A Citizen's Reading of the DPDP Act: What Changed and What Hasn't Yet
The law gives Indians a vocabulary for consent, but its promise depends on rules still being written
Two years after Parliament passed the Digital Personal Data Protection Act, an ordinary citizen filling out a loan application or downloading a health app still has only a hazy sense of what has actually changed. That hesitation is understandable. India's data protection law arrived after nearly a decade of drafts, a landmark privacy judgment from the Supreme Court in Justice K.S. Puttaswamy, and at least four earlier versions that were withdrawn or substantially rewritten. The version that finally passed is leaner than its predecessors, and its critics are right that leanness came at a cost. But it is also, for the first time, a law that gives an individual a specific, enforceable claim against those who misuse her data, rather than a set of guidelines that companies could interpret as they pleased.
What the law actually gives you
The DPDP Act's core idea is simple enough to state in a sentence: personal data may be processed only for a lawful purpose, with the consent of the person concerned or under one of a limited set of "legitimate uses" carved out in the Act, such as employment or medical emergencies. A citizen now has a statutory right to access what data a company holds about her, to seek correction of inaccurate data, to nominate someone to exercise her rights after death or incapacity, and to file a grievance that a data fiduciary is obliged to resolve within a prescribed period. None of this existed as a general legal right before 2023; it existed only in fragments, borrowed from the Information Technology Rules of 2011 or from RBI and SEBI circulars that applied to specific sectors.
The Act also introduces the idea of "significant data fiduciaries," a category of large processors who will face extra obligations such as data protection impact assessments and mandatory audits. This mirrors, loosely, the European Union's General Data Protection Regulation, though the Indian law is considerably lighter on documentation requirements and heavier on discretion vested in the central government to notify who counts as significant. That discretion is where the law's champions and its critics part company most sharply.
The unfinished architecture
A statute is only as good as the machinery that enforces it, and the DPDP Act's machinery, the Data Protection Board of India, has been slow to take shape. The Board is meant to function as a specialised adjudicatory body, hearing complaints and imposing penalties that can run into hundreds of crores for serious breaches. But its members are appointed by the central government, its proceedings are meant to be conducted largely online, and it has none of the structural independence that, say, the Telecom Disputes Settlement and Appellate Tribunal enjoys after decades of jurisprudence. Comparisons with the erstwhile Justice B.N. Srikrishna committee's original proposal, which envisaged a more autonomous authority with rule-making powers of its own, are not flattering to the final Act.
Equally consequential is the fact that large parts of the law's operative detail have been left to subordinate rules, which were still in draft form as late as 2025. These rules will determine how consent managers are registered and audited, what "verifiable parental consent" means in practice for the millions of Indian teenagers on social media, and how cross-border data transfer restrictions, which the Act leaves largely to government notification, will actually work. A law that delegates this much to executive rule-making is not unusual in Indian legislative practice, but it does mean that the DPDP Act's real character will only become visible once those rules are notified and, inevitably, litigated.
Consent fatigue and the limits of individual control
There is a deeper conceptual worry that the Act does not resolve, and to its credit acknowledges only implicitly: consent, as a regulatory mechanism, is buckling under its own weight. Anyone who has clicked "I agree" on a cookie banner without reading it understands the problem. The Act's answer is the consent manager, an interoperable platform through which individuals are meant to grant, review and withdraw consent across multiple services, modelled loosely on the account aggregator framework that the RBI helped build for financial data. It is a genuinely interesting idea, and if it works, it could reduce the cognitive burden of privacy decisions considerably. But consent managers require infrastructure, standards and a critical mass of adoption that does not yet exist outside pilot projects. Until they do, the practical experience of consent for most Indians will remain what it has always been: a checkbox clicked in haste.
The exemptions that worry civil liberties groups
The Act's most contested provision is Section 17, which allows the central government to exempt any of its instrumentalities from the entire Act "in the interest of sovereignty and integrity of India" or several other broadly worded grounds, without the safeguards of necessity and proportionality that the Puttaswamy judgment itself laid down as the constitutional test for restricting privacy. Civil society groups such as the Internet Freedom Foundation have argued that this exemption effectively lets government surveillance and law enforcement data processing escape the very law meant to constrain data misuse. The government's counter-argument, that national security and law enforcement need operational flexibility that a blanket application of consent and purpose limitation would frustrate, is not without merit; most privacy regimes, including the GDPR, carve out similar exceptions for state functions. The disagreement is less about whether such exemptions should exist than about how narrowly they are drawn and how they are checked, and on that count India's law leaves the government more room than most democracies would consider prudent.
What a citizen should actually do
Given all this, what should an ordinary user take away? First, that the DPDP Act is real progress, not cosmetic legislation; the right to seek erasure or correction of data, backed by a statutory grievance process, did not exist before in this form. Second, that its teeth are not yet fully grown, and enforcement in the near term will likely be sporadic, driven by high-profile breaches rather than routine compliance audits. Third, that citizens who want the law to work as intended have a real stake in how the subordinate rules are finalised, because those rules, not the headline Act, will decide whether consent becomes meaningful or remains theatre.
India has, in effect, built the frame of a data protection regime and left the wiring for later. That is not necessarily a design flaw; complex regulatory systems are often built incrementally, and the RBI's own data localisation rules for payments took years of iteration before they settled into a workable shape. But it does mean that the debate about Indian data protection is far from over. It has merely moved from Parliament to the more tedious, less visible arena of rule-making committees, where its outcome will matter just as much.


