No. The Digital Personal Data Protection Act, 2023 and the final DPDP Rules, 2025 create India’s statutory framework for digital personal data, but they do not supersedethe constitutional right to privacy recognised by the Supreme Court in Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1.

While, the DPDP framework governs  statutory data-protection obligations will apply. Puttaswamy remains the constitutional benchmark because it explains why privacy as a fundamental right under Article 21 and when State interference with it can be justified, namely where it meets the tests of legality, legitimate aim and proportionality.

 Sci API

What is the legal position on the DPDP Rules in 2026?

The first point businesses should understand is that the final DPDP Rules, 2025 have been notified, but not every provision is yet in force.

The Central Government made the final Rules through G.S.R. 846(E), dated 13 November 2025. Rule 1 provides for phased commencement:

  • Immediate Effect: Rules 1, 2 and 17 to 21 came into force on publication.

  • 12-Month Transition Window: Rule 4, dealing with registration and obligations of Consent Managers, comes into force one year after publication in the Official Gazette.

  • 18-Month Transition Window: Rules 3, 5 to 16, 22 and 23 come into force eighteen months after publication in the Official Gazette.

The DPDP Act itself has also been brought into force in stages through G.S.R. 843(E). Therefore, as of 5 October 2026, many of the substantive provisions concerning consent, Data Principal rights, security safeguards and other day-to-day compliance obligations are still within the statutory transition period. MeitY

Businesses should refer to the official DPDP Act, 2023 on India Code, the final DPDP Rules, 2025 published by MeitY and the official commencement notification G.S.R. 843(E) rather than treating the January 2025 draft Rules as the current law.

Until the relevant DPDP provisions commence, the existing Information Technology Act framework also remains important. In particular, section 43A of the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 continue to matter. Section 44(2) of the DPDP Act will eventually omit section 43A, but section 44(2) itself belongs to the later commencement group. India Code

What did the Supreme Court actually decide in Puttaswamy?

In Justice K.S. Puttaswamy (Retd.) v. Union of India, decided on 24 August 2017, a nine-judge Bench of the Supreme Court unanimously recognised privacy as a constitutionally protected right intrinsic to life and personal liberty under Article 21 and connected with the freedoms guaranteed by Part III of the Constitution.

 For modern businesses and technology companies, the Court expressly recognised informational privacy as a facet of the right to privacy. It also acknowledged that threats to informational privacy may arise from both State and non-State actors and emphasised the need for a robust data-protection regime. Sci API

The Court also made clear that privacy is not absolute. Any interference must satisfy three requirements 

Legality: there must be a valid legal basis for the interference.

Legitimate State aim: the intrusion must pursue a legally legitimate objective.

Proportionality: the means used must bear a rational and proportionate relationship to that objective.

The Supreme Court has continued to apply this framework in later privacy cases. You can read the Supreme Court’s judgment in Puttaswamy on the Court’s website.

 Sci API

Read the Supreme Court's Puttaswamy judgment.

Why this still matters in actual privacy disputes

It's tempting to think of Puttaswamy as a historic judgment that's now been "handled" by legislation. In practice, it's where privacy arguments still end up when something goes wrong with State power. 

The Court applied the legality, legitimate aim and proportionality test again in the Aadhaar case (Puttaswamy II, 2018), and in Anuradha Bhasin (2020) it required internet restrictions to meet proportionality. When a challenge targets a government order, a data-sharing arrangement or a statutory exemption, the question is rarely "did the DPDP Act apply?" It's "can this intrusion be justified under Article 21?"

For private companies, the day-to-day risk comes from the statute, but the constitutional standard shapes how courts read it, especially around exemptions and government access.

Does Puttaswamy apply to private companies in the same way as the DPDP Act?

Not exactly. This distinction is important.

Issue

Puttaswamy

DPDP Act and Rules

Nature

Constitutional privacy jurisprudence

Statutory data-protection framework

Main function

Protects the fundamental right to privacy and limits unconstitutional State interference

Regulates processing of digital personal data

Private businesses

Provides the constitutional background and recognises risks from non-State actors

Creates direct statutory obligations for Data Fiduciaries, including private businesses

Government processing

State action remains subject to constitutional scrutiny

Government processing may also be governed by the Act, including its statutory exemptions

Can it be replaced by the DPDP Act?

