Introduction
Privacy is no longer an abstract constitutional idea discussed only in courtrooms or academic journals. In today’s digital environment, privacy shapes everyday life. Every online purchase, banking transaction, biometric verification, location search, or social media interaction leaves behind data capable of being collected, stored, analyzed, and shared. As governments and corporations increasingly rely on digital systems, the question is no longer whether personal data is valuable, but who controls it and how far that control can extend.
India’s digital transformation has been exceptionally rapid. Over the last decade, the State has actively promoted digital governance through initiatives such as Aadhaar, Digital India, online welfare delivery systems, and electronic payment infrastructure. Simultaneously, private technology companies have expanded their influence over communication, commerce, entertainment, and financial transactions. This growth has created undeniable economic and administrative benefits, but it has also intensified concerns regarding surveillance, data breaches, profiling, and misuse of personal information.
For years, India lacked a dedicated legal framework capable of regulating the processing of personal data. The legal position changed significantly after the Supreme Court’s landmark decision in Justice K.S. Puttaswamy (Retd.) v. Union of India, where privacy was recognized as a fundamental right protected under the Constitution. The judgment transformed privacy from a vague constitutional value into an enforceable right linked directly to dignity, autonomy, and liberty.
The enactment of the Digital Personal Data Protection Act, 2023 (“DPDP Act”) represents Parliament’s legislative response to this constitutional development. The statute is unquestionably an important step toward establishing a formal data protection regime in India. However, the legislation also reveals an underlying tension that continues to define modern constitutional democracies: how should the law balance individual privacy against the State’s expanding digital and regulatory powers?
This article argues that while the DPDP Act introduces important safeguards, it remains a cautious and state-oriented framework rather than a fully rights-centric privacy law. Its long-term constitutional legitimacy will depend not merely upon statutory language, but upon judicial interpretation, institutional independence, and the willingness of the State to subject itself to meaningful accountability standards.
Privacy as a Constitutional Right
Indian constitutional jurisprudence did not always recognize privacy as a guaranteed fundamental right. Earlier Supreme Court decisions reflected a narrower understanding of constitutional liberty. In M.P. Sharma v. Satish Chandra, the Court rejected the argument that the Constitution explicitly protected privacy against search and seizure.Similarly, Kharak Singh v. State of Uttar Pradesh adopted a limited approach toward surveillance-related privacy claims.
However, technological developments fundamentally altered the nature of constitutional risks. The expansion of biometric identification systems, digital databases, and electronic surveillance mechanisms created concerns that earlier constitutional interpretations were no longer sufficient to protect individual liberty.
This shift became evident in Justice K.S. Puttaswamy (Retd.) v. Union of India. A unanimous nine-judge bench of the Supreme Court held that privacy forms an intrinsic part of the rights guaranteed under Articles 14, 19, and 21 of the Constitution. The Court recognised that informational privacy is central to personal autonomy and individual dignity.
Importantly, the judgment also established the proportionality standard for evaluating restrictions upon privacy. According to the Court, any invasion of privacy must satisfy four conditions:
The action must have legal sanction;
It must pursue a legitimate state objective;
The restriction must be necessary;
The measure adopted must be proportionate to the purpose sought to be achieved.
The DPDP Act must therefore be examined not merely as an ordinary regulatory statute, but as legislation operating within a constitutional framework shaped directly by Puttaswamy.
Core Features of the DPDP Act
The Digital Personal Data Protection Act, 2023 applies to the processing of digital personal data within India and also extends to entities outside India offering goods or services to individuals located in India
One of the central features of the legislation is its consent-based model. Section 6 requires consent to be free, informed, specific, unconditional, and unambiguous. In theory, this framework seeks to ensure that individuals retain meaningful control over their personal information.
The Act also grants rights to “data principals,” including the right to access information regarding processing activities, the right to seek correction or erasure of data, and the right to grievance redressal. These provisions reflect the growing recognition that individuals should not remain passive subjects within digital ecosystems dominated by large institutions.
The legislation imposes obligations upon “data fiduciaries,” namely entities processing personal data. Such entities are required to implement reasonable security safeguards, notify data breaches, and erase personal information once the purpose of processing has been fulfilled unless retention is legally necessary.
The Act additionally introduces safeguards concerning children’s data. Section 9 prohibits behavioral monitoring and targeted advertising directed at children and requires verifiable parental consent before processing children’s personal information.
The statute also establishes the Data Protection Board of India, which has authority to investigate non-compliance and impose financial penalties.
Viewed structurally, the legislation creates the appearance of a comprehensive privacy framework. Yet the real constitutional debate begins where the statute grants power back to the State itself.
The Constitutional Problem with Broad Government Exemptions
The most controversial provision of the DPDP Act is Section 17, which empowers the Central Government to exempt certain state instrumentalities from the application of the Act on grounds such as sovereignty, integrity of India, security of the State, and maintenance of public order.
No democratic legal system can completely deny the State surveillance or intelligence-gathering powers. National security and public order are unquestionably legitimate governmental concerns. However, constitutional democracies are judged not by whether they exercise power, but by whether such power is subject to meaningful legal restraint.
This is precisely where criticism of the DPDP Act becomes significant.
The legislation grants broad exemption powers without simultaneously creating strong independent oversight mechanisms. The Act does not mandate prior judicial approval for exempted processing activities, nor does it establish detailed statutory safeguards limiting the scope of executive discretion.
