India explainer

The DPDP Act, Explained: Does India's Data Law Actually Protect You?

India finally has a data-protection law. The DPDP Act promises rights over your personal data — but rights on paper and power in practice are not the same thing. Here's what it does, and doesn't.

Here is the DPDP Act explained in plain English, and the harder question underneath it: does India’s first dedicated data-protection law actually protect you? The Digital Personal Data Protection Act, passed in 2023 after nearly a decade of drafts, court battles and false starts, is a significant piece of legislation. For the first time, an Indian who hands over a phone number, an address, a face scan or a payment history has a written framework that says what companies may and may not do with it. That matters. But a law is a promise, and promises are only as good as the power standing behind them. So let’s look at what the DPDP Act says, what rights it gives you, and where — in my reading — the gap between rights on paper and protection in practice is widest.

What the DPDP Act is, and why it exists

India spent years without a comprehensive data-protection statute. The turning point was the Supreme Court’s 2017 judgment in the Puttaswamy case, which held that privacy is a fundamental right under the Constitution. Once privacy became a right, the state was more or less obliged to build a law to protect it. What followed was a long procession of draft bills — a 2018 version, a 2019 version, a 2022 version that was withdrawn — before the DPDP Act finally passed in 2023. The detailed rules that make the Act operational have been drafted and consulted on separately, and much of the real texture of enforcement lives in those rules rather than in the Act itself.

The reason it matters is scale. India is one of the largest digital populations on earth. Hundreds of millions of people transact, borrow, vote-enrol, get healthcare and prove their identity through digital systems every day. I’ve written before about Aadhaar and UPI — the identity and payments rails that made this possible — and about how much personal data those systems generate as a side effect of simply living a modern Indian life. A law that governs what happens to that data is not a niche concern. It touches almost everyone.

What the Act broadly requires

Strip away the legal vocabulary and the DPDP Act rests on a few plain ideas. The people it protects are called Data Principals — that’s you, the individual whose data it is. The organisations that collect and decide what to do with your data are Data Fiduciaries. The word “fiduciary” is chosen deliberately: it signals that a company holding your data is supposed to act as a trustee of it, not simply an owner. Whether that framing survives contact with commercial reality is exactly the question worth watching.

Broadly, the Act asks organisations to do a handful of things:

  • Get consent. As a general rule, a company must ask before it processes your personal data, and the request must be clear about what data is being collected and why. Consent is meant to be specific, informed and as easy to withdraw as it was to give.
  • Give notice. Alongside the consent request, you’re owed a plain-language notice explaining the purpose of the collection and how you can exercise your rights.
  • Limit the purpose. Data collected for one stated reason isn’t supposed to be quietly repurposed for something else. If a delivery app asks for your address to deliver a parcel, that’s not a licence to build a movement profile and sell it.
  • Keep it only as long as needed. Once the purpose is served, the data is meant to be erased rather than hoarded indefinitely.
  • Secure it and own the failure. Fiduciaries are expected to take reasonable safeguards against breaches, and to notify the regulator and affected people when a breach happens.

Some organisations — the ones handling data at large volume or of a particularly sensitive nature — can be designated Significant Data Fiduciaries and carry heavier obligations, broadly including independent audits and impact assessments. There are also carefully drawn rules around children’s data, where verifiable parental consent is generally required and behaviourally targeting minors is restricted.

The word “fiduciary” signals that a company holding your data is supposed to act as a trustee of it. Whether that survives contact with commercial reality is exactly the question worth watching.

The rights it gives you

This is the part that should matter most to an ordinary person, because it’s where an abstract law becomes something you can actually use. Broadly, the DPDP Act gives every Data Principal a bundle of rights over their own data:

  • The right to notice and information — to be told what a company holds about you and how it’s being processed.
  • The right to correction and updating — to fix data that’s wrong or incomplete, which matters enormously when a mistaken record can lock you out of a loan, a subsidy or a service.
  • The right to erasure — to ask that your data be deleted once there’s no lawful reason to keep it.
  • The right to grievance redress — to complain to the company first, through a defined process, and to expect a response.
  • The right to nominate — to name someone who can exercise these rights on your behalf if you die or become incapacitated, which is a thoughtful and unusually humane touch.

On paper this is a real advance. A decade ago, an Indian who wanted a company to delete their data had essentially no lever to pull. Now there is a named right and process. If you use it — and I’d encourage people to — you may find that companies which never thought about deletion are suddenly obliged to think about it.

Who enforces it: the Data Protection Board

Rights need a referee. The Act creates a Data Protection Board of India to handle complaints, investigate breaches and impose penalties on organisations that break the rules. The penalties are structured to be large enough to sting even sizeable companies — the framework is designed around significant financial consequences for serious failures, rather than the token fines that make non-compliance a rounding error. That, at least, is the intent.

The Board is where a lot of the Act’s real-world credibility will be decided. A data-protection regime is essentially only as strong as its regulator: how independent it is, how well-resourced, how willing to act against powerful players including the government itself. And this is precisely where critics have concentrated their concern.

The honest weaknesses

I want to be balanced here, because it would be easy either to dismiss the Act as toothless or to oversell it as a privacy revolution. Neither is true. But there are real, substantive criticisms that any honest explainer has to put on the table.

