Policy Update
Vibha Sethi
BACKGROUND
With the rapid expansion of India’s digital marketplace and internet user base, the government required a comprehensive legal framework to secure personal data and govern corporate processing practices.
● Policy Inception
- Historical Context: India initially lacked a standalone data protection law. The foundation was laid in 2017 with the constitution of the Justice B.N. Srikrishna Committee, which submitted the initial blueprint for data privacy.
- Final Enactment: Following multiple iterations, public consultations, and parliamentary debates, the bill received presidential assent on August 11, 2023, officially becoming the Digital Personal Data Protection (DPDP) Act, 2023.
● Need and Rationale
- Limitations of Existing Laws: Previously, data issues were handled under Section 43A of the Information Technology (IT) Act, 2000. This old framework was inadequate for today’s cloud computing, big data, and artificial intelligence models.
- Data Security Risks: India has one of the largest online populations globally. Foreign technology firms were harvesting and processing citizen data without adequate accountability, creating sovereign security and individual privacy concerns.
● Objectives
- Empowering Users: To grant citizens enhanced statutory rights and ownership over their personal digital footprints.
- Corporate Accountability: To establish strict legal obligations for entities collecting data, preventing unauthorized monetization and data misuse.
● Target Beneficiaries
- Digital Nagriks (Citizens): Everyday internet users who now have the legal right to know how, where, and why their personal data is processed.
- Domestic Tech Startups: Local private firms that benefit from a transparent, predictable regulatory environment, leveling the playing field against global tech monopolies.
● Key Provisions & Amendments
- Consent Architecture: Data processing is prohibited without an explicit, unambiguous notice and voluntary consent. Users retain the right to withdraw consent at any given point.
- Heavy Financial Penalties: The Act introduces a strict penalty structure. In case of data breaches or non-compliance, companies can be fined between ₹50 crore and ₹250 crore per instance, removing the old voluntary compliance system.
FUNCTIONING
Institutional Framework and Implementation Mechanism
The enforcement of this law is managed by a centralized statutory body called the Data Protection Board (DPB) of India. The DPB functions as a digital adjudicating authority, empowered to receive citizen complaints, direct investigations into corporate lapses, and levy financial penalties.
The operational workflow runs through a direct reporting architecture:
[Citizen / User] ──► Files a Complaint ──► [Data Protection Board (DPB)
│
▼
[Big Tech / SDF Platforms] ◄── Audits & Penalties ◄── (Conducts Investigation)
- Data Fiduciaries: Companies that determine the purpose of data collection are termed “Data Fiduciaries.” They are legally mandated to provide consent notices in clear language, accessible in any of the 22 languages listed in the Eighth Schedule of the Indian Constitution.
- Significant Data Fiduciaries (SDF): The government designates specific firms as SDFs based on the volume and sensitivity of the data they handle (e.g., banks and social media platforms). SDFs must appoint a resident Data Protection Officer (DPO) and conduct mandatory annual independent data audits.
Table 1: Statutory Penalty Structure Under the DPDP Act
| S.NO | Nature of Statutory Non-Compliance / Breach | Max Penalty Levied | Enforcing Adjudicating Authority | Operational Impact on Data Fiduciaries |
| 1. | Failure to Prevent Personal Data Leak | Upto ₹250 Crore | Data Protection Board (DPB) | Mandates strict corporate investments in secure cloud and encryption infrastructure. |
| 2. | Failure to Notify DPB/Users of Data Breach | Upto ₹200 Crore | Data Protection Board (DPB) | Removes the old corporate practice of hiding data leaks from stakeholders. |
| 3. | Non-Adherence to Children’s Data Protections | Upto ₹150 Crore | Data Protection Board (DPB) | Forces strict verification gates and completely bars targeted ads for minors. |
| 4. | Breach of SDF Special Compliance Obligations | Upto ₹150 Crore | Data Protection Board (DPB) | Requires mandatory hiring of local Data Protection Officers and annual audits. |
As detailed in Table 1, pursuant to the Schedule of the DPDP Act, 2023, the transition from voluntary corporate standards to strict, non-proportional statutory fines serves as a powerful deterrent. These statutory penalties impose heavy liabilities on Data Fiduciaries—ranging from ₹150 Crore for special compliance breaches up to ₹250 Crore for failing to prevent personal data leaks—forcing mandatory corporate investments in secure cloud and encryption infrastructure.
