INDIA Law and Practice Contributed by: Suvarna Mandal and Rishikaa, Saikrishna & Associates
mation, among others. This distinction between personal information and SPDI is important because the requirements and obligations on body corporates for handling personal informa - tion and SPDI are different under the SPDI Rules. Updating Data Protection Regulation Given the need to update the SPDI Rules due to their inherent gaps and rudimentary nature, the regulatory landscape for data protection, privacy and cybersecurity in India is gradually shifting towards ensuring and enforcing data protection in business operations, with the Supreme Court recognising the “right to privacy” as a funda - mental right under the Indian Constitution in 2017, in the case of Justice K.S. Puttaswamy (Retd) v Union of India. This case was monumen - tal and served as the impetus for the govern - ment to implement a dedicated data protection framework for India. Introduction of the Upcoming Law After several years of contemplation and multi - ple iterations through draft bills, the Parliament passed the DPDP Act in August 2023 to serve as the first dedicated legislation for data protection and privacy in India. The DPDP Act will replace the SPDI Rules once it comes into force, with any processing of personal information or data continuing to be governed by the SPDI Rules in the meantime. The DPDP Act provides a principles-based framework for the processing of “digital” per - sonal data – ie, personal data in digital form about an individual who is identifiable by or in relation to such data. It also applies to non-dig - ital personal data that is digitised subsequently. Unlike the SPDI Rules, the DPDP Act does not subcategorise personal data into sensitive per - sonal data.
Several obligations under the DPDP Act will be operationalised through the delegated legisla - tion or “rules” to be issued under the DPDP Act, such as cross-border transfer, notice require - ments, notification of “Significant Data Fidu - ciaries”, treatment of children’s data, consent managers, etc. Draft Rules Under the DPDP Act Nearly two years after the introduction of the DPDP Act, in January 2025 the Ministry of Electronics and Information Technology (Mei - tY) published the draft of the Digital Personal Data Protection Rules, 2025 (the “Draft DPDP Rules”), which was open for public comment until 5 March 2025. At present, these rules are in the draft stage and will be finalised after the stakeholder consultation process; they will then become effective upon their notification in the official gazette. The Draft DPDP Rules may undergo further changes considering public and stakeholder comments before they are finalised and notified. Notable provisions proposed in the Draft DPDP Rules include the following. Notice The DPDP Act requires every request for con - sent to be accompanied or preceded by a notice. As per the Draft DPDP Rules, this notice must be provided in clear, plain language, and must be presented independently of any other information. The notice must provide an itemised description of the personal data sought to be processed, its specified purpose, an itemised description of the goods or services to be pro - vided, a communication link for accessing the website and/or app, and a description of any other means for enabling the withdrawal of con - sent, the exercise of rights and making a com - plaint to the Data Protection Board of India.
187 CHAMBERS.COM
Powered by FlippingBook