The 2018 Bill was India’s first serious attempt at a data protection statute, and much of what it proposed did not survive. Read it now as the origin of the framework rather than a description of the law — because the Act eventually passed differs from it in nearly every structural choice.
Where it came from
Privacy, and data privacy in particular, became a major talking point as digitisation and surveillance capabilities expanded across both government and the private sector. The most prominent legislative response was Europe’s General Data Protection Regulation (GDPR).
In India, the groundwork was laid by the Supreme Court in Justice K.S. Puttaswamy (Retd.) v. Union of India, holding privacy to be a fundamental right. A committee headed by former Justice B.N. Srikrishna was then set up to frame privacy legislation, producing the draft Personal Data Protection Bill, 2018, open for public comment between July and October 2018.
What the 2018 Bill proposed
Definitions. The Bill replaced the GDPR’s data subjects and data controllers with data principals and data fiduciaries. A data principal is a natural person whose data is collected; a data fiduciary determines the purpose of processing. The word “fiduciary” was a deliberate choice, seeking to establish a trust-based relationship.
Application. To any data collected, disclosed, shared or processed within India, and — like the GDPR — to processing by entities outside India where connected with any business in India or involving profiling of data principals here.
Authority. A Data Protection Authority of six full-time members, selected by a committee comprising the Chief Justice of India or a nominated Supreme Court judge as chairman, the Cabinet Secretary, and a data protection expert.
Categories of data. Personal data identifying a natural person, and sensitive personal data covering passwords, financial data, credit history, medical history, sexual orientation, biometric and genetic data, religious or political affiliation, and caste or tribe membership — with power for the Authority to designate further categories.
Consent and privacy by design. Informed, clear and specific consent, withdrawable at any time, alongside privacy by design principles.
Two drafting concerns stood out. The Bill required consent prior to processing rather than at collection — so an entity could collect data and defer processing while remaining compliant. And it provided that where consent is withdrawn, all legal consequences of that withdrawal are borne by the data principal.
It also permitted processing for “reasonable purposes” — including detection of unlawful activity and fraud, whistleblowing, mergers and acquisitions, network security, credit scoring, debt recovery, and processing publicly available data.
Notice. Fiduciaries had to give notice of the basis and purposes of processing, categories of data, contact details, the right to withdraw consent, entities with whom data may be shared, cross-border transfers, retention period and grievance redressal. Breaches had to be notified to the Authority where likely to cause harm.
Localisation. A copy of any personal data was to be stored on a server or data centre in India, with cross-border transfer restricted to cases involving Authority-approved standard contractual clauses or jurisdictions designated as adequate.
Penalties. Up to 4% of global revenue or ₹15 crore, whichever is higher — plus criminal liability for offences including unlawful collection, transfer or sale of data and re-identification of anonymised data, carrying up to three years’ imprisonment, and classified as cognizable and non-bailable.
Exemptions. Broad exemptions for the State, including in the interests of security and defence — the provision that attracted most criticism, alongside the absence of amendments to the Aadhaar Act.
What actually happened
The 2018 draft became the Personal Data Protection Bill, 2019, was referred to a Joint Parliamentary Committee, and was withdrawn in August 2022. A new draft followed, and the Digital Personal Data Protection Act, 2023 was enacted in August 2023.
The Act differs from the Bill described above in nearly every structural respect:
- No separate category of sensitive personal data. The graded regime built around a sensitive category was dropped entirely.
- No general localisation mandate. Instead of requiring a copy in India, the Act permits transfer abroad except to countries the government notifies as restricted — close to the opposite default.
- A Data Protection Board of India, adjudicatory in function, rather than the Authority with rule-making powers the Bill envisaged.
- Penalties up to ₹250 crore per breach, on a schedule of specified defaults, rather than a percentage of global turnover.
- No criminal liability of the kind the Bill proposed.
- Data principals carry duties, including not filing false or frivolous complaints — a novel feature with no GDPR counterpart.
- State exemptions remain broad, so the central concern raised here was not resolved by the change in approach.
The terminology survived: data principal and data fiduciary are the terms the Act uses.
Why this still matters
Anyone assessing Indian data protection compliance should work from the DPDP Act, 2023 and the rules made under it. This post is useful for understanding how the framework was conceived and which ideas were abandoned — particularly localisation and the sensitive data category, both of which shaped a great deal of commentary that is now obsolete.
The through-line is that the concern flagged in the conclusion — that exemptions granted to the State could permit surveillance in a way ill-fitting a fundamental right — carried across from Bill to Act, and remains the substantial criticism of the law as passed.
The takeaways
- The 2018 Bill never became law — it was withdrawn in 2022.
- The DPDP Act, 2023 governs — with a Board, not an Authority.
- No sensitive data category and no localisation mandate in the Act.
- Penalties up to ₹250 crore, without the Bill’s criminal liability.
Frequently asked questions
Is the Personal Data Protection Bill law in India? No — it was withdrawn in August 2022 and replaced by the Digital Personal Data Protection Act, 2023.
Does India require data to be stored locally? The DPDP Act does not impose a general localisation mandate; it permits transfer abroad except to countries notified as restricted.
What penalties apply under the DPDP Act? Financial penalties up to ₹250 crore for specified defaults, without the criminal liability the earlier Bill proposed.
What is a data fiduciary? An entity that determines the purpose and means of processing personal data — the term carried over from the Bill into the Act.
Useful official resources
- Ministry of Electronics and Information Technology
- The Digital Personal Data Protection Act, 2023
