Introduction
Meaning of Data Privacy
- Meaning of Data Privacy: Data privacy refers to the protection and lawful handling of personal information relating to individuals. It concerns how personal data is collected, processed, stored, shared and deleted and seeks to ensure that individuals retain meaningful control over information relating to them. In India, the Digital Personal Data Protection Act, 2023 (DPDP Act), represents a significant development towards a comprehensive framework for the protection of digital personal data. The Act places particular emphasis on consent and requires personal data to be processed for a specified purpose communicated to the individual.
Meaning of Cybersecurity
- Meaning of Cybersecurity: Cybersecurity refers to measures adopted to protect computer systems, networks, electronic records and digital information against unauthorised access, misuse, disruption or destruction. India’s Information Technology Act, 2000, provides an important statutory foundation for addressing cyber offences, electronic transactions and aspects of information security.
Corporate Compliance
- Corporate Compliance: Corporate compliance involves ensuring that an organisation conducts its activities in accordance with applicable legislation, regulations and regulatory requirements. In the context of data and cybersecurity, compliance requires companies to establish appropriate policies, safeguards and procedures for handling personal data and responding to security incidents.
Growing Importance in the Digital Economy
- Growing Importance in the Digital Economy: The rapid expansion of digital services has resulted in organisations processing increasingly large volumes of personal information. At the same time, businesses face growing cybersecurity risks and increasingly complex regulatory obligations. Generative AI and other data-intensive technologies have further intensified these concerns because they may require the processing of vast and diverse datasets, creating tensions with principles such as purpose limitation and data minimisation.
Objectives and Scope
- Objectives and Scope: This article examines India’s evolving framework for data privacy, cybersecurity and corporate compliance, with particular focus on the DPDP Act, Information Technology Act, CERT-In framework and the EU GDPR. It analyses the obligations imposed on organisations, identifies practical compliance challenges and considers how businesses can balance technological innovation with privacy protection, cybersecurity and legal accountability.
Evolution of Data Protection and Cybersecurity Law
Evolution of Data Protection in India
India’s data protection framework has evolved alongside the rapid expansion of digital technology. Initially, Indian law primarily focused on regulating electronic records, electronic transactions and cyber offences rather than creating a comprehensive framework for personal data protection. The Information Technology Act, 2000, provided the foundational legal framework for electronic transactions and cybersecurity and subsequently became relevant to privacy and data-security obligations. Its framework includes provisions dealing with unauthorised access, privacy violations, disclosure of information and protection of computer systems.
A significant development was the recognition that the protection of personal information forms part of the constitutional right to privacy. In Justice K.S. Puttaswamy (Retd.) v. Union of India (2017), the Supreme Court recognised privacy as a fundamental right under Article 21 and other guarantees of Part III of the Constitution. This constitutional recognition strengthened the need for a dedicated statutory framework governing personal data.
The Constitutional Right to Privacy
The Puttaswamy judgement established privacy as an essential aspect of individual liberty and dignity. Informational privacy is particularly relevant in the digital age because individuals routinely provide personal information to governments, financial institutions, technology companies and online platforms.
The recognition of informational privacy consequently created a stronger legal basis for regulating the collection and processing of personal data and for requiring organisations to adopt appropriate safeguards.
Development of India’s IT and Cybersecurity Framework
The Information Technology Act, 2000, gradually became an important component of India’s cybersecurity framework. Its provisions address cyber offences, privacy-related violations and government powers concerning cybersecurity.
Section 70B is particularly significant because it establishes CERT-In as the national agency for cyber-incident response, including collection and analysis of cyber incidents, issuing alerts and advisories, and coordinating responses.
Shift Towards Comprehensive Data Protection
The enactment of the Digital Personal Data Protection Act, 2023, marked a further transition towards a dedicated data-protection regime. The Act expressly seeks to recognise both an individual’s right to protect personal data and the need for lawful processing of such data.
Its framework places particular emphasis on consent, specified purposes and responsible processing, thereby moving Indian law beyond the earlier, more fragmented approach to privacy and cybersecurity regulation.
Digital Personal Data Protection Act, 2023
Objectives and Applicability of the DPDP Act
The Digital Personal Data Protection Act, 2023 (DPDP Act), establishes a dedicated statutory framework for the processing of digital personal data in India. Its objective is to balance an individual’s right to protect personal data with the legitimate need of organisations to process such data for lawful purposes.
