India’s data protection journey represents a remarkable transformation from a fragmented regulatory approach to a comprehensive legal framework. For decades, the country relied on provisions originally designed for e-commerce and cybercrime, but recent legislative developments signal a fundamental shift toward robust privacy protections that align with global standards.
Table of Contents
- The Information Technology Act 2000: India’s first step
- Key amendments that expanded protection
- Recognizing the gaps in protection
- Industry initiatives toward EU standards
- The Digital Personal Data Protection Act 2023: A new era
- Core principles and requirements
- Implementation timeline and challenges
- The adequacy question remains open
- Looking ahead: Balancing sovereignty and compliance
The Information Technology Act 2000: India’s first step
When India entered the digital age, the Information Technology Act of 2000 emerged as the primary legal framework governing electronic transactions and cybercrime. This legislation, which came into force on October 17, 2000, was built on the United Nations Model Law on Electronic Commerce and primarily focused on facilitating e-commerce rather than protecting personal data.
The IT Act defined critical terms like data and computer database, emphasizing the handling of information in electronic form. While it addressed unauthorized access, hacking, and data theft, the Act’s approach to personal data protection was limited. Section 43A held organizations liable for negligence in implementing security measures, but this was far from a dedicated data protection regime.
Key amendments that expanded protection
The 2008 amendment marked a significant evolution. It introduced Section 66A, which penalized sending offensive messages, and Section 69, granting authorities power to intercept or monitor digital communications. More importantly, it made corporations responsible for implementing effective data security practices and liable for breaches. However, the Supreme Court later struck down Section 66A in 2015, ruling it violated the constitutional right to freedom of speech.
The IT Rules 2011 supplemented the Act by prescribing specific obligations for data controllers. These rules required every data controller handling sensitive personal data to maintain a privacy policy, appoint a grievance officer, and obtain prior consent before collecting personal information. Sensitive personal data was defined to include financial information, health conditions, sexual orientation, and biometric information.
Recognizing the gaps in protection
Despite these provisions, India’s data protection framework remained rudimentary. The IT Act was designed for a different era, focusing on cybercrime and e-commerce transactions rather than the nuanced challenges of personal data processing. There was no comprehensive legal framework addressing consent management, data principal rights, cross-border transfers, or accountability measures that modern data protection demands.
The limitations became increasingly apparent as India’s digital economy expanded. Businesses handling massive volumes of personal data from citizens lacked clear guidelines on processing obligations. The European Union commissioned a study in 2010 to assess India’s data protection adequacy and found the laws insufficient. This finding had significant implications for Indian businesses, particularly in the IT and business process outsourcing sectors that handled EU citizen data.
Industry initiatives toward EU standards
Recognizing the economic stakes, industry bodies took proactive steps. NASSCOM worked closely with the Department of Information Technology and Electronics to draft amendments that would align India’s framework with EU adequacy norms and US Safe Harbor principles. The goal was clear: achieve recognition as a country offering adequate data protection to facilitate smoother data flows from Europe.
According to NASSCOM, obtaining EU data adequacy status could increase revenues from the EU by approximately seven billion dollars annually through increased offshoring and cost savings. However, EU officials made it clear that data protection is a fundamental right that cannot be negotiated as part of trade deals. The path to adequacy would require genuine legislative reform.
The Digital Personal Data Protection Act 2023: A new era
After years of deliberation and multiple draft versions, India enacted the Digital Personal Data Protection Act in August 2023. This landmark legislation represents India’s first comprehensive data protection law, replacing the patchwork of IT Act provisions with a structured framework recognizing both individual rights and legitimate processing needs.
The DPDP Act applies to digital personal data processed within India, whether collected digitally or converted from non-digital form. Importantly, it has extraterritorial reach, applying to processing outside India if it relates to offering goods or services to individuals within the country. The Act establishes key roles including Data Fiduciaries (controllers), Data Processors, and Data Principals (individuals), with the Data Protection Board of India serving as the enforcement authority.
Core principles and requirements
The legislation is built on six fundamental principles: lawful, fair, and transparent processing; purpose limitation; data minimization; accuracy; storage limitation; and security safeguards. Data Fiduciaries must obtain free, specific, informed, unconditional, and unambiguous consent with clear affirmative action. They must provide privacy notices in clear language, available in English or any of the 22 languages in the Eighth Schedule of the Constitution.
