undertake such processing of personal data that is likely to cause any detrimental effect on the well-being of a child.

(3) A Data Fiduciary shall not undertake tracking or behavioural monitoring of children or targeted advertising directed at children.

(4) The provisions of sub-sections (1) and (3) shall not be applicable to processing of personal data of a child by such classes of Data Fiduciaries or for such purposes, and subject to such

S.10 Additional obligations of Significant Data Fiduciary

(1) The Central Government may notify any Data Fiduciary or class of Data Fiduciaries as Significant Data Fiduciary, on the basis of an assessment of such relevant factors as it may determine, including--

(a) the volume and sensitivity of personal data processed;

(b) risk to the rights of Data Principal;

(c) potential impact on the sovereignty and integrity of India;

(d) risk to electoral democracy;

(e) security of the State; and

(f) public order.

(2) The Significant Data Fiduciary shall--

(a) appoint a Data Protection Officer who shall--

(i) represent the Significant Data Fiduciary under the provisions of this Act;

(ii) be based in India;

(iii) be an individual responsible to the Board of Directors or similar governing body of t

S.11 Right to access information about personal data

(1) The Data Principal shall have the right to obtain from the Data Fiduciary to whom she has previously given consent, including consent as referred to in clause (a) of Section 7 (hereinafter referred to as the said Data Fiduciary), for processing of personal data, upon making to it a request in such manner as may be prescribed,--

(a) a summary of personal data which is being processed by such Data Fiduciary and the processing activities undertaken by that Data Fiduciary with respect to such personal data;

(b) the identities of all other Data Fiduciaries and Data Processors with whom the personal data has been shared by such Data Fiduciary, along with a description of the personal data so shared; and

(c) any other information related to the personal data of such Data Principal and its processing, as may be prescribed.

(2) Nothing contained in clause (b) or clause (c) of Sub-Secti

S.12 Right to correction and erasure of personal data

(1) A Data Principal shall have the right to correction, completion, updating and erasure of her personal data for the processing of which she has previously given consent, including consent as referred to in clause (a) of Section 7, in accordance with any requirement or procedure under any law for the time being in force.

(2) A Data Fiduciary shall, upon receiving a request for correction, completion or updating from a Data Principal,--

(a) correct the inaccurate or misleading personal data;

(b) complete the incomplete personal data; and

(c) update the personal data.

(3) A Data Principal shall make a request in such manner as may be prescribed to the Data Fiduciary for erasure of her personal data, and upon receipt of such a request, the Data Fiduciary shall erase her personal data unless retention of the same is necessary for the specified purpose or for co


Legal Commentary on Section 12 of the Digital Personal Data Protection Act, 2023

Introduction

Section 12 of the Digital Personal Data Protection Act, 2023 (DPDP Act) delineates the rights of Data Principals (individuals) regarding their personal data, emphasizing the rights to correction, completion, updating, and erasure. It forms a core component of the data protection framework, balancing individual privacy with lawful data processing.

What does Section 12 Say?

Section 12 grants Data Principals the right to:- Request correction, completion, and updating of their personal data.- Seek erasure of their personal data when the purpose for which data was processed is no longer valid or with withdrawal of consent.- The Data Fiduciary (entity processing data) must comply unless retention is necessary for legal obligations or other legitimate purposes.

Essential Ingredients

  • Right to Correction & Update: Data Principals can request amendments to inaccurate or incomplete data.
  • Right to Erasure: Data Principals can demand deletion of personal data, especially when processing is no longer justified.
  • Conditions for Erasure: Data must be erased unless retention is mandated by law or necessary for legitimate purposes.
  • Notice & Consent: Data Fiduciaries must provide notice and obtain consent before processing personal data, aligning with Sections 6 and 8.
  • Obligations of Data Fiduciary: Must ensure data accuracy and respond to correction or erasure requests promptly.

Scope of Section 12

  • Applies to digital personal data processed within India or outside India in connection with offering goods/services within India.
  • Encompasses all data collected in digital form or digitized later.
  • Excludes publicly available data and data processed for personal or domestic purposes.
  • Covers all Data Fiduciaries handling personal data, including government and private entities.
  • Balances individual rights with lawful processing, including exceptions for legal obligations, public interest, and national security.

Punishment for Non-Compliance

While Section 12 itself primarily confers rights, violations can lead to penalties under Chapter VIII of the DPDP Act:- Penalties for contravention of data erasure or correction obligations can extend up to INR 250 crore.- The Data Protection Board (DPB) has authority to adjudicate and impose penalties for breach of obligations.- Non-compliance may also attract civil liabilities and damages as per applicable laws.

Legal Comments

  • Right to Privacy - Recognized as a fundamental right under Article 21 of the Constitution, Section 12 operationalizes this right by empowering individuals to control their personal data [Karthick Theodore VS Registrar General Madras High Court].

  • Right to Erasure - Reflects the global trend, akin to GDPR’s Article 17, allowing individuals to request deletion of their data when no longer necessary or with withdrawal of consent, balancing privacy with lawful data processing [Dhritiman Ray VS University of Delhi].

  • Data Minimization & Purpose Limitation - Section 12 enforces that data must be erased when the purpose is fulfilled, aligning with principles of data minimization and purpose limitation, fundamental to data protection laws [Justice K. S. Puttaswamy (Retd. ) VS Union of India].

  • Consent & Notice - Mandates that Data Fiduciaries must inform Data Principals of processing and obtain explicit consent, reinforcing the rights to control and transparency [Karthick Theodore VS Registrar General Madras High Court].

  • Lawful Processing & Exceptions - Data can be retained if necessary for legal obligations, public interest, or national security, indicating a balanced approach respecting rights and state interests [Vysakh K. G. , S/o. Gokuldas VS Union Of India].

