Yours in Law logo
YoursInLaw
Article

DATA PROTECTION AND DIGITAL PRIVACY: PERSONAL INFORMATION LAWS IN INDIA.

The threats, challenges and drawbacks to Right to privacy in the digital era continues to undermine this Right to a great extent that needs early attention...

Ammar Ahmad

20 September 2026

INTRODUCTION:

Privacy is one of the most important Fundamental Right for the citizen's dignity and liberty of India guaranteed by the Indian Constitution. It enables an individual to make personal choices, maintain confidentiality, over-sensitive information and exercise autonomy free from unwarranted interference. The rapid growth of digital technologies has changed the way personal information and data is collected, stored, used and processed. A person's name, address, email, mobile number, Aadhar details, photographs, location, financial records, browsing history and data can now be collected and processed within seconds. While this development has made everyday life more convenient, it has also created serious questions regarding privacy and the control of personal data.

In India, Privacy as a whole Fundamental Right is recognized by the Hon'ble apex court in the landmark judgment of _Puttaswamy v. Union of India, 2017,1 where the retired judge named K.S. Puttaswamy, filed a case in 2012, Challenging the government's Aadhar Scheme that required individuals personal data and information for identification process. A Nine-judge bench of the Hon'ble Apex court held that Privacy is a vital element of Human Dignity and liberty and is Within the Scope of Art.21 of the Indian Constitution.2 The aim of this Fundamental Right is to protect and preserve private life, their sensitive information and protect them from unwanted and unnecessary interference and surveillance. However, the threats, challenges and drawbacks to Right to privacy in the digital era continues to undermine this Right to a great extent that needs early attention.

RECOGNITION OF PRIVACY AS A HUMAN RIGHT BY INTERNATIONAL INSTRUMENTS:

Privacy as a Human Right was first recognized by the Universal Declaration Of Human Rights, 1948, (UDHR). Art. 12 of the UDHR states that "No one shall be subject to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour or reputation. Everyone has the right to the protection of the law against any such interference and attacks."3 This international recognition of privacy as a human right was the first attempt that led other instruments to recognize privacy as a vital element of human dignity and liberty. The other international instrument, International Covenant on Civil and Political Rights, (ICCPR), 1966, recognized, repeated and strengthened the same principle in Art. 17 which states "No one shall be subject to arbitrary or unlawful interference with his privacy, family, home or correspondence, nor to unlawful attacks on his honour or reputation. Everyone has the right to the protection of the law against any such interference and attacks."4 The only difference between Art.12 of UDHR and Art.17 of ICCPR, lies in the fact that Art.17 of ICCPR, added and used the term "Unlawful" twice. These two instruments were the earliest recognition that led to the realization of privacy as a Fundamental Right.

FROM JUDGMENTS TO ENACTMENT:

The Constitution of India didn't use the term "Right to privacy" during the initial years of its commencement. Nevertheless, the Hon'ble Apex court gradually developed privacy protection through constitutional interpretations. The first realization began with M.P. Sharma v. Satish Chandra, 1954,5 where an eight judge bench of the Hon'ble Apex court held that the Constitution makers, having deliberately chosen not to recognise a fundamental right to privacy subject to constitutional limitations similar to those under the Fourth Amendment of the United States Constitution, provide no basis for importing such a right into another fundamental right through an artificial or strained interpretation. And then in Kharak Singh v. State of Uttar Pradesh, 1964,6 where Justice Ayyangar held that _"The right of privacy is not a guaranteed right under our constitution, and therefore the attempt to ascertain the movements of an individual is merely a manner in which privacy is invaded and is not an infringement of a fundamental right guaranteed in Part III."7

A Turing point came with Gobind v. State of Madhya Pradesh,8 where the Hon'ble court recognized that, although the right to privacy was not absolute, it could legitimately be derived from the constitutional guarantees embodied in Articles 19(1)(a), 19(1)(d), and 21. Later, in Rajagopal v State of Tamil Nadu (1994),9 The Hon'ble apex Court significantly recognised the right to privacy as a protection available to individuals against the media's unwarranted intrusion into their private lives and personal information. Another significant development emerged in People's Union for Civil Liberties v Union of India,10 wherein the Hon'ble apex Court, while dealing with the issue of telephone tapping, recognised it as a serious intrusion into an individual's privacy and accordingly prescribed procedural safeguards to prevent the arbitrary interception of private communications.

