Centre for Juridical Science and Policy Research
International Journal of Juridical Science and Policy (IJJSP)
Vol. 1 · Issue 1 · 2026
Key information
India’s data privacy laws have changed a lot over the ten years. Now we have the Digital Personal Data Protection Act of 2023 and the Digital Personal Data Protection Rules of 2025. These laws have created a system that is based on principles. This research looks at how things have changed from an policy point of view. It also considers the case of Justice K.S. Puttaswamy versus the Union of India which said that people have a right to privacy according to the Constitution. It looks at the bodies that now oversee the processing of personal data, such as the Data Protection Board of India, the Consent Manager ecosystem and the new obligations imposed on Significant Data Fiduciaries. It also talks about the differences between the Indian framework and the General Data Protection Regulation. It says that the General Data Protection Regulation is risk based, whereas the Indian framework is consent and notification based. Emerging and trend-setting issues are examined in detail such as how to govern AI and algorithmic decision-making, the conflict between data localisation and India’s plans for a Digital Public Infrastructure, dark patterns in platforms that users interact with and the three-stage enforcement timeline that ends in May 2027. The report finds that non-personal and non-digital data, independence of the regulatory Board and the impact of compliance on start-ups and micro, small and medium-sized businesses are still areas where there are gaps. India has a comprehensive set of laws to protect data privacy, but their effectiveness will depend on the strictness of enforcement, the attention they receive from the courts, and the degree of stakeholder involvement during the implementation period.