  • Balance with Freedom of Speech - The right to correction and erasure should be balanced against the public interest, especially in judicial records and judgments, where transparency is vital but privacy rights also need protection [T. V. S. Electronics Ltd. VS Collector of Central Excise, Bangalore].

  • Implication for Judicial Records - Courts have the discretion to redact personal data under Article 21 and Section 12, but cannot completely obliterate judicial records, maintaining transparency while respecting privacy [Karthick Theodore VS Registrar General Madras High Court].

  • Data Fiduciary Obligations - Entities processing personal data must ensure accuracy, security, and timely response to correction or erasure requests, with penalties for breach .

  • Inclusion of Data Principals’ Rights - Section 12 embodies the principle that individuals have control over their digital identity, aligning with global standards like GDPR and EU’s “right to be forgotten” [Dhritiman Ray VS University of Delhi].

  • Limitations & Public Interest - The right to erasure is subject to exceptions where data is necessary for public interest, legal compliance, or freedom of expression, preventing abuse of the right [Vysakh K. G. , S/o. Gokuldas VS Union Of India].

  • Protection against Data Breach & Misuse - The section emphasizes the importance of data security, with breach notifications and penalties, to prevent misuse and protect individual privacy .

  • Evolving Data Rights & Digital Age - Section 12 reflects the recognition that data rights are dynamic, adapting to technological advances and societal needs, as seen in global data protection frameworks [University Of Delhi vs Neeraj].

  • Implementation & Enforcement - The Data Protection Board is empowered to oversee compliance, investigate violations, and impose penalties, ensuring effective enforcement of Section 12 rights [Gopal Vttal, Bharti Airtel Ltd. VS Kamatci Shankar Arumugam].

  • Interaction with Other Laws - Section 12 rights coexist with other legal provisions, including criminal law, civil law, and constitutional protections, requiring a nuanced, case-specific approach [Dhritiman Ray VS University Of Delhi].

  • Transparency & Public Confidence - Ensuring that individuals can exercise control over their data fosters trust in digital services and judicial transparency, vital for democratic legitimacy [DPMI Vocational Pvt Ltd vs Union Of India].

  • Limitations & Safeguards - While empowering data subjects, the law recognizes the need for safeguards to prevent misuse, especially in sensitive sectors like health, finance, and judiciary [Shaurabh Kumar Tripathi VS Vidhi Rawal].

  • International & Comparative Perspective - The rights conferred under Section 12 mirror international standards such as GDPR, emphasizing global convergence in data privacy rights [Suo Motu VS Travancore Devaswom Board, Nanthancode, Kawdiar Post, Thiruvananthapuram, Represented By Its Secretary].

Summary

Section 12 of the Digital Personal Data Protection Act, 2023, enshrines the core rights of Data Principals to correct, update, and erase their personal data, subject to lawful exceptions. It imposes obligations on Data Fiduciaries to ensure data accuracy, security, and responsiveness, with penalties for violations. The section reflects a balanced approach, aligning with global data privacy principles, emphasizing individual autonomy, and fostering trust in digital ecosystems. Its enforcement mechanisms and scope aim to uphold privacy rights while accommodating legitimate state and societal interests.

**- [Karthick Theodore VS Registrar General Madras High Court], [Dhritiman Ray VS University of Delhi], [Vysakh K. G. , S/o. Gokuldas VS Union Of India], [Justice K. S. Puttaswamy (Retd. ) VS Union of India], [T. V. S. Electronics Ltd. VS Collector of Central Excise, Bangalore], [University Of Delhi vs Neeraj], , [Suo Motu VS Travancore Devaswom Board, Nanthancode, Kawdiar Post, Thiruvananthapuram, Represented By Its Secretary], [In Re : In The Matter Of Tackling The Issue Of ‘Digital Arrest Scams’, Cyber Crimes And Saving The Innocent People From Loosing Their Money And Lives], [Akshita Khosla vs University of Delhi], [Commr. of Customs, Bangalore VS M/s ACER India Pvt. Ltd. ], [Commr. of Customs, Bangalore VS M/s ACER India Pvt. Ltd. ], [Regin Vinny VS Union of India, Rep. by the Secretary, New Delhi], [Dhritiman Ray vs University of Delhi], [DPMI Vocational Pvt Ltd vs Union Of India], [Commissioner of Customs, Bangalore VS ACER India Pvt. Ltd. ], [00100061861], [Dharanidhar Karimojji VS Union Of India], [Raghuveer Sharan VS District Sahakari Krishi Gramin Vikas Bank], [Punit S/o. Bhimsingh Rajput VS State of Karnataka, By CPI Mudhol, Represented by State Public Prosecutor], [Vysakh K. G. , S/o. Gokuldas VS Union Of India]

S.13 Right of grievance redressal

(1) A Data Principal shall have the right to have readily available means of grievance redressal provided by a Data Fiduciary or Consent Manager in respect of any act or omission of such Data Fiduciary or Consent Manager regarding the performance of its obligations in relation to the personal data of such Data Principal or the exercise of her rights under the provisions of this Act and the rules made thereunder.

(2) The Data Fiduciary or Consent Manager shall respond to any grievances referred to in Sub-Section (1) within such period as may be prescribed from the date of its receipt for all or any class of Data Fiduciaries.

(3) The Data Principal shall exhaust the opportunity of redressing her grievance under this Section before approaching the Board.


S.14 Right to nominate

(1) A Data Principal shall have the right to nominate, in such manner as may be prescribed, any other individual, who shall, in the event of death or incapacity of the Data Principal, exercise the rights of the Data Principal in accordance with the provisions of this Act and the rules made thereunder.

(2) For the purposes of this section, the expression "incapacity" means inability to exercise the rights of the Data Principal under the provisions of this Act or the rules made thereunder due to unsoundness of mind or infirmity of body.


