The Data Protection Board Of India: An Institution Without Independence?
Aditi Prithviraj Patil, KLE Law College
Introduction
The definition of data, derived from the Latin word “datum”, meaning “something given”, becomes extremely relevant in today’s world when everything is run on data, based on data and decided by data. With the rise of globalisation and swift technological progress, it has emerged as one of the key resources in our everyday lives.
The Supreme Court, in Justice K. S. Puttaswamy v. Union of India, has acknowledged the right to privacy as a fundamental right under Article 21 of the Indian Constitution. Safeguarding individual privacy poses a significant challenge within data protection legislation. Over the last ten years, there has been a notable surge in the collection of personal data and digital transactions. This has raised significant concerns regarding privacy violations and the improper handling of data.
Prior to the year 2020, the handling of data was managed through limited sections of the Information Technology Act, 2000, which included the “Sensitive Personal Data or Information Rules.” In 2017, the government of India established the Justice B. N. Krishna Committee to examine and analyse the challenges and issues surrounding data protection in the country. There was no specific law dedicated solely to the “collection” and “processing” of personal digital data until then. Despite the Committee's draft Bill in 2018, it was substantially diluted by the time the legislation was made. Finally, after a series of proposed bills, in the year 2023, the Digital Personal Data Protection Bill was passed by both houses of Parliament. The Parliament enacted the Digital Personal Data Protection Act, 2023, which was objectively designed to safeguard the personal data of individuals. It examines the needs of new technologies like artificial intelligence, big data analytics, and the Internet of Things (IoT), which depend significantly on the processing of personal information.
