Data Protection Compliance Challenges Under the Digital Personal Data Protection Act, 2023

Authors

  • Giriraj Sharma Author

Keywords:

Digital Personal Data Protection Act, 2023, Data Protection, Privacy, Data Fiduciary, Consent, Compliance, Data Principal, Cross-Border Data Transfer

Abstract

India's transition to a data-driven economy has made the governance of personal information a matter of significant legal and commercial consequence. The Digital Personal Data Protection Act, 2023 (“DPDPA”), enacted following the Supreme Court's recognition of informational privacy as an incident of the fundamental right to life and personal liberty, represents India's first comprehensive, cross-sectoral data protection statute. This paper examines the extent to which the DPDPA furnishes a workable compliance framework for organisations operating in India, particularly following the notification of the Digital Personal Data Protection Rules, 2025 and the staggered commencement schedule running through May 2027. Adopting a doctrinal methodology grounded in the statute, subordinate rules, constitutional jurisprudence and contemporaneous regulatory material, the paper identifies eleven interlocking compliance challenges: regulatory ambiguity pending further guidance, the operational difficulty of meaningful consent at scale, data mapping across complex organisational architectures, the indeterminacy of “reasonable security safeguards,” the practical vindication of Data Principal rights, age verification for children's data, uncertainty surrounding Significant Data Fiduciary classification, third-party and vendor risk, cross-border transfer mechanics, disproportionate cost burdens on smaller entities, and the adequacy of the Data Protection Board's enforcement architecture. A comparative analysis with the European Union's General Data Protection Regulation situates these challenges within a broader regulatory context. The paper concludes that while the DPDPA establishes a coherent principled architecture, its effective operation remains substantially dependent on subordinate rule-making, institutional capacity-building within the Data Protection Board, and sector-specific guidance, without which the promise of workable compliance risks remaining only partially realised.

Downloads

Published

2026-09-23

Issue

Section

Articles

How to Cite

Data Protection Compliance Challenges Under the Digital Personal Data Protection Act, 2023. (2026). International Journal of Contemporary Multidisciplinary Studies and Innovation, 1(1), 17-32. https://ijcmsi.com/index.php/ijcmsi/article/view/3