DATA PROTECTION IN INDIA AFTER THE DIGITAL PERSONAL DATA PROTECTION ACT, 2023: A CRITICAL EVALUATION OF PRIVACY AND STATE POWER

DATA PROTECTION IN INDIA AFTER THE DIGITAL PERSONAL DATA PROTECTION ACT, 2023: A CRITICAL EVALUATION OF PRIVACY AND STATE POWER

AUTHOR – MS. AASHI DIXIT, BBA-LL.B (Hons.), LL.M. NET (LAW), INDEPENDENT ACADEMIC RESEARCHER

BEST CITATION – MS. AASHI DIXIT, DATA PROTECTION IN INDIA AFTER THE DIGITAL PERSONAL DATA PROTECTION ACT, 2023: A CRITICAL EVALUATION OF PRIVACY AND STATE POWER, INDIAN JOURNAL OF LEGAL REVIEW (IJLR), 6 (1) OF 2026, PG. 116-130, APIS – 3920 – 0001 & ISSN – 2583-2344. DOI – https://doi.org/10.65393/LDEO6679

I. Abstract

The Digital Personal Data Protection Act, 2023 represents a landmark development in India’s legal and regulatory framework governing the collection, processing, storage, and protection of personal data. Enacted in the aftermath of the Supreme Court’s historic recognition of the right to privacy as a fundamental right in Justice K.S. Puttaswamy v. Union of India (2017), the Act responds to a long-standing constitutional and legislative vacuum in data protection. In an era marked by rapid digitalization, expanding State surveillance capabilities, and the growing economic significance of data-driven innovation, the DPDP Act seeks to establish a consent-based regulatory regime that balances individual privacy, national interests, and economic development. This paper undertakes a critical evaluation of the DPDP Act, 2023 to assess whether it adequately complies with the constitutional standards articulated in Puttaswamy, particularly the requirements of legality, necessity, proportionality, and procedural safeguards. It interrogates the extent to which the Act protects informational autonomy and individual dignity while permitting data processing by the State and private entities. Special attention is devoted to examining the breadth of State exemptions, which allow the government to process personal data for purposes such as national security, public order, and governance, raising concerns about unchecked executive discretion and the potential normalization of mass surveillance.The study further analyzes the Act’s consent architecture, enforcement mechanisms, and institutional design, including the powers and independence of the Data Protection Board of India. It evaluates whether the absence of an independent, judicially insulated regulator and the limited avenues for redress weaken the effectiveness of data protection guarantees. Through a comparative analysis with global data protection frameworks, particularly the European Union’s General Data Protection Regulation (GDPR), the paper highlights both areas of convergence-such as recognition of data principal rights-and significant divergences, especially regarding State accountability, regulatory independence, and proportionality constraints. The paper argues that while the DPDP Act, 2023 constitutes an important step toward formalizing data protection in India, it simultaneously consolidates significant power in the executive, thereby raising serious concerns about constitutional compliance, democratic accountability, and the dilution of privacy protections. It concludes that without stronger safeguards, clearer limitations on State power, and enhanced institutional independence, the Act risks prioritizing governance efficiency and economic interests over the fundamental right to privacy, necessitating urgent legal and structural reforms.

Keywords: Digital Personal Data Protection Act, 2023; Right to Privacy; State Surveillance; Data Governance; Constitutional Proportionality