Digital Governance, Data Protection and the Constitutional Right to Privacy in India
Abstract
The expansion of digital governance in India, through biometric identification, platform-based welfare delivery and large-scale surveillance infrastructure, has transformed the relationship between citizen and State. This article examines whether the constitutional right to privacy, recognised in Justice KS Puttaswamy (Retd) v Union of India, is adequately secured by the Digital Personal Data Protection Act 2023 and its Rules. Using doctrinal legal research, it analyses constitutional provisions, statutory text and Supreme Court decisions to evaluate the accountability of the State as a holder of personal data.
The article argues that, although the Act imposes a consent-based framework on private actors, its wide exemptions for State instrumentalities, the executive’s power to call for information, the executive-dependent Data Protection Board and the amendment of the Right to Information Act 2005 weaken the constitutional test of legality, legitimate aim and proportionality. It concludes that constitutional accountability requires narrower statutory exemptions, an independent regulator and independent authorisation of State access to personal data.
Introduction
India’s governance has migrated onto digital rails. Welfare entitlements are delivered through biometric authentication, identity is verified through interoperable public infrastructure, and policing, taxation and public health increasingly depend on large databases. This transformation promises efficiency and inclusion, yet it concentrates extraordinary informational power in the State.1
The constitutional question is therefore no longer whether the State may collect personal data, but on what terms, with what safeguards and subject to whose scrutiny. 1Vrinda Bhandari and Renuka Sane, ‘Protecting Citizens from the State Post Puttaswamy: Analysing the Privacy Implications of the Justice Srikrishna Committee Report and the Data Protection Bill, 2018’ (2018) 14 Socio-Legal Review 143.
In Justice KS Puttaswamy (Retd) v Union of India (Puttaswamy I), a ninejudge Bench unanimously held that privacy is a fundamental right protected under article 21 and the freedoms guaranteed by Part III of the Constitution.2 The Court recognised informational privacy as a facet of that right and required that any State interference satisfy legality, a legitimate aim and proportionality.3 Parliament’s response, the Digital Personal Data Protection Act 2023 (DPDP Act), arrived six years later,4 and the Digital Personal Data Protection Rules 2025 were notified in November 2025 with obligations phased in until May 2027.5
This article argues that the DPDP Act disciplines private data fiduciaries with considerable rigour but treats the State with conspicuous generosity. Because the State is at once the largest collector of personal data and the principal potential violator of informational autonomy, the quality of State accountability is the true measure of the statute’s constitutional adequacy. The article sets out the research problem, objectives and methodology, analyses the constitutional and statutory framework against the jurisprudence of the Supreme Court, and closes with findings and proposals for reform.
1. Research Problem / Research Question
The research problem is the gap between the constitutional standard of State accountability and the statutory design of data protection in India.
Puttaswamy I requires that every State intrusion on privacy be backed by law, serve a legitimate aim and be proportionate to that aim. The DPDP Act, however, empowers the Central Government to exempt State instrumentalities from the Act by notification, permits non-consensual processing for a wide range of governmental functions, and places the new regulator under executive control. Whether such a design can be reconciled with article 21 and the rule of law is the central concern of this study.
The principal research question is: to what extent does the DPDP Act 2023, read with the Digital Personal Data Protection Rules 2025, give effect to the constitutional guarantee of privacy and secure the accountability of the State in digital governance? Three sub-questions follow. First, what constitutional principles govern the State’s collection and use of personal data? Second, do the exemptions and enforcement structures of the Act satisfy the test of legality, legitimate aim and proportionality? Third, what reforms are needed to align the statute with constitutional governance?
2. Objectives of the Study
The study pursues five objectives: (i) to trace the constitutional evolution of the right to privacy and its application to State data processing; (ii) to examine the DPDP Act and Rules as instruments of State accountability, with particular attention to sections 7, 17, 18–19, 36 and 44; (iii) to evaluate those provisions against the proportionality jurisprudence of the Supreme Court, including Puttaswamy I, the Aadhaar judgment and Anuradha Bhasin v Union of India; (iv) to draw limited comparative guidance from European Union law; and (v) to propose workable legislative and institutional reforms.
3. Research Methodology
This study adopts doctrinal legal research. It treats law as a body of authoritative texts and reasons from them by analysis, interpretation and critical evaluation. Primary sources comprise the Constitution of India, the DPDP Act and Rules, the Information Technology Act 2000, the Aadhaar Act 2016, the Right to Information Act 2005 and the decisions of the Supreme Court of India. Secondary sources include the report of the Justice BN Srikrishna Committee and scholarly commentary. European Union materials serve only as a comparative benchmark and not as binding authority.
