Information Technology Act, 2000
Privacy and Data Protection in India: IT Act to DPDP Act Explained
Privacy entered Indian technology law in fragments, a compensation section here, a confidentiality offence there, and acquired a constitutional spine only in 2017, when Puttaswamy made it a fundamental right and asked for the statute that became the DPDP Act, 2023. The field now runs on two clocks: the IT Act's s.43A and SPDI regime still operative, and the DPDP framework commencing in phases with its 2025 Rules. The pieces have appeared across Topics 54, 39 and 70; this note, as asked, assembles the whole subject: the right, the types of privacy, the IT Act provisions, the DPDP architecture, and the transition.
1. The Right and Its Types
Figure 1: The foundation case
📖 K.S. Puttaswamy v. Union of India, (2017) 10 SCC 1 Facts: In the Aadhaar litigation the Union questioned whether privacy was a fundamental right at all, resting on M.P. Sharma and Kharak Singh; a nine judge bench was constituted to answer. Held: Privacy is a fundamental right, intrinsic to life and personal liberty under Article 21 and reflected across Part III; the contrary readings of M.P. Sharma and Kharak Singh stand overruled. Any invasion must satisfy legality, a legitimate State aim, and proportionality. Informational privacy is expressly recognised, and the Union's commitment to a data protection law is recorded. |
Figure 2: The four faces of privacy
- Informational privacy and self-determination. Control over one's personal data, who collects it, for what purpose, how long it lives, the face of privacy that data protection law operationalises, and the interest behind consent, purpose limitation and erasure.
- Bodily and communication privacy. Bodily privacy covers biometrics, health and physical integrity, the sensitive core of the SPDI list; communication privacy protects calls and messages, the interest administered through the s.69 interception safeguards and the telephone tapping jurisprudence (Topics 70, 72)
- Surveillance and privacy. After Puttaswamy every surveillance power, interception, monitoring, traffic data collection, traceability, must pass legality, necessity and proportionality; the pending challenges to the s.69 framework and Rule 4(2) apply exactly this grid (Topics 70, 79)
2. Privacy Inside the IT Act
- Section 43A and the SPDI Rules. The 2008 answer: a body corporate possessing, dealing or handling sensitive personal data or information in a computer resource, negligent in implementing reasonable security practices and thereby causing wrongful loss or gain, pays compensation. The SPDI Rules, 2011 define the sensitive list, passwords, financial information, health condition, sexual orientation, medical records, biometrics, and prescribe consent, purpose limitation, disclosure limits and the IS/ISO 27001 benchmark (Topic 54)
- Section 72. The offence for the Act's own officials: disclosing records or information accessed under the Act's powers without consent, two years or fine or both, penalty enhanced under Jan Vishwas (Topic 65)
- Section 72A. The service provider offence: disclosure of personal information obtained under a services contract, without consent or in breach of contract, with intent or knowledge of wrongful loss or gain, three years or fine to five lakh or both, the provision that reaches errant employees and vendors (Topic 65)
- Section 66E and the content rules. Violation of bodily privacy through capturing or publishing private area images is s.66E, and the intermediary rules put privacy-invasive and morphed content on the short removal clocks (Topics 60, 74, 75)
- Data breaches. Under the current mix a breach engages s.43A compensation, s.43 liability of the intruder, CERT-In's six-hour reporting discipline, and, as the DPDP regime commences, fiduciary breach notification with schedule penalties (Topics 53, 64)
3. The DPDP Act, 2023 and the 2025 Rules
Figure 3: The cast of the new regime
- Scope. Digital personal data, personal data in digital form or digitised after collection, processed within India, or outside India in connection with offering goods or services to persons in India; personal or domestic use and publicly available data the principal has himself made public are outside.
- Data fiduciary vs body corporate, data principal vs user. The fiduciary is defined by determining purpose and means, a functional test replacing s.43A's body corporate; the data principal is the identified individual, a rights-holder where the SPDI Rules saw only a provider of information. Significant data fiduciaries, notified on volume, sensitivity and risk, add a resident data protection officer, independent audits and periodic impact assessments.
- Consent and its manager. Processing rests on consent, free, specific, informed, unconditional and unambiguous, given on a clear itemised notice, withdrawable as easily as given, or on defined legitimate uses such as voluntary provision, State functions, medical emergencies and employment purposes. Registered consent managers give principals a single interoperable dashboard.
