The Constitutional Enigma of India's Digital Personal Data Protection Act, 2023: Structural Exigency, State Exemptions, and the Dilution of Transparency
Abstract
The enactment of the Digital Personal Data Protection (DPDP) Act, 2023, marks a paradigm shift in India's evolving digital jurisprudence, ostensibly codifying the fundamental right to informational privacy recognized in Justice K.S. Puttaswamy v. Union of India. However, beneath its streamlined, twenty-six-section framework lies a complex matrix of constitutional and structural contradictions. This article provides a comprehensive evaluation of the DPDP Act, focusing on three systemic regulatory vulnerabilities. First, it critiques the "skeletal" architecture of the statute, which relies on excessive executive delegation that leaves critical compliance, localization, and operational parameters to future, unchecked rule-making. Second, it scrutinizes the extensive state exemptions under Section 17(2), evaluating their compliance with the constitutional standards of necessity and proportionality. Third, it examines the structural dependence of the Data Protection Board of India (DPBI) on executive oversight, which compromises its efficacy as an impartial regulator. Finally, the article analyzes the amendment to Section 8(1)(j) of the Right to Information (RTI) Act, 2005, arguing that the absolute restriction on personal data access threatens democratic accountability. By comparing these provisions with the European Union’s General Data Protection Regulation (GDPR), this paper demonstrates how the DPDP Act prioritizes state convenience over individual rights, transforming the right to privacy into an executive concession.