Every time you browse the internet, share a photo, or make an online purchase, you leave behind a trail of digital breadcrumbs. In India, where over 900 million people are now online, the question of who controls this data and how it’s used has become a pressing concern. The digital age has brought unprecedented convenience, but it has also exposed us to new forms of surveillance, data exploitation, and privacy violations that our legal systems are still struggling to address.
Table of Contents
- The scale of data collection in the digital ecosystem
- Cookies and online tracking mechanisms
- The gap between technological advancement and legal protection
- Key provisions of the DPDP Act
- Surveillance and government access to data
- Legislative gaps in internet privacy
- The challenge of enforcement and compliance
- Special obligations for significant data fiduciaries
- Cross-border data transfers and localization
- The path forward: balancing innovation and protection
The scale of data collection in the digital ecosystem
When you visit a website, use a mobile app, or interact with social media platforms, an invisible process begins. Companies deploy cookies and tracking technologies that follow your activity across websites, building detailed profiles of your behavior, preferences, and interests. Most users remain unaware they are being tracked online, creating a reasonable expectation of privacy that is routinely violated.
The scope of this data collection extends far beyond basic browsing habits. Digital platforms gather location data, search history, device information, contact lists, and even behavioral patterns. This information is then used for targeted advertising, algorithmic profiling, and in some cases, shared with third parties without meaningful consent. The problem becomes more acute when companies combine anonymized data with publicly available information, making it possible to identify specific individuals despite claims of anonymization.
Cookies and online tracking mechanisms
Cookies come in various forms, each with different privacy implications. Session cookies store temporary information during a website visit, while persistent cookies remain on your device for extended periods, tracking behavior over time. Marketing cookies enable targeted advertising by monitoring which products you view and which sites you visit. Some tracking mechanisms, like zombie cookies, recreate themselves even after deletion, raising serious concerns about user control over personal data.
Under India’s emerging data protection framework, websites must obtain explicit consent before using cookies that process personal data. However, many platforms employ dark patterns in their cookie banners, such as pre-ticked checkboxes or misleading button designs, that trick users into accepting all cookies. These deceptive practices violate both the Digital Personal Data Protection Act and consumer protection guidelines.
The gap between technological advancement and legal protection
India’s journey toward comprehensive data protection has been marked by significant delays. For years, the country relied on the Information Technology Act, 2000 and its associated rules, which provided limited protection for sensitive personal data. The landscape began changing in 2017 when the Supreme Court recognized privacy as a fundamental right under Article 21 of the Constitution in the landmark Puttaswamy judgment.
This recognition triggered efforts to create a standalone data protection law. After multiple drafts and revisions, Parliament passed the Digital Personal Data Protection Act in August 2023. However, the Act remains largely unimplemented, as the government has yet to notify its provisions or establish the Data Protection Board of India. This creates a peculiar situation where individuals have a constitutional right to privacy, but limited statutory mechanisms to enforce it.
Key provisions of the DPDP Act
Once operational, the DPDP Act will introduce several important protections. It requires organizations to obtain free, specific, informed, and unambiguous consent before processing personal data. Companies must provide clear privacy notices explaining what data they collect and how they use it. The law also grants individuals rights to access their data, correct inaccuracies, and request erasure when the purpose of collection is served.
For children under eighteen, the Act imposes stricter requirements. Companies must obtain verifiable parental consent and are prohibited from behavioral tracking or targeted advertising directed at minors. The draft rules specify methods for verifying parental identity, including the use of government-issued credentials or virtual tokens.
Surveillance and government access to data
Digital privacy challenges in India extend beyond commercial data collection to include state surveillance. The Information Technology Act grants law enforcement extensive powers to intercept communications and access user data. Provisions allow for real-time monitoring, interception, and decryption of online communications, often with minimal judicial oversight.
Projects like the Central Monitoring System have raised concerns about the proportionality of state surveillance. While security agencies argue these tools are necessary for national security and crime prevention, civil liberties advocates point to instances of unauthorized interceptions and the lack of adequate safeguards. The tension between security needs and privacy rights remains unresolved, with the DPDP Act providing broad exemptions for government data processing.