S.15 Duties of Data Principal

A Data Principal shall perform the following duties, namely:--

(a) comply with the provisions of all applicable laws for the time being in force while exercising rights under the provisions of this Act;

(b) to ensure not to impersonate another person while providing her personal data for a specified purpose;

(c) to ensure not to suppress any material information while providing her personal data for any document, unique identifier, proof of identity or proof of address issued by the State or any of its instrumentalities;

(d) to ensure not to register a false or frivolous grievance or complaint with a Data Fiduciary or the Board; and

(e) to furnish only such information as is verifiably authentic, while exercising the right to correction or erasure under the provisions of this Act or the rules made thereunder.



Legal Commentary on Section 15 of the DIGITAL PERSONAL DATA PROTECTION ACT, 2023

Introduction

Section 15 of the Digital Personal Data Protection Act, 2023 (DPDP Act) delineates the specific duties and responsibilities of Data Principals, emphasizing their role in safeguarding their personal data and ensuring responsible data practices. It forms part of the broader framework that balances individual rights with data fiduciaries' obligations, aligning with global privacy standards such as the EU GDPR and principles of informational privacy.

What does Section 15 Say

Section 15 prescribes that Data Principals shall perform certain duties in relation to their personal data, including providing informed consent, ensuring data accuracy, and exercising rights such as correction and erasure. It acts as a responsibility clause, complementing the rights granted under Sections 4-14, and emphasizes that these rights must be exercised responsibly to prevent misuse or abuse of data.

Essential Ingredients

  • Duties of Data Principals: Includes providing verifiable consent, updating or correcting data, and exercising their rights responsibly.
  • Balance of Rights and Responsibilities: Ensures that while Data Principals have rights, they also bear responsibilities to prevent misuse.
  • Informed Consent: Data Principals must give clear, specific, and informed consent before data collection or processing.
  • Data Accuracy and Correction: Obligates Data Principals to ensure data accuracy and update or erase data when necessary.
  • Prevention of Abuse: Aims to prevent the misuse of rights, including through false or malicious claims.

Scope of Section 15

Section 15 applies to all Data Principals whose personal data is processed under the DPDP Act, including children and persons with disabilities, and mandates responsible exercise of rights. It covers both online and offline data collection, digitized data, and aligns with the Act’s overarching goal of protecting informational privacy while fostering responsible data use.

Punishment for Section 15

While Section 15 itself primarily sets duties, violations—such as exercising rights irresponsibly or maliciously—may attract penalties under Sections 63, 64, or 70 of the Act, including monetary fines up to INR 10,000 for breaches. The Act emphasizes that misuse or abuse of rights can lead to penalties, ensuring accountability of Data Principals' responsible exercise of their duties.

Legal Comments

  • "Duties" - Section 15 mandates Data Principals to exercise their rights responsibly, including providing accurate data and exercising consent properly - [Section 15, DPDP Act, 2023]
  • "Informed Consent" - Emphasizes that consent must be clear, specific, and given after full disclosure, aligning with global privacy norms - [Section 6, DPDP Act, 2023]
  • "Responsibility" - Section 15 underscores that rights are coupled with responsibilities to prevent misuse or malicious exercise, promoting responsible data governance - [Section 15, DPDP Act, 2023]
  • "Data Accuracy" - Data Principals are obliged to ensure the correctness of their data and update or erase inaccuracies, reinforcing data integrity - [Section 12, DPDP Act, 2023]
  • "Balance of Rights and Duties" - The section balances individual rights with duties, preventing abuse and ensuring that rights are not exploited maliciously - [Section 15, DPDP Act, 2023]
  • "Scope" - Applies comprehensively to all individuals whose personal data is processed, including minors and persons with disabilities, covering both digital and physical data collection - [Section 2, DPDP Act, 2023]
  • "Accountability" - Encourages Data Principals to exercise their rights diligently, with penalties for misuse, fostering a culture of accountability - [Section 15, DPDP Act, 2023]
  • "Legal Sanctions" - Violations of duties under Section 15 may attract penalties up to INR 10,000, ensuring deterrence against irresponsible exercise - [Section 64, DPDP Act, 2023]
  • "Public Interest" - While rights are protected, exercising them irresponsibly or maliciously can undermine public trust and invoke sanctions - [Section 15, DPDP Act, 2023]
  • "Complementarity" - Section 15 complements the rights granted in Sections 4-14, emphasizing that rights come with corresponding duties to prevent data misuse - [Section 15, DPDP Act, 2023]
  • "Global Alignment" - Reflects principles similar to GDPR’s accountability and responsible data handling, promoting international best practices - [Section 15, DPDP Act, 2023]
  • "Preventing Misuse" - The duties are geared towards preventing malicious or false claims, safeguarding individual dignity and data integrity - [Section 15, DPDP Act, 2023]
  • "Responsibility Clause" - Acts as a safeguard ensuring Data Principals do not misuse their rights to harm others or manipulate data processes - [Section 15, DPDP Act, 2023]
  • "Responsibility to Data" - Emphasizes that exercising rights responsibly is essential to uphold the integrity of the data ecosystem - [Section 15, DPDP Act, 2023]
  • "Digital and Offline Data" - The duties extend to both digitally stored data and offline data that is digitized, ensuring comprehensive coverage - [Section 2, DPDP Act, 2023]
  • "Enforcement" - Violations may lead to penalties, including fines and disciplinary action, reinforcing the importance of exercising duties responsibly - [Section 64, DPDP Act, 2023]
  • "Holistic Data Governance" - Section 15 is part of the larger framework emphasizing responsible data governance, balancing rights with duties - [Section 15, DPDP Act, 2023]

In conclusion, Section 15 of the Digital Personal Data Protection Act, 2023, is a pivotal provision that emphasizes the responsible exercise of data rights by Data Principals. It aims to foster a culture of accountability, prevent misuse, and align India’s data privacy regime with international standards, ensuring that individual rights are exercised responsibly within a well-regulated ecosystem.