This creates a difficult constitutional question. If privacy is recognized as a fundamental right, can the executive retain such expansive authority to exempt itself from compliance obligations?
The Internet Freedom Foundation, in its analysis of the legislation, observed that the exemption framework may weaken accountability safeguards concerning state data processing.While supporters of the legislation argue that flexibility is necessary for governance and security purposes, critics contend that constitutional rights lose practical value if exceptions become excessively broad.
The issue is not whether the State should possess surveillance powers. Every modern government does. The issue is whether those powers are accompanied by adequate procedural safeguards capable of preventing arbitrary or disproportionate intrusion.
Concerns Regarding Institutional Independence
Another important issue concerns the structure of the Data Protection Board of India. Under the DPDP Act, appointments to the Board are made by the Central Government.[13]
Institutional independence is not a technical formality. In regulatory systems involving constitutional rights, independence is essential for public confidence. A data protection authority must be capable of acting impartially, including in cases where state agencies themselves are involved.
The European Union’s GDPR places considerable emphasis upon independent supervisory authorities insulated from executive control.[14] By contrast, the Indian framework adopts a comparatively executive-driven model.
This does not automatically invalidate the legislation. However, the concentration of appointment and operational authority within the executive raises legitimate concerns regarding impartial adjudication and institutional credibility.
A privacy regulator cannot merely exist in form; it must also inspire confidence that constitutional rights will be protected even when politically inconvenient.
Privacy Versus Transparency: The RTI Amendment Debate
The DPDP Act also amends Section 8(1)(j) of the Right to Information Act, 2005.[15] Previously, personal information could still be disclosed where larger public interest justified disclosure. The amendment removes this balancing standard.
This change has generated criticism from transparency advocates who fear that the amendment may reduce public accountability concerning information linked to public officials.
The debate reflects a larger constitutional tension between privacy and transparency. Both values are foundational within a democratic system. Excessive transparency may undermine individual privacy, while excessive secrecy may weaken democratic accountability.
The challenge lies in maintaining an equilibrium where neither principle completely overrides the other.
Conclusion
The Digital Personal Data Protection Act, 2023 is an important legislative milestone in India’s constitutional and digital evolution. It acknowledges that privacy cannot remain an abstract ideal in a society increasingly governed by digital infrastructure and large-scale data processing.
The legislation introduces meaningful protections through consent requirements, user rights, obligations upon data fiduciaries, and statutory penalties for non-compliance. It represents a serious attempt to establish a legal framework capable of regulating India’s rapidly expanding digital ecosystem.
At the same time, the Act reveals the continuing tension between constitutional liberty and state authority. Broad governmental exemptions, concerns regarding regulatory independence, and significant executive discretion ensure that debates surrounding the legislation are unlikely to disappear soon.
Ultimately, the future of privacy in India will not depend solely upon legislative enactment. It will depend upon whether constitutional principles articulated in Puttaswamy continue to meaningfully restrain concentrations of informational power — whether exercised by corporations or by the State itself.
A modern democracy cannot function without digital governance. But neither can constitutional freedom survive if privacy exists only in theory while exceptions consume the rule in practice.
Footnotes
Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1.
M.P. Sharma v. Satish Chandra, AIR 1954 SC 300.
Kharak Singh v. State of Uttar Pradesh, AIR 1963 SC 1295.
ustice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1.
Digital Personal Data Protection Act, 2023, 3.
Digital Personal Data Protection Act, 2023, 6.
Digital Personal Data Protection Act, 2023, 11–14.
Digital Personal Data Protection Act, 2023, 8.
Digital Personal Data Protection Act, 2023, 9.
Digital Personal Data Protection Act, 2023, Chapter V.
Digital Personal Data Protection Act, 2023, 17.
Internet Freedom Foundation, Initial Analysis of the Digital Personal Data Protection Bill, 2023 (2023).
Digital Personal Data Protection Act, 2023, 18.
General Data Protection Regulation, Regulation (EU) 2016/679, arts. 51–54.
Digital Personal Data Protection Act, 2023, 44(3)
Disclaimer
This article is published by CLEAR LAW (clearlaw.online) strictly for educational and informational purposes only. It does not constitute legal advice, legal opinion, or any form of professional counsel, and must not be relied upon as a substitute for consultation with a qualified legal practitioner. Nothing contained herein shall be construed as creating a lawyer-client relationship between the reader and the author, publisher, or CLEAR LAW (clearlaw.online).
All views, interpretations, and conclusions expressed in this article are solely those of the author and represent independent academic analysis. CLEAR LAW (clearlaw.online) does not endorse, verify, or guarantee the accuracy, completeness, or reliability of the content, and expressly disclaims any responsibility for the same.
While reasonable efforts are made to ensure that the information presented is accurate and up to date, no warranties or representations, express or implied, are made regarding its correctness, adequacy, or applicability to any specific factual or legal situation. Laws, regulations, and judicial interpretations are subject to change, and the content may not reflect the most current legal developments.
To the fullest extent permitted by applicable law, CLEAR LAW (clearlaw.online), the author, editors, and publisher disclaim all liability for any direct, indirect, incidental, consequential, or special damages arising out of or in connection with the use of, or reliance upon, this article.
Readers are strongly advised to seek independent legal advice from a qualified professional before making any decisions or taking any action based on the contents of this article. Reliance on any information provided in this article is strictly at the reader's own risk.
By accessing and using this article, the reader expressly agrees to the terms of this disclaimer.