Legislative gaps in internet privacy
Current laws fail to address several critical aspects of online privacy. The Information Technology Act does not regulate the merging and sharing of data across databases, nor does it specify whether users must be notified about the presence of cookies or given do-not-track options. Questions about the evidentiary status of social media content, the use of electronic identifiers across platforms, and the right to request deletion of personal content remain unanswered.
The challenge of enforcement and compliance
Even with the DPDP Act on the books, enforcement presents significant hurdles. The law prescribes substantial penalties ranging from INR 5 crores to INR 250 crores for different violations, but without an operational Data Protection Board, there is no mechanism to investigate complaints or impose sanctions. Research shows that over 60 percent of Indian enterprises report significant disruption from evolving privacy regulations, highlighting the operational complexity of compliance.
The draft Digital Personal Data Protection Rules, released in January 2025, introduce technical requirements that will require substantial infrastructure changes. Companies must implement consent management systems, automated data erasure workflows, and purpose-linked storage mechanisms. For businesses processing large volumes of data, particularly those with legacy systems, meeting these requirements within the prescribed timelines will be challenging.
Special obligations for significant data fiduciaries
The government may designate certain companies as Significant Data Fiduciaries based on the volume and sensitivity of data they process. These entities face heightened obligations, including conducting annual data protection impact assessments, appointing independent auditors, and implementing additional safeguards for algorithmic systems. The designation criteria and compliance requirements remain unclear, creating uncertainty for large platforms and digital services.
Cross-border data transfers and localization
India has adopted a nuanced approach to data localization. Unlike earlier drafts that proposed strict storage requirements, the final DPDP Act allows cross-border data transfers to any country except those specifically blacklisted by the government. However, sector-specific regulations impose stricter controls. The Reserve Bank of India mandates that all payment system data be stored within India, while securities and insurance regulators have similar requirements for their respective sectors.
These fragmented requirements create compliance challenges for multinational companies. While the DPDP Act itself does not mandate localization, the draft rules allow the government to restrict transfers of certain categories of personal data designated as sensitive. This creates uncertainty about future obligations and may require companies to maintain separate infrastructure for Indian operations.
The path forward: balancing innovation and protection
India stands at a crossroads in defining its approach to digital privacy. The country’s digital economy continues to grow rapidly, with innovations in fintech, e-commerce, and digital services transforming how people live and work. At the same time, incidents of data breaches, surveillance overreach, and privacy violations highlight the urgent need for robust legal protections.
The success of India’s data protection regime will depend on several factors. First, the government must operationalize the DPDP Act by establishing the Data Protection Board and notifying the necessary rules. Second, enforcement mechanisms must be strengthened to ensure companies face real consequences for violations. Third, the framework must balance the needs of innovation and economic growth with the fundamental right to privacy.
What do you think? How can India ensure that its data protection laws keep pace with rapidly evolving technologies while fostering digital innovation? What role should individuals play in protecting their own privacy in an increasingly connected world?
References
- https://www.mondaq.com/india/privacy-protection/1709336/legality-of-online-tracking-under-the-data-privacy-act-2023
- https://ssrana.in/articles/legality-of-online-tracking-under-the-data-privacy-act-2023
- https://www.dlapiperdataprotection.com/?t=law&c=IN
- https://www.livelaw.in/articles/data-privacy-law-in-india-and-digital-personal-data-protection-rules-analysis-310865
- https://www.privacyworld.blog/2025/04/the-impact-of-indias-new-digital-personal-data-protection-rules/
- https://cis-india.org/telecom/knowledge-repository-on-internet-access/internet-privacy-in-india
- https://www.csoonline.com/article/4090967/indias-new-data-privacy-rules-turn-privacy-compliance-into-an-engineering-challenge.html
- https://www.americanbar.org/groups/business_law/resources/business-law-today/2025-may/india-data-protection-law/
Leave a Reply