In 2023, the Digital Personal Data Protection Act (hereafter to be referred as “DPDP Act”) was passed by the Parliament. The Act passed after questions were raised with regard to the protection of data and its regulation within the Indian territory and the Act was passed to safeguard the private sphere of the citizens and to push through the idea of ‘digital economy’.
In a country like India, data breach has been a concern over decades. The only difference is – that the type of ‘data breach’ has been changing its horizons – from taking criminal dimensions to piracy and unlawful activities across the country.
In response to the growing concern over data-breaches, piracy, online/digital scams and other instances, the Central Government notified the DPDP Draft Rules under the DPDP Act of 2023. The said rules have been released and public opinions/consultation is open for the public at-large to give their suggestions and modifications to the said Rules – which will be finalised accordingly. The Rules have been released after a long period of time, but certain provisions have been made without keeping in mind the consequences, and many experts in the field of data protection law have criticised the same and said that this may be an ‘overreach by the Rules and inconsistent with the provisions of the act.’
Let us now examine the draft Rules in the light of the Act and whether the said Rules are feasible enough to tackle these challenges?