Funding Structure and Progress Status
The Data Protection Board (DPB) operates through direct budgetary allocations managed by the Ministry of Electronics and Information Technology (MeitY). Financial penalties recovered from corporate violators do not fund the board directly; they are deposited into the Consolidated Fund of India.
- Current Status (2026): Following the formal notification of the DPDP Rules on November 13, 2025, the compliance mechanism is currently in a structured, multi-phase transition period leading up to the final enforcement deadline of May 13, 2027. In preparation, major FinTech apps, banking networks, and e-commerce platforms have begun overhauling their user interfaces and data storage protocols. Many application developers are proactively testing and presenting explicit, DPDP-compliant consent pop-ups during user onboarding to align with the upcoming statutory mandates.
Evaluative Concerns and Challenges
- Compliance Burden on MSMEs: While tech giants have the capital to deploy automated compliance tools, small-and-medium enterprises face high operational costs in upgrading their IT infrastructure to meet these legal standard protocols.
- State Exemptions: The Act grants broad processing exemptions to government agencies under national security and public order clauses. Industry experts criticize this asymmetric application, arguing that public bodies should face similar accountability.
PERFORMANCE
● Capital Realignment and Enterprise Adaptation
By the current fiscal timeline, the structural performance of India’s technology market shows signs of enterprise-level adaptation. According to the Bain India Venture Capital Report 2026, institutional risk parameters have evolved, with Software and SaaS funding increasing approximately 1.5x year-over-year. Market indicators suggest foreign and domestic venture capital (VC) syndicates are expanding due-diligence parameters, reportedly prioritizing “Privacy-by-Design” IT architectures as a crucial hygiene checkpoint for institutional Series A and B equity allocations.
This financial realignment is reported to have caused a relative slowdown in speculative, raw-data-monetization startups. Conversely, it is driving an investment climate focused on data-secure Software-as-a-Service (SaaS) models, cybersecurity solutions, and advanced enterprise compliance management platforms. Furthermore, industry trackers indicate a notable trend in specialized Mergers and Acquisitions (M&A), where larger legacy firms are actively acquiring early-stage cybersecurity startups to absorb compliant data frameworks and mitigate potential statutory liabilities.
● Sub-Sectoral Progress
The speed of compliance and operational adjustment has varied significantly across different digital sub-sectors a trend highlighted in EY’s DPDP Compliance and Readiness Report:
- FinTech and Banking: This sector has demonstrated the fastest transition momentum. Financial platforms have extensively prioritized localizing data nodes to secure localized cloud servers, which risk-management analyses indicate has contributed to a downward trend in identity-theft indicators.
- E-Commerce Retailing: Retail networks have actively modified their consumer analytics engines. Moving away from aggressive third-party data tracking, consumer-facing platforms are actively restructuring around first-party, voluntary consumer interaction models to sustain targeted marketing. EY’s sectoral findings confirm that consumer retail and e-commerce organizations lead the industry, with roughly 50% having already initiated structured compliance programs.
- The HealthTech and Telemedicine Segment: Due to the highly sensitive nature of medical diagnostic records, HealthTech platforms have deployed strict end-to-end encrypted storage architectures. However, progress remains relatively slow compared to other sectors. Industry data indicates that fewer than 10% of healthcare firms have comprehensive pipelines in place. Enterprises are moving to institutionalize separate data-silos for patient identities and diagnostic outputs, ensuring that delivery strictly complies with the statutory guidelines monitored by the Data Protection Board.
IMPACT
● Economic Multipliers (The Financial Economics Angle)
The primary macroeconomic contribution of the DPDP framework is the institutionalization of Market Trust. Secure data protocols act as economic multipliers by driving higher user participation in digital markets:
- Cybersecurity Sector Expansion: According to industrial tracking from the Data Security Council of India (DSCI) and NASSCOM, regulatory mandates have substantially accelerated the core infrastructure. The domestic cybersecurity product sector has expanded significantly, growing from USD 1.05 billion in 2020 to USD 4.46 billion, registering a 34% Compound Annual Growth Rate (CAGR) driven by heightened regulatory and private investments in compliance infrastructure.