No

Must operate consistently with the Constitution

A breach by a private company does not automatically become a constitutional writ claim merely because Puttaswamy recognises privacy as a fundamental right. Private Data Fiduciaries are principally subjected to the obligations created by applicable statutes, rules, contracts and sector-specific regulation.

But Puttaswamy remains especially important when the validity of legislation, government processing, statutory exemptions or other State interference with privacy is challenged.

Can the Government rely on a DPDP exemption without considering Puttaswamy?

A statutory exemption and a constitutional justification are not necessarily the same question.

The DPDP Act contains exemptions, including provisions in section 17. When the relevant provisions commence, an exemption may determine whether particular obligations under the DPDP Act apply.

But legislation and executive action remain subject to the Constitution. A statutory exemption does not place State action outside constitutional judicial review. Where government action interferes with privacy, the principles flowing from Puttaswamy—including legality, legitimate purpose and proportionality remain relevant.

This is one of the most important reasons why it is inaccurate to say that the DPDP Act has “replaced” the constitutional right to privacy. Sci API

Is consent enough to make personal-data processing lawful?

Consent is important, but privacy compliance should not be reduced to obtaining a checkbox.

Under section 6 of the DPDP Act, consent must satisfy the statutory requirements once the relevant provisions commence. The Act also recognises certain legitimate uses under section 7, meaning consent is not the only basis contemplated by the statute. India Code

The final Rules make the notice supporting consent more specific. Rule 3 requires the notice to stand independently, use clear and plain language and provide an itemised description of the personal data involved and the specified purposes of processing. It must also provide a way for the Data Principal to withdraw consent, exercise rights and make a complaint. Rule 3 is part of the eighteen-month commencement group. MeitY

From a constitutional perspective, consent also cannot automatically validate otherwise unconstitutional State action. The broader question remains whether an intrusion into privacy has proper legal authority and can withstand constitutional scrutiny.

A practical example from client or advisory experience

Imagine a mid-sized health-tech startup with a polished privacy policy that assumes it is covered. A data-mapping exercise shows appointment records flowing to three third-party vendors, with no written processor terms, no defined retention period, and a sign-up flow that bundles marketing consent with account creation.

The privacy policy isn’t wrong. It simply describes a much tidier business than the one actually running.

The fix in a case like this is not a new policy. It is a data map, vendor contract amendments, a separate consent step and a retention schedule. All of that can be done well before the eighteen-month window closes.


What will the DPDP Rules require businesses to change?

The final Rules turn several principles in the DPDP Act into more operational requirements.

Rule 6 (security): sets  minimum reasonable security safeguardssuch as encryption, masking or tokenisation where appropriate, access controls, logs and monitoring, backups, processor-contract safeguards and appropriate technical and organisational measures. MeitY

Rule 7 ( breach notification): Affected Data Principals are to receive information about the breach without delay. the Data Protection Board must receive an initial intimation without delay and further specified information within seventy-two hours, subject to the Board permitting a longer period. MeitY

Rule 8 (retention and erasure): deals with retention and erasure in specified situations.

Rule 10 (Children): deals with verifiable parental consent for processing children's personal data. 

Rule 13(Significant Data Fiduciaries): imposes additional obligations on Significant Data Fiduciaries, including periodic data-protection impact assessments and audits. 

Rule 14 (Data Principal Rights): sets out mechanisms relating to the exercise of Data Principal rights.

Rule 15 (Cross Border): addresses transfers of personal data outside India subject to requirements that may be specified by the Central Government may specify. MeitY

These provisions should be built into business systems before they become applicable rather than dealt with only after commencement.

For many organisations, privacy compliance will also require changes to commercial contracts and vendor agreements, internal governance under corporate and strategic advisory processes, and employee confidentiality, access and data-handling practices covered by employment and business protection documentation.

What should businesses do during the transition period?

The safest approach is to use the transition period to build the compliance structure rather than waiting for the substantive provisions to commence.

