<p>India’s rapid digital transformation, driven by over 900 million internet users and vast public–private data ecosystems, necessitates a robust legal framework to govern personal data processing. The Digital Personal Data Protection Act 2023 (DPDP), enacted after the landmark Supreme Court judgment in Puttaswamy, is a foundational step toward recognizing privacy as a fundamental right. This paper critically examines the adequacy of the Act and whether it meets international “gold standards” of data protection, with particular focus on the European Union’s General Data Protection Regulation (GDPR). Utilizing a doctrinal legal methodology, the study analyses statutory provisions, judicial developments, and comparative standards using both primary and secondary sources. While the DPDP introduces key principles such as consent-based processing, individual rights, and the establishment of a Data Protection Board, it lacks several critical components found in the GDPR, including robust enforcement mechanisms, stronger rights for data subjects, and strict limitations on state surveillance and exemptions. As a result, India may fall short of the GDPR’s adequacy criteria under Article 45, which are essential for facilitating seamless cross-border data flows with the EU. In the era of Artificial Intelligence and automated decision-making, where personal data is constantly analysed, shared, and monetized, the need for a comprehensive, rights-centric data protection law becomes even more urgent. Ensuring public trust in AI systems and digital governance frameworks demands alignment with global best practices. This paper concludes with targeted recommendations to strengthen the DPDP and help position India as a privacy-respecting, innovation-friendly jurisdiction in the global digital economy.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Bridging the Gap: Assessing India's Digital Personal Data Protection Act in Light of the EU GDPR

  • Ali Alibeigi

摘要

India’s rapid digital transformation, driven by over 900 million internet users and vast public–private data ecosystems, necessitates a robust legal framework to govern personal data processing. The Digital Personal Data Protection Act 2023 (DPDP), enacted after the landmark Supreme Court judgment in Puttaswamy, is a foundational step toward recognizing privacy as a fundamental right. This paper critically examines the adequacy of the Act and whether it meets international “gold standards” of data protection, with particular focus on the European Union’s General Data Protection Regulation (GDPR). Utilizing a doctrinal legal methodology, the study analyses statutory provisions, judicial developments, and comparative standards using both primary and secondary sources. While the DPDP introduces key principles such as consent-based processing, individual rights, and the establishment of a Data Protection Board, it lacks several critical components found in the GDPR, including robust enforcement mechanisms, stronger rights for data subjects, and strict limitations on state surveillance and exemptions. As a result, India may fall short of the GDPR’s adequacy criteria under Article 45, which are essential for facilitating seamless cross-border data flows with the EU. In the era of Artificial Intelligence and automated decision-making, where personal data is constantly analysed, shared, and monetized, the need for a comprehensive, rights-centric data protection law becomes even more urgent. Ensuring public trust in AI systems and digital governance frameworks demands alignment with global best practices. This paper concludes with targeted recommendations to strengthen the DPDP and help position India as a privacy-respecting, innovation-friendly jurisdiction in the global digital economy.