The Act applies to the processing of digital personal data within India where the data is collected in digital form or is subsequently digitised. It also extends to processing outside India, where such processing is connected with offering goods or services to individuals in India. Certain personal or domestic processing and specified publicly available personal data are excluded.
Key Concepts
The Act establishes important roles within the data-processing relationship. The Data Principal is the individual to whom the personal data relates, while the Data Fiduciary determines the purpose and means of processing. A Data Processor processes personal data on behalf of a Data Fiduciary.
These distinctions are significant for corporate compliance because organisations determining how and why personal data is processed bear primary statutory responsibilities.
Grounds for Processing Personal Data
Under the Act, personal data may be processed for a lawful purpose, including where the Data Principal has provided consent or where the processing falls within specified legitimate uses.
Consent must be preceded or accompanied by a notice informing the Data Principal about the personal data proposed to be processed and the purpose of processing. This reflects the principle of purpose limitation: organisations should communicate why information is being collected and process it consistently with that purpose.
Notice and Consent
For organisations, notice and consent are central compliance requirements. A company must provide sufficient information to enable individuals to understand the intended processing.
The framework therefore requires organisations to move away from vague or open-ended descriptions of data use and towards clearly identified purposes. The issue becomes particularly significant for data-intensive technologies such as generative AI.
AI systems may require large datasets and continuous data collection, while purpose limitation and consent require greater specificity. This creates practical difficulties in determining whether data collected for one purpose can subsequently be reused for evolving AI applications.
Rights of Data Principals
The DPDP Act provides several rights to individuals. These include the right to access information concerning their personal data and processing activities, including information regarding data fiduciaries and data processors with whom their data has been shared.
Individuals also have rights relating to correction, completion, updating and erasure of personal data, subject to situations where retention is necessary for the specified purpose or required by law. They are further entitled to grievance redressal and may nominate another individual to exercise their rights in cases of death or incapacity.
Obligations of Data Fiduciaries
Data fiduciaries must establish mechanisms for addressing grievances and must ensure responsible processing and handling of personal data.
Special obligations apply to the processing of children’s data, including restrictions on tracking, behavioural monitoring and targeted advertising directed at children.
Significant Data Fiduciaries
The Central Government may designate certain organisations as Significant Data Fiduciaries based on relevant factors, including the volume and sensitivity of data processed.
Such entities may be subject to enhanced obligations, including the appointment of a Data Protection Officer, an independent Data Auditor, Data Protection Impact Assessments and periodic compliance audits.
Cross-Border Data Transfers
The DPDP framework permits cross-border transfers of personal data but allows the Central Government to restrict transfers to specified countries or territories through notification.
This is particularly relevant for multinational companies using foreign cloud infrastructure, international vendors and global data-processing systems.
Enforcement and Penalties
The Data Protection Board of India functions as the adjudicatory authority under the Act. It may inquire into personal-data breaches, hear complaints, direct remedial measures and impose monetary penalties for violations.
Its orders are appealable before the Telecom Disputes Settlement and Appellate Tribunal.
Corporate Compliance Under the DPDP Framework
For companies, compliance with the DPDP Act is therefore not limited to obtaining consent. It requires an integrated system involving:
- Privacy notices
- Data inventories
- Access and deletion mechanisms
- Grievance redressal
- Vendor management
- Security safeguards
- Breach-response procedures
Organisations must also consider how personal data moves between internal departments, processors and third parties.
The emergence of AI demonstrates why such compliance must remain dynamic. Difficulties surrounding data minimisation, continuous learning and withdrawal of consent show that organisations using AI-based systems may need stronger mechanisms for tracking the origin and subsequent use of personal data.
General Data Protection Regulation (GDPR)
Introduction to the GDPR
The General Data Protection Regulation (GDPR) is the European Union’s comprehensive framework for the protection of personal data. It establishes principles governing the collection, processing, storage and disclosure of personal information and places significant responsibilities on organisations that determine the purposes and means of processing. The GDPR is particularly important in the context of international business because its requirements can affect organisations operating outside the European Union when their activities fall within its territorial scope.
Territorial Scope and Extraterritorial Application
The GDPR may apply to organisations outside the European Union where their processing activities are connected with offering goods or services to individuals in the EU or monitoring their behaviour. Consequently, Indian companies providing digital services, operating online platforms or processing information relating to individuals in the EU may need to consider GDPR compliance alongside Indian data-protection requirements. This extraterritorial dimension makes GDPR particularly significant for multinational businesses and Indian technology companies involved in cross-border data processing.
