LIJDLR

Digital Personal Data Protection Act

AI, FAIRNESS AND FINANCIAL DATA: A LEGAL STUDY OF INDIA’S UPDATED DATA PROTECTION RULES FOR BANKS

AI, FAIRNESS AND FINANCIAL DATA: A LEGAL STUDY OF INDIA’S UPDATED DATA PROTECTION RULES FOR BANKS Pranav Kumar Saxena, B.A. LL.B. (H), LL.M., Associate Vice President (Legal), Kotak Mahindra Bank Ltd. (India) Download Manuscript doi.org/10.70183/lijdlr.2026.v04.181 Artificial Intelligence (AI) now plays a central role in India’s banking sector. Banks depend on AI systems for scoring credit risk, detecting fraud, monitoring transactions, automating customer interactions and supporting compliance processes. These systems promise efficiency and scale, but they also rely on continuous processing of personal and financial data. This increases concerns about fairness, transparency, accuracy and privacy. The Digital Personal Data Protection Act 2023 (DPDP) and the Digital Personal Data Protection Rules notified in 2025 have introduced a detailed and structured framework to govern the processing of such data. These Rules include strict standards for consent, retention, deletion, breach reporting, cross-border transfers and automated decision making. They also create new classifications, Significant Data Fiduciaries, under which most banks are likely to fall. This paper examines how these updated Rules affect AI enabled banking in India. It studies how the Rules shape responsibilities related to fairness, accountability and transparency in automated decision making. It also compares India’s approach with global models such as the GDPR, China’s PIPL and the United States’ sector specific system. While the new Rules mark a major step forward for data governance, the paper argues that India still needs clearer standards on algorithmic fairness, explainability, vendor management and audit requirements. The aim is to support a regulatory environment that encourages innovation while protecting financial data and strengthening trust in AI driven banking.

AI, FAIRNESS AND FINANCIAL DATA: A LEGAL STUDY OF INDIA’S UPDATED DATA PROTECTION RULES FOR BANKS Read More »

THE EVOLUTION OF PRIVACY AS A FUNDAMENTAL RIGHT IN THE AGE OF CYBER CRIME

THE EVOLUTION OF PRIVACY AS A FUNDAMENTAL RIGHT IN THE AGE OF CYBER CRIME Tanmay Gujarathi, Advocate at Bombay High Court (India) Download Manuscript doi.org/10.70183/lijdlr.2026.v04.128 This paper examines the development of privacy as a fundamental right in the context of rising cyber-crime and rapid digitalization. In the current digital world, huge amounts of personal data are produced, collected, and processed throughout day-to-day online activities, exposing individuals to increasing risks such as data theft, hacking, phishing, and cyber terrorism. The shocking rise in cyber-crime cases underlines the urgent need for strong legal safeguards to protect personal information and preserve individual autonomy. The paper looks into privacy not only as a negative right of exclusion but as a broad concept deep rooted in dignity, choice, and trust. It critically analyses the judicial recognition of privacy as a fundamental right under Articles 14, 19, and 21 of the Constitution, particularly through the landmark judgment in Justice K.S. Puttaswamy (Retd.) v. Union of India, which affirmed the right to privacy as inherent to life and personal liberty. At the same time, it acknowledges that this right is not absolute and may be reasonably restricted under law. The study adopts a doctrinal and analytical methodology, relying on constitutional provisions, judicial decisions, statutory frameworks, and secondary sources. Further, the paper classifies numerous forms of cyber-crimes and inspects India’s divided yet developing legal framework, as well as sector-specific legislation. It critically examines the Digital Personal Data Protection Act, 2023 as a major step toward establishing a comprehensive, rights-based data protection rule, while also recognising challenges relating to application, regulatory transparency, and potential state outreach. The paper concludes that protecting privacy in the digital era requires a balanced approach by combining strong legal frameworks, effective enforcement, technological safeguards, and public awareness, ensuring that privacy remains meaningful in an increasingly interconnected world.

