Introduction
In today's digital world, individuals regularly share personal information while using websites, mobile apps, social media platforms, online banking, e-commerce services, and government portals. To protect personal data and ensure responsible data handling, India enacted the Digital Personal Data Protection Act, 2023 (DPDP Act).
The DPDP Act establishes a legal framework for the collection, processing, storage, and use of digital personal data. It also grants individuals certain rights over their personal information while imposing obligations on organizations that process such data.
This guide explains the key features of the DPDP Act, the rights available to individuals, the responsibilities of organizations, and how individuals can seek redress if their rights are violated.
What is the DPDP Act, 2023?
The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's primary legislation governing the processing of digital personal data.
The Act aims to:
-
Protect individuals' personal data.
-
Promote responsible data processing.
-
Ensure transparency and accountability.
-
Provide individuals with enforceable privacy rights.
-
Create a legal framework for handling digital personal information.
What is Personal Data?
Under the DPDP Act, personal data generally means any data about an individual who can be identified by or in relation to that data.
Examples include:
-
Name.
-
Mobile number.
-
Email address.
-
Aadhaar number (where applicable).
-
PAN details.
-
Date of birth.
-
Address.
-
Biometric information.
-
Financial information.
-
IP address and certain online identifiers.
-
Photographs and digital records.
Who Does the DPDP Act Apply To?
The Act generally applies to organizations and persons processing digital personal data, including:
-
Private companies.
-
Startups.
-
E-commerce platforms.
-
Banks and financial institutions.
-
Healthcare providers.
-
Educational institutions.
-
Government bodies (subject to the provisions of the Act).
-
Digital service providers.
Its applicability depends on the circumstances and the provisions of the Act.
Rights of Individuals Under the DPDP Act
The Act provides several important rights to individuals, including:
-
Right to access information about personal data being processed.
-
Right to correct inaccurate or incomplete personal data.
-
Right to update personal information.
-
Right to erase personal data in certain circumstances.
-
Right to withdraw consent where processing is based on consent.
-
Right to grievance redressal.
-
Right to nominate another person to exercise rights in specified situations, as provided under the Act.
These rights are subject to the conditions and limitations prescribed by law.
Responsibilities of Organizations
Organizations processing personal data are generally required to:
-
Process personal data lawfully.
-
Obtain valid consent where required.
-
Use personal data only for lawful purposes.
-
Protect personal data with appropriate security measures.
-
Maintain transparency regarding data processing.
-
Respond to data-related requests.
-
Report certain personal data breaches as required under the Act.
What is Consent Under the DPDP Act?
Consent is an important basis for processing personal data under the Act.
Consent should generally be:
-
Free.
-
Specific.
-
Informed.
-
Unambiguous.
-
Given through a clear affirmative action.
Individuals also have the right to withdraw consent in accordance with the provisions of the Act.
What is a Personal Data Breach?
A personal data breach refers to an unauthorized or accidental event that compromises the confidentiality, integrity, or availability of personal data.
Examples include:
-
Unauthorized access.
-
Data leaks.
-
Hacking incidents.
-
Identity theft.
-
Accidental disclosure.
-
Loss of digital records.
Organizations are required to take appropriate action in accordance with the DPDP Act when a data breach occurs.
What to Do if Your Privacy Rights Are Violated
Step 1: Contact the Organization
Request clarification regarding:
-
What personal data is being processed.
-
Why it is being processed.
-
Correction or deletion of incorrect information, where applicable.
Step 2: Submit a Grievance
Use the organization's grievance redressal mechanism and retain a copy of your complaint.
Step 3: Preserve Evidence
Keep copies of:
-
Emails.
-
Screenshots.
-
Privacy policy.
-
Data requests.
-
Responses received.
-
Any relevant communications.
Step 4: Escalate the Matter
If the grievance remains unresolved, individuals may seek further remedies in accordance with the DPDP Act and applicable legal procedures.
Documents That May Be Required
Depending on the issue, you may need:
-
Identity proof.
-
Contact details.
-
Copies of communications.
-
Screenshots.
-
Emails.
-
Account details.
-
Privacy policy references.
-
Complaint acknowledgments.
-
Any other supporting documents.
Common Mistakes to Avoid
-
Sharing personal information with unverified websites.
-
Ignoring privacy notices.
-
Reusing weak passwords.
-
Not enabling two-factor authentication.
-
Clicking suspicious links.
-
Failing to report suspected data breaches promptly.
Tips to Protect Your Personal Data
-
Use strong and unique passwords.
-
Enable multi-factor authentication.
-
Regularly update your devices and applications.
-
Review app permissions before granting access.
-
Avoid sharing sensitive information unnecessarily.
-
Monitor your online accounts for suspicious activity.
-
Read privacy policies before using digital services.