← All articles

Court News

Privacy vs. Surveillance: India’s Data Protection Law in a Global Context

Updated 5 June 2026
Privacy vs. Surveillance: India’s Data Protection Law in a Global Context

Privacy vs. Surveillance: India’s Data Protection Law in a Global Context

 

As India enacts its Digital Personal Data Protection Act, the balance between liberty and security takes center stage.

 

How India’s privacy law compares with GDPR, and what it means for citizens, businesses, and global investors.

 

By Vishwas Kumar

New Delhi: June 04, 2026:

 

In August 2023, India passed the Digital Personal Data Protection Act (DPDP Act), a landmark law that reshaped the country’s digital governance. For a nation with over 1.4 billion people and one of the fastest‑growing internet economies, the legislation was overdue. It promises to safeguard citizens’ privacy while enabling businesses to thrive in a data‑driven world.

 

Several landmark constitutional cases have been decided on the basis of equality and fairness under Article 14 of the Constitution of India. This detailed guide explains the evolution of Article 14 jurisprudence through important Supreme Court decisions and legal principles.

 

The law arrives at a critical moment. India’s Supreme Court, in the Puttaswamy judgment (2017), declared privacy a fundamental right under Article 21 of the Constitution. Yet, concerns about surveillance, data misuse, and weak enforcement persisted. The DPDP Act is designed to bridge that gap, offering a framework for consent, accountability, and penalties.

 

Globally, India’s move is being closely watched. Comparisons with Europe’s GDPR and the US’s sector‑specific privacy laws highlight both strengths and weaknesses. While India’s law is comprehensive, critics argue that government exemptions could dilute its effectiveness.

 

This article explores the constitutional roots of privacy in India, the features of the DPDP Act, global comparisons, surveillance concerns, business implications, and the future of digital rights in the world’s largest democracy.

 

Section 1: Constitutional Roots of Privacy

 

Privacy in India was not explicitly mentioned in the Constitution but evolved through judicial interpretation. The turning point came in Justice K.S. Puttaswamy v. Union of India (2017), where a nine‑judge bench of the Supreme Court unanimously held that privacy is intrinsic to the right to life and liberty under Article 21.

 

This ruling laid the foundation for legislative action. It recognized privacy as essential to dignity, autonomy, and freedom in a digital society. The judgment also emphasized proportionality—any restriction on privacy must be necessary, reasonable, and subject to safeguards.

 

The DPDP Act reflects this constitutional ethos. It enshrines consent as the cornerstone of data processing and grants citizens rights to access, correct, and erase their data. By embedding privacy into law, India has aligned constitutional values with digital realities.

 

Section 2: Key Features of the DPDP Act

 

The DPDP Act introduces several critical features:

  • Consent‑based processing: Companies must obtain clear consent before collecting personal data.
  • Rights of individuals: Citizens can access, correct, and request deletion of their data.
  • Data fiduciaries: Entities handling data must ensure security and accountability.
  • Penalties: Non‑compliance can attract fines running into hundreds of crores.
  • Children’s data: Special safeguards require parental consent for processing minors’ information.

 

The law also establishes the Data Protection Board of India, tasked with enforcement and grievance redressal. While comprehensive, critics note that government agencies enjoy broad exemptions, raising concerns about unchecked surveillance.

 

Section 3: India vs. Global Privacy Laws

 

India’s DPDP Act is often compared to the EU’s GDPR, considered the gold standard in privacy regulation. Both emphasize consent, transparency, and accountability. However, GDPR has stricter enforcement mechanisms and independent regulators, while India’s framework is more centralized.

 

The US, by contrast, lacks a single federal privacy law. Instead, it relies on sector‑specific regulations like HIPAA (healthcare) and COPPA (children’s data). India’s comprehensive approach is closer to Europe’s model, though lighter in enforcement.

 

Other democracies, such as Brazil (LGPD) and South Africa (POPIA), have enacted similar laws. India’s entry into this club signals its ambition to be a trusted digital economy.

