India Unfolding
All sectorsVerified data
Data Protection & Cyber

Data Protection & Cyber

As India's digital economy exploded, so did the need to protect people's data. The journey ran from the Supreme Court's 2017 ruling that privacy is a fundamental right, to the Digital Personal Data Protection (DPDP) Act of 2023 — India's first comprehensive data-protection law — giving citizens rights over their personal data and setting duties and penalties for the companies that handle it. This timeline traces those milestones.

Server room of BalticServers
Server room of BalticServers · BalticServers.com · CC BY-SA 3.0 · Wikimedia Commons
2023
DPDP Act passed
2017
Privacy = fundamental right
1st
Comprehensive data law
Privacy & data rights
2017
Right to Privacy is fundamental
In the landmark Puttaswamy judgment, the Supreme Court unanimously rules that privacy is a fundamental right under the Constitution — the foundation for data-protection law.
2021
Cybersecurity rules tighten
2023
Digital Personal Data Protection Act
2025
DPDP Rules & enforcement
2017
1milestones
20172025
Latest
Right to Privacy is fundamental
In the landmark Puttaswamy judgment, the Supreme Court unanimously rules that privacy is a fundamental right under the Constitution — the foundation for data-protection law.

Why it matters Strong data rights build trust in the digital economy, protect citizens from misuse and breaches, and are essential as more of life moves online.

  • Right to Privacy fundamental right (SC, 2017)
  • DPDP Act 2023 — first comprehensive data-protection law
  • Source: MeitY / Supreme Court

History

As Aadhaar, UPI and smartphones put a billion Indians online, questions grew over who controls their data. In 2017 the Supreme Court, in the Puttaswamy case, unanimously ruled that privacy is a fundamental right — the constitutional foundation for data law.

The DPDP Act

After years of drafts, India passed the Digital Personal Data Protection Act in 2023 — its first comprehensive data-protection law. It gives people rights to access and erase their data, requires consent, and sets penalties and a Data Protection Board for companies that misuse personal data.

How it works

India's data-protection regime is built on consent. Under the DPDP Act, any organisation ('data fiduciary') must tell you clearly what personal data it collects and why, and can generally use it only with your permission — which you can withdraw. You get rights to access, correct and erase your data. A new Data Protection Board enforces the law, and a 'consent manager' system is meant to let people manage all their permissions in one place.

Outlook

The framework became real in November 2025 when the DPDP Rules were notified, operationalising the 2023 Act and setting up the Data Protection Board — with penalties up to ₹250 crore for serious breaches. The next step is putting the law into practice through a phased rollout (full compliance by 2027): building the consent-manager ecosystem, helping small businesses comply without being crushed, and balancing privacy with the data needs of India's booming digital economy and AI ambitions.

The road ahead

The next step is putting the law into practice — the new Data Protection Board actually enforcing the rules, and balancing privacy, innovation and state access.

By the numbers

Right to Privacy (SC, 2017); DPDP Act (2023) — first comprehensive data law; DPDP Rules & Data Protection Board (2025). Source: MeitY / Supreme Court.

Source: MeitY / Supreme Court — data-protection & privacy milestones, 2017–2025.