S.16 Processing of personal data outside India

(1) The Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified.

(2) Nothing contained in this Section shall restrict the applicability of any law for the time being in force in India that provides for a higher degree of protection for or restriction on transfer of personal data by a Data Fiduciary outside India in relation to any personal data or Data Fiduciary or class thereof.


S.17 Exemptions

(1) The provisions of Chapter II, except sub-sections (1) and (5) of Section 8, and those of Chapter III and Section 16 shall not apply where--

(a) the processing of personal data is necessary for enforcing any legal right or claim;

(b) the processing of personal data by any court or tribunal or any other body in India which is entrusted by law with the performance of any judicial or quasi-judicial or regulatory or supervisory function, where such processing is necessary for the performance of such function;

(c) personal data is processed in the interest of prevention, detection, investigation or prosecution of any offence or contravention of any law for the time being in force in India;

(d) personal data of Data Principals not within the territory of India is processed pursuant to any contract entered into with any person outside the territory of India by any person based in Indi


Legal Commentary on Section 17 of the Digital Personal Data Protection Act, 2023

Introduction

Section 17 of the Digital Personal Data Protection Act, 2023 (DPDPA) delineates specific exemptions and scenarios where certain obligations under the Act may not apply or are modified. It aims to balance individual rights with state interests and lawful processing needs, recognizing the complexities of real-world data processing.

What does Section 17 Say

Section 17 provides exemptions for the processing of personal data in particular circumstances, notably for law enforcement, national security, public order, and investigations. It permits processing without consent when necessary for the prevention, detection, investigation, or prosecution of offences or violations of law. The section also grants the Central Government immunity in certain contexts, particularly concerning sovereignty and integrity.

Essential Ingredients

  • Exemptions for Lawful Processing: Personal data processed for legal proceedings, investigations, or enforcement of law.
  • State Immunity: The Central Government’s immunity when processing data for sovereignty, integrity, or public order.
  • Scope of Processing: Limited to specific purposes such as crime prevention, national security, or lawful investigations.
  • Conditions for Exemption: Processing must be necessary and proportionate to the purpose.
  • Broad Interpretations: The section recognizes the need for flexibility in real-world scenarios, including internal investigations and enforcement.

Scope of Section

  • Applicability: Applies to personal data processed within India, especially when related to law enforcement, legal obligations, or national security.
  • Limitations: Exemptions are not absolute; they are confined to specific purposes such as crime prevention, investigation, or safeguarding sovereignty.
  • Exclusions: Certain exemptions are explicitly provided for State instrumentalities, with safeguards for privacy rights balanced against public interests.
  • Operational Flexibility: Allows government agencies and law enforcement to process personal data without prior consent under defined circumstances.

Punishment for Section

  • Penalties: Violations of the exemptions or misuse of processed data may attract penalties, including fines up to ₹250 crore for breaches related to security safeguards (DPDP Rules, 2025).
  • Non-compliance: Failure to adhere to the provisions or misuse can lead to significant legal consequences, including sanctions and penalties as per the Act.
  • Specific Penalties: Penalties for breach of duties under the Act, including processing outside the scope of exemptions, can range from ₹10,000 to ₹150 crore, depending on severity and nature of violation.

Legal Comments

  • "Exemptions" - Section 17 grants specific exemptions for lawful processing related to law enforcement and national security, balancing privacy with state interests [Source: "Section 17 | interpretation - DPDPA"].
  • "State Immunity" - The section empowers the Central Government with immunity to process personal data for sovereignty and public order, which may impact individual privacy rights [Source: "Section 17(2) | immunity for State purposes"].
  • "Purpose Limitation" - Processing under exemptions is restricted to prevention, detection, investigation, or prosecution of offences, ensuring purpose limitation [Source: "Personal data processed for law enforcement"].
  • "Necessity and Proportionality" - Processing must be necessary and proportionate, aligning with principles of lawful processing [Source: "Broad exemption scope recognizing real-world complexities"].
  • "Legal Framework" - Section 17 provides a legal basis for law enforcement to process personal data without consent, subject to safeguards [Source: "Scope and key definitions under DPDP Act"].
  • "Safeguards" - The Act emphasizes that exemptions should be exercised within the bounds of legality, necessity, and proportionality [Source: "Exemptions and accountability"].
  • "Immunity and Sovereignty" - The section’s immunity clause aims to protect national sovereignty but raises concerns regarding potential overreach and privacy erosion [Source: "Section 17(2) immunity for sovereignty"].
  • "Law Enforcement Use" - Permits processing for internal investigations and enforcement, but with a broad interpretation that may impact individual privacy rights [Source: "Internal investigations under the Act"].
  • "Penalties for Violations" - Breaching exemption provisions or misusing processed data can lead to hefty penalties, reinforcing compliance [Source: "Penalties for non-compliance under DPDP Act"].
  • "Balancing Rights and State Interests" - Section 17 attempts to strike a balance but may tilt towards state interests, necessitating oversight to prevent misuse [Source: "Decoding the DPDP Act"].
  • "Legal Certainty" - The section’s broad language provides flexibility but might impact legal certainty and individual rights if not properly regulated [Source: "Complexity of real-world scenarios"].
  • "Scope of Exemptions" - Exemptions are narrowly tailored but include broad categories like sovereignty, which could be subject to misuse [Source: "Exemptions under the DPDP Act"].
  • "Transparency and Oversight" - The section underscores the importance of oversight mechanisms to prevent abuse of exemptions [Source: "Regulatory safeguards"].
  • "Impact on Data Principals" - While exemptions facilitate law enforcement, they may limit the control and rights of data principals, raising privacy concerns [Source: "Safeguarding individual rights"].
  • "Legal Interpretation" - The section’s provisions require careful judicial and administrative interpretation to prevent overreach and protect fundamental rights [Source: "Recognition of complexity"].
  • "Alignment with International Norms" - The exemptions align with international practices allowing state processing for security, but must be balanced with privacy protections [Source: "Global data protection standards"].
  • "Framework for Law Enforcement" - Section 17 provides a structured legal framework for lawful data processing by authorities, essential for effective law enforcement [Source: "Legal framework for law enforcement"].

