The stories buried, spiked, or spun.
Government Secrets

India's DPDPA Falls Short

India's new data protection law lacks key privacy safeguards

Share
India's DPDPA Falls Short

The Digital Personal Data Protection Act of 2023, passed in India, has been touted as a major step forward in protecting the personal data of the country's 1.4 billion citizens. However, experts argue that the law falls short in several key areas. Notably, the DPDPA does not provide citizens with the right to data portability, a key provision found in the European Union's General Data Protection Regulation. This omission has raised concerns among privacy advocates, who argue that it will limit individuals' ability to control their personal data.

The DPDPA also imposes limited restrictions on government access to personal data, a provision that has been criticized by civil liberties groups. According to the law, government entities are permitted to process personal data for the delivery of goods and services, as well as for law enforcement purposes. While the law recognizes the potential risks associated with unchecked data processing, including financial loss, loss of reputation, and profiling, it does not provide sufficient safeguards to prevent these harms. The Indian government has not provided a clear explanation for the limited scope of the law, which has raised questions about the effectiveness of the DPDPA in protecting citizens' privacy.

In contrast to the DPDPA, the GDPR imposes significant fines on companies that fail to comply with its provisions, with penalties ranging up to $22.9 million or 4% of a company's global turnover. The DPDPA, on the other hand, does not specify similar penalties, which has raised concerns about the law's ability to deter non-compliance. As the use of personal data continues to grow, with an estimated 75% of companies worldwide using personal data for targeted advertising, the need for effective data protection laws has never been more pressing. The DPDPA's limitations have significant implications for the privacy and security of India's citizens, and it remains to be seen whether the law will be revised or expanded to address these concerns.

Marcus Webb
The Marcus Webb Take
Surveillance State & Tech Privacy

As I reflect on India's Digital Personal Data Protection Act, I firmly believe it falls short of providing adequate safeguards for citizens' online privacy. The current framework lacks teeth, allowing corporations to exploit personal data with relative impunity. If nothing changes, it's clear that big tech companies will be the winners, continuing to reap profits from the unchecked collection and monetization of Indian users' data. Meanwhile, the average citizen will remain vulnerable to data breaches and targeted manipulation. I strongly argue that India needs a more robust data protection regime to truly safeguard its citizens' digital rights.

Primary source: StationX
Cross-reference independently — do not take our word for it.

Disclosure: NewsAnarchist uses AI-assisted reporting with web search. Always verify primary sources linked above.

Part of our Government Secrets coverage
See the full picture on our Government Secrets hub — including our ongoing coverage of declassification, whistleblowers, and government transparency.
How We Report Government Secrets

This article is produced by NewsAnarchist's AI reporting system, not a human staff reporter. It's built from the primary source cited above (a declassified document, a FOIA release, an inspector general or congressional report, or a named whistleblower disclosure reported by outlets we cite) and reports what that source states, attributed to it — it reports what the document or disclosure states and does not speculate about what remains classified beyond that. Part of our Government Secrets hub. Found an error? Tell us.

THE DAILY BRIEFING
Get the stories buried, spiked, or spun — free every morning.
No spam. No ads. Unsubscribe anytime.
Share