The great Indian privacy push
The article discusses India's significant shift towards prioritizing data privacy with the introduction of the Digital Personal Data Protection Act, 2023 (DPDP Act). It highlights the transition from the older Information Technology Act, 2000, to a more comprehensive framework that emphasizes individual control over personal data, the roles of Data Principals and Data Fiduciaries, and the establishment of the Data Protection Board to enforce compliance.

Published on: 14 February 2025, 05:26 am
INDIA has always had a flair for grand gestures—the Great Indian Wedding, the Great Indian Family, the Great Indian Dream. Now, we are witnessing another uniquely Indian phenomenon: ‘the Great Indian Privacy Push.’ In a country where millions are navigating an increasingly digital world, the debate has shifted beyond mere data ‘collection’ to focus on who ‘controls’ it and how it is safeguarded. With the introduction of a structured privacy framework, India is setting the stage for a digital transformation that prioritizes data ‘protection.’
This push comes at a defining moment—a time when privacy is no longer a luxury but a necessity. Every time we tap ‘I Accept’ without a second thought, or trade our privacy for convenience, we leave behind digital breadcrumbs across the internet, often without realizing who is collecting them or for what purpose. With millions of Indians going about their digital lives this way, trust in those managing our data is no longer optional—it is essential. And now, for the first time, India is responding with a legal framework designed not just to regulate, but to redefine the rules of the game. This is not just a privacy framework; it is a privacy revolution at a scale that only India can attempt.
The Times, They Are A-Changin’: Meaning of ‘personal data’ at the heart of India’s Shift from the IT Act to the DPDP Act
With the introduction of the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the unveiling of the draft Digital Personal Data Protection Rules, 2025 (“Draft Rules”) for public comment, India has transitioned from a fragmented, sectoral approach to a comprehensive, structured data privacy regime. As G.K. Chesterton wisely put it, “Before you remove a fence, pause long enough to ponder why it was there in the first place.” Before fully embracing this shift, it is essential to examine where we were and what has changed.
With the introduction of a structured privacy framework, India is setting the stage for a digital transformation that prioritizes data 'protection.'
For over two decades, India’s digital privacy framework was governed by the Information Technology Act, 2000 (“IT Act”) and its attendant Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”). However, these regulations were primarily designed to address cybersecurity, electronic transactions, and preventing cybercrimes rather than to safeguard individual privacy rights. The SPDI Rules applied only to ‘Sensitive Personal Data’, such as passwords, financial details, health records, and biometric data, leaving general personal data largely unregulated.
The DPDP Act significantly expands the scope of protection by defining ‘personal data’ as any data ‘about’ or ‘in relation to’ an individual that makes them identifiable. This broad definition means that even behavioural patterns, geolocation data, license plate numbers and workplace affiliations which may not directly identify an individual and were previously (largely) unregulated, now fall under statutory protection.
A Borderless Regime
In today’s interconnected world, data flows do not stop at national borders – and neither does India’s new privacy framework. The DPDP Act casts a wide net, reaching far beyond Indian territory to encompass any entity processing data of individuals based out of India. Specifically, the DPDP Act applies to two scenarios: (i) processing of digital personal data within India, and (ii) processing outside India when it is connected to offering goods or services to individuals in India. This extra-territorial reach means that whether you are a tech giant in Silicon Valley or a boutique analytics firm in Tel Aviv, if you are handling data of individuals based out of India, you are bound by Indian privacy laws.