·PIB

International Data Privacy Day

In this note
  1. At a Glance
  2. Why in the News
  3. Background & Evolution
  4. Core Static Facts
  5. Multi-Dimensional Analysis
  6. Recent Developments (last 12-18 months)
  7. Prelims Hooks
  8. Mains Relevance
  9. Related Topics to Study Next
  10. Common Errors / Trap Areas
Practice
8 questions on this item
Check the answer for each question, or reveal all at once.
Practice MCQs →

1. At a Glance

  • International Data Privacy Day (Data Protection Day) observed annually on 28 January to raise public awareness on protection of personal data in the digital age [1].
  • Designated in 2006 by the Council of Europe to mark the signing of Convention 108 — the world's first legally binding international treaty on data protection [1].
  • For UPSC, the day is a hook for GS-II (rights, governance) and GS-III (cyber security, digital economy) — anchoring India's DPDP Act, 2023 and DPDP Rules, 2025 regime [1][2].

2. Why in the News

  • PIB Backgrounder (27 Jan 2026) released ahead of Data Privacy Day 2026 highlighting India as the 3rd-largest digitalised economy and reaffirming the citizen-centric DPDP framework [1].
  • DPDP Rules, 2025 notified on 14 November 2025 by MeitY, operationalising the DPDP Act, 2023 with an 18-month phased compliance timeline [2].
  • Union Budget 2025–26 earmarked ₹782 crore for cybersecurity to safeguard Digital Public Infrastructure (DPI) [1].

3. Background & Evolution

  • 1981: Council of Europe opens Convention 108 for signature — first binding data-protection treaty [1].
  • 2006: Council of Europe designates 28 January as Data Protection Day; later adopted globally as Data Privacy Day [1].
  • 2017: Justice K.S. Puttaswamy v. Union of India — Supreme Court declares Right to Privacy a fundamental right under Article 21 [1].
  • 2023 (11 August): Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) enacted by Parliament [3].
  • Jan 2025: Draft DPDP Rules released; 6,915 inputs received from citizens/stakeholders during consultation [4].
  • 14 Nov 2025: DPDP Rules, 2025 notified, fully operationalising the Act [2].

4. Core Static Facts

  • Observance date: 28 January (annually) [1].
  • Originating body: Council of Europe (2006); rooted in Convention 108 (1981) [1].
  • Nodal ministry (India): Ministry of Electronics and Information Technology (MeitY) [3].
  • Statutory framework: DPDP Act, 2023 + DPDP Rules, 2025 [2][3].
  • Design philosophy: SARAL — Simple, Accessible, Rational, Actionable [2].
  • Seven core principles: consent & transparency, purpose limitation, data minimisation, accuracy, storage limitation, security safeguards, accountability [2].
  • Regulator: Data Protection Board of India (DPBI) — fully digital institution; appeals to TDSAT (Telecom Disputes Settlement and Appellate Tribunal) [2].
  • Cybersecurity allocation: ₹782 crore (Budget 2025–26) [1].
  • India's digital economy rank: 3rd largest globally [1].

5. Multi-Dimensional Analysis

Legal / Constitutional

  • Operationalises Article 21 right to privacy per Puttaswamy (2017) via statutory backing [1].
  • DPDP Act balances privacy with RTI's transparency mandate [2].

Scientific / Technological

  • DPBI built as a fully digital, paperless body with online filing & mobile app for grievance tracking [2].
  • Phased 18-month compliance window for Data Fiduciaries to upgrade systems [2].

Social

  • Verifiable consent mandatory before processing children's data; carve-outs only for healthcare, education, real-time safety [2].
  • Standalone, plain-language consent notices for citizen comprehension [2].

Economic

  • Underpins trust in India's 3rd-largest digital economy; protects DPI (Aadhaar, UPI, DigiLocker) [1].
  • Compliance costs offset by predictable rules for innovation & cross-border data flows [1].

Governance / Administrative

  • Shared responsibility model: government + digital platforms + citizens [1].
  • Appellate route: DPBI → TDSAT keeps adjudication tech-specialised [2].

