Abstract
The Digital Personal Data Protection Act, 2023, marks the first-ever attempt at regulating the collection, processing, and protection of personal data in a progressively digital society in India. This law is based on the constitutional principles set out by the Supreme Court of India in K.S. Puttaswamy v. Union of India and seeks to operationalise the right to privacy through a legislative framework. The law ensures certain protections, including consent-based processing, greater rights granted to Data Principals, and stronger accountability mechanisms for major data fiduciaries. However, despite these positive changes, the law comes with certain constitutional and institutional problems. The overly expansive exceptions to government action in Section 17, liberal rules governing data transfer outside of India, and lack of clarity about the board’s independence are some examples. As one evaluates the Act, there is both reason to be optimistic and wary. The reasons to be optimistic include the fact that India has finally put a comprehensive data protection law on its statute books; however, reasons to be wary include the fact that some of the most critical provisions of the law may end up infringing upon people's privacy rights.