HomePostsDigital RightsReclaiming Informational Self-Determination in the DPDPA 2023: A Constitutional Case for Purpose...

Related Posts

Reclaiming Informational Self-Determination in the DPDPA 2023: A Constitutional Case for Purpose Limitation and Data Minimization

Introduction

Purpose limitation and data minimization are key principles of data protection. These principles serve as foundational pillars of data protection laws globally, exemplified by frameworks such as the EU General Data Protection Regulation (Article 5(b)–(c)); Canada’s Personal Information Protection and Electronic Documents Act (Schedule 1, Principles 4 and 5); Brazil’s General Data Protection Law (Article 6, I and III); the OECD Guidelines on the Protection of Privacy (Principles 7 and 9); the APEC Privacy Framework (Principles III and IV); the American Privacy Rights Bill (Section 3); and the California Consumer Privacy Act (§§ 1798.100(c), 7002(d)). Together, they serve as critical mechanisms to ensure that data processing aligns with the legitimate expectations and autonomy of the Data Principal.

Despite this, the question of whether the Digital Personal Data Protection Act, 2023 (“DPDPA 2023 or Act”) meaningfully incorporates and enforces these principles remains largely under-examined in existing legal and policy scholarship.

In this piece, we argue that the DPDPA 2023 and the accompanying Draft Digital Personal Data Protection Rules, 2025 (“DPDPA Rules 2025 or Rules”) fail to meaningfully operationalize the principles of purpose limitation and data minimization. In response, we argue for the necessity of reading these principles into the Act through a constitutional interpretive approach. Such a reading is essential not only to honor constitutional commitments but also to harmonize India’s data protection framework with global norms and safeguard the informational autonomy of individuals in the digital age.

I. Structural Flaws: Weak Enforcement of Purpose Limitation and Data Minimization

Purpose limitation requires that personal data (1) is collected for specified, explicit, and legitimate purposes, and (2) is not further processed in a manner that is incompatible with those purposes. Under the DPDPA 2023, consent must be obtained for a specific purpose specified by the Data Principal [Section 6(1)]. The provision for “legitimate uses” (alternate bases to process personal data to consent) states that “a Data Fiduciary may process personal data of a Data Principal for any of the following uses,” and then lists eight specific purposes [Section 7].

However, both these bases for processing — consent and legitimate uses — address only the first aspect of purpose limitation: that personal data must be collected for lawful and specified purposes. They do not prevent further processing in ways incompatible with those initial purposes. This omission significantly weakens the enforcement of the principle in practice.

DPDPA Rules 2025 Second Schedule codifies key safeguards under the Section 7(b) of the DPDPA 2023. They encode purpose limitation by ensuring not only that processing is done for “specified purposes,” but also that “processing is limited to such personal data as is necessary for such uses or achieving such purposes, as the case may be.” It is unclear why this safeguard was provided only for one of the legitimate use grounds [Section 7(b)] and not for the others. In the final draft of the Rules, this issue should be rectified. However, this safeguard is potentially ultra vires, as it introduces a substantive protection via delegated legislation which was not expressly present in the Act.

Data minimization, on the other hand, requires that the data collected is adequate, relevant, and limited to what is necessary for the purposes for which it is processed. This requirement is contained under the consent provision, but not under the legitimate uses provision. Section 6(1) of the DPDPA 2023, which deals with consent, codifies the requirement that collection “be limited to such personal data as is necessary for such specified purpose.” However, there is no corresponding language or safeguard under the legitimate uses provision in Section 7. This creates a significant regulatory inconsistency, leaving a large category of data processing activities without a binding minimization obligation.