6. Recent Developments (last 12-18 months)

  • 3 Jan 2025: MeitY releases Draft DPDP Rules, 2025 for public consultation (deadline 18 Feb 2025) [4].
  • Feb 2025: 6,915 inputs received on draft Rules [4].
  • Feb 2025: Union Budget 2025–26 allocates ₹782 crore for cybersecurity [1].
  • 14 Nov 2025: DPDP Rules, 2025 notified [2].
  • 27 Jan 2026: PIB Backgrounder for International Data Privacy Day [1].

7. Prelims Hooks

  • Data Privacy Day observed on 28 January [1].
  • Designated in 2006 by Council of Europe [1].
  • Marks anniversary of Convention 108 (1981) — first binding data-protection treaty [1].
  • DPDP Act, 2023 is Act No. 22 of 2023, enacted 11 August 2023 [3].
  • Nodal ministry: MeitY (not Ministry of Home Affairs) [3].
  • Design philosophy acronym: SARAL [2].
  • Regulator: Data Protection Board of India; appeals lie to TDSAT (not High Court directly) [2].
  • DPDP Rules notified on 14 November 2025 with 18-month phased compliance [2].
  • ₹782 crore for cybersecurity in Budget 2025–26 [1].
  • India = 3rd-largest digitalised economy globally [1].
  • Right to Privacy is a fundamental right under Article 21 (Puttaswamy, 2017) [1].
  • DPDP Act has 7 core principles [2].
  • Draft Rules drew 6,915 public inputs [4].

8. Mains Relevance

  • GS-II: Government policies, citizens' rights (Right to Privacy); statutory bodies (DPBI).
  • GS-III: Cyber security, digital economy, Digital Public Infrastructure.
  • Probable stems: 1. "Discuss how the DPDP Act, 2023 and DPDP Rules, 2025 operationalise the Puttaswamy verdict while balancing innovation and transparency." (GS-II) 2. "Examine the institutional architecture of the Data Protection Board of India. How does it differ from a conventional regulator?" (GS-II) 3. "Cybersecurity is integral to a trusted Digital Public Infrastructure. Analyse India's policy and budgetary response." (GS-III)

9. Related Topics to Study Next

  • Puttaswamy Judgment (2017) — constitutional foundation of privacy.
  • Digital Public Infrastructure (DPI) — Aadhaar/UPI/DigiLocker ecosystem the Act protects.
  • TDSAT — appellate forum for DPBI orders.
  • RTI Act, 2005 — interaction/tension with DPDP Act on disclosure [2].
  • Cyber Surakshit Bharat / CERT-In — cybersecurity operational arms.
  • GDPR (EU) — comparative international benchmark.
  • B.N. Srikrishna Committee (2017) — predecessor to DPDP framework.
  • Convention 108+ — modernised Council of Europe treaty.

10. Common Errors / Trap Areas

  • Wrong date: Some confuse with Safer Internet Day (Feb) — Data Privacy Day is 28 January.
  • Wrong origin: Designated by Council of Europe, NOT the EU/UN.
  • Wrong ministry: DPDP is under MeitY, not MHA or Ministry of Communications.
  • Appeal route: From DPBI appeals go to TDSAT, not directly to High Court / Supreme Court.
  • DPDP Act year vs Rules year: Act = 2023; Rules notified = 2025 (14 Nov).

Sources

  1. 1International Data Privacy Day — PIB Backgrounder, 27 Jan 2026pib.gov.in · tier 1
  2. 2DPDP Rules, 2025 Notified — PIB, 14 Nov 2025pib.gov.in · tier 1
  3. 3The Digital Personal Data Protection Act, 2023 — MeitYmeity.gov.in · tier 1
  4. 4Draft DPDP Rules, 2025 — 6,915 inputs — PIBpib.gov.in · tier 1
At the end · practice MCQs
8 questions on this item
Check the answer for each question, or reveal all at once.
Practice MCQs →

Also on 27 January

All 27 January articles →