Is India's Data Protection Board Independent Enough To Protect You?

Faraz Siddiqui

25 July 2026 3:00 PM IST

  • Is Indias Data Protection Board Independent Enough To Protect You?
    Listen to this Article

    Most people believe that once laws are enacted establishing regulatory oversight, regulator independence is a done deal. The Digital Personal Data Protection Act, 2023 is set to become the exception to this rule, and the arena in which this contest is playing out is the Supreme Court of India itself.

    The DPDP Act 2023 and the DPDP Rules 2025 notified on 13th November 2025, are currently before the Supreme Court, challenged in a clutch of writ petitions by journalist Geeta Seshu, the Software Freedom Law Centre, digital news platform The Reporters Collective, journalist Nitin Sethi and the National Campaign for People's Right to Information. The matter has been taken up by the CJI and a bench of other judges, and the status quo is for the time being sub judice. This article does not seek to comment on the petitioners' prospects before the Court, or engage in speculation on the issues likely to arise. Instead, it seeks to lay out, in easily-digested language, what these challenges are about in the first place – what grey areas in the law they have identified – and what Data Fiduciaries and ordinary citizen need to know about the discrepancy between what the DPDP Act promises and what its language actually delivers.

    The Grey Zone: Who Does The DPDP Act Actually Protect?

    The DPDP Act has the broad definition of "person" in it and, crucially, it does not draw a distinction between 'natural' and 'legal' persons. It states that individuals, companies, Hindu Undivided Families and the State can all qualify as a "person" under the Act. However, "personal data" is defined strictly in terms of information pertaining to an identifiable individual person. The implication of this technicality is that a company's data is not "personal data" in the eyes of the law, unless its owner is a natural person. This definitional grey area is one of the reasons why the Bench has asked the petitioners to address what it considers to be the issue of public data versus personal data, and whether the stated objectives of the DPDP Act apply only to 'natural persons' Until this dispute is laid to rest, businesses which process data on behalf of corporate clients face a compliance conundrum and a potential data security risk. The resolution of this dispute is one of the many reasons why the issues raised in these petitions are of great interest to Data Fiduciaries everywhere.

    The RTI Amendment: An Explicit Change with Implicit Consequences

    Section 44(3) of the DPDP Act 2023, which amended the Right to Information Act 2005, is another sticking point. Under Section 8(1)(j) of the Right to Information Act 2005, a public authority may disclose personal information about any public servant upon demonstration of overriding public interest in the disclosure. However, as it stands now, personal information of public servants are now exempted from disclosure as a category, with no public interest exception available at all marks a stark contrast to the legal standing prior to this enactment. This is an explicit statutory change, not an interpretation of law, and falls squarely within the issues raised by the petitioners. The amendment is being challenged on the grounds that the RTI framework is now significantly weakened, and the ability of the media and common citizens to hold public servants accountable has been hampered. Whether this amendment survives constitutional scrutiny is now squarely a question for the Court.

    Board Independence: A Structural Question, Not a Personal One

    The DPDP Act establishes the Data Protection Board under Section 18 and the composition and remit of the Board is the subject of much debate. Under Section 18 of the DPDP Act, the Board consists of a chairperson and other members appointed by the Central Government on the recommendations of the Search-cum-Selection Committee constituted by the Central Government - meaning that the majority of the Board is likely to comprise Government nominees. Furthermore, the Board reports to the Ministry of Electronics and Information Technology, which raises the question of whether it can truly act independently when it comes to cases concerning the Government of India, or the data protection concerns of its agencies and political leadership. This is, arguably, a question of structural design, and one which falls outside the purview of individual. It is the kind of issue that has been referred to the Supreme Court previously in similar contexts and it seems entirely reasonable that it should be referred there now. It is notable that this question has even arisen and that it did not get buried by the sheer gravity of the other issues raised in the petitions. That is the mark of a functional system of checks and balances, and not a weakness in it.

    What This Means for Compliance Right Now

    It bears mentioning that for every Data Fiduciary preparing for the DPDP Act's substantive commencement on 13 th May 2027, this litigation will not affect your obligations one bit. The Act comes into force regardless, and the Data Protection Board is fully operational. As of 13th November 2026, you are expected to put your Consents Manager infrastructure in place. It would be unwise to prepare for the total repeal of the DPDP Act, or for the provisions which the petitioners find most offensive to be struck down wholesale, but it is unwise to operate under the assumption that they will be either. As in similar matters, it is more prudent to prepare for the law as written, while keeping a close eye on how the Court rules on the specific sections under challenge, namely Sections 7, 17(2)(a), 19(3), 24, 36, 44(2)(a), and 44(3).

    The Path Forward

    India's Supreme Court has, since its landmark judgement in the Justice K.S. Puttaswamy v. Union of India verdict establishing privacy as a fundamental right under Article 21, been the locus of debates which touched on personal data protection. It was the very judgement that established the need for a comprehensive data protection framework in the first place- and it is only fitting that this Court has been tasked with assessing the DPDP Act's compliance with the Constitution in turn. The fact that this law has come into being, and can now be judged by the country's highest court, is itself a statement on support for privacy in the constitution. The Indian Supreme Court has always tackled such dilemmas with the responsibility expected of it. Whatever it rules, it will have affirmed, yet again, that India's young but resilient data protection framework rests in capable hands.

    Author is a Delhi based Legal Professional specialising in DPDP Act compliance and AI governance. Views are personal.

    Next Story