Authored by Kunwar Veer Vikram Pratap Singh, LL.M. (Cyber Law and Cyber Crime Investigation) candidate at the Uttar Pradesh State Institute of Forensic Science, Lucknow.
Introduction: The Paradigm Shift in Indian Privacy
The Digital Personal Data Protection Act (DPDP), 2023, marks a significant milestone in India’s legislative history as the country’s first comprehensive statute dedicated exclusively to the protection of personal data. However, despite the enactment of the Act and the gradual development of its operational framework, a substantial gap remains between India’s regulatory philosophy and internationally recognised privacy standards.
A mature regulatory regime, such as the General Data Protection Regulation (GDPR) of the European Union, is more of a ‘shield’, serving as the protection of individual human dignity and absolute informational autonomy, as compared to the DPDP Act,2023 in India, which functions as an ‘economic umbrella’. It is a development- and state-centric model designed to reduce compliance friction for enterprises, lower standard operating costs for technology startups, and maintain state flexibility, sometimes at the cost of full data subject rights.
This blog argues that although the Digital Personal Data Protection Act, 2023 represents an important milestone in India’s privacy framework, it prioritises economic governance and regulatory flexibility over a rights-based model of privacy protection. This article illustrates how the Act differs from internationally recognised principles regarding individual rights, institutional autonomy and cross-border data protection, by comparing it with the European Union’s General Data Protection Regulation (GDPR) and the data protection law in the United Kingdom.
Structural Divergence and Loopholes: India vs. Global Benchmarks
Several significant flaws and loopholes emerged after the enactment of the DPDP Act, 2023, which render it ineffective as a contemporary data defence tool:
A. The two different approaches: ‘Flattened’ Data Taxonomy, and the Tiered Sensitivity
Unlike the EU GDPR, Article 9, the DPDP Act,2023 does not provide for any hierarchical levels between ordinary ‘personal data’ and ‘special categories’ of data (health, financial, genetic, biometric, religious, etc.). The law falsely equates an individual’s email address or name with his or her highly sensitive medical history or biometric fingerprints, imposing a common standard of protection on them all. This “flattened” approach will reduce compliance costs for fintech and healthtech, while also posing significant systemic risk. Enhanced protection measures, e.g. Data Protection Impact Assessments (DPIAs), may not be required for processing of high-sensitivity data unless an entity can be designated as a Significant
Data Fiduciary (SDF) by executive discretion. The GDPR and UK regimes, on the other hand, have a more structured approach, imposing more stringent data protection requirements, such as additional security measures and special consent requirements for certain data types. The DPDP Act, 2023 also lacks some key individual rights that are included in the GDPR. The GDPR places a number of obligations on service providers, including Article 20 GDPR, which guarantees access to and transfer of personal data between service providers. Article 21 sets out the right to object to the processing of some types of data, and Article 22 guarantees that the law and similarly significant effects of a decision cannot be based solely on automated processing. These rights reinforce the information self-determination principle and the importance of giving the user control and authority over their personal data. The lack of a legislative mandate for privacy in the DPDP Act suggests that the legislative intent was not to provide wide-ranging privacy protections, but rather to ease compliance.
B. Pervasive State Exemptions vs. Statutory Independence
- The Domestic Flaw: Section 17 of the DPDP Act, 2023 provides for broad exemptions for public bodies under terms such as “sovereignty and integrity of India” or “security of the State”. Enforcement is completely lacking in structural independence, with the composition, appointments, tenure, and administrative functioning of the Data Protection Board of India (DPBI) being substantially controlled by the Central Government under the Act and accompanying rules. The DPBI’s composition, term of office, salaries and working methods are under absolute control of the central government. However, it is important to note that exemptions are not exclusive to India either. The GDPR also provides for the limitation of the data subject’s rights in the interests of national security, defence, public security, or criminal investigations (Articles 23 and analogous provisions). These exemptions, however, are still subject to proportionality, judicial and independent regulatory supervision. The principal difference between them is that where exemptions exist, they are subject to institutional safeguards when used.
- The Regulatory Chasm: This structure is highly vulnerable to regulatory distortion and capture, particularly regarding state-sponsored surveillance and state-over-processing of data. This is a radical departure from the European and UK Data Protection Authorities (DPAs), which have extensive institutional, financial, and legal autonomy from the state, protecting them from the power of the nation-state.
C. The narrow ‘Digital-only’ scope and Regulatory Arbitrage
The purpose of the DPDP Act is to impose strict limits on the scope of its jurisdiction by confining it to “personal data” that is collected online or digitised after being recorded offline. The Act does not apply to the use of physical records, including manual medical registers, paper hospital records and handwritten records.
This limitation immediately establishes a regulatory arbitrage loop. By storing data in highly sensitive paper formats, organisations can easily circumvent strict data tracking protocols, governance requirements and harsh financial consequences. This loophole is not allowed in mature global frameworks, such as the GDPR, which apply to any structured filing system, whether digital or physical.
There are two types of cross-border governance regimes: permissive and safeguard. Cross-border governance regimes can be either permissive or safeguard-first. India has embraced a very lax and reactive cross-border transfer regime. Data transfer can be made across borders automatically, except where the central government issues a restrictive destination “negative list” or “blacklist” of data types or countries.