This commentary synthesizes insights from the provided sources, emphasizing the balance between lawful exemptions and protection of individual rights within the framework of the Digital Personal Data Protection Act, 2023.

S.18 Establishment of Board

(1) With effect from such date as the Central Government may, by notification, appoint, there shall be established, for the purposes of this Act, a Board to be called the Data Protection Board of India.

(2) The Board shall be a body corporate by the name aforesaid, having perpetual succession and a common seal, with power, subject to the provisions of this Act, to acquire, hold and dispose of property, both movable and immovable, and to contract and shall, by the said name, sue or be sued.

(3) The headquarters of the Board shall be at such place as the Central Government may notify.


S.19 Composition and qualifications for appointment of Chairperson and Members

(1) The Board shall consist of a Chairperson and such number of other Members as the Central Government may notify.

(2) The Chairperson and other Members shall be appointed by the Central Government in such manner as may be prescribed.

(3) The Chairperson and other Members shall be a person of ability, integrity and standing who possesses special knowledge or practical experience in the fields of data governance, administration or implementation of laws related to social or consumer protection, dispute resolution, information and communication technology, digital economy, law, regulation or techno-regulation, or in any other field which in the opinion of the Central Government may be useful to the Board, and at least one among them shall be an expert in the field of law.


S.20 Salary, allowances payable to and term of office

(1) The salary, allowances and other terms and conditions of service of the Chairperson and other Members shall be such as may be prescribed, and shall not be varied to their disadvantage after their appointment.

(2) The Chairperson and other Members shall hold office for a term of two years and shall be eligible for re-appointment.


S.21 Disqualifications for appointment and continuation as Chairperson and Members of Board

(1) A person shall be disqualified for being appointed and continued as the Chairperson or a Member, if she--

(a) has been adjudged as an insolvent;

(b) has been convicted of an offence, which in the opinion of the Central Government, involves moral turpitude;

(c) has become physically or mentally incapable of acting as a Member;

(d) has acquired such financial or other interest, as is likely to affect prejudicially her functions as a Member; or

(e) has so abused her position as to render her continuance in office prejudicial to the public interest.

(2) The Chairperson or Member shall not be removed from her office by the Central Government unless she has been given an opportunity of being heard in the matter.


S.22 Resignation by Members and filling of vacancy

(1) The Chairperson or any other Member may give notice in writing to the Central Government of resigning from her office, and such resignation shall be effective from the date on which the Central Government permits her to relinquish office, or upon expiry of a period of three months from the date of receipt of such notice, or upon a duly appointed successor entering upon her office, or upon the expiry of the term of her office, whichever is earliest.

(2) A vacancy caused by the resignation or removal or death of the Chairperson or any other Member, or otherwise, shall be filled by fresh appointment in accordance with the provisions of this Act.

(3) The Chairperson and any other Member shall not, for a period of one year from the date on which they cease to hold such office, except with the previous approval of the Central Government, accept any employment, and shall also disclose to the Central Government any subsequent a

S.23 Proceedings of Board

(1) The Board shall observe such procedure in regard to the holding of and transaction of business at its meetings, including by digital means, and authenticate its orders, directions and instruments in such manner as may be prescribed.

(2) No act or proceeding of the Board shall be invalid merely by reason of--

(a) any vacancy in or any defect in the constitution of the Board;

(b) any defect in the appointment of a person acting as the Chairperson or other Member of the Board; or

(c) any irregularity in the procedure of the Board, which does not affect the merits of the case.

(3) When the Chairperson is unable to discharge her functions owing to absence, illness or any other cause, the senior-most Member shall discharge the functions of the Chairperson until the date on which the Chairperson resumes her duties.


S.24 Officers and employees of Board

The Board may, with previous approval of the Central Government, appoint such officers and employees as it may deem necessary for the efficient discharge of its functions under the provisions of this Act, on such terms and conditions of appointment and service as may be prescribed.


S.25 Members and officers to be public servants

The Chairperson, Members, officers and employees of the Board shall be deemed, when acting or purporting to act in pursuance of provisions of this Act, to be public servants within the meaning of Section 21 of the Indian Penal Code (45 of 1860).


S.26 Powers of Chairperson

The Chairperson shall exercise the following powers, namely:--

(a) general superintendence and giving direction in respect of all administrative matters of the Board;

(b) authorise any officer of the Board to scrutinise any intimation, complaint, reference or correspondence addressed to the Board; and

(c) authorise performance of any of the functions of the Board and conduct any of its proceedings, by an individual Member or groups of Members and to allocate proceedings among them.


S.27 Powers and functions of Board

(1) The Board shall exercise and perform the following powers and functions, namely:--

(a) on receipt of an intimation of personal data breach under Sub-Section (6) of Section 8, to direct any urgent remedial or mitigation measures in the event of a personal data breach, and to inquire into such personal data breach and impose penalty as provided in this Act;

(b) on a complaint made by a Data Principal in respect of a personal data breach or a breach in observance by a Data Fiduciary of its obligations in relation to her personal data or the exercise of her rights under the provisions of this Act, or on a reference made to it by the Central Government or a State Government, or in compliance of the directions of any court, to inquire into such breach and impose penalty as provided in this Act;

(c) on a complaint made by a Data Principal in respect of a breach in observance by a Consent Manager of its ob

S.28 Procedure to be followed by Board

(1) The Board shall function as an independent body and shall, as far as practicable, function as a digital office, with the receipt of complaints and the allocation, hearing and pronouncement of decisions in respect of the same being digital by design, and adopt such techno-legal measures as may be prescribed.

