India’s new Digital Personal Data Protection Act establishes a comprehensive framework for handling personal data, granting individuals significant control over their information while defining strict obligations for companies. Fiduciaries must obtain clear consent, ensure data security, and provide mechanisms for users to access, correct, or delete their data. This shift aims to empower citizens in the digital realm, balancing individual rights with the operational needs of businesses operating within the country’s growing digital economy. However, the legislation introduces substantial government powers that raise concerns regarding privacy and transparency. The state retains broad authority to exempt entities, including government agencies, from compliance and to block content or access data for security and sovereignty reasons. These provisions have drawn criticism from digital rights advocates and journalists, who argue that the law prioritizes data processing over privacy protection and potentially dilutes the Right to Information by enabling surveillance without meaningful safeguards. This article is highly relevant to open data advocates because it sets the legal boundaries for data accessibility and accountability in India. The act’s exemption for government entities and its limitations on the Right to Information create a complex environment where open data initiatives must navigate significant state-level restrictions. Understanding these legal constraints is crucial for anyone attempting to promote transparency or utilize public data, as the law’s broad surveillance powers may impede efforts to maintain an open and accountable information ecosystem.
Source: telecom.economictimes.indiatimes.comPublished on 2023-08-14