Then came the landmark judgment of K.S. Puttaswamy v. Union of India, 2017, where the Nine judge bench of the Hon'ble apex court unanimously held that _"Privacy is a constitutionally protected right which emerges primarily from the guarantee of life and personal liberty in Article 21 of the Constitution."11 The judgment holds particular significance for digital privacy as it recognised informational privacy as an important aspect of the right to privacy. In today's digital environment, privacy is not confined merely to physical spaces or private communications. Information concerning an individual's identity, preferences, habits, relationships and activities may disclose substantial details about that individual's personal life.

FROM INFORMATION TECHNOLOGY ACT, 2000, TO DIGITAL PERSONAL DATA PROTECTION ACT, 2023:

Before the DPDP Act,12 India did not have a comprehensive general data protection legislation. The Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 provided certain protections concerning personal and sensitive information. Some of the provisions such as, Section 66E - which penalises the intentional or knowing capture, publication, or transmission of images of a person's private areas without their consent, where such conduct infringes upon the person's privacy,13 Section 72 - It penalises the unauthorised disclosure of electronic records, books, or information obtained or accessed by a person while exercising powers conferred under the Information Technology Act or its rules,14 Section 72A - Penalizes any person or intermediary who discloses personal or sensitive information obtained under a lawful contract without the consent of the individual.15, were some of the provisions deal with the protection of privacy. However, the rapid development of digital services and technology exposed the limitations of this framework. India needed a comprehensive law dealing with the collection, processing, storage and protection of digital personal data. The Digital Personal Data Protection Act, 2023 establishes India's legal framework for regulating the processing of digital personal data, while recognising an individual's right to safeguard their personal data and allowing such data to be processed for lawful purposes. Further, the penalties for violations under the DPDP Act, 2023 may extend up to ₹250 crores, depending upon the nature and extent of the contravention. However, the penalty is payable to the Central Government rather than being directly awarded to individuals whose personal data has been compromised. Section 44(3)16 of the DPDP Act, 2023 also significantly changes the relationship between data protection and the Right to Information framework, particularly Section 8(1)(j) of the Right to Information Act, 2005, thereby raising concerns regarding transparency and access to information.

DRAWBACKS TO PRIVACY IN DIGITAL ERA:

The major drawback to privacy in digital era lies in the fact that, India with other developed nations is constantly moving toward Artificial intelligence era. Despite the progress made by the DPDP Act, 2023, there are several challenges and drawbacks that hinders protection of privacy in digital era. The rapid advancement of digital technologies has transformed the manner in which individuals communicate, transact, and access public services. While these innovations have significantly enhanced efficiency and connectivity, they have simultaneously intensified the concerns regarding protection of privacy in the digital era. According to CERT-In, India witnessed over 29 lakh Cyber security incidents in 2025, reflecting the rapidly increasing vulnerability of personal information in the digital ecosystem,17 A 2024 PwC India survey involving 3,233 consumers found that only 16% of respondents were aware of the DPDP Act, while 56% were unaware of their rights relating to personal data,18 The 2026, Bank of Baroda, data breach illustrates how cybersecurity failure within financial institutions may expose highly sensitive information despite a secure core banking system,19 and The Reserve Bank of India's Annual Report 2024–25 indicates that frauds were predominantly reported under the digital payments category, particularly those involving card and internet transactions, when measured by the number of reported fraud cases.20 These are not just the threats or challenges to privacy in a digital environment but the alerts signals that require immediate and significant intervention. The real effective implementation begins where the awareness of privacy is a concern and a Fundamental Right in a true sense.

CONCLUSION:

India has travelled a significant distance in the development and recognition of privacy as a Fundamental Right. From the initial judgment of realization to the landmark Puttaswamy judgment, the Hon'ble Apex court has progressively recognized privacy as an essential constitutional value. The DPDP Act, 2023, along with the DPDP Rules, 2025, marks a significant further development in this area by establishing a statutory framework for the protection of digital personal data. However, the effectiveness of India's privacy framework will ultimately depends upon its implementation. A data protection laws shall protect individuals without unnecessarily preventing innovation and technology. At the same time, technological progress cannot be used as a reason to weaken constitutional rights. The Digital Personal Data Protection Act, 2023 constitutes India's first dedicated legislative framework specifically designed to regulate and protect digital personal data. However, the Act confers broad powers upon the Central Government to exempt certain activities undertaken by the State from its application. The DPDP Act, 2023 provides for monetary penalties of up to ₹250 crore for specified contraventions, including failure to take reasonable security safeguards to prevent personal data breaches.21

Thus, India needs greater awareness of privacy and the violations that can result in data breaches, identity theft and the compromise of personal information. Merely recognising privacy as a right is not sufficient unless that right is effectively protected in practice and not treated as merely a legal term. Only through such meaningful protection can privacy truly stand as a cornerstone of individual freedom in the digital era.