(2) The Board may, on receipt of an intimation or complaint or reference or directions as referred to in Sub-Section (1) of Section 27, take action in accordance with the provisions of this Act and the rules made thereunder.

(3) The Board shall determine whether there are sufficient grounds to proceed with an inquiry.

(4) In case the Board determines that there are insufficient grounds, it may, for reasons to be recorded in writing, close the proceedings.

(5) In case the Board determines that there are sufficient grounds to proceed with inquiry, it may, for reasons to be re

S.29 Appeal to Appellate Tribunal

(1) Any person aggrieved by an order or direction made by the Board under this Act may prefer an appeal before the Appellate Tribunal.

(2) Every appeal under Sub-Section (1) shall be filed within a period of sixty days from the date of receipt of the order or direction appealed against and it shall be in such form and manner and shall be accompanied by such fee as may be prescribed.

(3) The Appellate Tribunal may entertain an appeal after the expiry of the period specified in Sub-Section (2), if it is satisfied that there was sufficient cause for not preferring the appeal within that period.

(4) On receipt of an appeal under Sub-Section (1), the Appellate Tribunal may, after giving the parties to the appeal, an opportunity of being heard, pass such orders thereon as it thinks fit, confirming, modifying or setting aside the order appealed against.

(5) The Appellate Tribunal shall s

S.30 Orders passed by Appellate Tribunal to be executable as decree

(1) An order passed by the Appellate Tribunal under this Act shall be executable by it as a decree of civil court, and for this purpose, the Appellate Tribunal shall have all the powers of a civil court.

(2) Notwithstanding anything contained in Sub-Section (1), the Appellate Tribunal may transmit any order made by it to a civil court having local jurisdiction and such civil court shall execute the order as if it were a decree made by that court.


S.31 Alternate dispute resolution

If the Board is of the opinion that any complaint may be resolved by mediation, it may direct the parties concerned to attempt resolution of the dispute through such mediation by such mediator as the parties may mutually agree upon, or as provided for under any law for the time being in force in India.


S.32 Voluntary undertaking

(1) The Board may accept a voluntary undertaking in respect of any matter related to observance of the provisions of this Act from any person at any stage of a proceeding under Section 28.

(2) The voluntary undertaking referred to in Sub-Section (1) may include an undertaking to take such action within such time as may be determined by the Board, or refrain from taking such action, and or publicising such undertaking.

(3) The Board may, after accepting the voluntary undertaking and with the consent of the person who gave the voluntary undertaking vary the terms included in the voluntary undertaking.

(4) The acceptance of the voluntary undertaking by the Board shall constitute a bar on proceedings under the provisions of this Act as regards the contents of the voluntary undertaking, except in cases covered by Sub-Section (5).

(5) Where a person fails to adhere to any term of the vo

S.33 Penalties

(1) If the Board determines on conclusion of an inquiry that breach of the provisions of this Act or the rules made thereunder by a person is significant, it may, after giving the person an opportunity of being heard, impose such monetary penalty specified in the Schedule.

(2) While determining the amount of monetary penalty to be imposed under Sub-Section (1), the Board shall have regard to the following matters, namely:--

(a) the nature, gravity and duration of the breach;

(b) the type and nature of the personal data affected by the breach;

(c) repetitive nature of the breach;

(d) whether the person, as a result of the breach, has realised a gain or avoided any loss;

(e) whether the person took any action to mitigate the effects and consequences of the breach, and the timeliness and effectiveness of such action;

(

S.34 Crediting sums realised by way of penalties to Consolidated Fund of India

All sums realised by way of penalties imposed by the Board under this Act, shall be credited to the Consolidated Fund of India.


S.35 Protection of action taken in good faith

No suit, prosecution or other legal proceedings shall lie against the Central Government, the Board, its Chairperson and any Member, officer or employee thereof for anything which is done or intended to be done in good faith under the provisions of this Act or the rules made thereunder.


S.36 Power to call for information

The Central Government may, for the purposes of this Act, require the Board and any Data Fiduciary or intermediary to furnish such information as it may call for.


S.37 Power of Central Government to issue directions

(1) The Central Government or any of its officers specially authorised by it in this behalf may, upon receipt of a reference in writing from the Board that--

(a) intimates the imposition of monetary penalty by the Board on a Data Fiduciary in two or more instances; and

(b) advises, in the interests of the general public, the blocking for access by the public to any information generated, transmitted, received, stored or hosted, in any computer resource that enables such Data Fiduciary to carry on any activity relating to offering of goods or services to Data Principals within the territory of India,

after giving an opportunity of being heard to that Data Fiduciary, on being satisfied that it is necessary or expedient so to do, in the interests of the general public, for reasons to be recorded in writing, by order, direct any agency of the Central Government or any intermediary to block for access by th

S.38 Consistency with other laws

(1) The provisions of this Act shall be in addition to and not in derogation of any other law for the time being in force.

(2) In the event of any conflict between a provision of this Act and a provision of any other law for the time being in force, the provision of this Act shall prevail to the extent of such conflict.


S.39 Bar of jurisdiction

No civil court shall have the jurisdiction to entertain any suit or proceeding in respect of any matter for which the Board is empowered under the provisions of this Act and no injunction shall be granted by any court or other authority in respect of any action taken or to be taken in pursuance of any power under the provisions of this Act.