- Global Data Node Positioning:By aligning India’s data rules with global standards like Europe’s GDPR, the policy enhances international trust. Global enterprises are systematically evaluating Indian data ecosystems for secure offshore data hosting, strategically positioning India as an emerging global technology hub for secure computing.
● Job Creation and Human Capital Development
The law has established an independent corporate job market. The mandatory requirement for Significant Data Fiduciaries (SDFs) to hire dedicated Data Protection Officers (DPOs), compliance lawyers, and specialized privacy auditors has opened up thousands of high-wage technical roles. This trend bridges the gap between software engineering, corporate law, and applied mathematics, retaining premium intellectual talent within the domestic borders.
EMERGING ISSUES
Industrial feedback from the ground highlights three critical operational challenges:
- Lack of Proportional Penalties: The statutory penalty framework lacks sub-tier classifications for mid-market businesses. A genuine clerical or administrative error could risk a mid-sized firm facing institutional bankruptcy due to the high flat penalties.
- Cross-Border Service Overlaps: Indian export-oriented IT service firms face administrative friction while balancing MeitY compliance guidelines against overlapping, external international privacy frameworks across foreign jurisdictions.
- State Accountability Concerns: The wide processing exemptions granted to public bodies under national security clauses create an uneven playing field. Legal experts point out that the absence of strict independent oversight on state-managed citizen databases could lead to systemic data handling vulnerabilities, reducing public trust in government-run digital platforms.
WAY FORWARD
To secure the long-term economic gains of the DPDP act, the following regulatory steps are recommended:
- Compliance Sandbox for MSMEs: MeitY should establish a regulatory sandbox providing technical tools and temporary penalty relaxations for early-stage startups and small firms, reducing their market entry costs.
- Inter-Departmental Alignment: The Data Protection Board must synchronize its regulatory audits with existing sector overseers like the RBI and SEBI to eliminate redundant compliance reporting for financial enterprises.
- Judicial Oversight on State Exemptions: To address accountability gaps, MeitY should introduce a transparent, judicial or independent technical oversight body to review government data-processing requests. Government exemptions should be bound by a strict “necessity and proportionality” test, ensuring public systems remain as secure and accountable as private platforms.
SELECTED REFERENCE AND IMPORTANT LINKS
- Ministry of Electronics and Information Technology (MeitY), Government of India. The Digital Personal Data Protection Act, 2023 Gazette Notification. Available at: egazette.gov.in
- The Gazette of India, Legislative Department, Ministry of Law and Justice. Digital Personal Data Protection Act, 2023 Complete Text. Available at: egazette.gov.in
- Justice B.N. Srikrishna Committee Report (2018). A Free and Fair Digital Economy: Protecting Privacy, Empowering Indians. Ministry of Electronics and Information Technology. Available at: pib.gov.in
- Data Security Council of India (DSCI). Indian Cybersecurity Product Landscape Report 3.0. NASSCOM Research Portfolio. Available at: dsci.in
- Cabinet Secretariat, Government of India. Press Information Bureau (PIB) Archive on Digital India Expansion and Citizen Privacy Rules. Available at: pib.gov.in
- Data Protection Board of India (DPB). Citizen Grievance Redressal and Corporate Data Adjudication Operational Guidelines. Ministry of Electronics and Information Technology. Available at: pib.gov.in
- The Gazette of India, Legislative Department, Ministry of Law and Justice, Government of India. DPDP Act, 2023 Official Publication (No. 25 of 2023). Available at: egazette.gov.in
- NASSCOM Insights Portal. The Corporate Compliance Cost and Matrix Analysis of the DPDP Act on Indian Tech MSMEs. Available at: dsci.in
About the Contributor
Vibha Sethi is a researcher and policy enthusiast with interests in public policy, governance, international relations, trade frameworks, and strategic studies. Her work focuses on evidence-based policy analysis, geopolitical developments, and emerging global challenges, with particular attention to India’s strategic, economic, and developmental priorities. She is actively engaged in analytical writing, policy research, and academic discussions related to governance, security, and international affairs.
Acknowledgement
The author extends sincere gratitude to the IMPRI team for their expert guidance and constructive feedback throughout the process.
Reviewed by Ameya Satam and Paridhi Passi
Disclaimer: All views expressed in the article belong solely to the author and do not necessarily represent the views or policies of the organisation.
Read more at IMPRI:
India-Australia Uranium Deal and India’s Future in Nuclear Energy




