Why Personal Data Became a Governance Issue in India

2 MIN READ

Ten years ago, nobody made laws about what happens to your personal data. Nobody really thought to — data was scattered, hard to search, and mostly stayed on paper. Today, India has an entire Act built around protecting it, with its own rules, rights and penalties. Here’s the short version of how that happened, starting with one court case that changed everything.

THE STORY IN THREE STEPS

24 AUG 2017

Privacy becomes a right

A nine-judge Supreme Court bench rules, unanimously, that privacy is a fundamental right for every Indian, protected under Article 21. The case started as a challenge to the Aadhaar ID scheme, but the ruling reached far beyond it.

2017–2023

The gap

India goes online fast — UPI payments, Aadhaar-linked services, e-commerce, dozens of apps asking for your data every week. A right has just been recognised, but there’s still no single law telling organisations how to handle the data it’s meant to protect.

11 AUG 2023

The DPDP Act

Parliament passes the Digital Personal Data Protection Act to close that gap, after years of drafts and consultation. The Rules explaining exactly how to follow it arrive more than two years later, in November 2025.

A rapidly expanding digital ecosystem is enabling faster services, greater transparency and wider access. Now since privacy became a right, protecting personal data stopped being a nice-to-have. It became something the government had to actively build a system for — a committee to design it, years of drafts to refine it, and eventually an Act to enforce it. That’s also why the DPDP Act feels different from ordinary paperwork: it exists to protect a right that already exists, not just to create new forms to fill in.

Common misconception — That India just copied Europe’s GDPR. It didn’t. This law grew out of an Indian court case about an Indian identity scheme, not an imported European framework, even though global developments did shape parts of India’s thinking along the way.

Personal data became India’s business the moment privacy became India’s right.

SOURCES  Puttaswamy v. Union of India (2017), case background — Supreme Court Observer — https://www.scobserver.in/cases/puttaswamy-v-union-of-india-fundamental-right-to-privacy-case-background/   ·   The DPDP Act, 2023 — official text, MeitY — https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf

Ready to get compliant?

Talk to our team or register your organisation to get started with ConveyGrid.

Privacy Overview

We use cookies to help you navigate efficiently and perform certain functions. You will find detailed information about all cookies under each consent category below.

The cookies that are categorised as "Necessary" are stored on your browser as they are essential for enabling the basic functionalities of the site.

We also use third-party cookies that help us analyse how you use this website, store your preferences, and provide the content and advertisements that are relevant to you. These cookies will only be stored in your browser with your prior consent.

You can choose to enable or disable some or all of these cookies but disabling some of them may affect your browsing experience.

Necessary

Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.

Analytics

Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.

Marketing

Advertisement cookies are used to provide visitors with customised advertisements based on the pages you visited previously and to analyse the effectiveness of the ad campaigns.