In 1950, when the Constitution of India came into force, nobody imagined a world where a person's shopping habits, location history, financial transactions, and personal conversations could be stored, analyzed, and monetized in seconds.
For decades, privacy was never viewed as a separate legal right. It was simply assumed to exist within the broader framework of personal liberty. Today, when India has transformed into a digital economy, that assumption was challenged. India now has its own dedicated privacy legislation — the Digital Personal Data Protection Act, 2023 (DPDPA). But reaching this point took more than seventy years.
The Early Years: Privacy Without a Privacy Law (1950–2000)
When the Constitution was drafted, privacy was not expressly recognized as a Fundamental Right. No dedicated data protection legislation existed, and information was largely maintained in physical records.
For nearly five decades, privacy disputes were addressed indirectly through constitutional protections relating to life and personal liberty. At the time, data protection was simply not viewed as a separate regulatory concern.
- Privacy was not expressly recognized as a Fundamental Right.
- No dedicated data protection legislation existed.
- Information was largely maintained in physical records.
The Internet Changes Everything (2000–2010)
India's digital revolution created new challenges. In 2000, India enacted the Information Technology Act, 2000, primarily to regulate electronic records and cybercrime.
As online services grew, concerns emerged regarding unauthorized collection of personal information, data breaches, lack of transparency, and weak accountability mechanisms.
To address some of these concerns, India introduced Section 43A of the IT Act and the Sensitive Personal Data Rules, 2011. These rules were India's first serious attempt at regulating personal data. However, they remained limited in scope and were never designed to serve as a comprehensive privacy framework.
The Turning Point: The Puttaswamy Judgment (2017)
The most significant moment in India's privacy journey came in 2017. In the landmark Justice K.S. Puttaswamy v. Union of India case, a nine-judge bench of the Supreme Court unanimously held that privacy is a Fundamental Right under the Constitution of India.
Privacy is a Fundamental Right under the Constitution of India.
This judgment transformed privacy from a policy issue into a constitutional guarantee. The Court recognized informational privacy, individual autonomy, and data protection as a component of human dignity. This decision laid the foundation for modern privacy law in India.
The Srikrishna Committee (2018)
Following the judgment, the Government constituted an expert committee under Justice B.N. Srikrishna. The Committee's report became India's first comprehensive roadmap for privacy regulation.
It introduced concepts that are now common in privacy governance — many of which ultimately influenced the DPDPA.
- Data Principal
- Data Fiduciary
- Consent-based processing
- Purpose limitation
- Accountability
- Data protection impact assessments
India's Legislative Journey (2018–2023)
India's privacy law evolved through multiple drafts and revisions before the Digital Personal Data Protection Act was enacted in 2023. This marked India's transition from fragmented privacy regulation to a dedicated data protection framework.
- 2018First Personal Data Protection Bill introduced.
- 2019Revised Bill tabled before Parliament.
- 2021–2022Extensive parliamentary review and stakeholder consultations.
- 2022Previous bill withdrawn.
- 2023Digital Personal Data Protection Act enacted.
The DPDPA Era (2023 Onwards)
The DPDPA reflects a uniquely Indian approach to privacy regulation. Privacy is no longer merely an IT issue — it is now a boardroom issue.
- Right to access information
- Right to correction and erasure
- Right to grievance redressal
- Right to nominate another individual
- Accountability, transparency, lawful processing, and security safeguards for organizations
What Comes Next?
India's privacy journey is far from over. The next phase is likely to focus on artificial intelligence governance, cross-border data transfers, sector-specific regulations, and enhanced enforcement and penalties.
For businesses, the message is clear: privacy is no longer a compliance checkbox. It has become a strategic business function that directly influences trust, reputation, and growth.
Conclusion
India's data privacy evolution tells the story of a country adapting its legal framework to a rapidly changing digital economy.
From a Constitution that never expressly mentioned privacy to the enactment of the DPDPA in 2023, India has undergone one of the most significant privacy transformations in the world.
The organizations that embrace privacy today will be the ones best positioned to succeed tomorrow.