Abstract
For more than sixty years it was unclear whether the Constitution of India protected privacy at all. That uncertainty ended on 24 August 2017, when a nine-judge bench of the Supreme Court in Justice K. S. Puttaswamy (Retd.) v. Union of India unanimously held that privacy is a fundamental right flowing from Articles 14, 19 and 21, and that any interference by the State must satisfy the tests of legality, legitimate aim, proportionality and adequate procedural safeguards. Parliament responded only in 2023, and the Rules giving effect to that statute were notified on 13 November 2025, under which the main duties of data fiduciaries become binding only by 13 May 2027. The research problem is the distance between what the Constitution now promises and what the statutory framework delivers.
The study traces the evolution of privacy in Indian constitutional jurisprudence, examines the statutory framework now governing personal data and State surveillance, measures digital expansion and privacy-related harm from official data, and sets the Indian framework against the General Data Protection Regulation. The central question is whether the Digital Personal Data Protection Act, 2023 satisfies the proportionality standard laid down in Puttaswamy. The hypothesis is that constitutional recognition of privacy in India has outpaced its statutory realisation, and that the present framework disciplines private data fiduciaries far more effectively than it disciplines the State.
The design is doctrinal and descriptive-analytical, and uses secondary data only, drawn from peer-reviewed journal articles, academic books, reported judgments, and official reports of TRAI, the National Crime Records Bureau, UIDAI, the Reserve Bank of India, CERT-In, MeitY, the World Bank, UNCTAD and the ITU. Thematic analysis, doctrinal analysis and descriptive statistics have been applied, and every figure has been traced to a named official publication.
Six findings emerge. Broadband subscribers rose from 131.49 million in November 2015 to 1,065.88 million by March 2026. Cybercrime cases registered by the National Crime Records Bureau rose from 52,974 in 2021 to 86,420 in 2023, an increase of about 63 per cent in two years. A wide urban-rural gap persists, with tele-density of 151.47 per cent in urban India against 60.46 per cent in rural India in March 2026, which limits the usefulness of a consent-based law. The Indian statute is narrower than the General Data Protection Regulation, providing no right to data portability, no separate category of sensitive personal data and no safeguard against automated decision-making. Broad State exemptions under Section 17, an executive-appointed Data Protection Board and the amendment of the Right to Information Act, 2005 by Section 44(3) weaken accountability. Most significantly, no surveillance reform has followed Puttaswamy: interception under Section 69 of the Information Technology Act, 2000 and Section 5(2) of the Indian Telegraph Act, 1885 still requires no prior judicial authorisation.
The paper concludes that the constitutional promise of 2017 remains only partly realised. It recommends an independent regulator, prior judicial authorisation for interception, restoration of the public-interest override in the Right to Information Act, a safeguard against automated decisions, and digital literacy in regional languages so that consent becomes meaningful.
IJCRT's Publication Details
Unique Identification Number - IJCRT2608256
Paper ID - 312675
Page Number(s) - c336-c352
Pubished in - Volume 14 | Issue 8 | August 2026
DOI (Digital Object Identifier) -   
Publisher Name - IJCRT | www.ijcrt.org | ISSN : 2320-2882
E-ISSN Number - 2320-2882
Cite this article
  Samreen Alvi,  Nadeem Alam,   
"Right to Privacy in the Digital Era in India", International Journal of Creative Research Thoughts (IJCRT), ISSN:2320-2882, Volume.14, Issue 8, pp.c336-c352, August 2026, Available at :
http://www.ijcrt.org/papers/IJCRT2608256.pdf