The Digital Personal Data Protection Act, 2023
Act No. 22 of 2023, assented to on 11 August 2023. It governs what any business in India: including this one: may do with personal data held in digital form, and what you can require of them. This page summarises it. Where the summary and the Act differ, the Act is what counts.
The two words it turns on
- Data Principal: you, the person the data is about. For a child, it means the parent or lawful guardian; for a person with a disability, their lawful guardian (s. 2(j)).
- Data Fiduciary: whoever decides the purpose and means of processing. That is Deepsoch AI here. The word is chosen carefully: a fiduciary holds something on trust for somebody else (s. 2(i)).
A Data Processoris a third party processing on the fiduciary’s behalf (s. 2(k)). The fiduciary stays responsible for what its processors do, whatever the contract between them says (s. 8(1)).
Personal data is any data about an identifiable individual (s. 2(t)). That last word does a great deal of work: data that no longer identifies anybody has stopped being personal data, which is why records can be kept in redacted form rather than having to be destroyed outright.
When processing is allowed at all
Only for a lawful purpose, and only on one of two grounds: your consent, or one of the “certain legitimate uses” the Act lists (s. 4). A lawful purpose means any purpose not expressly forbidden by law.
Consent has to be free, specific, informed, unconditional and unambiguous, with a clear affirmative action, and limited to the data the stated purpose actually needs (s. 6(1)). The Act’s own illustration is a telemedicine app asking for your contact list: consent to that part is not valid, because a contact list is not needed to provide telemedicine.
Any part of a consent that would infringe the Act is invalid to that extent (s. 6(2)). You cannot be asked to sign away your right to complain.
The s. 7 legitimate uses cover things consent would be a strange fit for: data you volunteered for an obvious purpose, State functions, legal obligations, court orders, medical emergencies, epidemics, disasters, and certain employment purposes.
What you are owed before anything happens
A notice, given with or before the request for consent, saying what data is wanted, what for, how to exercise your rights, and how to complain to the Board (s. 5(1)). You are entitled to read it in English or any language in the Eighth Schedule to the Constitution (s. 5(3)).
If a business had your consent from before the Act commenced, it owes you the same notice as soon as reasonably practicable (s. 5(2)).
Your rights
- Withdraw consent, as easily as you gave it: s. 6(4). The Act says the ease must be comparable, so a one-click sign-up cannot become a three-email cancellation. The consequences are yours to bear (s. 6(5)), and withdrawal does not make the earlier processing unlawful. Once you withdraw, processing must stop within a reasonable time, and the fiduciary must make its processors stop too (s. 6(6)).
- Know what is held: s. 11. A summary of your personal data and what is being done with it, plus the identity of every other fiduciary and processor it has been shared with and a description of what was shared.
- Correct, complete, update and erase: s. 12. On request, inaccurate data must be corrected, incomplete data completed, and data erased, unless retention is necessary for the stated purpose or required by another law.
- A working complaints route: s. 13. Readily available, with a response inside a prescribed period. You must use it before going to the Board (s. 13(3)).
- Nominate someone: s. 14. To exercise your rights if you die or become unable to.
There is one more right you have without asking for it. Even with no request from you, a fiduciary must erase your data once the purpose is no longer served, and the purpose is deemed no longer served if you neither use the service nor exercise any right for a period the Rules set, s. 8(7) and s. 8(8). Going quiet is itself an instruction to delete.
What is required of the business
- Responsible for compliance regardless of any agreement to the contrary (s. 8(1)). A processor may only be used under a valid contract (s. 8(2)).
- Data used to make a decision about you, or shared onward, must be complete, accurate and consistent (s. 8(3)).
- Reasonable security safeguards, to prevent a breach (s. 8(5)). This is the obligation the Act penalises most heavily.
- On a breach, inform the Board and every affected person (s. 8(6)).
