India Issues New Data Protection Rules
Published on:
Share this post

Article Summary
Summary of India's Data Protection Rules
Constitutional Background:
- The Supreme Court of India recognized the right to privacy as a fundamental right (Article 21 of the Constitution).
Legislation:
- The Digital Personal Data Protection Act (DPDP Act) was enacted in August 2023.
- The Ministry of Electronics and IT (MeitY) has now notified data protection rules under this act, which aim to create a functional privacy law.
Implementation Timeline:
- Full implementation will take 12 to 18 months.
- Key provisions like informed consent for data processing and breach notifications will only be operational after this timeframe.
Data Protection Board of India (DPB):
- The DPB will ensure compliance and is operational, with its head office in New Delhi and will consist of four members.
Data Localisation:
- Significant data fiduciaries will be defined based on their data processing volume, sensitivity, and potential risk to national sovereignty.
- Personal and traffic data should not be transferred outside India, reflecting a local data processing mandate.
Industry Reactions:
- The tech industry, including companies like Meta, Google, and Microsoft, is expected to resist the data localization requirement.
- Industry bodies, such as Nasscom, emphasize the need for interoperability in international data transfers.
Children's Data Protection:
- Companies must collect “verifiable” parental consent for processing children's personal data, offering flexibility for the adoption of compliance mechanisms.
Data Breach Protocols:
- Data fiduciaries are obligated to inform users immediately after a data breach, detailing the breach's nature, consequences, and mitigation efforts.
Penalties:
- Failure to implement adequate security measures to prevent data breaches can incur penalties of up to ₹250 crore.
Exemptions and Controversies:
- The Act provides extensive exemptions for government bodies concerning national security, public order, and friendly state relations.
- Concerns have been raised regarding potential weakening of the Right to Information (RTI) Act.
Security Measures:
- Data fiduciaries must implement reasonable security measures, including encryption and access controls, to safeguard personal data.
- Clear, standalone notices detailing the personal data collected and the purposes of processing are mandated.
International Cooperation:
- The government acknowledges the significance of developing international data transfer mechanisms in cooperation with key trading partners.
These rules represent a significant step in India's approach to data privacy, balancing between empowering citizens and addressing national security concerns.
Key Terms & Concepts
| Ministry of Electronics and IT | Notified data protection rules |
| Digital Personal Data Protection Act | Fundamental data protection law |
| Data Protection Board of India | Key adjudicatory body |
| Right to Information Act | Amended regarding data disclosure |
| Data Protection Rules, 2025 | Specifies personal data processing |
| New Delhi | Head office for DPB |
| Rs 250 crore | Maximum penalty for data breaches |
| Nasscom and Data Security Council of India | Industry response on data transfers |
| Significant data fiduciaries | Subject to specific regulations |
| Data localization requirement | Data processing within India |
| Verifiable parental consent | Requirement for children's data |