- Security safeguards and breach notification. Every fiduciary takes reasonable security safeguards to prevent breach; on a personal data breach, the fiduciary intimates each affected principal and the Board in the manner and timelines the Rules prescribe, the obligation carrying the schedule's highest penalties.
- Children's data. For a child under eighteen, verifiable parental consent precedes processing; tracking, behavioural monitoring and targeted advertising directed at children are barred, with exemptions for notified classes and purposes.
- Cross-border transfers. Transfer is permitted to any country except those restricted by notification, a blacklist design, with sectoral laws such as RBI payment data localisation continuing to apply.
Figure 4: The principal's rights and duties
- Rights of the principal. Access to a summary of data and processing; correction, completion, updating and erasure, erasure following once purpose or consent is spent unless retention is legally required; grievance redressal with the fiduciary first; and nomination. The principal owes duties too, no impersonation, no false complaints, breach drawing the schedule's token penalty.
- The Data Protection Board of India. A digital-first adjudicator: it inquires into breaches and complaints, directs remediation, and imposes the schedule's civil penalties, up to Rs 250 crore for failure of security safeguards, with appeals to the TDSAT. It is a penalty body, not a compensation forum, a deliberate contrast with s.43A (Topic 39)
- The 2025 Rules and commencement. The DPDP Rules, 2025, notified in November 2025, operationalise notice, breach intimation, children's consent, significant fiduciary obligations and the Board's working, with obligations phased over roughly eighteen months from notification and the Board machinery first; the final phase carries the IT Act amendments, omission of s.43A, the s.81 proviso addition and the s.87(2)(ob) omission (Topics 39, 84)
4. IT Act vs DPDP Act
Figure 5: The outgoing and incoming regimes
- Personal data vs sensitive personal data. The SPDI Rules protected only the sensitive list; the DPDP Act protects all digital personal data in one class, with sensitivity handled through significant fiduciary designation and children's provisions rather than a separate category.
- Compensation vs penalty. s.43A compensates the injured individual through adjudication; the DPDP Act penalises the fiduciary before the Board, the principal's monetary remedy lying, if anywhere, in general law, the most examined structural difference.
- What survives. ss.72 and 72A, s.66E and the intermediary rules continue untouched: the DPDP Act replaces the s.43A civil regime, not the IT Act's privacy offences or content machinery.
⚠ Exam trap Date the layers: Puttaswamy in 2017 makes privacy fundamental and demands legality, legitimate aim and proportionality; the DPDP Act of 2023 begins phased commencement with the 2025 Rules; and until the final phase, s.43A and the SPDI Rules remain the operative compensation regime, so both frameworks are simultaneously true in the transition. Keep the vocabulary straight, body corporate and SPDI under the IT Act, data fiduciary, data principal and personal data under the DPDP Act, and remember that the Board imposes penalties but does not award the individual compensation, the precise point where the two regimes part. |
5. Frequently Asked Questions
How does the DPDP Act differ from Section 43A of the IT Act?
Section 43A gives a compensation remedy against a body corporate negligent in securing sensitive personal data or information, adjudicated under Section 46. The DPDP Act replaces this with a full regulatory regime: every data fiduciary processing any digital personal data owes statutory duties of notice, consent, purpose limitation, security safeguards, breach notification and honouring the principal's rights of access, correction and erasure, enforced by the Data Protection Board through civil penalties reaching Rs 250 crore. On the final commencement phase, Section 43A stands omitted and the DPDP Act joins the Copyright and Patents Acts in the Section 81 proviso.
What did Puttaswamy decide about privacy?
A nine judge bench held unanimously that privacy is a fundamental right, intrinsic to Article 21 and pervading Part III, overruling M.P. Sharma and Kharak Singh to the contrary. Every invasion must satisfy legality, a legitimate State aim and proportionality. The judgment expressly recognised informational privacy, anticipated a data protection statute, and now supplies the standard against which surveillance powers, traceability mandates and internet restrictions are tested.
6. Related Topics
- Topic 39: The DPDP transition. The commencement phases and IT Act amendments in detail.
- Topic 70: Section 69 and privacy. The surveillance side of the same right.