The approach is analytical and normative: it first extracts the constitutional standard from the case law and then measures statutory provisions against it. The study has three limitations. It is not empirical and does not assess how the Act operates in practice. The Rules were notified only recently, and most substantive obligations are not yet in force. The Data Protection Board has not yet produced a body of decisions, so conclusions about enforcement are necessarily predictive.
4. Main Discussion and Legal Analysis
4.1 Constitutional foundations of informational privacy
Early decisions were hesitant. In MP Sharma v Satish Chandra the Court declined to read a privacy right into the Constitution when upholding search and seizure powers, and in Kharak Singh v State of UP the majority struck down night-time domiciliary visits under article 21 but rejected a general fundamental right to privacy.6
The jurisprudence shifted with Gobind v State of MP, which accepted a limited privacy right subject to compelling State interest, and with Maneka Gandhi v Union of India, which required that any law depriving personal liberty be just, fair and reasonable, thereby bringing articles 14, 19 and 21 into a single protective framework.7 In R Rajagopal v State of Tamil Nadu and PUCL v Union of India the Court linked privacy to personal information and communications, and in the latter laid down procedural safeguards against telephone tapping, including authorisation at a senior level and periodic review.8
Puttaswamy I overruled MP Sharma and Kharak Singh to the extent that they denied the existence of the right.9 Its significance for digital governance lies in three propositions. First, privacy protects informational self-determination, that is, an individual’s control over the dissemination of personal information. Second, the right is enforceable against the State, although the Court acknowledged that informational privacy also demands protection against private actors. Third, restrictions must satisfy a threefold test: a law must exist, it must pursue a legitimate State aim, and the means adopted must be proportionate to that aim.10 Kaul J, in addition, urged the Union to put in place a robust data protection regime balancing individual interests against legitimate State concerns.
4.2 The State as a data fiduciary
Digital governance changes the character of State power. A welfare beneficiary cannot negotiate the terms on which the State collects her biometric or demographic data because the benefit is conditional on disclosure. The relationship is one of dependency and asymmetry, which is why consent alone cannot legitimise State processing. Balkin’s theory of information fiduciaries, under which entities that collect and use personal data owe duties of care and loyalty to the persons concerned, applies with greater force to a State that holds such data on public trust.11
Constitutional governance supplies the corresponding principles: data should be collected for a specified lawful purpose, limited to what is necessary, retained no longer than needed, protected against breach, and open to independent scrutiny. The Justice Srikrishna Committee likewise recommended that the State be bound by the same obligations as private entities, subject only to narrowly drawn exceptions.12
State accountability in this setting has three dimensions. Substantive accountability means that processing must be lawful, necessary and proportionate. Procedural accountability requires notice, a hearing where appropriate, reasoned orders and review. Institutional accountability demands an independent regulator and courts capable of enforcing these duties against government itself. A statute that is weak on any one dimension leaves the constitutional guarantee incomplete.
4.3 The asymmetry of the DPDP framework
The DPDP Act is built on notice and consent, supplemented by a closed list of ‘legitimate uses’ that permit non-consensual processing.13 Section 7 allows the State and its instrumentalities to process data without fresh consent in order to provide subsidies, benefits, services, certificates, licences and permits, where the individual has previously consented or the data already exists in a State database, and also to perform any function under law or in the interests of the sovereignty and integrity of India.14 Section 17(2)(a) goes further: the Central Government may by notification exempt any instrumentality of the State from the Act on grounds that echo article 19(2), including the security of the State and public order.15 Section 17(4) separately relieves State processing of the duty to erase data once its purpose is served and, in specified cases, of rights of access and correction.16
The executive’s reach extends to the regulator and to the law of transparency. Under section 36 the Central Government may require the Board and any data fiduciary to furnish information it calls for, and the Rules prescribe minimum retention of logs for purposes connected with State use.17 The Board’s chairperson and members are appointed by the Central Government for two-year terms, with eligibility for reappointment, which sits uneasily with the independence that adjudication against the State requires.18 Finally, section 44(3) amends section 8(1)(j) of the Right to Information Act 2005 so that personal information is exempt from disclosure, removing the earlier qualification that allowed disclosure where the larger public interest so required.19 The effect is to weaken a transparency tool that citizens have used to hold public officials to account.