THE EVOLUTION OF PRIVACY AS A FUNDAMENTAL RIGHT IN THE AGE OF CYBER CRIME Read More »

SEBI AND DATA GOVERNANCE: EXAMINING JURISDICTIONAL OVERLAPS UNDER INDIA’S DIGITAL PERSONAL DATA PROTECTION FRAMEWORK

SEBI AND DATA GOVERNANCE: EXAMINING JURISDICTIONAL OVERLAPS UNDER INDIA’S DIGITAL PERSONAL DATA PROTECTION FRAMEWORK Rethiga Ramesh, Student, LLM in Business Law, Tamil Nadu Dr. Ambedkar Law University, School of Excellence in Law, Tamil Nadu, Chennai (India) Download Manuscript doi.org/10.70183/lijdlr.2026.v04.94 The role of financial market authorities has changed due to the growing datafication of securities market. The securities exchange board of India (SEBI) in India now heavily depends on the mandatory know your customer (KYC) regulations, centralized registries, transaction level surveillance, algorithmic trading oversights, and digital grievance redressal system, all of which entail the large-scale collection, processing, sharing, and retention of transactional and personal data. While these practices are justified in the interests of market integrity and investor protection, they raise significant legal questions in the context of the DPDPA, which establishes a comprehensive framework for personal data protection grounded in consent, purpose limitation, data minimization, the accountability. This article addresses whether SEBI’s data intensive regulatory framework effectively positions it as a de facto data regulator, given the absence of any explicit legislation stating the same. In addition to the DPDPA and the constitutional privacy jurisprudence under justice case K.S.Puttaswamy vs union of India, this article examines SEBI rules, circulars, and surveillance in systems using a doctrinal and analytical methodology. It illustrates how SEBI has functional authority over the data life cycle insecurities markets, leading to jurisdiction overlap and conflicts between data protection law and security regulation. This article makes the case that the DPDPA assumes regulatory coexistence without offering clear institutional hierarchy or conflict resolution procedures, therefore failing to effectively handle the function of sectoral regulators. This regulatory silence risks diluting investor privacy protection, increasing compliance uncertainty for intermediaries, and undermining constitutional requirements of proportionality and democratic accountability. This article suggests a harmonized regulatory structure that acknowledges SEBI functional data governance role while incorporating strong data privacy protections, drawing on limited comparative observations from the US and the UK. It concludes that an order to meet in both market integrity and constitutional legitimacy in India’s data driven financial ecosystem, it is imperative to explain the interaction between securities regulation and data privacy laws.

SEBI AND DATA GOVERNANCE: EXAMINING JURISDICTIONAL OVERLAPS UNDER INDIA’S DIGITAL PERSONAL DATA PROTECTION FRAMEWORK Read More »

PERSONALITY RIGHTS: AN EMERGING INTELLECTUAL PROPERTY RIGHT OR A SHIELD AGAINST DEEPFAKES?

PERSONALITY RIGHTS: AN EMERGING INTELLECTUAL PROPERTY RIGHT OR A SHIELD AGAINST DEEPFAKES? Manik Tindwani, Advocate, Rajasthan High Court (India) Vidhi Jangid, Student, University Five Year Law College, University of Rajasthan, Jaipur (India) Navya Paniyar, Student, University Five Year Law College, University of Rajasthan, Jaipur (India) Download Manuscript doi.org/10.70183/lijdlr.2025.v03.195 Personality rights now sit at a very fragile intersection of privacy, dignity, and commercial value in digital India. Rapid growth of generative AI and deepfake tools makes identity itself a manipulable asset which travels across borders in seconds. Celebrities, influencers, and ordinary users all face the risk that their face, voice, or mannerisms may be cloned for endorsement, humour, or even fraud without consent. Indian constitutional jurisprudence has recognised privacy and autonomy, yet statutory protection for personality remains fragmented across intellectual property and tort law. Recent Delhi High Court actions by film stars and digital creators show how personality rights are being tested against AI tools, deepfake filters, and viral content practices. This research examines whether personality rights in India are actually evolving into a distinct intellectual property right, or whether they still function mainly as a dignitary shield. It analyses how copyright, trademark, and passing off doctrines are stretched to respond to AI generated misappropriation of persona. It further evaluates whether such incremental judicial innovations are sufficient to deal with deepfakes, synthetic media, and cross border online harms. Comparative insights from EU and US frameworks highlight alternative approaches to publicity and image rights and raise important questions for Indian reform. The paper argues that Indian law must carefully frame personality rights to protect individuals against AI driven exploitation without chilling creativity, satire, and technological progress.

