This paper examines whether privacy under the DPDP Act, 2023, is an indefeasible
right—one that cannot be lost, annulled, or defeated. Analysing significant case laws,
the paper concludes that privacy is fundamental but conditionally defeasible through
statutory exemptions and legitimate state interests. The DPDP Act reflects a
"qualified rights" model where privacy yields to judicial transparency, national
security, and law enforcement necessity.
Keywords: DPDP Act 2023, Right to Privacy, Right to be Forgotten, Open Court,
Defeasibility, Fundamental Rights, Qualified Rights
I. INTRODUCTION
The Digital Personal Data Protection Act, 2023, follows the Supreme Court's
recognition of privacy as fundamental under Article 21 (Puttaswamy, 2017).
However, while the Act protects personal data, it permits broad exemptions: courts
are exempt from data processing restrictions (Section 17(1)(b)), law enforcement
from obtaining consent (Section 17(1)(c)), and state agencies can be exempted for
national security (Section 17(2)(a)). This statutory architecture renders privacy
"defeasible"—subject to limitation when competing interests prevail—rather than
indefeasible (incapable of defeat).
The doctrine of "incrementation" explains this development:
Phase 1: Constitutional Foundation (2017)
In Puttaswamy, the Supreme Court declared privacy a fundamental right under
Article 21. However, it was conceptualised as an abstract right, subject to
"reasonable restrictions" imposed by law. The Court did not define the scope of
permissible limitations, creating ambiguity.
Phase 2: Judicial Experimentation (2021-2024)
Subsequent High Court judgments began "incrementing" (expanding) privacy
protections beyond constitutional text, often using inherent powers to create rights
that no statute provided. The most notable example is Karthick Theodore v. Registrar
General (2024), where the Madras High Court attempted to create a judicially-
enforced "Right to be Forgotten" even where the DPDP Act explicitly exempted
courts. This phase reflects judicial activism in expanding privacy.
Phase 3: Legislative Codification (2023)
Parliament "incremented" the law by creating a specific statutory framework in the
DPDP Act. However, unlike the judicial expansion, which sought to include court
records within privacy protection, the legislative incrementation excluded the
judiciary entirely through Section 17(1)(b). The legislature deliberately prioritised
judicial transparency over individual data control, signalling a pullback from the
expansive approach.
This oscillation reveals a fundamental tension: courts attempted to make privacy
indefeasible; Parliament deliberately made it defeasible.
II. THE LEGAL FRAMEWORK UNDER THE DPDP ACT, 2023
A. Objectives and Key Features
The DPDP Act, 2023, pursues four core objectives:
Protection of digital personal data against unauthorised processing
Recognition of data principals' rights to access, correct, and erase their
data
Regulation of data fiduciaries (entities processing personal data)
Establishment of the Data Protection Board of India for adjudication
The Act introduces a consent-centric framework with principles of purpose limitation,
data minimisation, and security. However, its defeasibility arises through exemptions
that override data principal rights.
B. The Right to Erasure Under Section 12 (Not Truly "Indefeasible")
Section 12(3) grants Data Principals the right to request "correction, completion,
updating and erasure" of personal data that is:
Inaccurate or misleading
No longer required for the purpose for which it was collected
Retention is based on consent, which has been withdrawn
Processed illegally
However, the right is subject to exceptions. A Data Fiduciary need not comply if the
data is:
Required for legal compliance
Essential for pursuing legal claims
Necessary for public interest (journalistic, scientific, or historical purposes)
Part of exempt processing under Section 17
Critical Limitation: For judicial records (Section 17(1)(b)), the right to erasure is
practically unenforceable because courts are entirely exempted from DPDP
obligations.
C. The Section 17 Exemptions: The Architecture of Defeasibility
Section 17 of the DPDP Act constructs a hierarchical shield that renders privacy
rights defeasible:
Effect: Courts and tribunals are entirely exempted from DPDP obligations. This
means:
No obligation to obtain consent before publishing judgments
No obligation to grant Right to Erasure requests (Section 12)
No obligation to anonymise litigants' names except in statutory cases (sexual
offences, juveniles)
The Data Protection Board has no jurisdiction over court decisions
Constitutional Implication: This exemption prioritises the "Open Court" principle
(transparency in judicial proceedings, a constitutional requirement) over individual
informational privacy. The exemption recognises that judicial records are public
documents, and individuals have no absolute right to redact them merely because
publication causes them discomfort.
Effect: When law enforcement agencies process personal data for investigation or
prosecution, Data Principals lose nearly all DPDP protections, including the right to
access, correction, and erasure during the investigation phase.
Effect: The Central Government can exempt any state agency from all DPDP
provisions if it determines the exemption is necessary for national security or public
order. This is a blanket power with minimal procedural safeguards.
Defeasibility Mechanism: The exemption applies not only to processing but also to
the government's power to furnish such data to other state agencies. A Data
Principal cannot invoke DPDP rights to prevent state data sharing for security
purposes.
Effect: The government can retain personal data indefinitely without deletion, even
if:
The original purpose has been served
Consent was conditional on limited retention
The data is outdated or irrelevant
This nullifies the Right to Erasure for citizens against the state, making privacy
defeasible in the state-citizen relationship.
III. CASE LAW ANALYSIS: THE FOUR POLES OF DEFEASIBILITY
A. NIPUN SAXENA v. UNION OF INDIA (2018)—PRIVACY
APPROACHES INDEFEASIBILITY
Core Holding: The Supreme Court held that sexual offence victims' identities must
be absolutely protected under Section 228A IPC 1 , trumping media freedom (Article