Key Principles
The GDPR is based upon several fundamental principles of data protection. These include lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality and accountability.
Purpose Limitation
Purpose limitation requires personal data to be collected for specified and legitimate purposes and not subsequently used in an incompatible manner.
Data Minimisation
Data minimisation requires organisations to limit collection to information necessary for the relevant purpose.
Storage Limitation
Storage limitation requires personal data not to be retained longer than necessary.
Integrity and Confidentiality
The principle of integrity and confidentiality requires organisations to adopt appropriate technical and organisational measures against unauthorised access, loss, destruction or disclosure.
Rights of Data Subjects
The GDPR provides individuals with extensive rights concerning their personal information, including rights relating to access, rectification, erasure and control over processing. These rights are intended to strengthen individual control over personal data and impose corresponding responsibilities upon organisations.
Data Controllers and Data Processors
The GDPR distinguishes between data controllers, who determine the purposes and means of processing, and data processors, who process information on behalf of controllers. This distinction is significant for corporate compliance because organisations must clearly allocate responsibilities when personal data is shared with vendors, cloud providers or other third parties. The GDPR also requires appropriate contractual arrangements with processors and records of processing activities.
Data Breach Notification
The GDPR establishes specific obligations concerning personal data breaches. Under Article 33, a controller is generally required to notify the competent supervisory authority within 72 hours of becoming aware of a qualifying breach. Where a breach is likely to create a high risk to individuals, communication to affected data subjects may also be required under Article 34.
GDPR Penalties and Accountability
A major feature of the GDPR is its emphasis on accountability. Organisations must not merely comply with data-protection principles but should be capable of demonstrating compliance through appropriate policies, records, audits, governance mechanisms and risk assessments.
Relevance for Indian Companies
GDPR compliance is particularly relevant to Indian companies engaged in international technology, outsourcing and digital services. The GDPR’s principles of purpose limitation and data minimisation also provide useful comparative perspectives for understanding India’s DPDP framework. The uploaded research material notes that both regimes address purpose limitation and minimisation, while the GDPR does not generally exclude personal data merely because it is publicly available.
Thus, for Indian businesses operating across jurisdictions, GDPR compliance and Indian data-protection compliance may need to be addressed simultaneously, requiring coordinated privacy policies, contractual safeguards, processing records, security measures and breach-response mechanisms.
Information Technology Act, 2000 and Cybersecurity in India
Role of the Information Technology Act, 2000
The Information Technology Act, 2000 (IT Act), forms one of the principal statutory foundations of India’s digital and cybersecurity framework. Its original objective was to provide legal recognition to electronic records, electronic communication and electronic commerce, while also facilitating electronic filing and digital transactions. Over time, its provisions have acquired wider importance in addressing cyber offences, privacy violations, information security and intermediary liability.
Data Protection and Compensation
Section 43A is particularly relevant to corporate data protection because it addresses compensation for failure to protect sensitive personal data or information where an organisation handling such information is negligent in maintaining reasonable security practices. This provision established an important connection between corporate responsibility and information security, even before the enactment of the comprehensive DPDP framework. Companies handling personal information are therefore expected to adopt appropriate safeguards rather than treating cybersecurity merely as a technical concern.
Cyber Offences
The IT Act contains provisions dealing with several forms of cybercrime. Section 66 addresses dishonest or fraudulent acts involving computer-related activities. Other provisions address specific offences such as identity theft, cheating by personation using computer resources, violation of privacy and cyber terrorism. These provisions are significant for companies because cyber incidents may involve not only data breaches but also criminal conduct affecting customers, employees, systems and corporate assets.
Government Powers and Cybersecurity
The Act also provides certain powers to the Central Government concerning digital security. Section 69 deals with interception, monitoring or decryption of information in specified circumstances. Section 69A concerns the blocking of public access to information, while Section 69B provides for monitoring and collection of traffic data for cybersecurity purposes. These provisions illustrate the balance within India’s IT framework between individual privacy, digital security and the legitimate requirements of law enforcement and national security.
Protected Systems and Critical Infrastructure
The Act provides special protection to critical information infrastructure. Section 70 deals with protected systems, while Section 70A provides for the establishment of an authority for the protection of critical information infrastructure. This is particularly important for sectors where disruption of digital systems could have significant consequences for national security, the economy or essential public services.