REFERENCES:

Cases

  • Justice K.S. Puttaswamy (Retd.) v Union of India (2017) 10 SCC 1.
  • M.P. Sharma v Satish Chandra AIR 1954 SC 300; [1954] SCR 1077.
  • Kharak Singh v State of Uttar Pradesh AIR 1963 SC 1295; [1964] 1 SCR 332.
  • Gobind v State of Madhya Pradesh [1975] 3 SCR 946.
  • R. Rajagopal v State of Tamil Nadu (1994) 6 SCC 632.
  • People's Union for Civil Liberties v Union of India (1997) 1 SCC 301.

Legislation:

Constitution of India 1950

Information Technology Act 2000

Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011

Digital Personal Data Protection Act 2023

Digital Personal Data Protection Rules 2025

Right to Information Act 2005

International Instruments:

  • International Covenant on Civil and Political Rights (adopted 16 December 1966, entered into force 23 March 1976) 999 UNTS 171.
  • Universal Declaration of Human Rights, adopted 10 December 1948, UNGA Res 217 A (III) (UN Doc A/810).

Government Publications:

  • Press Information Bureau, Government of India, 'Assistance to States to Tackle Cyber Incidents' (24 March 2026) https://www.pib.gov.in/PressReleasePage.aspx?PRID=2244504 accessed 4 August 2026.
  • Reserve Bank of India, Annual Report 2024–25 (2025).
  • PwC India, How aware and prepared are Indian consumers and businesses to navigate the new era of digital privacy? (2024).

Newspaper Article:

Footnotes

  1. Justice K.S. Puttaswamy (Retd.) v Union of India (2017) 10 SCC 1.

  2. Right to life and Personal liberty.

  3. Universal Declaration of Human Rights, adopted 10 December 1948, UNGA Res 217 A(III) (UN Doc A/810) art 12.

  4. International Covenant on Civil and Political Rights (adopted 16 December 1966, entered into force 23 March 1976) 999 UNTS 171 art 17.

  5. M.P. Sharma v Satish Chandra AIR 1954 SC 300; [1954] SCR 1077.

  6. Kharak Singh v State of Uttar Pradesh [1964] 1 SCR 332.

  7. Kharak Singh v State of Uttar Pradesh [1964] 1 SCR 332, 351.

  8. Gobind v State of Madhya Pradesh [1975] 3 SCR 946.

  9. R. Rajagopal v State of Tamil Nadu (1994) 6 SCC 632.

  10. People's Union for Civil Liberties v Union of India (1997) 1 SCC 301.

  11. Justice KS Puttaswamy (Retd) v Union of India (2017) 10 SCC 1, 508 [320] (Chandrachud J).

  12. The Digital Personal Data Protection Act, 2023 establishes the legal framework for protecting digital personal data and regulating its lawful processing in India.

  13. Information Technology Act 2000 (Act 21 of 2000), s 66E.

  14. Information Technology Act 2000 (Act 21 of 2000), s 72.

  15. Information Technology Act 2000 (Act 21 of 2000), s 72A.

  16. The Digital Personal Data Protection Act, 2023, s 44(3).

  17. Press Information Bureau, Government of India, 'Assistance to States to Tackle Cyber Incidents' (24 March 2026) https://www.pib.gov.in/PressReleasePage.aspx?PRID=2244504 accessed 14 August 2026.

  18. PwC India, 'How aware and prepared are Indian consumers and businesses to navigate the new era of digital privacy?' (2024) 13 https://www.pwc.in/assets/pdfs/aware-prepared-indian-consumers-businesses-navigate-new-era-digital-privacy.pdf accessed 15 August 2026.

  19. The Times of India, 'Bank of Baroda Confirms Data Breach: Employee Email Account Hacked, Bank Says Core Banking Systems Untouched' (27 July 2026) https://timesofindia.indiatimes.com/technology/tech-news/bank-of-baroda-confirms-data-breach-employee-email-account-hacked-bank-says-core-banking-systems-untouched/articleshow/132667491.cms accessed 15 August 2026.

  20. Reserve Bank of India, Annual Report 2024–25 (2025) ch VI, para VI.62 and Table VI.3 https://www.rbi.org.in/scripts/AnnualReportPublications.aspx?Id=1436 accessed 16 August 2026.

  21. Digital Personal Data Protection Act 2023, ss 33–34 and sch.