Information Technology Act, 2000
Privacy and Data Protection under the IT Act, 2000
The IT Act was not enacted as a privacy law, and for most of its life India had no general data protection statute. Privacy protection was therefore assembled from scattered provisions: a civil duty on companies to secure sensitive data, offences for unauthorised disclosure and for capturing private images, and procedural safeguards around state interception. The Supreme Court's recognition of privacy as a fundamental right in 2017 set the stage for a dedicated law, the Digital Personal Data Protection Act, 2023, which will replace the central provision of the IT Act regime. This note explains the old regime, the constitutional foundation, and the transition.
1. A House Guarded by Separate Locks
Until recently, personal data in India was like a house protected by a few unrelated locks: one on the bedroom (private images, s.66E), one on the safe (sensitive data held by companies, s.43A), one on the servants' mouths (disclosure by service providers and officials, ss.72 and 72A), and a rule that the police may enter only with a warrant (interception safeguards, s.69). Each lock worked, but large parts of the house were open. The DPDP Act, 2023 replaces the separate locks with a single security system covering all digital personal data.
Figure 1: How privacy protection developed
2. The Constitutional Foundation
📖 Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1 Bench: Nine judges. Held: The right to privacy is intrinsic to the right to life and personal liberty under Article 21 and to the freedoms in Part III. M.P. Sharma and Kharak Singh were overruled to the extent they held otherwise. Privacy includes informational privacy, and the Court noted the need for a robust data protection regime. Test: An intrusion must satisfy legality (a law), a legitimate state aim, and proportionality between the object and the means, with procedural safeguards against abuse. |
Figure 2: The test for a valid intrusion into privacy
- Puttaswamy (Aadhaar), (2019) 1 SCC 1. A five-judge Bench largely upheld the Aadhaar scheme applying the proportionality test, but struck down Section 57 of the Aadhaar Act so far as it allowed private entities to demand Aadhaar authentication on the basis of contract.
- People's Union for Civil Liberties v. Union of India, (1997) 1 SCC 301. Telephone tapping infringes privacy unless done under procedure established by law; the Court laid down safeguards, which shaped the later interception rules under both the Telegraph Act and Section 69 of the IT Act.
- Right to be forgotten. High Courts have given limited recognition to it, for example Jorawer Singh Mundy v. Union of India (Delhi High Court, 2021), directing removal of a judgment acquitting the petitioner from search results. The DPDP Act now gives a statutory right to erasure.
3. Privacy Provisions of the IT Act
Figure 3: Where privacy sits in the IT Act
- Section 43(b). Downloading, copying or extracting data without permission attracts compensation.
- Section 66C. Fraudulent or dishonest use of another's electronic signature, password or unique identification feature: up to three years and fine up to ₹1 lakh.
- Section 66E. Intentionally capturing, publishing or transmitting the image of a private area of a person without consent, in circumstances violating privacy: up to three years or fine up to ₹2 lakh or both.
- Section 72. A person who, in exercise of powers under the Act, has secured access to any electronic record or information and discloses it without consent: since 30 November 2023 a penalty of up to ₹5 lakh (formerly up to two years or fine up to ₹1 lakh)
- Section 67C. Intermediaries must preserve and retain information as prescribed, which serves investigation but is also a point of tension with privacy.
- Sections 69 and 69B. State powers of interception, decryption and traffic data monitoring, subject to the 2009 Rules. A direction under Section 69 must be issued by the competent authority with reasons, is reviewed by a review committee, and lasts at most 60 days at a time and 180 days in all.
4. Section 43A and the SPDI Rules, 2011
Section 43A, Information Technology Act, 2000 (substance) Where a body corporate, possessing, dealing or handling any sensitive personal data or information in a computer resource which it owns, controls or operates, is negligent in implementing and maintaining reasonable security practices and procedures and thereby causes wrongful loss or wrongful gain to any person, such body corporate shall be liable to pay damages by way of compensation to the person so affected. |
- Body corporate. Includes a company, firm, sole proprietorship or other association of individuals engaged in commercial or professional activities.
- Reasonable security practices. As agreed between the parties, as specified by law, or, failing both, as prescribed by the Central Government.
- The Rules. The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, known as the SPDI Rules.
Figure 4: Sensitive personal data or information under Rule 3
- Exclusion. Information freely available in the public domain or furnished under the RTI Act is not sensitive personal data.
- Privacy policy (Rule 4). Publish a policy on the website stating what is collected, why, how it is disclosed and the security practices followed.
- Consent and collection (Rule 5). Obtain written consent (by letter, fax or email) before collecting sensitive data; collect only for a lawful purpose that needs it; tell the provider the purpose and recipients; retain it no longer than needed; allow review, correction and withdrawal of consent; and appoint a grievance officer who resolves complaints within one month.
