- Digital Personal Data Protection Act, 2023 (DPDP Act): Provides a legal framework for processing digital personal data in India.
- Objective: Balances individuals’ right to protect personal data with the lawful processing of such data.
- Data Principal: The individual to whom the personal data relates.
- Data Fiduciary: The person/entity that determines the purpose and means of processing personal data.
- Consent: The Act provides a framework for processing personal data based on consent, subject to specified provisions.
- Data security: Data Fiduciaries are required to take reasonable security safeguards to prevent personal-data breaches.
- RTI interface: The law has raised concerns about its possible implications for the Right to Information Act, 2005, particularly regarding access to personal information.
- Key issue: The major governance challenge is balancing privacy with transparency and accountability.
UPSC Prelims Practice Question
Q. With reference to the Digital Personal Data Protection Act, 2023, consider the following statements:
- It deals with the processing of digital personal data.
- An individual to whom personal data relates is called the Data Principal.
- An entity determining the purpose and means of processing personal data is called the Data Fiduciary.
- The Act completely prohibits the processing of personal data without the consent of the Data Principal.
Which of the statements given above is/are correct?
A. 1, 2 and 3 only
B. 1 and 4 only
C. 2, 3 and 4 only
D. 1, 2, 3 and 4
Answer: A. 1, 2 and 3 only
Explanation: The Act provides for circumstances in which personal data may be processed without consent, subject to its provisions. Therefore, Statement 4 is incorrect.