PERSONALITY RIGHTS: AN EMERGING INTELLECTUAL PROPERTY RIGHT OR A SHIELD AGAINST DEEPFAKES? Read More »

DATA PROTECTION IN CYBERSPACE: A COMPARATIVE LEGAL STUDY OF INDIA’S DPDP ACT, 2023 AND THE DPDP RULES, 2025 WITH THE EU GDPR

DATA PROTECTION IN CYBERSPACE: A COMPARATIVE LEGAL STUDY OF INDIA’S DPDP ACT, 2023 AND THE DPDP RULES, 2025 WITH THE EU GDPR Aaditya Gautam Balaji, LL.M. (Cyber Law and Cyber Security) student at SRM School of Law, SRMIST (India) Download Manuscript doi.org/10.70183/lijdlr.2025.v03.190 The rapid expansion of digital technologies has intensified concerns surrounding the collection, processing and cross-border movement of personal data, prompting jurisdictions to adopt comprehensive data protection frameworks. This paper undertakes a comparative cyber law analysis of India’s Digital Personal Data Protection regime, as operationalised through the DPDP Act, 2023 and DPDP Rules, 2025, with the European Union’s General Data Protection Regulation (GDPR). Using a doctrinal and comparative methodology, the study examines key dimensions of both regimes, including definitions and scope, lawful bases and consent architecture, rights of individuals, obligations of data fiduciaries/controllers, enforcement mechanisms, and cross-border data transfer frameworks. The analysis reveals that while the DPDP framework incorporates several globally recognised data protection principles, it reflects a distinct regulatory philosophy shaped by administrative efficiency, developmental priorities and regulatory flexibility. In contrast, the GDPR adopts a more rights-centric and institutionally robust model with detailed procedural safeguards and a decentralised supervisory structure. The paper argues that these structural and doctrinal differences have significant implications for individual rights protection, regulatory interoperability and compliance practices in an increasingly global digital economy. It concludes by offering targeted recommendations aimed at strengthening India’s data protection framework while maintaining contextual relevance and facilitating greater alignment with international standards.

DATA PROTECTION IN CYBERSPACE: A COMPARATIVE LEGAL STUDY OF INDIA’S DPDP ACT, 2023 AND THE DPDP RULES, 2025 WITH THE EU GDPR Read More »

CORPORATE COMPLIANCE IN THE ERA OF DATA PROTECTION AND CYBERSECURITY LAWS

CORPORATE COMPLIANCE IN THE ERA OF DATA PROTECTION AND CYBERSECURITY LAWS Rajat Sharma, LLM Student at Geeta Institute of Law (India) Download Manuscript doi.org/10.70183/lijdlr.2025.v03.127 The digital transformation of corporate ecosystems has fundamentally reshaped compliance obligations, particularly in the domains of data protection and cybersecurity. This research paper titled “Corporate Compliance in the Era of Data Protection and Cybersecurity Laws” examines the evolving legal landscape governing corporate accountability in India under the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, and related regulatory frameworks. It explores how corporate governance, ethical responsibility, and fiduciary obligations intersect with data protection mandates, requiring businesses to adopt privacy-by-design and risk-based compliance systems. The study further analyses international frameworks such as the EU’s GDPR, UK Data Protection Act, 2018, and US sectoral models, comparing their influence on India’s compliance regime. Emphasis is placed on corporate liability, enforcement mechanisms, cybersecurity risk management, and cross-border data transfer obligations. The paper concludes that an integrated governance model-rooted in ethics, transparency, and accountability-is vital for sustaining trust and resilience in the digital economy. The research adopts a doctrinal methodology, using statutory interpretation, judicial precedents, and comparative legal analysis to propose reforms that strengthen compliance culture and align Indian corporate regulation with global data protection standards.

CORPORATE COMPLIANCE IN THE ERA OF DATA PROTECTION AND CYBERSECURITY LAWS Read More »

