**Executive Summary**
The document is an answer to Unstarred Question No. 2776 in Lok Sabha regarding data secrecy concerns after the implementation of the Digital Personal Data Protection Act, 2023. It clarifies that the Act safeguards individual rights while allowing lawful data processing. The Act and Rules, notified on November 13, 2025, establish an 18-month phased implementation period with key milestones.
**Key Points / Main Content**
*Digital Personal Data Protection Act, 2023 ("Act")*
* Provides for processing digital personal data in a manner that recognizes individual rights and lawful data processing needs.
* Requires Data Fiduciaries to ensure lawful processing of personal data and outlines obligations for transparency, purpose limitation, data minimization, accuracy, security safeguards, and respect for Data Principals' rights.
*Implementation Timeline (as per Act and Digital Personal Data Protection Rules, 2025)*
* Phase 1: Establishment and operationalisation of the Data Protection Board of India.
* Phase 2 (within one year): Registration and functioning of Consent Managers.
* Phase 3 (within eighteen months): Compliance obligations for Data Fiduciaries (including data principal rights, security safeguards, and breach notification).
*Data Fiduciary Obligations*
* Implement strong security safeguards and erase personal data upon withdrawal of consent (unless legally required).
* Adopt appropriate technical and organizational safeguards, such as encryption or masking, to protect personal data and prevent breaches.
* Promptly notify affected Data Principals and the Data Protection Board of India in the event of a personal data breach.
*Data Protection Board*
* The Act envisages the Data Protection Board to address violations of the Act
* Can investigate breaches, issue corrective directions, and impose monetary penalties (up to 250 crore).
* Penalties are determined based on factors like nature of breach, harm caused, safeguards in place, severity, and recurrence.
*Government Initiatives*
* Ensuring widespread awareness and adoption of the DPDP Act by educating citizens on their rights and responsibilities.
* Undertaking capacity-building initiatives, including workshops, conferences, expert sessions, and digital outreach campaigns.
**Impact Analysis**
* **Data Fiduciaries**
**Impact:** Required to comply with the Act and Rules, implement security safeguards, and notify data breaches.
**Action Required:** Implement necessary technical and organizational measures to ensure compliance, develop data breach notification procedures, and prepare for audits by the Data Protection Board.
* **Data Principals (Individuals)**
**Impact:** Granted rights to protect their personal data and the right to be notified in the event of a personal data breach.
**Action Required:** Understand their rights under the Act and monitor how their data is being processed by Data Fiduciaries.
* **Public Agencies**
**Impact:** Required to ensure transparency in data collection.
**Action Required:** Implement measures to ensure transparency in data collection practices and adhere to the requirements of the Act.
* **Data Protection Board of India**
**Impact:** Central role in enforcing the Act and imposing penalties for violations.
**Action Required:** Establish and operationalise the Board, develop procedures for investigating breaches, and define penalty structures.
Key Entities Referenced
Digital Personal Data Protection Act, 2023: The primary legislation discussed, providing for the processing of digital personal data and protecting individual rights.
Data Protection Board of India: The regulatory body established under the Digital Personal Data Protection Act, 2023 to address violations and impose penalties.
Digital Personal Data Protection Rules, 2025: Rules notified to provide a timeline for phased implementation of the Digital Personal Data Protection Act, 2023.
Data Fiduciaries: Entities responsible for ensuring lawful processing of personal data under the Digital Personal Data Protection Act, 2023.
GOVERNMENT OF INDIA
MINISTRY OF ELECTRONICS AND INFORMATION TECHNOLOGY
LOK SABHA
UNSTARRED QUESTION NO. 2776
TO BE ANSWERED ON: 17.12.2025
INCREASE OF DATA SECRECY CONCERN
†2776. SHRI UMMEDA RAM BENIWAL:
Will the Minister of ELECTRONICS AND INFORMATION TECHNOLOGY be pleased to state:
(a) whether data secrecy concerns have increased after the Implementation of new Digital Personal Data
Protection Act;
(b) if so, the safety measures taken in this regard; and
(c) whether the Government has ensured transparency in data collection by the public agencies and if
so, the details thereof?
ANSWER
MINISTER OF STATE FOR ELECTRONICS AND INFORMATION TECHNOLOGY
(SHRI JITIN PRASADA)
(a) to (c): The Digital Personal Data Protection Act, 2023 (“Act”) provides for the processing of
digital personal data in a manner that recognises both the rights of the individual to protect their
personal data and the need to process such personal data for lawful purposes.
Key features of Act
The Act requires all Data Fiduciaries to ensure lawful processing of personal data. It lays down
clear obligations relating to transparency, purpose limitation, data minimization, accuracy, security
safeguards and respect for the rights of Data Principals.
Notification of Act and Rules
The Act, and the Digital Personal Data Protection Ru les, 2025 (“Rules”) notified on 13
November, 2025 provide a timeline for phased implementation of its provisions over an eighteen-
month transition period, including the establishment of the Data Protection Board. The Rules
specify the following implementation timelines:
● Phase 1: Establishment and operationalisation of the Data Protection Board of India
● Phase 2 (within one year): Registration and functioning of Consent Managers
● Phase 3 (within eighteen months): Compliance obligations for Data Fiduciaries including data
principal rights, security safeguards and breach notification.It requires Data Fiduciaries to implement strong security safeguards, erase personal data upon
withdrawal of consent (unless retention is legally required), and comply within the transition
period.
The Rules further require Data Fiduciaries to adopt appropriate technical and organizational
safeguards, such as encryption or masking, to protect personal data and prevent breaches.
The Act envisages the Data Protection Board to address violations of the Act. It can investigate
breaches, issue corrective directions, and impose penalties. Penalties are to be determined based
on factors like nature of breach, harm caused, safeguards in place, severity and recurrence.
In the event of a personal data breach, Data Fiduciaries are required to promptly notify the affected
Data Principals and the Data Protection Board of India. Upon receipt of breach intimation, the
Data Protection Board may conduct an inquiry and impose monetary penalties in accordance with
the Act.
The Board is empowered to investigate breaches, issue corrective directions, and impose penalties
up to ₹250 crore, taking into account factors like nature of breach, harm caused, safeguards in
place, severity and recurrence.
The Government is ensuring widespread awareness and adoption of the DPDP Act by educating
citizens on their rights and responsibilities. Capacity-building initiatives, including workshops,
conferences, expert sessions, and digital outreach campaigns are also being undertaken.
*****