These features mark a retreat from earlier drafts. Clause 42 of the Personal Data Protection Bill 2018 permitted processing in the interests of State security only where it was authorised by law, followed a procedure established by that law, and was necessary and proportionate.20 Section 17(2)(a) of the 2023 Act contains no express requirement of necessity or proportionality, and no procedure for reasoned decision-making or review.
5. Relevant Statutory and Judicial Analysis
5.1 Proportionality in the case law
The Supreme Court has refined the proportionality standard since Puttaswamy I. In Modern Dental College v State of MP it identified four elements: a legitimate goal, a rational connection between the measure and the goal, necessity in the sense that no less restrictive but equally effective alternative exists, and a proper balance between the importance of the goal and the extent of the infringement.21 In the Aadhaar case (Puttaswamy II) the majority upheld the scheme for welfare delivery after applying that test, but struck down section 57, which allowed private entities to demand Aadhaar authentication, and section 33(2), which allowed disclosure of identity and authentication information in the interests of national security without judicial oversight, and it read down section 33(1) so that the affected person must be heard.22 The decision thus validated large-scale digital governance while insisting on independent safeguards against State disclosure.
Anuradha Bhasin v Union of India applied proportionality to an internet shutdown. The Court held that orders restricting fundamental rights must be published and reasoned, are open to judicial review, and cannot suspend the internet indefinitely, and it required periodic review of such orders.23 In PUCL the Court insisted on procedural safeguards for interception, and in Manohar Lal Sharma v Union of India, concerning the alleged use of Pegasus spyware, it held that invoking national security does not exclude judicial review and appointed an expert technical committee to inquire.24 Together these decisions establish that State claims of security or efficiency must be justified on the record and always remain open to scrutiny.
5.2 Testing section 17(2)(a) and related provisions
Applying that framework, the first requirement is legality. Section 17(2)(a) is a statutory provision, and the notification power is defined by subject-matter. But legality in the constitutional sense demands more than the existence of a statute; the law must be clear and precise and must not confer unguided discretion. The statute leaves the selection of exempted bodies entirely to the executive, with no criteria, no duty to give reasons and no provision for review, which creates a real risk of arbitrariness under article 14.
The second requirement, a legitimate aim, is readily met, since the enumerated grounds mirror article 19(2). The difficulty lies in the third. A blanket exemption of an agency from every obligation under the Act, including purpose limitation, security safeguards and breach notification, is not the least restrictive means of protecting security interests. An agency may have a compelling need to withhold notice from a suspect, yet no apparent need to leave its databases unsecured or to retain data indefinitely. Proportionality would require exemptions tailored to specific obligations and specific operations. The absence of independent prior authorisation or after-the-fact review also falls short of the safeguards demanded in PUCL, Puttaswamy II and Anuradha Bhasin. The weakness is compounded by interception powers that survive outside the Act, namely section 69 of the Information Technology Act 2000 and section 20 of the Telecommunications Act 2023, under which authorisation rests with the executive and review lies with executive committees.25
Similar concerns attach to section 44(3). Privacy and transparency are both facets of constitutional accountability, and the Court has long treated access to official information as an incident of article 19(1)(a).26 By exempting personal information without a public-interest override, the amendment forecloses the balancing that proportionality requires. The legitimate-use provision in section 7 is more defensible where it is tied to benefits the individual has sought, but its reliance on prior consent or existing State databases means that data collected under earlier regimes may be reused for new purposes, which strains the principle of purpose limitation.
5.3 A comparative perspective
European Union law offers a useful benchmark. Article 23 of the General Data Protection Regulation allows restriction of data subject rights for security and public-interest purposes, but only by a legislative measure that respects the essence of fundamental rights and is necessary and proportionate in a democratic society.27 In Schrems II the Court of Justice invalidated the EU–US Privacy Shield because United States surveillance programmes were not limited to what is strictly necessary and offered affected persons no effective redress.28 The lesson is that security-based exemptions are lawful only where they are bounded by law and accompanied by remedies. The DPDP Act, by contrast, relies on executive notification and offers no equivalent remedy against State processing that falls within an exemption.
6. Findings / Observations
- The constitutional standard is settled. Privacy is a fundamental right under article 21, and State interference must satisfy legality, a legitimate aim and proportionality, as refined in Modern Dental, Puttaswamy II and Anuradha Bhasin.
- The DPDP Act is asymmetrical. Private fiduciaries face detailed duties and heavy penalties, whereas State bodies benefit from the legitimate-use provisions of section 7, the relaxations of section 17(4) and the power of exemption under section 17(2)(a).
- Section 17(2)(a) lacks criteria, reasons, time limits, independent authorisation and review. Because it contains no necessity or proportionality requirement, it is vulnerable to challenge under articles 14 and 21, or at least to a narrowing interpretation.
