If you have conducted a survey, run interviews, collected health information, or scraped social media data as part of your research, India’s data protection law now applies to you.
The Digital Personal Data Protection Act, 2023 — commonly called the DPDP Act — received Presidential assent in August 2023 and partially came into effect on 13 November 2025, with full enforcement expected by 13 May 2027. The DPDP Rules, 2025, notified alongside the Act, provide the detailed operational requirements — covering consent collection, notice obligations, breach reporting, and record-keeping.
For most researchers in India, this is new legal territory. This guide explains what the Act means in plain terms, what your obligations are when collecting personal data, and — critically — how the research exemption under Section 17 works and when you can rely on it.
What Counts as Personal Data Under the Act
The DPDP Act covers the processing of digital personal data — any information that identifies an individual — collected online, or collected offline and subsequently digitised.
In a research context, this includes: survey responses linked to names or contact details, interview recordings, health or medical records, photographs, government ID numbers, demographic data tied to identifiable individuals, and social media posts where the account is not anonymised.
If your research involves any of these, you are a Data Fiduciary under the Act — the entity that determines the purpose and means of processing personal data. That role carries legal obligations.
Your Core Obligations as a Researcher
The Act defines obligations for data fiduciaries, including requirements for obtaining valid consent, specifying a clear purpose for data usage, enabling withdrawal of consent, and ensuring grievance redressal mechanisms.
Translated into research practice, this means:
1. Obtain free, informed, and specific consent. Before collecting any personal data, your participant must be told — in plain language — what data you are collecting, why you need it, and who will have access to it. A vague “data may be used for research purposes” clause in fine print does not satisfy the Act’s consent standard.
2. Collect only what you need. Data minimisation is a core obligation — only strictly necessary data should be processed. If your research question does not require knowing a respondent’s religion or income bracket, do not collect it.
3. Retain data only as long as necessary. Data should only be retained as long as necessary and securely deleted thereafter. Build a data retention and deletion schedule into your research protocol before you begin, not after.
4. Keep it secure. Compliance requires secure infrastructure — encryption, access controls, and secure storage. For most individual researchers, this means password-protected encrypted files, not raw spreadsheets on shared drives.
5. Report breaches. All personal data breaches must be reported to the Data Protection Board, irrespective of their gravity or damage caused. Penalties can extend up to Rs. 250 crore.
The Section 17 Research Exemption — and Its Limits
Here is the part most researchers get wrong: there is a research exemption, but it is narrower than it appears.
Section 17(2)(b) of the DPDP Act provides a partial exemption — specifically, Sections 5 through 8 of the Act (which govern consent and notice requirements) do not apply — but only where the identity of the data principal cannot be inferred from the data, and the processed data is not used to make any decision specific to an individual.
In practical terms, this means:
- If your data is genuinely anonymised and your findings will not be used to make any decision about a specific individual, the consent and notice requirements under Sections 5–8 may not apply to you.
- If your data is pseudonymised (coded but re-linkable), you are not exempt. The exemption requires that identity cannot be inferred, not merely that it has been obscured.
- If you are conducting policy research that will be used to make administrative decisions affecting identifiable people — even in aggregate — the exemption does not protect you.
The Central Government has not yet released the prescribed standards that define the exact scope of this exemption. This is a significant grey area. The prudent approach: do not rely on the exemption as your primary compliance strategy. Obtain proper consent, anonymise your data rigorously, and treat the exemption as a backstop rather than a starting point.
A Practical Checklist for Your Next Research Project
Before you collect a single data point involving personal information, run through these:
- Have I identified every category of personal data I will collect?
- Have I prepared a clear, plain-language consent notice explaining purpose, storage, and access?
- Is the data collection limited strictly to what my research question requires?
- Have I defined how long I will retain the data and how I will delete it?
- Is the data stored in an encrypted, access-controlled environment?
- If I am claiming the Section 17 exemption, can I demonstrate that individual identity genuinely cannot be inferred from my dataset?
- Have I designated a point of contact for participant grievances?
Why This Matters for Indian Researchers Specifically
India’s research community — particularly in social sciences, public health, law, and developmental studies — routinely handles personal data at scale. Household surveys, clinical studies, legal aid interviews, field research in rural communities: all of these now fall within the Act’s ambit.
The DPDP Act is operational. The Data Protection Board of India is constituted. Penalties are real. And unlike the era of informal research ethics — where an IRB approval letter was often the beginning and end of data protection compliance — the law now creates independent legal obligations regardless of your institution’s internal protocols.
Build data protection into your research design from day one. Your participants’ trust, your institution’s liability, and increasingly, your research’s credibility depend on it.
This article is intended as a general research guide and does not constitute legal advice. Researchers dealing with sensitive categories of data or large-scale data collection should consult a qualified data protection practitioner.