S.40 Power to make rules

(1) The Central Government may, by notification, and subject to the condition of previous publication, make rules not inconsistent with the provisions of this Act, to carry out the purposes of this Act.

(2) In particular and without prejudice to the generality of the foregoing power, such rules may provide for all or any of the following matters, namely:--

(a) the manner in which the notice given by the Data Fiduciary to a Data Principal shall inform her, under Sub-Section (1) of Section 5;

(b) the manner in which the notice given by the Data Fiduciary to a Data Principal shall inform her, under Sub-Section (2) of Section 5;

(c) the manner of accountability and the obligations of Consent Manager under Sub-Section (8) of Section 6;

(d) the manner of registration of Consent Manager and the conditions relating thereto, under Sub-Section (9) of Section 6;

S.41 Laying of rules and certain notifications

Every rule made and every notification issued under Section 16 and Section 42 of this Act shall be laid, as soon as may be after it is made, before each House of Parliament, while it is in session, for a total period of thirty days which may be comprised in one session or in two or more successive sessions, and if before the expiry of the session immediately following the session or the successive sessions aforesaid, both Houses agree in making any modification in the rule or notification or both Houses agree that the rule or notification should not be made or issued, the rule or notification shall thereafter have effect only in such modified form or be of no effect, as the case may be; so, however, that any such modification or annulment shall be without prejudice to the validity of anything previously done under that rule or notification.



Legal Commentary on Section 41 of the DIGITAL PERSONAL DATA PROTECTION ACT, 2023

Introduction

Section 41 of the Digital Personal Data Protection Act, 2023 (DPDPA) plays a crucial role in ensuring transparency and accountability in the rule-making process related to data protection regulations. It mandates parliamentary oversight over rules and notifications issued under the Act, thereby reinforcing the legislative framework's legitimacy.

What does Section 41 Say?

Section 41 stipulates that all rules made and notifications issued under Section 16 and Section 42 of the DPDPA must be laid before Parliament for a period of at least 30 days. This provision allows Parliament to scrutinize, modify, or annul such rules and notifications, ensuring they are not arbitrary or beyond the scope of the Act.

Essential Ingredients

  • Mandatory laying before Parliament: All rules and notifications under Sections 16 and 42 must be submitted to Parliament.
  • Timeframe: The rules must be laid before Parliament for at least 30 days.
  • Scrutiny and review: Parliament has the power to scrutinize, modify, or annul the rules and notifications.
  • Scope of application: Applies specifically to rules under Sections 16 and 42, which pertain to data processing and compliance mechanisms.

Scope of Section

Section 41 applies to all rules and notifications issued under Sections 16 and 42 of the DPDPA, which relate to the regulation of data fiduciaries and enforcement agencies. It ensures that the legislative oversight extends to the administrative rules that operationalize the Act’s provisions.

Punishment for Section

Section 41 itself does not prescribe any specific penalties or punishments. Its primary function is procedural, ensuring transparency and parliamentary oversight over rule-making processes.

Legal Comments

  • Transparency - Section 41 mandates that all rules and notifications are laid before Parliament, promoting transparency in the rule-making process [Source: "section 41 | interpretation - DPDPA"].
  • Parliamentary oversight - It empowers Parliament to scrutinize, modify, or reject rules, thereby preventing arbitrary rule-making [Source: "Section 41 - Digital Personal Data Protection Act (DPDP)"].
  • Procedural safeguard - The 30-day laying period acts as a procedural safeguard to ensure legislative review and accountability [Source: "section 41 | interpretation - DPDPA"].
  • Scope limitation - Applies specifically to rules under Sections 16 and 42, which deal with data processing and enforcement mechanisms [Source: ""].
  • Rule-making process - Ensures that the process of rule-making under the Act remains within the bounds of legislative oversight, aligning with constitutional principles [Source: ""].
  • Legislative scrutiny - Facilitates legislative scrutiny, allowing Parliament to assess the compatibility of rules with the Act’s objectives [Source: ""].
  • Administrative accountability - Promotes administrative accountability by requiring notification submission for parliamentary review [Source: ""].
  • Legal legitimacy - Enhances the legal legitimacy of rules and notifications issued under the Act by subjecting them to parliamentary approval [Source: ""].
  • Limit on executive power - Acts as a check on executive power in rule-making, ensuring rules are not made unilaterally [Source: ""].
  • Alignment with constitutional principles - Upholds the constitutional principle of legislative oversight over executive rule-making [Source: ""].
  • Preventing arbitrariness - Ensures rules are not arbitrary or capricious, as they are subject to parliamentary review [Source: ""].
  • Legal transparency - Promotes transparency in the regulatory framework governing digital personal data [Source: ""].
  • Impact on governance - Strengthens governance by integrating parliamentary oversight into the rule-making process [Source: ""].
  • Implementation safeguard - Acts as an implementation safeguard, ensuring rules are publicly accessible and subject to democratic scrutiny [Source: ""].
  • Non-compliance implications - While Section 41 does not prescribe penalties, non-compliance with procedural requirements could undermine the validity of rules [Source: ""].
  • Enforcement mechanism - Serves as an enforcement mechanism for transparency, not through penalties but through procedural requirements [Source: ""].

Note: The analysis is based on the references provided, focusing on procedural and oversight aspects of Section 41. Specific penalties or enforcement measures are not applicable to this section directly but are related to the overall compliance framework of the Act.

S.42 Power to amend Schedule

(1) The Central Government may, by notification, amend the Schedule, subject to the restriction that no such notification shall have the effect of increasing any penalty specified therein to more than twice of what was specified in it when this Act was originally enacted.

(2) Any amendment notified under Sub-Section (1) shall have effect as if enacted in this Act and shall come into force on the date of the notification.


