India’s Data Protection Regime: Weak Enforcement & Government Overreach

On January 5, 2025, almost two years after the promulgation of the Digital Personal Data Protection Act, 2023 (DPDPA), the Ministry of Electronics and Information Technology (MeitY) published a draft of the Digital Personal Data Protection Rules (DPDPR). The Ministry is inviting public comments/feedback until March 5, 2025.

While the DPDPR aims to clarify and strengthen the DPDPA, concerns persist regarding its enforcement mechanisms, the independence of the Data Protection Board (DPB), and its ability to uphold user rights. This blog post will specifically delve into irregularities afflicting the establishment of the DPB and compare the DPDPR with the European Union’s General Data Protection Regulation (GDPR), which is widely regarded as the gold standard for data protection.

The DPB has been one of the most awaited innovations of the DPDPA. With the accumulation of data assuming increasing importance, the capability of its misuse rises with every passing day. In this context, the establishment of the DPB cements the enforcement of a much-needed data protection law. However, what the DPDPA (and the DPDPR) presents to us is a body that cannot independently conduct regulatory oversight and can lead to more harm being caused to users’ rights than before.

One of the most significant flaws in the DPDPA is the structure of the DPB, the regulatory body responsible for its enforcement. Unlike the GDPR’s independent Data Protection Authorities (DPAs), a requirement that is explicitly mentioned under Article 52, the DPB is a Central Government-appointed and controlled body. DPAs may have their flaws, but they are financially and institutionally independent and retain the ability to penalise both private companies and government entities. For instance, the Dutch DPA imposed a fine of 30.5 million euros on Clearview AI for building an illegal database that has billions of photos of faces. In a separate case, the Irish DPA fined Meta a whopping 251 million euros following an investigation into a data breach.

In contrast, Rule 16 of the DPDPR requires the Central Government to constitute a Search-cum-Selection Committee, with the Cabinet Secretary at its helm, along with Secretaries to the Government of India in charge of the Department of Legal Affairs, and the Ministry of Electronics and Information Technology, in addition to two experts of repute having special knowledge or practical experience in the relevant field. Rule 16(4), in particular, shields the decisions of the Search-cum-Selection by stipulating that it cannot be called into question on grounds such as vacancies, absences, or defects in its constitution. The provision remains vague on whether situations exist for which the said Committee can be scrutinised.

Moreover, an indication of immense power in the hands of the Central Government over the functioning of the DPB can be found in Rule 20 of the DPDPR. This rule states that the Central Government holds the power to “specify, appoint such officers and employees as it may deem necessary for the efficient discharge of its functions under the provisions of Act”. This influence speaks volumes about the ability of the DPB to act impartially and independently.  

Coupled with organisational issues, other issues afflict the DPB as well and find their place, or lack thereof, in the DPDPA or DPDPR. These include the inability of the DPB to act upon complaints and conduct independent audits of companies and government agencies. Further, though the DPB is empowered to impose fines, the enforcement mechanisms remain unclear due to a lack of clarity pertaining to, amongst other things, situations which involve non-compliance on the part of entities. Further, unlike the DPAs under GDPR, they cannot suspend data processing activities if violations pose a risk to fundamental rights. 

In the absence of sufficient safeguards or requirements for independent functioning, serious concerns are raised regarding the lack of autonomy, potential for biased enforcement, and opaque governance. It is pertinent to remember that the government itself is a major data processor (through Aadhaar, DigiLocker, etc.), and controlling appointments of the DPB may lead to situations where there is a conflict of interest, and the DPB finds itself being reluctant to penalise state agencies for data breaches.

A compromised DPB can also negatively affect the EU in several ways, particularly in terms of data privacy and cross-border data flow. Businesses in the EU may need to invest more resources in ensuring that data processing activities in India meet GDPR standards. This could involve additional audits, legal advice, and technological measures, all of which could increase operational costs.

EU businesses could also be exposed to greater legal risks due to dangers posed by India’s weak enforcement. They could face legal action from data subjects or regulatory bodies in the EU if it is found that they are not meeting the GDPR’s stringent requirements for data protection, even if they are processing data in India. This could also spell trouble for India, given the EU’s track record concerning strict requirements for adequacy decisions regarding third-country data transfers. In 2020, the Court of Justice of the European Union invalidated the EU-US Privacy Shield on account of the US not providing proper safeguards to protect the data of EU citizens.

An unaccountable DPB may lead to weaker enforcement of data protection laws in India, increasing the risk of data breaches and misuse. EU businesses could face reputational damage, lawsuits, or penalties under GDPR if customer or employee data is mishandled due to inadequate data protection in India. This is particularly concerning for businesses with large-scale data operations or sensitive data transfers to India. 

Certain amendments to the DPDPR are necessary to ensure that the DPB operates independently and effectively. First and foremost, the DPB must function as an independent statutory body rather than one controlled by the Central Government. Its finances need to be independent of executive control, and members of the DPB should be appointed through a process ideally overseen by the judiciary. Similarly, Rule 16 of the DPDPR should also be revised to ensure that the Search-cum-Selection Committee is not overwhelmingly comprised of persons from the Central Government and should include experts, both legal and technical, from the industry, judiciary, and civil society organisations.

It is also important to strengthen the powers of the DPB to prevent it from assuming the position of a “sitting duck”. In order to do so, the DPB should be empowered to impose fines on both private and public entities. Moreover, similar to the DPAs under GDPR, DPBs should possess the power to conduct independent audits of companies and government entities. For the sake of accountability, the DPB should be mandated to publish periodic reports detailing enforcement actions, fines imposed, and its decisions.

Though the DPDPR ushers in a new era of change in the Indian digital landscape, it is not devoid of challenges that need to be addressed if data protection is to be achieved. In particular, an independent DPB is essential for maintaining trust, compliance, and in the context of EU and India, the security of data exchanges. Without it, not only are data principals left up the creek without a paddle when faced with big corporations, it could also lead to businesses, especially those in the EU, facing higher costs, legal risks, operational challenges, and potential disruptions in their relationships with Indian partners and markets.