 

Section 4: Surveillance & Security Concerns

 

One of the most debated aspects of the DPDP Act is its government exemptions. The law allows data processing without consent for reasons of national security, public order, and emergencies. Critics argue this could enable mass surveillance.

 

Globally, surveillance has been contentious. The US faced backlash over the NSA’s mass data collection programs. The EU enforces strict safeguards to prevent abuse. India’s challenge is to balance security needs with constitutional rights.

 

Judicial oversight will be crucial. Courts must ensure that surveillance is proportionate and subject to accountability. Without checks, privacy risks being undermined by state power.

 

Section 5: Business & Investor Implications (400 words)

 

For businesses, the DPDP Act introduces compliance costs but also builds trust. Startups must invest in data security, while multinationals must align Indian operations with global standards.

 

Investors see opportunity. Legal tech, cybersecurity, and compliance platforms are poised for growth. India’s law enhances its reputation as a safe digital hub, attracting global capital.

 

Section 6: Future Outlook

 

The future of privacy in India depends on enforcement. Strong regulators, judicial oversight, and public awareness will determine success.

 

AI and big data will test the law’s resilience. As algorithms process personal information, safeguards must evolve. India’s scale and democratic framework position it to lead global debates on digital rights.

 

Ultimately, the DPDP Act is more than legislation—it is a statement of constitutional morality in the digital age. By balancing liberty with security, India can chart a path that resonates worldwide.

 

40 FAQs with Answers

 

Basics of the DPDP Act

1. What is the Digital Personal Data Protection Act?
It is India’s 2023 law regulating how personal data is collected, stored, and processed, ensuring privacy rights for citizens.

2. Why was the DPDP Act introduced?
To safeguard individual privacy, align India with global standards, and build trust in its digital economy.

3. Who enforces the DPDP Act?
The Data Protection Board of India oversees compliance, handles complaints, and imposes penalties.

4. What rights do citizens have under the Act?
They can access, correct, and request deletion of their personal data, and file grievances if misused.

5. Does the law apply to foreign companies?
Yes, any company processing data of Indian citizens must comply, even if based abroad.

 

Constitutional Context

6. Is privacy a fundamental right in India?
Yes, recognized by the Supreme Court in the landmark Puttaswamy judgment of 2017.

7. How does Article 21 relate to privacy?
Article 21 guarantees the right to life and liberty, which courts have interpreted to include privacy.

8. Can the government override privacy rights?
Only under specific exemptions for national security, public order, or emergencies.

9. How do courts protect privacy?
Through judicial review, ensuring laws and government actions comply with constitutional values.

10. What is constitutional morality in privacy?
It means upholding dignity, liberty, and fairness beyond the written text of the law.

 

Global Comparisons

11. How does India’s law compare to GDPR?
Both emphasize consent and accountability, but GDPR has stricter enforcement and independent regulators.

12. How does it compare to US privacy laws?
The US relies on sector‑specific laws, while India has a comprehensive framework covering all data.

13. What about Brazil’s LGPD?
India’s law shares similarities with Brazil’s LGPD, focusing on consent and individual rights.

14. How does South Africa regulate privacy?
Through POPIA, which is comparable to India’s DPDP Act in scope and protections.

15. Is India’s law globally recognized?
Yes, it positions India as a major player in global digital governance.

 

Surveillance Concerns

16. Does the government have exemptions under the Act?
Yes, for national security, public interest, and emergencies, though these raise concerns.

17. Is surveillance a threat to privacy?
Unchecked surveillance can undermine privacy, making judicial oversight essential.

18. How do other countries handle surveillance?
The EU enforces strict safeguards, while the US has faced criticism for mass surveillance programs.

19. Can citizens challenge surveillance in India?
Yes, through constitutional remedies like writ petitions in High Courts and the Supreme Court.

20. What role does the judiciary play in surveillance?
It ensures surveillance measures remain proportionate and do not violate fundamental rights.

 

Business & Compliance

21. What obligations do companies have under the Act?
They must obtain consent, secure data, and report breaches promptly.

