The History of Indian Privacy — Series

    India's Data Protection Story: Two Decades to Get It Right

    From a colonial-era IT Act to a constitutional right to privacy to a landmark 30-clause law — India's path to data protection was slow, contested, and ultimately significant. Written by Yuvaraj S., Founder, truConsent.

    Editorial Introduction

    Why This Series Exists

    Data protection isn't a compliance checkbox. It isn't a legal department problem. It is the foundation of digital trust — and trust is the only durable competitive advantage in any industry where users have a choice. Understanding how India got to its current data protection framework isn't just historical curiosity. It explains why the law is structured the way it is, what trade-offs were made deliberately, and what the obligations actually mean for the companies that must comply with them.

    India arrived late to privacy legislation compared to the jurisdictions that set the global standard. The European Union had a comprehensive directive in 1995 and the GDPR in 2018. Canada enacted PIPEDA in 2001. Singapore passed its Personal Data Protection Act in 2013. India, with one of the world's largest digital economies, did not have a standalone data protection law until August 2023 — a gap that exposed Indian businesses to reputational and regulatory risk while simultaneously leaving Indian data principals without formal recourse.

    But India's DPDPA 2023 didn't merely catch up — it introduced concepts the world had not seen before. The most significant of these is the licensed Consent Manager: a regulated intermediary that holds a licence from the Data Protection Board of India, operates under direct regulatory oversight, and is independently accountable for the consent it manages on behalf of Data Fiduciaries. No other jurisdiction has this model. The EU's GDPR requires Data Protection Officers but not licensed consent intermediaries. The US has no equivalent at all. India created something new.

    This series documents how we got here. It is written for founders, compliance leads, product managers, and legal teams who need more than a summary of the Act's provisions — who need to understand the reasoning behind the law, the debates that shaped it, and the implementation work that still lies ahead. The history runs across four phases spanning 23 years, from the IT Act 2000 to the Presidential assent in August 2023.

    Phase 0 · 2000–2016

    The Forgotten Origins

    The intellectual groundwork for Indian data protection was laid well before the legislative process began in earnest. A visionary committee report, a handful of statutory provisions, and years of civil society advocacy created the foundation — even if nobody built on it at the time.

    May 2000

    IT Act Introduced

    Section 43A created India's first formal data protection obligation — a duty of 'reasonable security practices' for companies handling sensitive personal data. Penalties were civil, not criminal.

    April 2011

    SPDI Rules Notified

    The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules defined sensitive personal data, required consent, and mandated a privacy policy. Applied only to private companies; rarely enforced in practice.

    January 2012

    Justice A.P. Shah Committee Formed

    The Planning Commission constituted a Group of Experts on Privacy chaired by Justice A.P. Shah. The committee was tasked with developing a national framework for privacy law.

    October 2012

    Shah Committee Report

    Nine foundational privacy principles: consent, purpose limitation, collection limitation, data quality, access and correction, accountability, disclosure, security, and openness. The report proposed a statutory right to privacy and an independent regulator. It was never acted upon.

    2012–2016

    Aadhaar Expansion & Civil Society Pushback

    As Aadhaar enrolment scaled to hundreds of millions of residents, civil society organisations challenged its data collection scope. The Shah Report was cited repeatedly in these challenges as evidence that India had deliberately chosen not to enact privacy protections.

    2013–2015

    Snowden Revelations & GDPR Momentum

    Edward Snowden's disclosures catalysed global privacy reform. The EU's GDPR negotiation process entered its final stages. India's legislative gap became starkly visible to multinational companies operating in the country.

    Editorial note: This phase laid the intellectual groundwork. The Shah Report was visionary — nine privacy principles in 2012 that anticipate much of what GDPR codified in 2018. But it was ignored, much like many things that arrive too early. The ideas survived because civil society and legal scholars kept citing them. When the legislative process finally began in 2017, the Shah Committee's framework shaped the debate even though its report had never been acted upon.

