
Data privacy in India and the Digital Personal Data Protection Act
Data privacy GD topic: what the DPDP Act and Rules 2025 require, when each part starts, the penalties, State exemptions, points for and against, and how to open the GD.
Data privacy is a person's control over information about themselves. Examples are a name, a phone number, a location and a purchase history. India's main law on it is the Digital Personal Data Protection Act, 2023, known as the DPDP Act. It sets rules for any company or government body that collects and uses digital personal data, and it gives each person rights over that data.
It is in the news because the law is now being switched on in stages. The Government notified the start dates on 13 November 2025, and the Data Protection Board provisions came into force that day. The duties on companies start later, and most of them begin on 13 May 2027.
Background
The starting point is the Supreme Court's judgment in Justice K.S. Puttaswamy v Union of India on 24 August 2017. It held that privacy is a fundamental right under Article 21 of the Constitution. A law to protect it took years. A Bill of 2019 was withdrawn in August 2022, and a new Bill was passed by Parliament on 7 and 9 August 2023 and received the President's assent on 11 August 2023.
The Act uses its own words. A data principal is the person the data is about, and a data fiduciary is the company or body that decides how to use it. The Act covers digital personal data, and also data collected on paper and then digitised. It gives a person the right to access their data, correct or erase it, and complain. It also lets a person name someone to act for them in case of death or incapacity.
The Act has three start dates, set by the Government on 13 November 2025. The Board provisions began that day. A smaller group of provisions begins on 13 November 2026, and the rest on 13 May 2027, including the penalty provisions. The DPDP Rules, 2025 add detail. A company must tell the Data Protection Board about a breach without delay, and give full details within 72 hours. It must also keep logs of its processing for at least one year.
Penalties are capped by the Schedule of the Act. A failure to keep reasonable security safeguards can cost up to ₹250 crore, and children's data and breach notice can each cost up to ₹200 crore. Fines go to the Consolidated Fund of India, not to the person affected. The widget below lets you weigh these caps against a company's profit.
Points in favour
- It gives people enforceable rights. Before this Act, India had no single law on personal data. A person can now ask a company for access, correction or erasure, and complain to the Data Protection Board if the company does not respond.
- It puts real money behind the duties. The Schedule allows penalties up to ₹250 crore for weak security and up to ₹200 crore for not reporting a breach. The Board must consider the nature, gravity and repeat nature of a breach before it sets the amount.
- It protects children. The Act defines a child as anyone under 18 and requires a parent's verifiable consent. It also bars tracking, behavioural monitoring and targeted advertising aimed at children.
- It is built to be workable for small firms. The Government can exempt startups from some duties under section 17(3), and the Rules give most companies 18 months to prepare. Supporters say this avoids the heavy load that harsher laws put on small businesses.
- It follows the Supreme Court and ends a long wait. Puttaswamy made privacy a fundamental right in 2017, and earlier Bills were dropped. Supporters say a clear law, even an imperfect one, is better than none.
Points against
- The State has wide exemptions. Under section 17(2)(a), the Centre can exempt State bodies in the interests of security and public order. PRS Legislative Research said these exemptions lack safeguards such as proportionality, which may allow surveillance without checks.
- It changes the Right to Information Act. Section 44(3) rewrites the RTI exemption for personal information. Critics say this could make it easier to refuse information that the public wants to see, such as details about public officials.
- A person gets no compensation. Fines under section 34 go to the Consolidated Fund of India. PRS notes that the Act drops earlier rights to compensation, and it has no right to data portability or to be forgotten.
- The Board's independence is open to question. Under section 20, its members serve for two years and can be reappointed. The Government appoints them through a committee led by the Cabinet Secretary, so critics ask whether the Board can act firmly against the State.
- The Act is narrow in reach and slow to start. It covers digital personal data and has no separate category for sensitive data such as health or biometrics. The main duties begin only on 13 May 2027, so for now there is little a person can enforce.
Opening the discussion
You can open with the legal base. "In 2017 the Supreme Court held that privacy is a fundamental right. The DPDP Act is the law that tries to put that into practice." This works when you want to set the frame before the group argues about details.
You can open with the penalty. "A company can face a fine of up to ₹250 crore for weak security. But the money goes to the Government, not to the person whose data leaked." This works when the group wants a sharp fact that has two sides.
You can open with a question to the group. "Should a student have the same privacy rights over a private app as over the State?" This works when you want to bring in the State exemptions early.
Concluding the discussion
A good conclusion names one strong point from each side and says what would improve the law. Most groups end on stronger safeguards for State access and on clear, fast enforcement.
"We heard that the Act gives people rights and puts large penalties on companies, and that it protects children. We also heard that State exemptions are wide, that the RTI change worries many, and that most duties start only in May 2027. So the Act is a real step, but it will be judged by how the Board is run and how the exemptions are used."
Facts worth quoting
| Fact | Figure | Source and year |
|---|---|---|
| Privacy held a fundamental right | 24 August 2017 | Puttaswamy judgment, 2017 |
| DPDP Act passed by Parliament | 7 and 9 August 2023 | Parliament, 2023 |
| Rules and Board provisions begin | 13 November 2025 | MeitY notification, 2025 |
| Most company duties begin | 13 May 2027 | MeitY notification, 2025 |
| Maximum penalty, weak security safeguards | ₹250 crore | DPDP Act Schedule, 2023 |
| Maximum penalty, failing to notify a breach | ₹200 crore | DPDP Act Schedule, 2023 |
| Age that counts as a child | Under 18 | DPDP Act, section 2(f) |
| Breach details due to the Board | Within 72 hours | DPDP Rules, 2025 |
Mistakes to avoid
- Saying the whole Act is already in force. The Board provisions began in November 2025, but most duties begin only on 13 May 2027. Give the dates.
- Saying fines go to the affected person. They go to the Consolidated Fund of India under section 34. The Act has no right to compensation for the person.
- Calling it a copy of the EU's GDPR. The DPDP Act covers only digital data, has no separate sensitive-data category and uses a narrower set of lawful grounds. Name one real difference.
- Attacking or defending the Government as a whole. Talk about specific sections, such as section 17 and section 44(3), and about the data.
Practise group discussion
Reading won't make you fluent. Book a group discussion and practise speaking in a group. You will get a detailed feedback report after the session.
Book a group discussion


