Privacy on the internet encompasses the right of individuals to control their personal information in the digital environment. Data protection is the legal framework governing how personal data is collected, processed, stored, and shared. The right to privacy is a fundamental right under Art.21 (post-Puttaswamy, 2017).
Legal Framework
| Provision | Subject |
|---|---|
| Art.21 Constitution | Right to life and personal liberty (includes privacy: Puttaswamy) |
| IT Act S.43A | Body corporate: reasonable security practices for sensitive personal data |
| IT Act S.66E | Violation of privacy (publishing private images) |
| IT Act S.69 | Government power: interception/monitoring/decryption |
| IT Act S.69A | Power to block websites (privacy vs. state interest) |
| IT Act S.72 | Breach of confidentiality (information obtained under IT Act) |
| IT Act S.72A | Disclosure of personal information in breach of contract |
| DPDP Act 2023 | Comprehensive data protection framework |
| IT (SPDI) Rules 2011 | Sensitive personal data: body corporate obligations (still operative until DPDP rules notified) |
Right to Privacy as Fundamental Right
Puttaswamy Framework (2017)
| Principle | Content |
|---|---|
| Status | Privacy is intrinsic part of Art.21 (life, liberty, dignity) |
| Components | (1) Bodily privacy, (2) Informational privacy, (3) Privacy of choice |
| Not absolute | Subject to reasonable restrictions |
| Triple test | Any interference must satisfy: (a) Legality (prescribed by law), (b) Legitimate aim (state interest), (c) Proportionality (means proportionate to aim) |
| Overrules | MP Sharma (1954) and Kharak Singh (1963) minority view: privacy IS a fundamental right |
Why: In the digital age, informational privacy (control over personal data) is the most threatened dimension. Every online transaction generates data that can be aggregated, profiled, and misused. Constitutional protection ensures state and private actors cannot violate data privacy without legal basis, legitimate purpose, and proportionate means.
Illustration: DPDP Act in Everyday Life
Scenario: You download a food delivery app. During signup, it asks for: name, phone, address, location access.
| What App Does | DPDP Act Position | |:--|:--|:--| | Uses your address to deliver food | Lawful (purpose you consented to) | | Uses your location to show nearby restaurants | Lawful (necessary for stated purpose) | | Shares your phone number with insurance companies for cold-calling | Unlawful purpose limitation violated (S.5); you consented for food delivery, not insurance marketing | | Stores your data for 5 years after you delete your account | Unlawful storage limitation violated; data must be erased when purpose no longer served | | You request deletion of your account + all data | Your right to erasure (S.12); app must comply unless retention is required by law (e.g., tax records) | | App suffers a data breach exposing 1 lakh users' details | App must notify Data Protection Board + affected users (S.8(6)); failure → up to Rs.250 crore penalty |
Key takeaway: Every time you share data with an app/website, ask: "What did I consent to?" If the entity uses data beyond that purpose → DPDP violation.
Digital Personal Data Protection Act, 2023
Key Concepts
| Term | Meaning |
|---|---|
| Data Principal | Individual whose data is collected (equivalent to "data subject" in GDPR) |
| Data Fiduciary | Entity that determines purpose and means of processing (equivalent to "data controller") |
| Significant Data Fiduciary (SDF) | High-risk fiduciary designated by government (additional obligations) |
| Consent Manager | Registered entity facilitating consent management for Data Principals |
| Data Processor | Entity processing data on behalf of Data Fiduciary |
| Personal Data | Any data about an individual identifiable by or in relation to such data |
| Data Protection Board of India | Adjudicatory body for complaints and breaches |
Principles
| Principle | Content |
|---|---|
| Consent-based processing | Data processed only with free, specific, informed, clear consent (S.6) |
| Purpose limitation | Data collected only for specified, lawful purpose (S.5) |
| Data minimization | Only data necessary for stated purpose collected |
| Storage limitation | Data retained only as long as necessary for purpose |
| Accuracy | Data Fiduciary must ensure data is accurate and complete |
| Security | Reasonable security safeguards to prevent breach (S.8) |
| Accountability | Fiduciary responsible for compliance; must demonstrate compliance |
Rights of Data Principal (S.11-14)
| Right | Content |
|---|---|
| Right to access | Know what data is being processed and how |
| Right to correction and erasure | Correct inaccurate data; erase data no longer necessary |
| Right to grievance redressal | Complain to Data Fiduciary and Data Protection Board |
| Right to nominate | Nominate person to exercise rights in case of death/incapacity |
Obligations of Data Fiduciary (S.8-10)
| Obligation | Content |
|---|---|
| Obtain valid consent (S.6) | Before or at time of collection |
| Give notice (S.5) | Inform Data Principal of: data collected, purpose, rights, grievance mechanism |
| Implement security safeguards (S.8) | Reasonable security to prevent breach |
| Report breaches (S.8(6)) | Notify Data Protection Board and affected Data Principals |
| Erase on request (S.12) | Unless retention required by law |
| Additional for SDF (S.10) | Data Protection Impact Assessment, DPO appointment, independent audit |
Penalties
| Contravention | Maximum Penalty |
|---|---|
| Failure to take security safeguards leading to breach | Rs.250 crores |
| Failure to notify breach | Rs.200 crores |
| Non-compliance with children's data provisions | Rs.200 crores |
| Non-compliance with additional SDF obligations | Rs.150 crores |
| Non-compliance by Data Principal (false complaints, etc.) | Rs.10,000 |
| Any other contravention | Rs.50 crores |
Violations of Privacy on Internet
| Type of Violation | Description | Provision |
|---|---|---|
| Unauthorized surveillance | Monitoring online activity without consent or legal authority | Art.21 (Puttaswamy triple test) + S.69 IT Act (lawful interception) |
| Data breach | Unauthorized access to personal data stored by organizations | S.43A IT Act + DPDP Act S.8 |
| Voyeurism | Capturing/publishing intimate images without consent | S.66E IT Act (3 years + Rs.2 lakhs) |
| Doxing | Publishing personal information (address, phone) online without consent | S.72A IT Act + tort of invasion of privacy |
| Profiling | Automated processing to evaluate personal aspects (behavior, preferences) | DPDP Act: requires consent + purpose limitation |
| Dark patterns | Deceptive UI design to trick users into sharing more data | DPDP Act + Consumer Protection Act |
| Cookie tracking | Monitoring browsing behavior through persistent cookies | DPDP Act consent requirements |
Recall Check
- What is the triple test for interference with privacy under Puttaswamy?