    Phase 1 · 2017–2018

    Constitutional Trigger

    A single Supreme Court judgment changed everything. The Puttaswamy verdict didn't just resolve a case about Aadhaar — it created a constitutional mandate for data protection legislation that no government could responsibly ignore.

    July 2017

    Srikrishna Committee Formed

    Even before the Supreme Court judgment was handed down, the Ministry of Electronics and Information Technology formed a 10-member expert committee under Justice B.N. Srikrishna to study and identify key data protection issues in India.

    August 24, 2017

    Puttaswamy vs. Union of India

    A 9-judge constitutional bench unanimously held that the right to privacy is a fundamental right protected under Article 21 of the Constitution. The judgment created a constitutional obligation — the government could no longer treat data protection as optional.

    July 2018

    Srikrishna Committee Report & Draft Bill

    "A Free and Fair Digital Economy" — the committee's 213-page report recommended an independent Data Protection Authority, rights-based legislation, consent-based processing, and data mirroring requirements for certain categories of data. The accompanying draft bill had 98 clauses.

    Editorial note: The Puttaswamy judgment didn't just change privacy law — it created a constitutional obligation. The government could no longer treat data protection as a policy option to be weighed against other priorities. Privacy was now a fundamental right, and any statutory scheme that violated it without meeting the tests of legality, legitimate aim, proportionality, and procedural safeguards would be constitutionally vulnerable.

    Phase 2 · 2019–2022

    The Legislative Odyssey

    The Personal Data Protection Bill entered Parliament in 2019 with high expectations and exited in August 2022 without ever becoming law. Two years of Joint Parliamentary Committee work produced a report so contested that the government concluded it was easier to start over than to defend it.

    December 2019

    PDP Bill 2019 Introduced

    The Personal Data Protection Bill, 2019 was introduced in the Lok Sabha. It had 99 clauses covering data localisation, social media intermediary obligations, broad state exemptions, and a Data Protection Authority. It was immediately referred to a Joint Parliamentary Committee.

    2020–2021

    JPC Consultations

    The Joint Parliamentary Committee received over 200 written submissions from industry bodies, civil society, government ministries, and international organisations. The process was extended multiple times due to the scale of feedback and the COVID-19 pandemic.

    December 2021

    JPC Report Submitted

    A 542-page report with 93 recommended amendments was submitted to Parliament. The report retained broad state exemptions and introduced controversial provisions on non-personal data. Industry criticism focused on overreach; civil society criticism focused on inadequate safeguards against state surveillance.

    August 2022

    Government Withdraws the Bill

    The government withdrew the Personal Data Protection Bill citing the need for a "comprehensive, modern, technology-neutral legal framework." Five years of legislative work — two committee stages, hundreds of submissions — was reset.

    Editorial note: The withdrawal was unprecedented in recent Parliamentary history. But in hindsight, it was the right call. The 2019 Bill had grown so complex and so deeply contested — by industry on one side and civil society on the other, for almost entirely opposite reasons — that it risked becoming unworkable even if it passed. Better to go back to first principles than to produce a law that nobody believed in and that would face immediate constitutional challenges.

    Phase 3 · 2022–2023

    Rewriting & Fast-Tracking

    The government came back with a bill that was radically simpler: 30 clauses instead of 99. No data localisation. A public consultation that produced 2,000+ submissions. And a Parliamentary process that moved with unusual speed.

    November 2022

    DPDP Bill 2022 Released for Consultation

    A dramatically simplified draft — just 30 clauses, down from 99. Data localisation was dropped. Deemed consent was introduced. Graded penalties were proposed. The MeitY portal received over 2,000 public submissions during the 30-day consultation window.

    August 3, 2023

    DPDP Bill 2023 Introduced in Lok Sabha

    The final Bill introduced in Parliament retained the 30-clause structure with refinements: ₹250 crore maximum penalty, clearer notice and consent language, verifiable parental consent for children under 18, and explicit provisions for the Consent Manager model.

