Concept Page

Data Protection Authority of India

The Data Protection Authority of India is a proposed regulatory body. It will oversee data privacy and security in India. The authority is envisioned in the Digital Personal Data Protection Bill.

The Data Protection Authority of India (DPA‑India) is a statutory regulator envisaged under the Digital Personal Data Protection Bill, 2022 (DPDP Bill) to enforce privacy rights, oversee compliance with data‑handling obligations, and adjudicate breaches of personal data across the country. Its creation marks the first dedicated, independent body tasked with safeguarding digital privacy in a nation of over 1.4 billion internet users, positioning India alongside the European Union’s GDPR framework and signalling a shift from sector‑specific rules to a unified data‑governance regime. ## Origins and Legislative Evolution India’s data‑privacy journey began with the Supreme Court’s landmark judgment in Justice K.S. Puttaswamy v. Union of India (2017), which affirmed privacy as a fundamental right under Article 21 of the Constitution. The ruling prompted the Ministry of Electronics and Information Technology (MeitY) to draft the Personal Data Protection Bill (PDPB) in 2019, which underwent extensive parliamentary debate before being superseded by the DPDP Bill in December 2022. The DPDP Bill was passed by the Lok Sabha on 7 August 2022 and by the Rajya Sabha on 11 August 2022, after which it was transmitted to the President for assent. The authority’s legal foundation is codified in Chapter III of the bill, beginning with Section 4, which mandates the establishment of a “Data Protection Authority” as a body corporate with a distinct legal personality. ## Key Provisions Governing the Authority Section 4 of the DPDP Bill stipulates that the DPA‑India will be constituted by a chairperson and up to six members, each appointed by the central government for a non‑renewable term of five years. Section 5 outlines eligibility criteria, requiring members to possess “expertise in data protection, information technology, or law.” Section 6 enumerates the Authority’s functions, including the issuance of directions to data fiduciaries, the conduct of audits, and the maintenance of a public register of processing activities. Section 7 confers investigative powers such as the ability to summon individuals, requisition documents, and impose interim measures. Finally, Section 9 prescribes penalties of up to 4 % of a fiduciary’s worldwide turnover or INR 5 crore (whichever is higher) for violations, mirroring the punitive scale of the EU GDPR. ## Mechanism of Operation The DPA‑India will receive complaints through an online portal hosted on the MeitY website, a channel that, as of July 2025, recorded over 12 000 submissions in its pilot phase. Upon receipt, the Authority may order a preliminary inquiry within ten working days, after which it can mandate a full investigation lasting up to ninety days, extendable by a further thirty days with judicial approval. Findings are published in a quarterly “Data Protection Bulletin,” which, according to the 2024 draft guidelines, must include the number of audits conducted, the categories of breaches identified, and the aggregate fines levied. The Authority is also empowered to issue “data‑locality” directives, compelling cross‑border transfers to adhere to the “adequacy” standards defined in Schedule II of the bill. ## Current Status and Implementation Timeline As of July 2026, the DPDP Bill remains pending presidential assent, and the DPA‑India has not yet been operationalized. The Ministry of Finance, in its 2025 budget speech, allocated INR 1.2 billion for the Authority’s inaugural fiscal year, earmarking funds for staffing, IT infrastructure, and public awareness campaigns. A draft Rules‑making exercise, released in February 2026, invites stakeholder comments on the Authority’s procedural code, with the final rules expected by the end of 2026. Meanwhile, the Ministry of Electronics and Information Technology has issued interim guidelines on “data‑safety impact assessments,” which the prospective Authority will later formalize. ## Significance in the Global and Domestic Landscape The establishment of DPA‑India is poised to harmonize India’s data‑privacy regime with international standards, facilitating cross‑border data flows essential for the burgeoning AI and fintech sectors. By providing a single point of accountability, the Authority aims to reduce regulatory fragmentation that previously existed across the Information Technology Act 2000, the Telecom Regulatory Authority of India, and sector‑specific guidelines. Its enforcement powers are expected to curb practices highlighted in recent reports—such as the exploitation of workers’ behavioural data for AI training—thereby reinforcing consumer trust and supporting the objectives of India’s National AI Strategy, which emphasizes ethical AI development. In comparison, the Authority’s penalty ceiling aligns closely with