S.43 Power to remove difficulties

(1) If any difficulty arises in giving effect to the provisions of this Act, the Central Government may, by order published in the Official Gazette, make such provisions not inconsistent with the provisions of this Act as may appear to it to be necessary or expedient for removing the difficulty.

(2) No order as referred to in Sub-Section (1) shall be made after the expiry of three years from the date of commencement of this Act.

(3) Every order made under this Section shall be laid, as soon as may be after it is made, before each House of Parliament.


S.44 Amendments to certain Acts

(1) In Section 14 of the Telecom Regulatory Authority of India Act, 1997 (24 of 1997), in clause (c), for sub-clauses (i) and (ii), the following sub-clauses shall be substituted, namely:--

"(i) the Appellate Tribunal under the Information Technology Act, 2000 (21 of 2000);

(ii) the Appellate Tribunal under the Airports Economic Regulatory Authority of India Act, 2008 (27 of 2008); and

(iii) the Appellate Tribunal under the Digital Personal Data Protection Act, 2023.".

(2) The Information Technology Act, 2000 (21 of 2000) shall be amended in the following manner, namely:--

(a) Section 43A shall be omitted;

(b) in Section 81, in the proviso, after the words and figures "the Patents Act, 1970 (39 of 1970)", the words and figures "or the Digital Personal Data Protection Act, 2023" shall be inserted; and

(c) in Section

Sch. SCHEDULE

THE SCHEDULE

[See Section 33 (1)]

Sl. No.

Breach of provisions of this Act or rules made thereunder

Penalty


Legal Commentary on the Digital Personal Data Protection Act, 2023 - Schedule

Introduction

The Digital Personal Data Protection Act, 2023 (DPDPA) represents a significant legislative step in India towards safeguarding personal data. It establishes a comprehensive framework for the processing of digital personal data, recognizing individuals' rights to privacy and data protection.

What does Section Says

The Schedule of the DPDPA outlines the penalties for various offenses related to the processing of personal data, including breaches of duty by data fiduciaries and violations concerning children's data.

Essential Ingredients

  • Data Fiduciaries: Entities that determine the purpose and means of processing personal data.
  • Data Principals: Individuals whose personal data is being processed.
  • Penalties: Specific financial penalties are prescribed for various breaches.

Scope of Section

The Schedule applies to all entities processing digital personal data within India, regardless of where the data was originally collected. It includes provisions for both online and offline data that has been digitized.

Punishment for Section

Penalties range from INR 10,000 for minor breaches to INR 250 crore for severe violations, such as unauthorized processing or failure to protect children's data.

Legal Comments

  • Data Protection Framework - The DPDPA establishes a comprehensive framework for the protection and processing of personal data in India. - [Source Reference]
  • Explicit Consent - The Act mandates obtaining explicit consent from individuals before collecting or processing their data. - [Source Reference]
  • Penalties for Breaches - Financial penalties for breaches range from INR 10,000 to INR 250 crore, depending on the severity of the violation. - [Source Reference]
  • Children's Data Protection - The Schedule specifies penalties of up to INR 200 crore for non-fulfillment of obligations concerning children's data. - [Source Reference]
  • Data Fiduciaries' Duties - The Act introduces duties for data fiduciaries, including the obligation to protect personal data. - [Source Reference]
  • Cross-Border Data Transfers - The DPDPA permits cross-border data transfers to jurisdictions outside of India, subject to certain conditions. - [Source Reference]
  • Regulatory Authority - The Data Protection Board of India is established as the enforcement body for the Act. - [Source Reference]
  • Scope of Application - The Act applies to the processing of digital personal data collected online or offline and digitized. - [Source Reference]
  • Rights of Data Principals - The Act outlines the rights of data principals, including the right to access and rectify their personal data. - [Source Reference]
  • Non-Personal Data Exclusion - The DPDPA focuses exclusively on digital personal data and does not apply to non-personal data. - [Source Reference]
  • Compliance Obligations - Entities must comply with the obligations set forth in the Act to avoid penalties. - [Source Reference]
  • Grievance Redressal - The current provisions do not include a grievance redressal mechanism, which may be a concern for data principals. - [Source Reference]
  • Maximum Penalty Cap - The maximum penalty cap has been set at INR 250 crore, which is a significant deterrent for non-compliance. - [Source Reference]
  • Data Processing Principles - The Act defines six different data protection principles that must be adhered to by data fiduciaries. - [Source Reference]
  • Legislative Evolution - The DPDPA is the first cross-sectoral law on personal data protection in India, reflecting years of deliberation. - [Source Reference]
  • Financial Penalties - The penalties are designed to be proportionate to the nature of the violation, ensuring accountability. - [Source Reference]
  • Data Security Obligations - Entities are required to implement adequate security measures to protect personal data from breaches. - [Source Reference]
  • Public Awareness - The Act emphasizes the need for public awareness regarding data protection rights and responsibilities. - [Source Reference]
  • Impact on Businesses - Businesses must adapt their data processing practices to comply with the new legal framework established by the DPDPA. - [Source Reference]
  • International Standards - The DPDPA aligns with international data protection standards, enhancing India's global data protection posture. - [Source Reference]

SupremeToday Portrait Ad

Enter the Future of Legal Excellence with SupremeToday AI

Elevate your legal practice with advanced AI-driven research and drafting solutions. Experience unmatched efficiency, precision, and security, tailored exclusively for legal professionals.

experience-legal
logo-black

An indispensable Tool for Legal Professionals, Endorsed by Various High Court and Judicial Officers

Please visit our Training & Support
Center or Contact Us for assistance

qr

Scan Me!

India’s Legal research and Law Firm App, Download now!

For Daily Legal Updates, Join us on :

whatsapp-icon Back to top