- Institutional independence is deficient. The Central Government appoints the Board, can call for information under section 36 and is itself the most significant respondent that the Board will face, which creates a structural conflict of interest.
- Section 44(3) reduces transparency by removing the public-interest balance from the personal-information exemption in the Right to Information Act, thereby diminishing a key mechanism of democratic accountability.
- Accountability gaps lie outside the Act. Executive-controlled interception regimes endure, and the Rules’ retention requirements extend the State’s access to private-sector data.
- Enforcement remains untested. The Rules are only partly in force, and judicial review will probably determine how far the constitutional standard is read into the statute.
7. Conclusion and Suggestions
The digital State cannot be both guardian and unchecked collector of personal data. The DPDP Act is a significant advance because it finally gives India a horizontal data protection statute, but it does not yet translate the promise of Puttaswamy I into enforceable State accountability. Its exemptions, its executive-dependent regulator and its dilution of the right to information leave the most powerful data fiduciary, the State, with the least effective constraints. The following reforms are suggested.
- Section 17(2)(a) should be amended so that exemptions are granted only by reasoned notification, are confined to specified provisions and operations, expressly require necessity and proportionality, are time-limited and are placed before Parliament.
- The Board’s independence should be secured through a selection committee that includes members outside the executive, fixed non-renewable tenure and financial autonomy.
- State access to personal data and interception should require prior authorisation by a judicial or independent authority, followed by review, notification to the individual where possible, and published transparency reports.
- Section 44(3) should be repealed, or section 8(1)(j) of the Right to Information Act 2005 restored with its public-interest override.
- State data fiduciaries should carry enhanced duties, including data protection impact assessments, publication of purposes and retention periods, and accountability for breaches.
- Pending legislative reform, courts should read section 17(2)(a) down so that the Puttaswamy proportionality test governs every notification, and Parliament should provide for periodic statutory review of the Act.
Constitutional governance requires that digital power be at least as accountable as the analogue power it replaces.
8. Bibliography
Table of Cases
- Anuradha Bhasin v Union of India (2020) 3 SCC 637
- Case C-311/18 Data Protection Commissioner v Facebook Ireland Ltd and Maximillian Schrems (Schrems II) EU:C:2020:559
- Gobind v State of Madhya Pradesh (1975) 2 SCC 148
- Justice KS Puttaswamy (Retd) v Union of India (2017) 10 SCC 1
- Justice KS Puttaswamy (Retd) v Union of India (2019) 1 SCC 1
- Kharak Singh v State of Uttar Pradesh AIR 1963 SC 1295
- Maneka Gandhi v Union of India (1978) 1 SCC 248
- Manohar Lal Sharma v Union of India [2021] SCC OnLine SC 985
- Modern Dental College and Research Centre v State of Madhya Pradesh (2016) 7 SCC 353
- MP Sharma v Satish Chandra AIR 1954 SC 300
- People’s Union for Civil Liberties v Union of India (1997) 1 SCC 301
- R Rajagopal v State of Tamil Nadu (1994) 6 SCC 632
- State of Uttar Pradesh v Raj Narain (1975) 4 SCC 428
Table of Legislation and Instruments
- Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act 2016 (India)
- Constitution of India 1950
- Digital Personal Data Protection Act 2023 (India)
- Digital Personal Data Protection Rules 2025 (India)
- Information Technology Act 2000 (India)
- Information Technology (Procedure and Safeguards for Interception, Monitoring and Decryption of Information) Rules 2009 (India)
- Personal Data Protection Bill 2018 (India) (draft)
- Regulation (EU) 2016/679 (General Data Protection Regulation) [2016] OJ L119/1
- Right to Information Act 2005 (India)
- Telecommunications Act 2023 (India)
Secondary Sources
- Balkin JM, ‘Information Fiduciaries and the First Amendment’ (2016) 49 UC Davis Law Review 1183
- Bhandari V and Sane R, ‘Protecting Citizens from the State Post Puttaswamy: Analysing the Privacy Implications of the Justice Srikrishna Committee Report and the Data Protection Bill, 2018’ (2018) 14 Socio-Legal Review 143
- Bhatia G, The Transformative Constitution: A Radical Biography in Nine Acts (HarperCollins India 2019)
- Committee of Experts under the Chairmanship of Justice BN Srikrishna, ‘A Free and Fair Digital Economy: Protecting Privacy, Empowering Indians’ (Ministry of Electronics and Information Technology, July

