An independent data protection regulator is essential for meaningful data governance in India.
Q. "An independent data protection regulator is essential for meaningful data governance in India." Examine. (15 marks, 250-350 words)
Independence of a data regulator means insulation of its appointment, tenure and functioning from the Executive — which is itself the country's largest processor of citizen data. With the DPDP Rules, 2025 notified on 14 November 2025 [2], the design of the Data Protection Board of India makes this claim largely valid, though not sufficient by itself.
Why independence is essential - Checking state processing: K.S. Puttaswamy (2017) made privacy a fundamental right under Article 21; a body dependent on the government cannot credibly test state surveillance against necessity and proportionality [1]. - Credible rights enforcement: the Rules give Data Principals rights to access, correct and erase data, and an 18-month phased compliance window for fiduciaries [2] — these are meaningful only if breach complaints are adjudicated impartially. - Expert design: the Justice B.N. Srikrishna Committee (2018) premised India's framework on an autonomous authority; regulatory credibility also underpins investor confidence in the digital economy.
Where the present design falls short - The Data Protection Board is constituted by and answerable to the Central Government — unlike SEBI or TRAI, its structural dependence is a key ground of challenge [1]. - Section 44(3) amended Section 8(1)(j) of the RTI Act, 2005, removing the express public-interest override; an executive-linked Board then effectively arbitrates transparency claims [1]. - In March 2026, a three-judge Bench headed by CJI Surya Kant issued notice to the Union on a petition by journalist Geeta Seshu and SFLC, agreeing to examine what constitutes "personal" versus "public" data [1].
But independence alone is not enough - The Government maintains the amendment codifies the Puttaswamy balance, with Section 8(2) of the RTI Act still permitting public-interest access [3]. - Statutory clarity of definitions, adjudicatory capacity and consultative rule-making — the draft Rules drew 6,915 public inputs [4] — matter equally.
Meaningful data governance thus rests on twin pillars: an autonomous regulator and precise, rights-respecting definitions. Securing tenure and funding of the Board, and restoring a calibrated public-interest test, would let privacy and transparency reinforce rather than cancel each other — the balance Puttaswamy itself envisaged.
(~330 words)
Sources: 1. "SC to study what constitutes 'personal data' in DPDP laws" — The Hindu, 13 March 2026 (no verified link available) — SC notice, Board's executive dependence, Section 44(3) and RTI dilution 2. Government notifies DPDP Rules to empower citizens and protect privacy — PIB — 14 November 2025 notification, Data Principal rights, 18-month phased compliance 3. DPDP Act, 2023 Upholds Privacy While Preserving Transparency Under RTI — PIB — Government's position on the RTI amendment and Section 8(2) 4. Draft DPDP Rules, 2025 Receive 6,915 Inputs from Citizens and Stakeholders — PIB — scale of public consultation