Data Principals enjoy several rights including access to information about processing activities, correction and erasure of personal data, grievance redressal mechanisms, and the right to nominate someone to exercise their rights in case of death or incapacity. Notably, the Act introduces special protections for children, prohibiting tracking, behavioral monitoring, and targeted advertising directed at them.
Implementation timeline and challenges
The DPDP Rules were finally released in November 2025, operationalizing the Act through a phased implementation. The Data Protection Board was established in November 2025, with registration for consent managers opening in November 2026, and full compliance requirements for consent, privacy notices, and security becoming effective by May 2027.
Organizations must now prepare for substantial compliance investments. Unlike the GDPR, the DPDP Act does not differentiate between regular and sensitive personal data, applying broadly to any identifiable individual data. It also lacks a small business exemption, though companies can petition for individual exemptions. Penalties range from Rs 10,000 to Rs 250 crores, depending on the breach severity.
The adequacy question remains open
Despite these advances, questions persist about whether the DPDP Act will secure an EU adequacy decision. The Act notably exempts processing of foreign individuals’ data in India when done pursuant to contracts with persons outside India, potentially undermining adequacy prospects. Concerns also remain about government surveillance powers and limited parliamentary oversight of intelligence services.
In May 2025, the European Data Protection Supervisor blocked data transfers to India, citing gaps in cross-border rights and enforcement mechanisms. Unlike the EU’s proactive adequacy assessment system, India allows outbound data transfers unless specifically restricted by government notification. This fundamental difference in approach creates challenges for achieving equivalence with EU standards.
Looking ahead: Balancing sovereignty and compliance
India’s data protection evolution reflects the complex balance between protecting citizen privacy and enabling digital economic growth. The DPDP Act grants significant exemptions to government agencies for sovereignty, security, and public order purposes, raising concerns about whether the framework provides adequate checks on state surveillance powers comparable to EU requirements.
For Indian businesses, particularly in IT services and BPO sectors handling international data, the path forward involves dual compliance strategies. Organizations must implement DPDP Act requirements domestically while using Standard Contractual Clauses or Binding Corporate Rules for EU data transfers until adequacy is achieved.
The journey from the IT Act 2000 to the DPDP Act 2023 demonstrates India’s commitment to building a robust data protection regime. While challenges remain in achieving full EU compliance and addressing concerns about government access to data, the framework represents a significant step forward. As implementation proceeds through 2027, the effectiveness of enforcement mechanisms and willingness to address adequacy gaps will determine whether India achieves its goal of becoming a trusted global data processing destination.
What do you think? How will India’s approach to balancing national security exemptions with privacy protections affect its prospects for EU adequacy recognition? Can the DPDP Act’s consent-centric model effectively protect personal data in an era of complex data processing ecosystems?
References
- https://en.wikipedia.org/wiki/Information_Technology_Act,_2000
- https://www.termsfeed.com/blog/india-it-act-of-2000-information-technology-act/
- https://oercs.berkeley.edu/privacy/international-privacy-laws/india-privacy-law
- https://www.business-standard.com/article/economy-policy/data-adequacy-grant-to-india-non-negotiable-says-eu-envoy-113051700013_1.html
- https://www.computerworld.com/article/2564896/indian-law-may-satisfy-data-protection-concerns.html
- https://en.wikipedia.org/wiki/Digital_Personal_Data_Protection_Act,_2023
- https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
- https://www.mwe.com/insights/what-to-know-about-indias-new-privacy-law/
- https://www.cookieyes.com/blog/india-digital-personal-data-protection-act-dpdpa/
- https://www.urmconsulting.com/blog/updated-data-protection-laws-introduced-by-chile-and-india
- https://www.medianama.com/2025/05/223-eu-denies-data-export-india-gaps-data-protection-law/
- https://www.saikrishnaassociates.com/eu-authority-blocks-data-transfer-to-india-and-the-future-of-cross-border-transfers-from-the-eu-under-the-dpdp-act/
Leave a Reply