Concur News
  • Home
  • India
  • Startup
  • Regulation
  • Interview
  • Press Release
  • Login
August 26, 2025
No Result
View All Result
Concur News

Home » How India’s Data Protection Law is Reshaping Policy and Business

How India’s Data Protection Law is Reshaping Policy and Business

August 26, 2025
in Global, India, LAW, Privacy
Reading Time: 4 mins read
How India’s Data Protection Law is Reshaping Policy and Business
Share on LinkedinShare on Whatsapp

In 2023, India introduced the Digital Personal Data Protection Act, 2023 (DPDP Act), marking the start of a new chapter in privacy regulation. In January 2025, the government also released the Draft DPDP Rules, 2025 for public feedback. This consultation ended on 5 March 2025.

Although the President has already signed the DPDP Act, it has not yet taken effect. Until the law officially comes into force, the 2011 SPDI Rules (Sensitive Personal Data or Information) continue to regulate data protection in India. The Ministry of Electronics and Information Technology (MeitY) is also considering a two-year transition period to give businesses time to prepare for the new regime.

Government officials have urged companies to start aligning their systems with the DPDP Act, but the lack of finalized rules makes this difficult. The upcoming rules, along with directions from the Data Protection Board of India (DPB), will add further operational requirements. For now, businesses must comply with the SPDI Rules while simultaneously preparing for the DPDP framework.

Consent Foundation

Transition Difficulties

At first glance, a two-year transition may seem sufficient. However, the SPDI Rules offer only a basic framework with weak enforcement. This makes the shift to the more comprehensive DPDP Act much harder. In addition, the DPDP Act works alongside sector-specific laws, which may impose stricter rules on areas like cross-border data transfers. Startups and smaller firms, in particular, may struggle with the added costs and infrastructure demands.

The DPDP Act’s principles-based design also brings fresh challenges at both the policy and operational levels.

Policy Uncertainty

Several provisions create uncertainty for businesses. For instance, the government has previously taken strong actions on data security, such as banning Chinese apps in 2020 for unauthorized data transfers. Yet, recent statements by the MeitY minister about hosting the Chinese AI model DeepSeek in India reflect a softer approach, causing confusion.

The DPDP Act gives the government wide powers to restrict cross-border data transfers. Draft rules require all transfers to follow government orders, raising the risk of frequent policy shifts. This lack of clear safeguards could lead to arbitrary decisions, discouraging investor and business confidence.

Another grey area lies in personal data breach notifications. The draft rules require companies to report any breach “without delay” and submit a detailed report within 72 hours. Since “without delay” is undefined, this could conflict with existing rules from CERT-In, leading to duplication and confusion.

Moreover, companies must report all breaches, no matter how minor. This could overwhelm both the DPB and affected users with excessive alerts, potentially damaging reputations and delaying real crisis management.

Multiple Reporting Burdens

The breach reporting rules do not align with other frameworks, such as the CERT-In Directions on Cybersecurity or the Telecom Cyber Security Rules, 2024. This fragmented system forces businesses to report the same incident to multiple authorities, creating unnecessary complexity instead of a single streamlined process.

Data Localisation and Government Powers

The draft rules revive data localisation requirements for certain “significant data fiduciaries.” These entities may be prohibited from sending specific categories of personal or traffic data outside India. This is a shift from earlier moves to relax localisation demands, and it may clash with foreign laws that require disclosure of data to overseas regulators.

The government also reserves broad powers to demand information from companies and intermediaries. These powers lack clear procedural safeguards and do not reflect the privacy protections laid down by the Supreme Court in the landmark Puttaswamy judgment (2017), which requires legality, necessity, and proportionality for any action that infringes privacy. Without limits, such powers tilt the balance heavily in favour of the state, potentially at the cost of privacy rights and business ease.

The Way Forward

The DPDP Act and draft rules are undoubtedly a major step toward aligning India with global privacy standards. However, unresolved issues remain. The real challenge lies not just in the law itself but in how the rules are drafted and implemented.

For India to succeed, the framework must strike a balance—protecting individual rights while supporting innovation and ease of doing business. A clear, consistent, and well-coordinated regulatory approach will be key to achieving that balance.


Also read: Interview with Simran Gupta: How a Freelance Corporate Lawyer Navigates India’s Evolving Data Privacy Era

Tags: Data privacyData ProtectionDPDPAPrivacy

Related Posts

Canada Updates Rules on Biometric Technology Usage
Global

Canada Updates Rules on Biometric Technology Usage

August 26, 2025
Over 6,900 Responses Collected on Draft DPDP Rules 2025 from Citizens
India

Over 6,900 Responses Collected on Draft DPDP Rules 2025 from Citizens

August 26, 2025
Interview with Simran Gupta: How a Freelance Corporate Lawyer Navigates India’s Evolving Data Privacy Era
Interview

Interview with Simran Gupta: How a Freelance Corporate Lawyer Navigates India’s Evolving Data Privacy Era

August 26, 2025
Road Ministry
India

Road Ministry Unveils Data Sharing Policy for National Transport Repository

August 21, 2025

RECOMMENDED NEWS

IT Ministry Receives Nearly 7,000 Comments on Draft Data Protection Rules

IT Ministry Receives Nearly 7,000 Comments on Draft Data Protection Rules

1 month ago
Data Privacy Act’s Rules on Children Draw Criticism from Experts

Data Privacy Act’s Rules on Children Draw Criticism from Experts

4 weeks ago
IIT-Roorkee Breach Puts Caste, Financial, and Contact Details of 30,000 Students and Alumni at Risk

IIT-Roorkee Breach Puts Caste, Financial, and Contact Details of 30,000 Students and Alumni at Risk

2 weeks ago
verizon business

Ransomware Causes 51% of Data Breaches in Asia-Pacific, Verizon Report Finds

4 months ago

BROWSE BY TOPICS

AI AI in education AI Privacy banks Children privacy Compliance Consent consent managers Cross-Border Cybercrime Cyber security Data Data breach Data leak Data privacy data privacy in education Data Protection Data security Data Violation Digital DPDP DPDPA DPDP Act EU Fines GDPR google Hack Hacked Interview Investigation Law Meity penalty Personal data Press Release Privacy privacy rights RBI SPAM Tech giants Technology TRAI Training Trending

701, The Capital, BKC(E), Mumbai, India

Follow us on social media:

Categories

Categories Layout
  • Africa
  • America
  • India
  • Asia
  • Europe
  • Japan
  • Business
  • Events
  • Regulation
  • Law
  • News
  • Privacy
  • Startup
  • Technology
Categories Layout
  • Apps
  • Cybercrime
  • Data
  • Data Breach
  • Data Privacy
  • Data Protection
  • Digital
  • FBI
  • Investment
  • Law
  • Privacy
  • Tech Giants
  • DPDP
  • DPDPA

Harmonize Data Compliance

Footer with Animated Button
Effortlessly align your data compliance with Concur, ensuring seamless integration and robust adherence to regulatory standards.
BOOK A DEMO
  • About
  • Advertise
  • Careers
  • Home
  • Demo

© 2025 Concur - consent manager

Welcome Back!

OR

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • News
  • Business

© 2025 Concur - consent manager