India Implements Data Protection Rules
Published on:
Share this post

Article Summary
Summary of Data Protection Rules Notification by MeitY
Legal Framework
- Digital Personal Data Protection Act (DPDP Act): Received Presidential assent in August 2023; operational with certain provisions in force.
- Right to Privacy: Declared a fundamental right by the Supreme Court of India in 2017.
Implementation Timeline
- Full implementation of key protections (informed consent, specific legitimate uses of data, data breach notifications) will take 12 to 18 months post-notification of rules.
Data Protection Board of India (DPB)
- Establishment and operationalization of the DPB to ensure compliance with data protection laws.
- Composed of four members with the headquarters in New Delhi.
- Controversial Amendment: Amendment to the Right to Information (RTI) Act to restrict disclosure of personal information about public officials.
Data Processing Regulations
- Government to classify “significant data fiduciaries” based on the volume, sensitivity, and risks posed by their data processing concerning:
- Sovereignty
- Electoral democracy
- Security and public order
- Broader data localization requirements, restricting the transfer of personal and traffic data outside India.
Definition of "Significant Data Fiduciaries"
- Expectation to include major tech companies such as Meta, Google, Apple, Microsoft, and Amazon.
Children's Data Protection
- Requirement for "verifiable" parental consent before processing children's personal data.
- Flexibility given to companies to select their methods for compliance.
Breach Notification Requirements
- Data fiduciaries must notify affected individuals "without delay" after a breach, detailing:
- Nature, extent, timing, and location of the breach.
- Consequences for users.
- Steps taken to mitigate risks.
- Penalties for inadequate safeguards can reach up to Rs 250 crore.
Exemptions and Critics
- Several exemptions provided to the government for data processing on grounds of:
- National security
- Friendly relations with other states
- Public order
- Concerns raised about potential weakening of RTI Act, including objections from civil society and government think tank, Niti Aayog.
Data Fiduciary Obligations
- Implementation of reasonable security measures such as encryption, access control, and monitoring for unauthorized access.
- Clear and comprehensive notifications to data principals prior to data processing, including:
- Itemization of collected personal data.
- Purpose of data processing.
Conclusion
The recent enactment of data protection rules represents a significant step in India's journey toward comprehensive data privacy legislation. It intends to balance the protection of individual rights with national interests, amidst ongoing debates about governance, data localization, and digital rights in the era of rapid technological growth.
Key Terms & Concepts
| Digital Personal Data Protection Act | Privacy law enacted in 2023 |
| Data Protection Board of India | Key adjudicatory body |
| Right to Information Act | Amended for personal data provisions |
| Rs 250 crore | Maximum penalty for data breach |
| 12 to 18 months | Timeline for full implementation |
| Niti Aayog | Government think tank raised concerns |
| Data fiduciary | Entity processing personal data |
| Data localization requirement | Limits data transfer outside India |
| Meta, Google, Apple, Microsoft, Amazon | Potential significant data fiduciaries |
| Informed consent | User permission for data processing |
| Parental consent | Requirement for children's data processing |