CERT-In and Section 70B
Section 70B establishes the Indian Computer Emergency Response Team (CERT-In) as the national agency responsible for responding to cybersecurity incidents. Its functions include collecting and analysing information regarding cyber incidents, issuing alerts and advisories, taking emergency measures and coordinating incident-response activities. The CERT-In Directions, 2022, were issued under Section 70B and impose cybersecurity obligations on specified entities. They include incident reporting, maintenance of ICT logs and appointment of a point of contact for communication with CERT-In.
Confidentiality and Disclosure
The IT Act also addresses unauthorised disclosure of information. Section 72 deals with breach of confidentiality and privacy, while Section 72A addresses disclosure of information in breach of lawful contracts. These provisions reinforce the principle that information obtained in a professional or contractual relationship cannot be improperly disclosed.
Intermediary Liability
Section 79 provides a framework for limitation of intermediary liability subject to prescribed conditions. This is particularly relevant to online platforms and digital service providers, which may host or transmit information generated by third parties.
Corporate Liability
Section 85 is relevant to corporate compliance because it addresses offences committed by companies and circumstances in which persons responsible for the conduct of the company’s business may also become liable.
Corporate Cybersecurity Compliance
Consequently, cybersecurity compliance under the IT Act should be approached as a corporate governance responsibility involving legal, technical and managerial functions. Companies must maintain appropriate security practices, establish incident-response mechanisms and ensure that contractual arrangements with vendors and service providers adequately address cybersecurity responsibilities. The IT Act therefore continues to operate as an important component of India’s cybersecurity architecture alongside the DPDP Act, CERT-In Directions and other sector-specific regulatory requirements.
CERT-In and Corporate Cybersecurity Compliance
Meaning And Role Of CERT-In
The Indian Computer Emergency Response Team (CERT-In) is India’s national agency for responding to cybersecurity incidents. It operates under Section 70B of the Information Technology Act, 2000, and is responsible for collecting, analysing and disseminating information relating to cyber incidents, issuing alerts and advisories, coordinating responses and taking appropriate emergency measures.
CERT-In therefore serves as an important link between the government’s cybersecurity infrastructure and private organisations. Its role extends beyond responding to attacks after they occur and includes strengthening preparedness and promoting coordinated incident response.
CERT-In Directions and Corporate Obligations
The CERT-In Directions, 2022, issued under Section 70B, impose important cybersecurity and incident-reporting obligations on specified entities. Organisations are required to maintain appropriate records, establish mechanisms for reporting incidents and ensure that CERT-In can communicate with an identified organisational point of contact.
These requirements have significant implications for corporate compliance because cybersecurity teams cannot operate independently from legal and governance functions. Companies must ensure that their internal policies and procedures are aligned with applicable regulatory requirements.
Key CERT-In Corporate Cybersecurity Requirements
- Cyber Incident Reporting One of the most important CERT-In requirements concerns the reporting of specified cyber incidents. Timely reporting enables the national cybersecurity agency to analyse threats, identify patterns and coordinate responses where incidents affect multiple organisations. From a corporate perspective, this requires companies to establish an internal escalation mechanism through which technical teams can promptly inform management and legal or compliance personnel of reportable incidents. Failure to identify and escalate an incident promptly may create additional regulatory and legal exposure.
- Log Retention And Record-Keeping Cybersecurity compliance also involves maintaining appropriate technical records and logs. The CERT-In framework requires covered entities to maintain logs for the prescribed period and ensure that relevant information can be made available when legally required. Record-keeping serves two purposes: it assists organisations in investigating and responding to cybersecurity incidents while also providing evidence of compliance with regulatory requirements. Companies should therefore integrate log management into their broader information security and governance policies.
- Appointment Of Cybersecurity And Compliance Personnel Effective compliance requires clear allocation of responsibility. Organisations should designate appropriate personnel or a point of contact for communication with CERT-In and establish internal reporting channels. The role should not be viewed as exclusively technical. Legal and compliance professionals may need to determine whether an incident triggers reporting duties, contractual obligations, privacy obligations or potential liability towards affected individuals and business partners.
- Corporate Incident Response Mechanisms A company should maintain a documented incident-response plan covering identification, containment, investigation, reporting, recovery and post-incident review. The plan should establish who has authority to make decisions and when cybersecurity incidents must be escalated to senior management. Where an incident involves personal data, organisations must also consider obligations arising under the DPDP framework, alongside the IT Act and CERT-In requirements. Consequently, a single cybersecurity incident may trigger multiple legal and regulatory considerations.