    August 7, 2023

    Passed in Lok Sabha

    The Digital Personal Data Protection Bill, 2023 was passed by the Lok Sabha with minimal debate time — a reflection of the government's determination to close the legislative cycle.

    August 9, 2023

    Passed in Rajya Sabha

    The Rajya Sabha passed the Bill two days later. Opposition members raised concerns about the state exemption clause, but the Bill cleared without substantive amendments.

    August 11, 2023

    Presidential Assent

    The Digital Personal Data Protection Act, 2023 received Presidential assent and was published in the Official Gazette. India had a data protection law.

    Six years. Three drafts. Two withdrawals. One Supreme Court judgment. And finally, a law that India can build on. The DPDPA 2023 is not perfect — its state exemptions are broad, its penalties are lower than GDPR, and its Rules remain pending. But it exists. It creates obligations. And it creates rights. That is a foundation worth building on.

    DPDPA Innovation

    What DPDPA Introduced That No Law Has Before

    India didn't just adopt GDPR language and localise it. Three features of the DPDPA have no direct equivalent anywhere else in the world.

    1

    Licensed Consent Manager

    Not a software tool. A regulated entity directly accountable to the Data Protection Board of India. The Consent Manager holds a licence, operates under regulatory oversight, and is liable independently of the Data Fiduciary it serves. India is the only country in the world with this model.

    2

    Data Principal vs. Data Subject

    The deliberate choice of "Principal" over "Subject" reflects an active-agency framework. A data subject is a passive entity whose data is processed. A data principal is an actor with rights, agency, and the ability to grant or withdraw consent. The word choice is not cosmetic — it signals how the law expects individuals to relate to their own data.

    3

    Deemed Consent

    Processing without explicit consent is permitted in specific, enumerated scenarios: delivery of state benefits, performance of a contract the individual is party to, compliance with a legal obligation, national security, and medical emergencies. This serves a similar function to GDPR's "legitimate interest" basis but is narrower and more prescriptive — each scenario is explicitly listed rather than left to controller interpretation.

    Implementation Outlook

    What's Still Coming: DPDPA Rules 2025

    The Act passed in August 2023 but enforcement depends entirely on the Rules being notified. As of 2025, the Rules are still being finalised. The gap between the Act and the Rules is not a technicality — it is the operational reality that every compliance team must navigate.

    Status note: Businesses that wait for the Rules before starting compliance work are already behind. The Act itself imposes obligations. The Rules will add specificity and operational requirements. By the time the Rules land, organisations that haven't started will face a compressed timeline to operationalise a complex consent and data governance framework.

    Significant Data Fiduciary (SDF) Definition

    The Rules will specify which companies qualify as SDFs based on volume of data processed, sensitivity, cross-border transfer activity, and systemic risk to national security or public order. SDFs face additional obligations: mandatory Data Protection Officer, Data Auditor, and periodic Data Protection Impact Assessments.

    Age Verification Mechanism for Children

    The Act requires verifiable parental consent before processing data of users under 18. The Rules must specify what "verifiable" means in practice — a technically and operationally difficult requirement that most platforms are not currently equipped to meet.

    Cross-Border Data Transfer — Prohibited Countries List

    DPDPA uses a negative-list model: transfers are permitted everywhere except the countries specified in the Rules. This list has not yet been published. Until it is, Indian businesses cannot fully map their cross-border transfer compliance obligations.

    DPBI Composition & Operational Rules

    The Data Protection Board of India will be the adjudicatory body for DPDPA complaints and enforcement. Its composition, quorum requirements, complaint process, appeal mechanisms, and operational procedures all depend on the Rules.

    India's Licensed Consent Manager

    truConsent is not a CMP. Not a cookie banner.

    India is the only country where a Consent Manager is a licensed intermediary accountable to a regulator. truConsent is built specifically for DPDPA 2023 — consent lifecycle, data principal rights, breach management, and more.