DPDPA
DPDPA
The Digital Personal Data Protection Act (DPDPA) of 2023 , passed by the Indian Parliament
in August 2023, which aims to regulate the processing of digital personal data within India ,
balancing privacy rights with the needs of businesses and government, and mirroring
global data protection standards.
This is an act to provide for the processing of digital personal data in a manner that
recognises both the right of individuals to protect their personal data and the need to
process such personal data for lawful purposes and for matters connected therewith or
there to .
Parliament of India
● Scope of this act : Applies to the processing of digital personal data within India ,
including data collected in digital form or digitized from non-digital form .
The Act outlines the obligations of data fiduciaries, including providing clear information
about data processing, obtaining informed consent, and implementing security
safeguards.
● Data Principals' Rights : Citizens are empowered with rights, such as the right to access
their data, correct inaccuracies, demand erasure, and object to processing.
● Regulatory Body: The Act provides for the establishment of the Digital Personal Data
Protection Authority (DPDA) as the regulatory body for implementation and enforcement.
● Penalties: The Act includes provisions for financial penalties for breaches of rights,
duties, and obligations.
● Data Localization: The 2023 law reverses course on the issue of data localization, stating
that the government may restrict data flows to certain countries by notification, but this will
not impact measures taken by sector-specific agencies that have or may impose
localization requirements.
Legal issues :
1. Whether the Aadhaar Project violates the right to privacy of the citizens and is
unconstitutional?
2. Whether Right to Privacy is a fundamental right under Article 21 given in Part III of
Indian Constitution?
3. Whether Aadhar Act's provisions mandating the linking of Aadhar with mobile numbers,
bank accounts and school admissions be struck down?
"BUT LINKING WITH MOBILE NUMBER, BANK ACCOUNTS & SCHOOL ADMISSIONS
NOT MANDATORY."
ARTICLE 21 : No person shall be deprived of shall be deprived of his life or personal liberty
except according to procedure established by law.
STEP 2
STEP 3
Third, it must be proportionate i.e., such state action must be necessary and the action
ought to be the least intrusive.
• Right to be forgotten
The Digital Personal Data Protection Act (DPDPA), enacted in 2023, is India's first data
protection law, aiming to regulate the pro-cessing of digital personal data and empower
individuals with rights over their data, while also outlining obligations for data fiduciaries .
• Lawful, Fair, and Transparent Processing: Data processing must be lawful, fair, and
transparent.
• Purpose Limitation: Data can only be used for the purposes specified at the time of
obtaining consent.
• Storage Limitation: Data should be stored only as long as necessary for the specified
purpose.
• Accountability: Mechanisms for addressing data breaches and breaches of the Act's
provisions.
Penalties:
Violations of the Act can result in penalties, including fines of up to INR 250 crore.
Name RUCHIRANI GOUDA
SEM 2
ROLL NO 130650324059