Data protection regulation in India has been undertaken through a patchwork of national and sectoral regulations over the past two decades. However, in 2023, with the enactment of the Digital Personal Data Protection Act (DPDPA), India now has a comprehensive, horizontally applicable data protection law. From an operational perspective, a number of granular compliance requirements under the law are expected to be finalised through delegated legislation in the form of rules and notifications. Additionally, the DPDPA's scope of applicability is restricted to compliances around processing of personal data. The larger data governance framework in India is also likely to delve into complexities around non-personal data such as anonymisation and other technical interventions which enable deidentification of personal data.
In this larger context, the aim of this report is to examine the future roadmap for implementation of the overarching data protection framework in India, after the enactment of the Digital Personal Data Protection, 2023.
Part I of the report delves into three focus areas which hold priority from an implementation and compliance perspective for data fiduciaries and other stakeholders in the ecosystem; reporting and managing personal data breaches, the functioning of consent managers, and regulatory certainty around cross-border data flows.
Part II of the report takes a futuristic and holistic perspective to data protection regulations and examines the nuances of anonymised data. The intended objective of Part II of the report is to set the context for India to explore its regulatory approach and standards around anonymisation of personal data.