- What is the maximum penalty under DPDP Act for failure to prevent a data breach?
- What is the difference between Data Fiduciary and Data Processor?
Key Cases
KS Puttaswamy v. Union of India (2017) KS-Puttaswamy-v-Union-of-India-2017 Issue: Whether the right to privacy is a fundamental right under the Constitution of India. Rule: Privacy is an intrinsic part of the right to life and personal liberty under Art.21; includes informational privacy, bodily privacy, and privacy of choice; subject to proportionality test. Held: 9-judge bench unanimously declared privacy a fundamental right. Triple test established: legality, legitimate aim, proportionality. Foundation for all subsequent data protection legislation.
KS Puttaswamy v. Union of India (Aadhaar) (2018) KS-Puttaswamy-v-Union-of-India-Aadhaar-2018 Issue: Whether the Aadhaar scheme (biometric identification linked to services) violates the right to privacy. Rule: State surveillance/data collection must pass proportionality test; purpose limitation and data minimization are constitutional requirements; linking Aadhaar to bank accounts/PAN is proportionate but linking to school admission/mobile numbers is disproportionate. Held: Supreme Court (4:1) upheld Aadhaar's constitutional validity but struck down: S.57 (use by private entities), mandatory linking to bank accounts for non-welfare purposes, and mandatory mobile linking. Proportionality applied section by section.
Distinctions
| Aspect | IT Act S.43A (Pre-DPDP) | DPDP Act, 2023 |
|---|---|---|
| Scope | Only body corporates handling sensitive personal data | All Data Fiduciaries processing digital personal data |
| Trigger | Negligence in security practices causing wrongful loss | Any non-compliance with data protection principles |
| Penalty | Compensation (determined by Adjudicating Officer) | Up to Rs.250 crores per breach |
| Rights | No explicit data principal rights | Comprehensive rights (access, correction, erasure, grievance) |
| Consent framework | Reasonable security practices + privacy policy | Specific, informed, free consent; consent managers |
| Regulator | Adjudicating Officer (IT Act) | Data Protection Board of India |
| Applicability | Sensitive personal data only | All personal data (digital) |
| Extra-territorial | Not explicit | Applies to processing outside India if offering goods/services to Indians |
Flashcards
Q: What are the three components of the right to privacy (Puttaswamy)? A: (1) Bodily privacy (physical integrity), (2) Informational privacy (control over personal data), (3) Privacy of choice (autonomy in personal decisions).
Q: What is the maximum penalty under DPDP Act for security breach? A: Rs.250 crores.
Q: What is a Data Fiduciary under DPDP Act? A: Any person who alone or in conjunction with other persons determines the purpose and means of processing personal data.
Q: What is the triple test for privacy interference (Puttaswamy)? A: (1) Legality: interference prescribed by law, (2) Legitimate aim: serves a state interest, (3) Proportionality: means used are proportionate to the aim pursued.
Q: What is S.66E IT Act? A: Violation of privacy: intentionally capturing, publishing, or transmitting the image of a private area of any person without consent. Punishment: 3 years + Rs.2 lakhs.
Q: What did the Aadhaar judgment (2018) strike down? A: S.57 Aadhaar Act (use by private entities), mandatory linking to bank accounts for non-welfare schemes, and mandatory mobile number linking. Found disproportionate.
Q: What are the rights of a Data Principal under DPDP Act 2023? A: Right to access information about processing, right to correction and erasure, right to grievance redressal, right to nominate (in case of death/incapacity).
Q: What is a Significant Data Fiduciary (SDF)? A: A Data Fiduciary designated by government based on volume/sensitivity of data processed; subject to additional obligations: Data Protection Impact Assessment, Data Protection Officer appointment, independent audit.
Exam Scenario
A social media company collects detailed user data (location, browsing history, contacts) and shares it with advertisers without explicit user consent. A user discovers this and files a complaint. Advise on rights and remedies under the DPDP Act 2023.
Under DPDP Act 2023: (1) The social media company is a Data Fiduciary (determines purpose/means of processing). (2) Sharing data with advertisers without consent violates S.6 (consent-based processing) and S.5 (purpose limitation: data collected for social media use, not advertising). (3) User's rights: Right to access (S.11): demand disclosure of what data is shared and with whom. Right to erasure (S.12): demand deletion of data shared with advertisers. Right to grievance redressal (S.13): complain to the company's grievance officer; if unresolved, escalate to Data Protection Board. (4) Penalty: Up to Rs.250 crores if security safeguards inadequate; up to Rs.50 crores for general non-compliance with consent/purpose requirements. (5) Additionally: if the sharing caused wrongful loss, S.43A IT Act (compensation for negligent security practices). (6) Constitutional claim: violation of Art.21 right to informational privacy (Puttaswamy): collection beyond stated purpose fails proportionality test. The user has strong grounds for both regulatory complaint and civil action.