- Disclosure (Rule 6). Only with prior permission, unless agreed by contract or needed for legal compliance, but mandated government agencies may obtain it on a written request for verification of identity, or for prevention, detection, investigation or prosecution of offences.
- Transfer (Rule 7). Within or outside India only to an entity ensuring the same level of protection, and only if necessary for a lawful contract or with consent.
- Security (Rule 8). A documented information security programme; ISO/IEC 27001 or an approved industry code is deemed compliance, with audit at least once a year.
Figure 5: Civil negligence and criminal disclosure
⚠ Limits of the IT Act regime The regime protected only 'sensitive' data, bound only bodies corporate and not the State, depended on negligence and proof of wrongful loss or gain, had no dedicated regulator, and gave individuals few enforceable rights. These gaps, highlighted after Puttaswamy, led to the Justice B.N. Srikrishna Committee report of 2018, the Personal Data Protection Bill, 2019, its withdrawal in 2022, and finally the DPDP Act, 2023. |
5. The Digital Personal Data Protection Act, 2023
- Enactment. Act 22 of 2023, which received assent on 11 August 2023.
- Scope (s.3). Digital personal data processed in India, and processing outside India connected with offering goods or services to persons in India. Personal data made publicly available by the individual is excluded.
- Grounds (ss.4 to 7). Processing only for a lawful purpose, on free, specific, informed and unambiguous consent after notice, or for certain legitimate uses such as data voluntarily provided for a specified purpose, State functions, legal obligations and emergencies.
- Duties of Data Fiduciaries (s.8). Ensure accuracy, take reasonable security safeguards, notify personal data breaches to the Data Protection Board and each affected person, and erase data once the purpose is served.
- Children (s.9). Verifiable parental consent for those below 18, and no tracking, behavioural monitoring or targeted advertising directed at children.
- Rights of Data Principals (ss.11 to 14). Access to information, correction and erasure, grievance redressal and nomination; with duties under Section 15 not to file false or frivolous complaints.
- Cross-border transfer (s.16). Permitted except to countries the Central Government restricts by notification.
- Enforcement. The Data Protection Board of India inquires into breaches and imposes penalties of up to ₹250 crore per breach (Schedule), with appeal to TDSAT. Penalties go to the State; the Act does not provide compensation to the affected person.
- Exemptions (s.17). Including processing for enforcing legal rights and preventing or investigating offences, and processing by notified State instrumentalities in the interest of sovereignty, security, public order and similar grounds.
Commencement and Effect on the IT Act
- DPDP Rules, 2025. Notified on 13 November 2025, with the Act brought into force in phases: the Board and administrative provisions immediately, consent manager provisions after 12 months, and the substantive obligations after 18 months, that is, in May 2027.
- Section 43A. Section 44(2) of the DPDP Act omits Section 43A of the IT Act. It is scheduled to take effect with the substantive provisions in May 2027; until then, Section 43A and the SPDI Rules continue to apply.
- What survives. The offences in Sections 66C and 66E, the civil penalties in Sections 72 and 72A, and the interception and blocking provisions continue alongside the DPDP Act.
Figure 6: The old regime and the new
⚠ Exam trap Do not write that the DPDP Act has already repealed Section 43A. It omits Section 43A only from the date Section 44(2) comes into force, scheduled for May 2027. Also remember the change in remedy: Section 43A gives the victim compensation, while the DPDP Act imposes penalties payable to the State. |
6. Quick Revision and Memory Aids
- 'Separate locks to one security system'. IT Act provisions to the DPDP Act.
- 'Legality, aim, proportion, safeguards'. The Puttaswamy test.
- 'PFH SMB R'. SPDI categories: Passwords, Financial, Health, Sexual orientation, Medical, Biometric, Related details.
- '43A negligent company compensates; 72A discloser pays up to ₹25 lakh'. Two civil data wrongs (72A decriminalised in 2023)
- '60 days, 180 days'. Maximum duration of an interception direction.
- 'Nov 2025, Nov 2026, May 2027'. The three phases of DPDP commencement.
7. Frequently Asked Questions
Which provisions of the IT Act protect privacy?
Sections 43(b), 43A, 72 and 72A (civil), Sections 66C and 66E (criminal), and the safeguards governing interception and monitoring under Sections 69 and 69B.
What is sensitive personal data under the SPDI Rules?
Passwords, financial information, physical, physiological and mental health conditions, sexual orientation, medical records, biometric information, and details relating to these provided to or received by a body corporate.
What is the relationship between the DPDP Act and Section 43A?
Section 44(2) of the DPDP Act omits Section 43A. Until that provision takes effect, scheduled for May 2027, Section 43A and the SPDI Rules continue to govern the security of sensitive personal data.
8. Related Topics
- Topic 7: Contraventions and Offences. Where the privacy offences sit.
- Topic 9: Electronic Evidence. Privacy of electronic material in trials.