This turns the global standard on its head, as is the case in the Regulatory Chasm. The European and British systems require a proactive ‘safeguard first’ approach. To enable personal data to move beyond the jurisdiction in which it originated, it must be accompanied by adequate legal arrangements, including formal procedures (Adequacy Decisions), Binding Corporate Rules (BCRs) or Standard Contractual Clauses (SCCs).
India’s decision to adopt an executive-driven blacklist is based on geopolitical flexibility rather than on continuous, legally binding data protection. This distinction is especially important as cross-border data transfers become an increasingly key factor in participation in the global digital economy. Jurisdictions with adequate protection enjoy smoother information flows with international markets, increased investor confidence, and a lighter burden for multinational companies.
Strategic Recommendations: A Roadmap for Global Alignment
Further rulemaking and legislative changes must pay attention to three systemic interventions to fill in the structural gap between the DPDP Act,2023 and international standards:
- Retroactively apply a tiered risk model using Targeted SDF Mandates: The executive rules have to implement a tiered risk model through the SDF designation. All entities that handle health, financial, genetic, or biometric data will automatically be categorised as SDFs and required to implement Zero-trust architecture, comply with compulsory encryption standards, and conduct Data Protection Impact Assessments (DPIAs).
- Make Data Portability a technical requirement: The rules should make data portability a technical obligation, ensuring no vendor lock-in and market competition. Data fiduciaries should be compelled to use a standardised framework based on India’s Account Aggregator (AA) network and implement open, secure, interoperable Application Programming Interfaces (APIs) that enable the seamless transfer of data principals’ digital footprints.
- Insulate DPBI via Independent Judicial Oversight: The Data Protection Board of India (DPBI) should be structurally insulated from the Executive to acquire International Adequacy status and minimise regulatory capture. The identity of board members should be determined by a selection panel, including a formal judicial committee headed by the judiciary, and the board’s tenure and budget allocation should be statutorily guaranteed against one-sided government interference.
- The positive outcomes of the DPDP Act: While it is limited, the DPDP Act, 2023 introduces a few significant changes to the Indian privacy regime. It places strong emphasis on consent as a key basis for processing personal data, mandates that data fiduciaries issue clear notices before collecting data, establishes a Data Protection Board of India for the redressal of grievances, and introduces high financial penalties for non-compliance. These changes are quite different from the previous scattered legal system in India. But these safeguards can only be effective if there is institutional independence, enforceable individual rights, and proportionate restrictions on executive discretion.
Conclusion: Toward an Accountable Digital Future
The enactment of the Digital Personal Data Protection (DPDP) Act, 2023, is an ambiguous moment in the country’s digital journey. Administrative rules come with a welcome timeframe for compliance, yet they fail to provide a bridge across the structural gap between India’s home framework and global data protection principles.
The existing legal system undermines data portability because it allows data sensitivity levels to be ignored, allows individuals to benefit from advanced data portability which is not really necessary, and leaves the enforcement of the law flexible enough to be subject to political pressure.
This misalignment is not just a policy dispute – it is a serious impediment to domestic constitutional parties and to international economic integration. The Supreme Court, in the historic judgment of Justice K.S. Puttaswamy v. Union of India (2017), declared privacy a fundamental right under Article 21. The Court developed a four-part test to determine whether a state intrusion is legal and has a legitimate state purpose, is proportionate, and has strict procedural protections in place.
The DPDP Act puts these constitutional limits to the test. Section 17 also provides very broad powers of exemption for state agencies, allowing a variety of vague concepts, such as “public order” or “security of the State,” to be invoked to justify such exemptions. This unchecked power is directly at odds with the principle of proportionality enshrined in the Puttaswamy judgment. In addition, Section 44(3) of the Act brings a structural regression by amending Section 8(1)(j) of the Right to Information (RTI) Act, 2005. The law goes so far as to actively contravene the transparency requirements laid down in CPIO v. Supreme Court of India (2019), which prohibits disclosure of personal information of public officials. Such overlapping weaknesses have already prompted a sharp constitutional critique and a string of writ petitions before the judiciary questioning whether this Act permits the government to conduct surveillance without third-party checks.
At the international level, this isolationist architecture erects high barriers to economic integration. In line with global standards, specifically the landmark Schrems II case (2020) of the Court of Justice of the European Union (CJEU), a country’s data protection regime must be essentially equivalent to global standards for cross-border data transfers. This evaluation is solely based on limitations of the state and supervision bodies’ absolute autonomy. India is struggling to become data adequate, as the Data Protection Board of India (DPBI) is structurally and budgetarily dependent on the central executive.
The statute needs to be consistent with India’s constitutional jurisprudence if India is to be a leader in the global digital economy rather than a divider. There is no definition of regulatory resilience that excludes the application of the principles of Puttaswamy, but one that involves their full application. India can improve its privacy regime by adopting subsequent rules, introducing targeted protection mechanisms for vulnerable personal data, and establishing a judicially insulated DPBI, thereby achieving world-class digital constitutionalism.
Finally, bringing the provisions of the DPDP Act, 2023, closer to international standards would not entail abandoning India’s regulatory priorities. Instead, more institutional independence, greater data subject rights, and more proportionate state exemptions will strengthen the constitutional right to privacy upheld in Justice K.S. Puttaswamy, improve India’s chances of being recognised by other countries as adequate for cross-border digital trade, and increase India’s participation in the global digital economy. These changes would allow India to become economically developed without infringing basic rights.