Businesses should:

  1. Map what personal data is collected, where it comes from, where it is stored and who receives it.

  2. Identify the purpose and proposed legal basis for each important processing activity.

  3. Review privacy notices and consent flows against sections 5 and 6 and Rule 3.

  4. Review contracts with cloud providers, SaaS platforms, marketing agencies and other processors.

  5. Implement access controls, logging, encryption or other appropriate security measures and a documented breach-response process.

  6. Establish procedures for access, correction, erasure, grievance and nomination requests once the Data Principal rights become operative.

  7. Review retention periods, children's data, employee data and cross-border transfers separately instead of assuming one privacy policy solves every issue.

A website privacy policy can form part of this framework, but it should not be confused with every statutory notice or internal compliance requirement. Law Wallet's existing Privacy Policy illustrates the type of public-facing disclosure businesses commonly maintain.

What businesses commonly get wrong

The following are common pitfalls. Adjust this list to reflect what you actually see in practice.

•         Treating the privacy policy as the whole project. It is the most visible piece, but it does not show whether your vendors are bound, whether you can delete data on request, or whether anyone knows what to do on the day of a breach.

•         Assuming “legitimate uses” means “no consent needed”. Section 7 is specific. It is not a general escape hatch.

•         Waiting for commencement. Mapping data, fixing vendor contracts and building a breach-response process all take months. Starting in month 17 is too late.

•         Forgetting employees. HR data, CCTV, device monitoring and background checks are personal data too, and they rarely appear in a first compliance exercise.

•         Ignoring the old rules. Section 43A and the 2011 SPDI Rules still apply during the transition.


Does complying with the DPDP Act automatically mean there is no privacy risk?

No. DPDP compliance and constitutional privacy are related but different legal questions.

A business may also be subject to sector-specific requirements, cybersecurity obligations, contractual confidentiality duties, employment obligations and other applicable laws. Financial institutions, insurers, healthcare businesses and regulated digital businesses may have additional requirements imposed by their respective regulators.

Likewise, where the State is processing personal data, compliance with the wording of a statute does not by itself eliminate the possibility of a constitutional challenge.

The better way to understand India's privacy regime is therefore:

Puttaswamy provides the constitutional foundation. The DPDP Act creates the statutory architecture. The DPDP Rules provide much of the operational machinery.

They work together rather than replacing one another.

Frequently Asked Questions

Is the right to privacy still a fundamental right after the DPDP Act?

Yes. Puttaswamy remains binding constitutional law. Parliament's enactment of a data-protection statute does not extinguish the fundamental right to privacy recognised under Article 21 and Part III. Sci API

Are all DPDP Rules already enforceable in October 2026?

No. The final Rules have staggered commencement dates. As of 5 October 2026, Rules 1, 2 and 17 to 21 are in force, while Rule 4 and the major operational Rules have later commencement periods specified by Rule 1. MeitY

Were the January 2025 DPDP Rules the final Rules?

No. Those were draft Rules issued for consultation. The final Rules were subsequently made through G.S.R. 846(E) in November 2025 and were followed by a corrigendum in December 2025. MeitY

Does Puttaswamy prohibit all collection of personal data?

No. Privacy is not an absolute right. Lawful interference may be permissible where constitutional requirements including legality, legitimate purpose and proportionality are satisfied. Sci API

Can a business process personal data without consent?

The DPDP Act contemplates both consent and the “certain legitimate uses” specified in section 7. Whether a particular processing activity falls within section 7 must be determined from the statutory provision and the facts; it should not be treated as a general exemption from obtaining consent. India Code

Does a privacy policy itself make a company DPDP-compliant?

No. A privacy policy is only one part of compliance. Businesses also need appropriate processing purposes, notices and consent mechanisms where applicable, security safeguards, retention systems, processor arrangements, breach procedures and mechanisms for Data Principal rights.

Do the old IT Act privacy rules still matter?

Yes, during the transition they can. Section 43A of the Information Technology Act and the 2011 SPDI Rules have not yet disappeared merely because the DPDP Act and final Rules have been notified. The DPDP Act's provision omitting section 43A is itself subject to phased commencement.