22. What are penalties for violations?
Fines can reach hundreds of crores depending on the severity of non‑compliance.

23. How does the law affect startups?
It increases compliance costs but builds consumer trust in digital services.

24. How does it affect multinationals?
They must align Indian operations with global privacy frameworks, similar to GDPR compliance.

25. Are investors interested in India’s privacy law?
Yes, it enhances confidence in India’s digital economy and regulatory environment.

 

Citizen Rights

26. Can individuals delete their data?
Yes, they can request erasure of personal information held by companies.

27. Can children’s data be processed?
Only with parental consent, ensuring stronger safeguards for minors.

28. How can citizens file complaints?
Through the Data Protection Board, which investigates and resolves grievances.

29. What protections exist against misuse?
Strict penalties and grievance mechanisms deter misuse of personal data.

30. Does the law cover biometric data?
Yes, sensitive personal information like biometrics is included.

 

Future Outlook

31. Will India strengthen enforcement of the Act?
Likely, as digital adoption grows and privacy concerns intensify.

32. Can AI be regulated under this law?
Yes, if AI systems process personal data, they must comply with the Act.

33. Will surveillance laws evolve in India?
They may, with judicial and legislative oversight shaping future reforms.

34. Could India lead global privacy debates?
Yes, given its scale, democratic framework, and growing digital economy.

35. How does this law affect citizens daily?
It gives individuals more control over their personal data and digital footprint.

 

Miscellaneous

36. What is a data fiduciary?
An entity that decides how personal data is processed, such as companies or organizations.

37. What is a data principal?
The individual whose personal data is being processed.

38. What is cross‑border data transfer?
Sharing data outside India, subject to rules and government approvals.

39. Does the law apply to government agencies?
Yes, but with certain exemptions for security and public interest.

40. Why is this law significant globally?
It positions India as a leader in digital governance, influencing global privacy standards.

 

Conclusion

 

India’s Digital Personal Data Protection Act (DPDP Act) represents a watershed moment in the country’s constitutional and legal journey. It is not merely a piece of legislation—it is a reflection of how India interprets the fundamental right to privacy in the age of technology. Rooted in the Supreme Court’s recognition of privacy as intrinsic to Article 21, the Act bridges constitutional ideals with the realities of a digital economy where data is the new currency.

 

The law’s emphasis on consent, accountability, and individual rights signals a shift toward empowering citizens. For the first time, individuals have enforceable rights to access, correct, and erase their personal data. This is a significant step in aligning India with global standards like the EU’s GDPR, while tailoring the framework to its own socio‑economic context. Yet, the Act also highlights the tension between liberty and security. Government exemptions for national security and public order remain controversial, raising fears of unchecked surveillance. The challenge ahead lies in ensuring that these powers are exercised proportionately and subject to judicial oversight.

 

For businesses, the DPDP Act is both a challenge and an opportunity. Compliance will require investment in data security and governance, but it also builds trust in India’s digital ecosystem. Startups and multinationals alike must adapt, while investors see potential in legal tech, cybersecurity, and compliance solutions. In this sense, the Act strengthens India’s reputation as a safe and reliable digital hub, critical for attracting global capital.

 

Globally, India’s move is significant. As one of the largest democracies and digital markets, its approach to privacy will influence debates worldwide. Countries in Asia, Africa, and Latin America may look to India’s model as they craft their own frameworks. By balancing innovation with rights, India positions itself as a leader in digital governance.

 

Looking forward, the success of the DPDP Act will depend on enforcement, judicial vigilance, and public awareness. Technology evolves rapidly—AI, big data, and biometrics will test the resilience of privacy protections. India must ensure that constitutional morality—justice, liberty, equality, and dignity—remains at the heart of digital governance.

 

In conclusion, the DPDP Act is more than a law; it is a constitutional milestone. It embodies India’s commitment to protecting citizens in a digital age while navigating the delicate balance between privacy and surveillance. If implemented effectively, it could transform India into a global leader in digital rights, setting a precedent for democracies worldwide.