- Consequences Of Non-Compliance Non-compliance with cybersecurity requirements can expose companies to regulatory action, financial consequences, contractual disputes and reputational damage. A significant data breach may additionally result in claims by affected individuals, investigation by authorities and loss of customer confidence. The possibility of such consequences demonstrates why cybersecurity should form part of enterprise risk management, rather than being treated merely as an information-technology issue.
- Role Of Corporate Legal Departments Corporate lawyers play an increasingly important role in cybersecurity compliance. Their responsibilities may include reviewing privacy policies, drafting data-processing and confidentiality clauses, assessing vendor contracts, advising on incident-reporting obligations and coordinating regulatory responses. They must also understand the interaction between the DPDP Act, the IT Act, the CERT-In framework and contractual obligations. Effective corporate compliance therefore requires continuous coordination between legal, information security, human resources and management teams.
Ultimately, CERT-In compliance represents one component of a broader corporate cybersecurity programme. Organisations must combine preventive security measures, regulatory reporting, documentation, employee awareness, contractual safeguards and incident-response planning to manage cybersecurity risks effectively.
Corporate Compliance: Practical and Legal Dimensions
Data Protection Governance Within Companies
Data protection has become an important component of corporate governance because companies routinely collect and process information relating to customers, employees, vendors and other individuals.
Effective governance requires organisations to identify what personal data they hold, why it is collected, who can access it and how long it is retained.
Under the DPDP framework, organisations must establish appropriate systems for lawful processing and protection of personal data. Compliance should therefore be incorporated into the company’s broader risk-management and governance structure rather than treated as an isolated technical function.
Key Corporate Data Protection Compliance Areas
- Privacy Policies and Internal Policies: Companies should maintain clear privacy policies and internal data-protection procedures explaining how personal data is collected, processed, stored and shared. Privacy notices should communicate relevant information to data principals and should correspond with the actual practices followed by the organisation. Internal policies should also address employee access, password and authentication requirements, data retention, use of personal devices, remote access and procedures for reporting suspected security incidents.
- Employee Data and Workplace Privacy Corporate compliance extends to personal data relating to employees. Organisations may process information concerning recruitment, payroll, attendance, performance, benefits and other employment-related matters. Companies should therefore ensure that employee data is accessed only by authorised personnel and is processed for legitimate and clearly defined purposes. Confidentiality obligations should also be incorporated into employment agreements and internal policies where appropriate.
- Vendor and Third-Party Compliance Modern businesses frequently depend on third-party service providers such as cloud-storage providers, payment processors, software companies and outsourcing agencies. These relationships can create additional privacy and cybersecurity risks because personal data may move outside the immediate control of the organisation. Companies should conduct appropriate vendor assessments and establish contractual safeguards governing data security, confidentiality, permitted processing, incident reporting, access controls and responsibility for breaches.
- Data Processing Agreements Where personal data is processed by another organisation, contractual arrangements should clearly identify the respective responsibilities of the parties. A well-drafted data-processing agreement can specify the permitted purpose of processing, security standards, confidentiality obligations, breach-reporting procedures and requirements concerning deletion or return of data. Such contractual mechanisms are particularly important for companies operating across jurisdictions and attempting to comply simultaneously with Indian requirements and the GDPR.
- Data Breach Response Companies should maintain a documented data-breach response mechanism. The process should identify how a breach will be detected, investigated, contained and reported. A coordinated response is particularly important because a single incident may involve several legal obligations. For example, cybersecurity incidents may require engagement with CERT-In, while incidents involving personal data may also raise obligations under the DPDP framework. Legal teams should therefore work alongside cybersecurity professionals from the earliest stage of an incident.
- Data Retention And Deletion Data should not be retained indefinitely merely because technological systems permit indefinite storage. Organisations should establish appropriate retention schedules based on the purpose for which information was collected and applicable legal or contractual requirements. Where data is no longer required, appropriate deletion or anonymisation procedures should be followed, subject to circumstances in which retention is legally necessary.
- Board-Level Responsibility And Risk Management Privacy and cybersecurity risks can have substantial financial, regulatory and reputational consequences. Accordingly, senior management and boards should treat data protection as part of enterprise risk management. Periodic assessments, internal audits, employee training and review of cybersecurity controls can help organisations identify weaknesses before they result in regulatory violations or significant data breaches.
