{"id":6860,"date":"2025-01-08T20:00:00","date_gmt":"2025-01-09T02:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/cybersecurity-operations\/india-overhauled-national-data-privacy-rules"},"modified":"2025-01-08T20:00:00","modified_gmt":"2025-01-09T02:00:00","slug":"india-readies-overhauled-national-data-privacy-rules","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2025\/01\/08\/india-readies-overhauled-national-data-privacy-rules\/","title":{"rendered":"India Readies Overhauled National Data Privacy Rules"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltfd3e9f53ee8a35e6\/677ea1e2827b1f6d4cab241a\/India-Wavebreakmedia_Ltd_IFE-240405_3-Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/india-readies-overhauled-national-data-privacy-rules.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/india-readies-overhauled-national-data-privacy-rules.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The government of India has drafted rules that will define how companies inside and outside of the country must handle its citizens&#8217; data privacy.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A year and a half ago, India enacted its first ever comprehensive national data protection law: <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/data-privacy\/india-data-protection-bill-passed-despite-privacy-concerns\">the Digital Personal Data Protection (DPDP) Act<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. The act defined key privacy rights for Indian citizens \u2014 to access, update, correct, challenge, port, and erase their data, plus additional safeguards for children&#8217;s data \u2014 and various obligations of data stewards to secure user data, maintain its accuracy, limit how it&#8217;s used, and more.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Organizations have not yet been forced to adjust their data trafficking practices, as the act was waiting on a set of clearly defined rules of implementation. On Jan. 3, India&#8217;s Ministry of Electronics and Information Technology (MeitY) released those <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/innovateindia.mygov.in\/dpdp-rules-2025\/\">draft rules, designed to operationalize DPDP<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. In 22 provisions and seven schedules, the DPDP Rules provide businesses with a framework for complying with the act once the government begins to enforce it.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For years leading up to this point, &#8220;As the digital infrastructure in India has grown exponentially, the absence of safety mechanisms for individuals has left citizens vulnerable,&#8221; says Pankit Desai, CEO and co-founder of Sequretek. That makes DPDP &#8220;a landmark regulation, long overdue. It&#8217;s not just a regulatory framework \u2014 it is a signal of India&#8217;s readiness to prioritize citizen welfare in the digital age.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"India's Long Road to Data Privacy\">India&#8217;s Long Road to Data Privacy<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In 1941, Khrarak Singh, a citizen of India&#8217;s northern state of Uttar Pradesh, was tried for gang robbery (dacoity). He was let off thanks to an absence of evidence, but police kept an eye on him nonetheless. They visited his home at night, kept tabs on his movements, and monitored various aspects of his personal life: his employment, social life, and habits, for example.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Eventually Singh filed a petition, arguing that the surveillance violated his constitutional rights. On Dec. 18, 1962, six judges of India&#8217;s Supreme Court ruled that though some of the police tactics amounted to harassment, many of their surveillance measures were legally permissible. Privacy, they argued, was not a fundamental right under the country&#8217;s constitution.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">That remained the case until 2017, after India&#8217;s government proposed the &#8220;Aadhaar&#8221; project, giving all citizens identification numbers backed with various demographic and biometric data. Overseeing a challenge to Aadhaar, Chief Justice of India JS Khehar explained, \u201cIt is essential for us to determine whether there is a fundamental right to privacy in the Indian Constitution,&#8221; citing the Kharak Singh case. In August 2017, a nine-judge bench declared that privacy was a right given to India&#8217;s citizens under its constitution.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Their ruling opened the floodgates to data protection legislation, first and most notably the proposed Personal Data Protection Bill of 2019. However, the bill was proved both expansive and restrictive. The bill covered both personal and non-personal data, but was stringent in mandating that sensitive personal data not leave the borders of the country, yet also lenient in allowing the government to exempt itself for various reasons. Regardless, the bill was withdrawn in August 2022. It was followed in spirit by the more neutral DPDP, which will finally become operational once the latest proposed rules are finalized.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"New Rules of the Road\">New Rules of the Road<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The DPDP rules are mostly industry standard: companies must notify customers about the data they collect, and if it&#8217;s breached, encrypt it at rest and in transit, delete it after three years of inactivity, and so on.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Most notably, they grant substantial control to the data principal (individual) over their personal data, including the ability to determine when, how, where, and for what purpose their data is used,&#8221; notes Rama Krishna Gudipati, head of customer success at CloudSEK. &#8220;Additionally, the introduction of penalties for non-compliance adds an important layer of accountability.&#8221; Failing to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/endpoint-security\/china-backed-smishing-campaign-targets-india-post-users\">notify customers of a breach<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, for example, or betraying obligations around children&#8217;s data, could cost companies up to INR 200 crore (around $23 million).<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Certain provisions are more debatable, though, like the continued exceptions afforded to government agencies. Sequretek&#8217;s Desai says that &#8220;The exemption granted to the government from these rules raises questions about fairness and accountability, especially given the government&#8217;s significant role as a service provider,&#8221; says Sequretek&#8217;s Desai. &#8220;India&#8217;s digital infrastructure is heavily influenced by government-led initiatives, unlike in the West, where private enterprises dominate,&#8221; making the rule more impactful than it would be in other countries.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The deadline for submitting feedback on the new draft rules is Feb. 18. After the rules are activated, MeitY stated in a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/pib.gov.in\/PressReleasePage.aspx?PRID=2090271\">Jan. 5 press release<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, &#8220;An adequate period would be provided so that all stakeholders, from small enterprises to large corporates, may transition smoothly to achieve compliance with the new law.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/india-overhauled-national-data-privacy-rules\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The government of India has drafted rules that will define<\/p>\n","protected":false},"author":12,"featured_media":6861,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-6860","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/india-readies-overhauled-national-data-privacy-rules-scaled.jpg?fit=2560%2C1440&ssl=1",2560,1440,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/india-readies-overhauled-national-data-privacy-rules-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/india-readies-overhauled-national-data-privacy-rules-scaled.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/india-readies-overhauled-national-data-privacy-rules-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/india-readies-overhauled-national-data-privacy-rules-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/india-readies-overhauled-national-data-privacy-rules-scaled.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/india-readies-overhauled-national-data-privacy-rules-scaled.jpg?fit=2048%2C1152&ssl=1",2048,1152,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/india-readies-overhauled-national-data-privacy-rules-scaled.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/india-readies-overhauled-national-data-privacy-rules-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/india-readies-overhauled-national-data-privacy-rules-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/india-readies-overhauled-national-data-privacy-rules-scaled.jpg?fit=2560%2C1440&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/6860","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=6860"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/6860\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/6861"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=6860"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=6860"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=6860"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}