While the right to data erasure could potentially address the absence of substantive purpose limitation and data minimization obligations, its current framing under the DPDPA 2023 and Rules 2025 is also inadequate. Data Fiduciaries are required to erase personal data once consent is withdrawn by the Data Principal or when it is “reasonable to assume that the specified purpose is no longer being served,” whichever occurs earlier [Section 8(7)]. DPDPA 2023 Section 8(8) states that such an assumption may be drawn if the Data Principal no longer approaches the Fiduciary for the intended purpose or exercises rights over the data. However, the DPDPA 2023 and Rules 2025 fail to prescribe a definitive timeline or criteria for interpreting inactivity as the end of a purpose, except in the case of three Data Fiduciaries classes (social media, e-commerce, and e-gaming) [DPDPA Rules 2025, Third Schedule]. This gap leaves excessive discretion with Data Fiduciaries to determine data retention periods, weakening the regulatory framework’s ability to meaningfully enforce purpose limitation and data minimization.

The cumulative impact of the absence of meaningful purpose limitation and data minimization is profound. It permits broad, discretionary processing of personal data without effective safeguards against secondary, unrelated, or excessive uses. This increases the risk of downstream harms such as profiling, targeted advertising, discrimination, and unwarranted surveillance. The absence of direct statutory accountability for Data Processors further compounds these concerns. Data Processors handle a wide range of sensitive, large-scale, and high-risk data operations, and in the absence of clear obligations, personal data may be processed or retained far beyond what is necessary, with little legal restraint or oversight.

Such regulatory gaps fundamentally undermine the principle of informational self-determination. They enable profiling and targeting that can produce discriminatory effects, breaching the principle of non-discrimination. Moreover, unchecked surveillance and data misuse risk chilling free speech, dissent, and association, as individuals may self-censor or avoid exercising these constitutional rights in digital spaces.

Thus, this constitutional infirmity strikes at the core of the DPDPA 2023. The absence of substantive purpose limitation and data minimization affects every data processing activity under the Act, rendering its protective framework structurally inadequate. Without these foundational safeguards, the DPDPA 2023 falls short of functioning as an effective or rights-respecting data protection regime.

II. Constitutionalizing Data Protection: A Path to Remedying DPDPA’s 2023 Structural Flaw

In Puttaswamy v. Union of India(2017) (“Puttaswamy I”) and Puttaswamy v. Union of India (2018) (“Puttaswamy II”), the Supreme Court affirmed that the right to privacy has both negative and positive dimensions.  The negative aspect restrains the State from intruding upon an individual’s life and personal liberty, while the positive aspect imposes a constitutional obligation on the State to actively protect individual privacy.  In Puttaswamy I, in the opinions of Justice D.Y. Chandrachud, and Justice Sanjay Kishan Kaul, as well as in the majority opinion of Puttaswamy II, the Supreme Court held that data protection measures are essential for safeguarding and operationalising the right to privacy, particularly given the risks posed from private entities who play an outsized role in the digital age. 

Accordingly, the State bears a positive constitutional duty to establish an effective, rights-respecting data protection framework that safeguards privacy against both state and non-state actors. The DPDPA 2023 represents the legislative attempt to discharge this duty. As such, its interpretation must be guided by the constitutional principles laid down in the Puttaswamy judgments and by broader constitutional values.

In Puttaswamy II, the majority,  observed that:

Thus, it is evident from various case laws cited above, that data collection, usage and storage (including biometric data) in Europe requires adherence to the principles of consent, purpose and storage limitation, data differentiation, data exception, data minimization, substantive and procedural fairness and safeguards, transparency, data protection and security” (Para 187, 447(1)(d)).

The Supreme Court further noted that “only by such strict observance of the above principles can the State successfully discharge the burden of proportionality” (Para 187). Then, it began the to check the constitutionality of Aadhaar against these data protection principles. Even in Puttaswamy I, the opinions of Justice D.Y. Chandrachud, and Justice Sanjay Kishan Kaul emphasized the centrality of purpose limitation and data minimization.

The mandate for purpose limitation and data minimization is strengthened by the fact that these norms are indispensable for realising and protecting the right to informational self-determination, recognized as an essential facet of the constitutional right to privacy in the Puttaswamy judgments. 