- Publish the contact details of a Data Protection Officer or someone who can answer for the processing (s. 8(9)), and run an effective grievance mechanism (s. 8(10)).
Children
Anyone under eighteen (s. 2(f)). Processing their data needs verifiable parental or guardian consent (s. 9(1)). Beyond that, a business must not process a child’s data in a way likely to harm their well-being, and must not track them, monitor their behaviour, or direct advertising at them, s. 9(2) and s. 9(3). These are flat prohibitions, not things consent can unlock.
Significant Data Fiduciaries
The Central Government may designate a business, or a class of them, as a Significant Data Fiduciary, judged on the volume and sensitivity of the data, risk to your rights, and risks to India’s sovereignty, electoral democracy, security and public order (s. 10(1)). One that is designated must appoint a Data Protection Officer based in India and answerable to its board, appoint an independent data auditor, and carry out periodic Data Protection Impact Assessments (s. 10(2)).
The Board, and what it can do
The Data Protection Board of India: s. 18, receives breach intimations and complaints, inquires into them, and imposes penalties. It functions as a digital office, decided online end to end (s. 28(1)). In an inquiry it holds the powers of a civil court to summon people and inspect documents (s. 28(7)), but may not seize equipment or stop a business operating (s. 28(8)).
It can direct that a complaint go to mediation (s. 31), and can accept a voluntary undertaking instead of proceeding, which then bars proceedings on the same matter unless the undertaking is broken (s. 32). A complaint it finds false or frivolous can earn the complainant a warning or costs (s. 28(12)).
Appeals go to the Telecom Disputes Settlement and Appellate Tribunal within sixty days (s. 29), which aims to decide within six months and must record its reasons if it does not. Civil courts are barred from matters the Board is empowered over (s. 39).
Penalties
| Breach | Up to |
|---|---|
| Failing to take reasonable security safeguards, s. 8(5) | ₹250 crore |
| Failing to report a breach to the Board or to you, s. 8(6) | ₹200 crore |
| Breaching the obligations about children, s. 9 | ₹200 crore |
| Breaching a Significant Data Fiduciary’s extra duties, s. 10 | ₹150 crore |
| Any other provision of the Act or its Rules | ₹50 crore |
| A Data Principal breaching their own duties, s. 15 | ₹10,000 |
In setting an amount the Board weighs the gravity and duration of the breach, the kind of data involved, whether it has happened before, whether the business gained from it, and what it did to put it right (s. 33(2)). Penalties go to the Consolidated Fund of India (s. 34). After two penalties, the Government may order access to the service blocked in the public interest (s. 37).
Where the Act does not reach
- Data you process for a purely personal or domestic purpose, and data you have deliberately made public yourself (s. 3(c)). The Act’s illustration is somebody publishing their own details on social media.
- Enforcing a legal claim, court and regulatory functions, investigating offences, corporate mergers, and establishing the assets of a loan defaulter (s. 17(1)).
- Research, archiving and statistical purposes, provided no decision is taken about any individual (s. 17(2)(b)) .
- State instrumentalities the Government notifies, on grounds of sovereignty, security, foreign relations and public order (s. 17(2)(a)).
It does reach processing done outside India, where that processing relates to offering goods or services to people in India (s. 3(b)).
Two things it changed elsewhere
Section 43A of the Information Technology Act, 2000, the old compensation route for a body corporate’s failure to protect sensitive personal data, was repealed (s. 44(2)). And section 8(1)(j) of the Right to Information Act, 2005 was replaced with a flat exemption for “information which relates to personal information” (s. 44(3)).
When it takes effect
The Act commences on dates the Central Government notifies, and different provisions may commence on different dates (s. 1(2)). Much of the operational detail, the inactivity period after which data must be erased, the form of a breach notice, how quickly a grievance must be answered, how verifiable parental consent is obtained, is left to Rules made under s. 40. Read those alongside the Act; the Act sets the obligation and the Rules set the number.