THE EVOLUTION AND REGULATION OF E-COMMERCE IN INDIA: LEGAL FRAMEWORK, CHALLENGES, AND FUTURE DIRECTIONS

THE EVOLUTION AND REGULATION OF E-COMMERCE IN INDIA: LEGAL FRAMEWORK, CHALLENGES, AND FUTURE DIRECTIONS Dr. Siddhant Chandra, Assistant professor at Xavier law school , Xavier University (Kolkata) Dhiraj Kumar Sharma, Student of B.A LL.B 9th semester, Vinoba Bhave University, Hazaribag, Jharkhand (India) Download Manuscript doi.org/10.70183/lijdlr.2025.v03.123 India’s e-commerce sector has emerged as one of the fastest-growing digital markets globally, with projections indicating exponential growth from USD 107.7 billion in 2024 to USD 650.4 billion by 2033. This transformative growth is driven by increasing internet penetration, widespread smartphone adoption, robust digital payment infrastructure exemplified by the Unified Payments Interface (UPI), and progressive government initiatives such as Digital India. However, this rapid expansion has necessitated the development of a comprehensive legal and regulatory framework to address multifaceted challenges including consumer protection, data privacy, intermediary liability, intellectual property rights infringement, and cross-border taxation complexities. This research article examines the evolution of e-commerce in India through the lens of its regulatory architecture, analyzing key legislations such as the Information Technology Act 2000, Consumer Protection (E-Commerce) Rules 2020, and the Digital Personal Data Protection Act 2023. The study explores the dichotomy between marketplace and inventory-based business models, investigates emerging issues related to artificial intelligence-driven commerce, counterfeit goods proliferation, and cross-border transactions, and evaluates dispute resolution mechanisms including online dispute resolution platforms. Through doctrinal analysis and examination of judicial precedents, this article identifies critical gaps in the current regulatory framework and proposes recommendations for harmonizing consumer protection with innovation. The findings reveal that while India has established a progressive regulatory ecosystem, challenges persist in enforcement, platform accountability, and adapting to rapidly evolving technologies. The article concludes that a balanced approach integrating technological advancement with robust consumer safeguards is essential for sustainable e-commerce growth in India’s digital economy.

THE EVOLUTION AND REGULATION OF E-COMMERCE IN INDIA: LEGAL FRAMEWORK, CHALLENGES, AND FUTURE DIRECTIONS Read More »

CONSENT MECHANISMS UNDER THE DIGITAL PERSONAL DATA PROTECTION ACT, 2023: A COMPARATIVE LEGAL ANALYSIS WITH GDPR AND CCPA/CPRA

CONSENT MECHANISMS UNDER THE DIGITAL PERSONAL DATA PROTECTION ACT, 2023: A COMPARATIVE LEGAL ANALYSIS WITH GDPR AND CCPA/CPRA Vedant Raj Chaurasiya,BBA LLB (Final Year – X Sem.), Amity Law School, Amity University Madhya Pradesh Download Manuscript doi.org/10.70183/lijdlr.2025.v03.61 Consent remains a foundational pillar in contemporary data protection frameworks, yet its normative basis, scope, and enforceability vary significantly across jurisdictions. India’s enactment of the Digital Personal Data Protection Act, 2023 (DPDP Act) signals a shift towards a consent-centric model, but this framework departs in meaningful ways from the paradigms established under the European Union’s General Data Protection Regulation (GDPR) and California’s Consumer Privacy Act (CCPA), as enhanced by the California Privacy Rights Act (CPRA). This paper conducts a structured comparative and doctrinal analysis to examine how each of these regimes conceptualizes consent, the role of enforcement mechanisms, and the degree of autonomy afforded to individuals. The GDPR situates consent within a rights-based approach, requiring it to be freely given, informed, specific, and revocable—supported by institutional safeguards like independent data protection authorities and mandatory risk assessments. Conversely, the CCPA/CPRA reflects a consumer-choice model where transparency and opt-out functionality dominate, with consent obligations emerging only in limited scenarios. The DPDP Act, though framed around consent, weakens its efficacy by introducing expansive “deemed consent” provisions and lacking critical oversight tools such as mandatory Data Protection Impact Assessments (DPIAs) or a fully independent regulatory authority. The analysis further explores the consequences of this design on India’s cross-border data transfer capability, especially its divergence from GDPR adequacy standards. Arguing for the evolution of a consent-plus architecture, this paper recommends enhancements such as fiduciary accountability, dynamic and context-sensitive consent models, and user interfaces tailored to India’s socio-linguistic diversity. These interventions are imperative for strengthening user autonomy, enhancing legal coherence, and enabling India’s data regime to stand alongside global best practices in digital rights governance.

CONSENT MECHANISMS UNDER THE DIGITAL PERSONAL DATA PROTECTION ACT, 2023: A COMPARATIVE LEGAL ANALYSIS WITH GDPR AND CCPA/CPRA Read More »