Broad exemptions for the state

The most consistent criticism is that the Act carves out wide exemptions for government bodies. Broadly, the state can grant itself or its agencies relief from various obligations on grounds such as national security, sovereignty, public order and the like. Critics argue these grounds are drawn expansively and with limited independent oversight, which means the single largest collector of Indians’ personal data — the government — operates under looser constraints than a private company does. When a data-protection law binds the corner shop more tightly than the surveillance apparatus, you have to ask who it’s really protecting.

This is the pattern I keep returning to in my writing, and it’s worth naming plainly: how technology gets captured is rarely a dramatic seizure. It’s a set of quiet exceptions, written in calm legal language, that leave the powerful largely untouched while the rules bear down hardest on everyone with the least leverage.

Questions about the regulator’s independence

The second concern is structural. Critics have questioned how independent the Data Protection Board can really be, given how its members are appointed and how closely it sits to the executive. A regulator whose leadership and terms are shaped by the government it may one day have to investigate is in an awkward position. Independence isn’t a matter of good intentions; it’s a matter of design — fixed terms, transparent appointments, secure funding, insulation from pressure. The more of that design is missing, the more the Board’s teeth depend on the goodwill of the very people it’s meant to hold accountable.

Consent that can become a formality

There’s also a practical worry that consent, in the real world, degrades into a box you tick to get on with your life. If every app and service simply presents a take-it-or-leave-it consent screen, the “choice” is often no choice at all — especially for essential services you can’t realistically refuse. This is the mechanism at the heart of surveillance capitalism: manufacture a moment of consent, then treat it as a permanent licence. A good implementation of the rules can push back on this with genuine granularity and easy withdrawal. A weak one lets consent theatre continue with a legal blessing.

Concerns raised about the right to information

Some commentators have also raised concerns about how the DPDP Act interacts with existing transparency laws, worrying that amendments could make it harder to obtain certain personal information in the public interest — for example, in journalism or accountability work. This is contested territory and worth watching as the rules are finalised, rather than something to state as settled.

When a data-protection law binds the corner shop more tightly than the surveillance apparatus, you have to ask who it’s really protecting.

Rights on paper versus power in practice

Here is the through-line, and it’s the same one I trace across almost everything I write about technology and India. A law is a distribution of power dressed in the language of principle. To read it well, follow three questions: who takes — whose data-gathering does the law enable or leave alone? Who pays — who bears the cost when things go wrong? And who can actually fight back — how much friction stands between an ordinary person and a remedy?

By those tests, the DPDP Act is genuinely mixed. It gives real, usable rights to individuals — that’s the “who can fight back” column filling in, for the first time. But the exemptions and the questions over the regulator’s independence tilt the “who takes” column back toward the state and, indirectly, toward large incumbents who can absorb compliance costs that crush smaller rivals. A right you technically hold but can’t easily exercise against the biggest data collector in the country is a right on paper. Whether it becomes protection in practice depends almost entirely on the parts that aren’t finished yet: the rules, the Board’s composition, and the political will to enforce against power rather than only against the weak.

This is not cynicism. It’s the difference between reading the text of a law and reading its likely life. And it connects to a larger argument I’ve made about data colonialism: the value extracted from a billion people’s data flows overwhelmingly upward and outward, and a domestic law is one of the few instruments that could, in principle, redirect some of that power back toward the people it’s taken from. Whether India’s law does that, or merely formalises the existing order with a friendlier vocabulary, is still being decided.

What it means for an ordinary Indian

So, practically, what should you do with all this? A few things.

  1. Know that you now have named rights. You can ask a company what it holds on you, ask it to correct or delete that data, and complain through a defined grievance process. These aren’t theoretical. The more people use them, the more real they become.
  2. Treat consent as a decision, not a reflex. When an app asks for permissions it doesn’t obviously need, that’s a signal. You won’t always be able to refuse, but noticing is the first act of self-defence.
  3. Keep your grievance trail. If a company mishandles your data, the process broadly runs company-first, then escalation to the Board. Save your correspondence; a paper trail is leverage.
  4. Watch the rules, not just the Act. The most consequential details — timelines, thresholds, how children’s data and exemptions actually operate — live in the rules being finalised. That’s where the law’s real strength or weakness will show.

My honest bottom line: the DPDP Act is a meaningful, overdue step, and I’d rather live with it than without it. It moves India from having essentially no data-protection law to one with real individual rights. But it is not, on its own, protection. Its value will be decided by how it’s implemented and, above all, by whether enforcement can bind the powerful as tightly as the powerless. Rights on paper are the beginning of the story. Power in practice is how it ends — and that part is still being written.

Kenney Jacob is the author of Captured, a history of who takes, who pays, and who fights back.

Frequently asked questions

What is the DPDP Act?

India's Digital Personal Data Protection Act — the country's dedicated law governing how organisations collect and use personal data. Broadly, it requires consent for most processing, sets duties for those handling data, and grants individuals certain rights over their information.

What rights does the DPDP Act give you?

In general terms, rights to be informed about and consent to how your data is used, to seek correction and erasure, and to grievance redress. The strength of those rights in practice depends heavily on enforcement and on the exemptions written into the law.

Does the DPDP Act actually protect your privacy?

It is a real step, but critics point to broad exemptions — particularly for the state — and to questions about independent enforcement. A law is only as strong as the power behind it, so 'rights on paper' and 'protection in practice' can diverge.

← All articles