Abstract
India is about to lose the only real protection its law gives to health and biometric information and almost no one has noticed. The old law, the Information Technology Act, 2000 and its 2011 Rules, treats medical and biometric data as “sensitive personal data” that deserves extra care, and a Bill drafted in 2019 would have gone further and named genetic data itself as protected. But the Parliament passed, the Digital Personal Data Protection Act, 2023, which threw that special category out. When its main provisions take effect on 13 May 2027, it repeals Section 43A of the older Act and puts nothing in its place. So, in two consecutive years India did two contradictory things: it built the tools to collect genetic material on a large scale, through the Criminal Procedure (Identification) Act, 2022 and the Genome India Project, while tearing down the legal protection for it. Drawing on the long-running debate about “genetic exceptionalism”, on how Europe, the United States and Britain handle the problem, and on the collapse and sale of the DNA-testing company 23andMe, this paper makes a simple argument: genetic data is genuinely different from ordinary personal data in three ways, Indian law no longer reflects that difference, and the chance to fix it runs out on that date. It ends with eight practical reforms, several of which need no change to the main law at all.