Back to About the DPDPA
History, Evolution, and Key Policy Shifts
The DPDPA's legislative journey - from the Srikrishna Committee to the 2023 Act, and the key policy shifts across iterations.
8 min read
Justice Srikrishna Committee (2017-2018)
The journey began with the constitution of the Justice B.N. Srikrishna Committee in 2017, following the Puttaswamy judgment. The Committee submitted its report 'A Free and Fair Digital Economy: Protecting Privacy, Empowering Indians' along with a draft Personal Data Protection Bill on July 27, 2018.
The draft Bill was comprehensive, covering both personal and non-personal data, establishing a Data Protection Authority, and proposing data localisation requirements.
Personal Data Protection Bill, 2019
The Government introduced the Personal Data Protection Bill on 11 December 2019 in the Lok Sabha through the Minister of Electronics and IT. It was immediately referred to a Joint Parliamentary Committee (JPC), which conducted extensive deliberations over two years.
The JPC, chaired by P.P. Chaudhary (succeeding Meenakshi Lekhi), submitted its report after 78 sittings and extensive stakeholder consultations on 16 December 2021, with 81 amendments and 12 recommendations. Key JPC additions included provisions on non-personal data, social media intermediaries, and enhanced penalties.
Withdrawal and Fresh Start (2022)
On 3 August 2022, the Government withdrew the 2019 Bill citing the need for a 'comprehensive legal framework' and the significant amendments suggested by the JPC. This was a controversial decision given the years of deliberation invested.
The withdrawal signalled a policy shift towards a simpler, more focused approach to data protection - separating personal data protection from non-personal data governance and digital regulation.
DPDPA 2023 - The Final Act
The Digital Personal Data Protection Bill, 2023 was introduced and passed in August 2023, having been passed by the Lok Sabha on 7 August and the Rajya Sabha on 9 August, with Presidential assent on 11 August 2023. At 44 sections, it was significantly simpler than the 2019 Bill (98 sections).
Key simplifications: removal of non-personal data provisions; adoption of the negative list for cross-border transfers (replacing data localisation); simplified consent framework; removal of social media intermediary provisions; and a single category of personal data.
Key Policy Shifts Across Versions
Major policy shifts include: (a) from comprehensive to focused - the DPDPA covers only digital personal data, not non-personal data; (b) from data localisation to permissive transfers - the negative list replaced mandatory localisation; (c) from complex consent to simplified consent - granular consent requirements were streamlined; (d) from Data Protection Authority to Board - a narrower adjudicatory body replaced the broader regulatory authority; and (e) from criminal penalties to civil penalties - the DPDPA imposes only civil financial penalties.
Related Resources
Frequently Asked Questions
On This Page
Quick ResourcesDisclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.
