Home India ELECTRONICS AND INFORMATION TECHNOLOGY Parliament Question: Increase of Data Secrecy Concern...
Date: 2025-12-17 Category: Not Applicable State: Union Government Country: India

Parliament Question: Increase of Data Secrecy Concern

Issued by ELECTRONICS AND INFORMATION TECHNOLOGY · Not Applicable

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task

Executive Summary & Key Takeaways

**Executive Summary** The document is an answer to Unstarred Question No. 2776 in Lok Sabha regarding data secrecy concerns after the implementation of the Digital Personal Data Protection Act, 2023. It clarifies that the Act safeguards individual rights while allowing lawful data processing. The Act and Rules, notified on November 13, 2025, establish an 18-month phased implementation period with key milestones. **Key Points / Main Content** *Digital Personal Data Protection Act, 2023 ("Act")* * Provides for processing digital personal data in a manner that recognizes individual rights and lawful data processing needs. * Requires Data Fiduciaries to ensure lawful processing of personal data and outlines obligations for transparency, purpose limitation, data minimization, accuracy, security safeguards, and respect for Data Principals' rights. *Implementation Timeline (as per Act and Digital Personal Data Protection Rules, 2025)* * Phase 1: Establishment and operationalisation of the Data Protection Board of India. * Phase 2 (within one year): Registration and functioning of Consent Managers. * Phase 3 (within eighteen months): Compliance obligations for Data Fiduciaries (including data principal rights, security safeguards, and breach notification). *Data Fiduciary Obligations* * Implement strong security safeguards and erase personal data upon withdrawal of consent (unless legally required). * Adopt appropriate technical and organizational safeguards, such as encryption or masking, to protect personal data and prevent breaches. * Promptly notify affected Data Principals and the Data Protection Board of India in the event of a personal data breach. *Data Protection Board* * The Act envisages the Data Protection Board to address violations of the Act * Can investigate breaches, issue corrective directions, and impose monetary penalties (up to 250 crore). * Penalties are determined based on factors like nature of breach, harm caused, safeguards in place, severity, and recurrence. *Government Initiatives* * Ensuring widespread awareness and adoption of the DPDP Act by educating citizens on their rights and responsibilities. * Undertaking capacity-building initiatives, including workshops, conferences, expert sessions, and digital outreach campaigns. **Impact Analysis** * **Data Fiduciaries** **Impact:** Required to comply with the Act and Rules, implement security safeguards, and notify data breaches. **Action Required:** Implement necessary technical and organizational measures to ensure compliance, develop data breach notification procedures, and prepare for audits by the Data Protection Board. * **Data Principals (Individuals)** **Impact:** Granted rights to protect their personal data and the right to be notified in the event of a personal data breach. **Action Required:** Understand their rights under the Act and monitor how their data is being processed by Data Fiduciaries. * **Public Agencies** **Impact:** Required to ensure transparency in data collection. **Action Required:** Implement measures to ensure transparency in data collection practices and adhere to the requirements of the Act. * **Data Protection Board of India** **Impact:** Central role in enforcing the Act and imposing penalties for violations. **Action Required:** Establish and operationalise the Board, develop procedures for investigating breaches, and define penalty structures.

Key Entities Referenced

Digital Personal Data Protection Act, 2023: The primary legislation discussed, providing for the processing of digital personal data and protecting individual rights. Data Protection Board of India: The regulatory body established under the Digital Personal Data Protection Act, 2023 to address violations and impose penalties. Digital Personal Data Protection Rules, 2025: Rules notified to provide a timeline for phased implementation of the Digital Personal Data Protection Act, 2023. Data Fiduciaries: Entities responsible for ensuring lawful processing of personal data under the Digital Personal Data Protection Act, 2023.
Official Source Record View Original Source →
See Full Document Text
GOVERNMENT OF INDIA MINISTRY OF ELECTRONICS AND INFORMATION TECHNOLOGY LOK SABHA UNSTARRED QUESTION NO. 2776 TO BE ANSWERED ON: 17.12.2025 INCREASE OF DATA SECRECY CONCERN †2776. SHRI UMMEDA RAM BENIWAL: Will the Minister of ELECTRONICS AND INFORMATION TECHNOLOGY be pleased to state: (a) whether data secrecy concerns have increased after the Implementation of new Digital Personal Data Protection Act; (b) if so, the safety measures taken in this regard; and (c) whether the Government has ensured transparency in data collection by the public agencies and if so, the details thereof? ANSWER MINISTER OF STATE FOR ELECTRONICS AND INFORMATION TECHNOLOGY (SHRI JITIN PRASADA) (a) to (c): The Digital Personal Data Protection Act, 2023 (“Act”) provides for the processing of digital personal data in a manner that recognises both the rights of the individual to protect their personal data and the need to process such personal data for lawful purposes. Key features of Act The Act requires all Data Fiduciaries to ensure lawful processing of personal data. It lays down clear obligations relating to transparency, purpose limitation, data minimization, accuracy, security safeguards and respect for the rights of Data Principals. Notification of Act and Rules The Act, and the Digital Personal Data Protection Ru les, 2025 (“Rules”) notified on 13 November, 2025 provide a timeline for phased implementation of its provisions over an eighteen- month transition period, including the establishment of the Data Protection Board. The Rules specify the following implementation timelines: ● Phase 1: Establishment and operationalisation of the Data Protection Board of India ● Phase 2 (within one year): Registration and functioning of Consent Managers ● Phase 3 (within eighteen months): Compliance obligations for Data Fiduciaries including data principal rights, security safeguards and breach notification.It requires Data Fiduciaries to implement strong security safeguards, erase personal data upon withdrawal of consent (unless retention is legally required), and comply within the transition period. The Rules further require Data Fiduciaries to adopt appropriate technical and organizational safeguards, such as encryption or masking, to protect personal data and prevent breaches. The Act envisages the Data Protection Board to address violations of the Act. It can investigate breaches, issue corrective directions, and impose penalties. Penalties are to be determined based on factors like nature of breach, harm caused, safeguards in place, severity and recurrence. In the event of a personal data breach, Data Fiduciaries are required to promptly notify the affected Data Principals and the Data Protection Board of India. Upon receipt of breach intimation, the Data Protection Board may conduct an inquiry and impose monetary penalties in accordance with the Act. The Board is empowered to investigate breaches, issue corrective directions, and impose penalties up to ₹250 crore, taking into account factors like nature of breach, harm caused, safeguards in place, severity and recurrence. The Government is ensuring widespread awareness and adoption of the DPDP Act by educating citizens on their rights and responsibilities. Capacity-building initiatives, including workshops, conferences, expert sessions, and digital outreach campaigns are also being undertaken. *****

Continue your research