- Role Of Corporate Lawyers And Compliance Officers Corporate lawyers and compliance officers play a central role in translating legal requirements into practical organisational procedures. Their responsibilities may include reviewing privacy policies, drafting confidentiality and data-processing clauses, assessing vendor agreements, advising management regarding regulatory requirements and coordinating responses to data breaches.
Integrated Corporate Cybersecurity and Privacy Compliance
Effective compliance ultimately requires cooperation between legal, IT, cybersecurity, human resources and management teams. The objective is not simply to satisfy statutory requirements but to create a sustainable system in which privacy and cybersecurity are integrated into the company’s everyday decision-making and risk-management practices.
Comparative Analysis and Key Challenges
DPDP Act v. GDPR
The Digital Personal Data Protection Act, 2023, and the General Data Protection Regulation (GDPR) both seek to establish a structured framework for the lawful processing and protection of personal data. Both regimes recognise the importance of principles such as purpose limitation, data minimisation, transparency and accountability.
However, the two frameworks differ in their regulatory design and scope. The DPDP Act adopts the terminology of ‘data principals’, ‘data fiduciaries’ and ‘data processors’, while the GDPR uses ‘data subjects’, ‘controllers’ and ‘processors’.
The GDPR also provides a comparatively extensive catalogue of individual rights and establishes detailed requirements concerning areas such as records of processing, data protection impact assessments and breach notification.
The DPDP framework, on the other hand, has been designed specifically for India’s digital environment and establishes the Data Protection Board of India as its principal enforcement authority.
It also adopts a differentiated approach towards certain categories of organisations through the concept of Significant Data Fiduciaries.
Overlap Between DPDP, IT Act and CERT-In Requirements
Indian businesses must increasingly navigate multiple and interconnected legal requirements. The IT Act, 2000, continues to address cyber offences, information security, confidentiality and intermediary liability, while the DPDP Act focuses specifically on the processing and protection of digital personal data.
CERT-In adds another layer by establishing cybersecurity and incident-response requirements. Section 70B of the IT Act identifies CERT-In as the national agency for responding to cyber incidents, while the CERT-In Directions impose additional operational requirements on covered entities.
Consequently, a single cybersecurity incident involving personal data may potentially raise privacy, cybersecurity, contractual and regulatory issues simultaneously.
Major Compliance Challenges
- One of the principal challenges is regulatory overlap. Companies may have to determine which obligations apply to a particular incident, processing activity or category of data.
- Cross-border data flows present another difficulty, particularly for multinational organisations using foreign cloud providers and global data-processing infrastructure. Businesses operating internationally may need to comply with both Indian requirements and GDPR obligations.
- Rapid technological development creates further uncertainty. Technologies such as artificial intelligence, cloud computing and automated data processing constantly create new methods of collecting and processing information. The challenge for regulators is to provide effective protection without unnecessarily restricting technological innovation.
- Finally, organisations face practical challenges involving compliance costs, employee awareness, third-party risks, cybersecurity preparedness and continuous monitoring. Effective compliance therefore requires more than adopting a written privacy policy; it requires an integrated system of legal, technical and organisational safeguards.
Conclusion
Data privacy, cybersecurity and corporate compliance have become closely interconnected aspects of modern business operations.
The increasing dependence of companies on digital platforms, electronic records, cloud services and data-driven technologies has made the protection of personal information and digital infrastructure an essential corporate responsibility.
India’s legal framework has developed significantly from the foundational Information Technology Act, 2000, towards a more comprehensive data-protection regime under the Digital Personal Data Protection Act, 2023.
The IT Act continues to provide important provisions concerning cyber offences, confidentiality, information security and intermediary liability, while CERT-In plays a central role in coordinating responses to cybersecurity incidents under Section 70B.
The DPDP framework, meanwhile, focuses specifically on the lawful processing and protection of digital personal data and establishes rights and obligations for data principals and data fiduciaries.
The GDPR provides an important international point of comparison, particularly for Indian companies engaged in cross-border operations.
Its emphasis on transparency, purpose limitation, data minimisation and accountability demonstrates the growing global importance of responsible data governance.
Ultimately, compliance cannot be achieved through isolated legal or technical measures. Companies must integrate privacy governance, cybersecurity controls, contractual safeguards, employee awareness, incident-response mechanisms and regulatory compliance into their broader corporate governance structures.
As technologies such as artificial intelligence and cloud computing continue to develop, India’s legal framework will need to remain sufficiently adaptable to protect individual privacy while supporting responsible technological innovation.