Section 4(1) of the DPDPA 2023 requires that any processing of personal data by a Data Fiduciary of a Data Principal must be carried out “in accordance with the provisions of this Act and for a lawful purpose.” Lawful purpose is defined as any purpose which is not expressly forbidden by law. In the Supreme Court’s decision in Maneka Gandhi v. Union of India (1978), the Court interpreted law to mean a requirement of a just, fair, and reasonable law (Para 21).  In the context of the right to privacy, this standard has been interpreted as the narrow tailoring rule in People’s Union for Civil Liberties v. Union of India (1997) and proportionality test in Puttaswamy II.  In the latter, the Court’s proportionality test was backed by substantive data protection and administrative law safeguards, including purpose limitation and data minimization. Thus, purpose limitation, and data minimization must be read in Section 4(1) of the DPDPA 2023. For purpose limitation, incidental subsequent processing that is connected to the initial, specified purpose may be permitted; however, processing for a distinct secondary purpose is not allowed.

III. Proportionality as a Guiding Principle under the DPDPA 2023

Advocate General Szpunar, in his opinion in the Latvijas Republikas Saeima case (2020), observed that the principles governing the processing of personal data in Article 5 of the EU General Data Protection Regulation (“GDPR”) including purpose limitation, storage limitation, and data minimization are rooted in the principle of proportionality. The principle, in fact, serves as a foundational pillar of the GDPR. In light of the constitutional mandate articulated in the Puttaswamy decisions, the proportionality test should likewise operate as a key interpretive tool for the DPDPA 2023. This would be particularly relevant in addressing key constitutional infirmities and ambiguities within the Act. In particular, it would ensure that data processing is tied to clearly defined and lawful purposes, adheres to the principles of purpose limitation and data minimization, subjects processing under legitimate use grounds to tests of suitability, necessity, and balancing, and requires that any exceptions or State information requests are narrowly framed, proportionate, and supported by adequate procedural safeguards.

It should be noted, however, that this paper does not attempt to offer a comprehensive or systematic account of how proportionality might be formally adopted as a guiding interpretive principle under the DPDPA. Rather, it seeks to highlight the relevance and potential utility of proportionality in interpreting certain provisions of the Act  a task that future academic and judicial literature may take up in greater depth.

IV. Conclusion

The DPDPA 2023, in its current form, fails to meaningfully operationalize the constitutional principles of purpose limitation and data minimization core safeguards essential for protecting informational self-determination in the digital age. Despite their express endorsement in the Puttaswamy judgments and their centrality in comparative data protection frameworks, the DPDPA 2023 and Rules 2025 leave significant gaps, enabling broad, unchecked data processing and retention. This undermines privacy rights, heightens the risk of misuse, and erodes constitutional protections for individual autonomy.

To address these structural flaws, this paper proposed a constitutional interpretive approach, reading these safeguards into Section 4(1) of the DPDPA in light of the Puttaswamy decisions. Such an interpretation would require personal data processing to adhere to the principles of purpose limitation and data minimization.

A final observation is warranted. While discourse around the DPDPA is expanding, much of it remains detached from constitutional principles. For any data protection framework to meaningfully guarantee the right to privacy, it must be firmly grounded in constitutional values. Puttaswamy I and Puttaswamy II offer not only a doctrinal foundation but also normative guidance on the limits and design of rights-respecting data regulation. In this context, the principle of proportionality should serve as both a constitutional benchmark and a guiding interpretive tool for reading and applying the DPDPA’s provisions. Future scholarship and judicial scrutiny must build on this foundation to realize a rights-protective data governance framework in India.

Rudraksh Lakra
B.A., LL.B. (Hons.) degree from Jindal Global Law School, India (2023).

Rudraksh Lakra is a technology law advocate and policy analyst. He holds a B.A., LL.B. (Hons.) degree from Jindal Global Law School, India (2023).

Nidhi Jha
LLM candidate at Central European University

Nidhi Jha is an LLM candidate at Central European University (2024–25) and a graduate of Jindal Global Law School, India (2024).

[citationic]

Featured Artist