LIJDLR

Regulation

CYBER RISK ASSOCIATED WITH QR CODES AND THEIR REGULATION IN INDIA

CYBER RISK ASSOCIATED WITH QR CODES AND THEIR REGULATION IN INDIA Akshaya A, LLM (Cyber Space Law and Justice), 1st Year, Student at School of Excellence in Law, The Tamil Nadu, Dr. Ambedkar Law University, Chennai (India) Download Manuscript doi.org/10.70183/lijdlr.2026.v04.175 QR code (Quick response codes) are one of the major digital transformations in India. Several countries around the world have adopted QR code for availing various digital services, most especially for mobile payments. Every digital development will definitely have risks or complications, threats and vulnerabilities. So, this paper evaluates whether there is sufficient legal framework for regulation of QR codes used in various sector in India such as banking/merchant payment, business, education, government services, web access etc. The widespread adoption of digital services for everyday transactions, without fully understanding of it’s their implications raise concerns about potential future issues. Therefore, effective collaboration between the financial sector, especially the Reserve Bank of India, cyber security centres, e-governance regulatory bodies, and educational institutions is essential to ensure safe and secure digital access and transactions. Developing countries like India, must take proactive initiatives to strengthen rules and raise awareness about the appropriate usage of QR codes in this digital age. Sector specific regulations of QR code is developed primarily in the banking and financial sector, whereas in most other sectors QR codes are widely used but the regulatory framework remains largely silent. Technical enhancement to a QR code should also ensure its reliability and functionality. AI based scams and other advanced risk are often closely associated with the rapid growth of emerging technologies. So, law should always be ready to prevent or curb the risk out of these emerging digital technologies. The increasing us of QR codes raises significant concerns on security and privacy. Mere awareness is not sufficient to address the risk arising from digital initiatives. A Combined approach of legal reforms and technical advancement is essential to mitigate this risk and to build to “Secure Digital India”.

CYBER RISK ASSOCIATED WITH QR CODES AND THEIR REGULATION IN INDIA Read More »

THE REGULATORY CONUNDRUM: A MULTIDIMENSIONAL ANALYSIS OF THE DIGITAL PERSONAL DATA PROTECTION ACT, 2023, AND ITS IMPLICATIONS FOR INDIAN STARTUPS

THE REGULATORY CONUNDRUM: A MULTIDIMENSIONAL ANALYSIS OF THE DIGITAL PERSONAL DATA PROTECTION ACT, 2023, AND ITS IMPLICATIONS FOR INDIAN STARTUPS Parul Shukla, Law Centre II, University of Delhi. Download Manuscript doi.org/10.70183/lijdlr.2025.v03.78 The Digital Personal Data Protection Act, 2023 (DPDP Act), marks India’s first comprehensive data protection legislation, reaffirming the constitutional right to privacy as upheld in K.S. Puttaswamy v. Union of India (2017). This paper employs a multidimensional analytical framework encompassing political, social, economic, technological, environmental, and legal (PSETEL) lenses to evaluate the Act’s implications on India’s startup ecosystem, particularly data-intensive sectors such as SaaS, health-tech, ed-tech, and fintech. Politically, while aligning with global benchmarks like the GDPR, the Act asserts digital sovereignty through the creation of the Data Protection Board of India, which wields enforcement and adjudicatory powers under Section 27, thus balancing innovation incentives under Section 17(1)(e) with concerns of potential executive overreach. Socially, the Act enhances data principal rights, including informed consent, correction, and erasure, expected to improve consumer trust, though requirements like verifiable parental consent (Section 9) may affect user acquisition strategies, especially in ed-tech sectors. Economically, compliance costs are projected to increase by 7–10% for early-stage startups due to obligations such as appointing Data Protection Officers and conducting Data Protection Impact Assessments, with non-compliance penalties extending up to Rs. 250 Crores under Schedule I. Technologically, the Act necessitates system-wide changes in data processing and architecture to meet principles of data minimization and purpose limitation, though its regulatory silence on AI and ML raises compliance ambiguities. Environmentally, data localization mandates could elevate energy demands through the expansion of domestic data centers, albeit offset partially by sustainable data minimization practices. Legally, the Act’s extraterritorial scope (Section 3), mandatory breach reporting (Section 8), and amendments to the RTI Act create regulatory uncertainties and increase administrative burdens, particularly for cross-border operations. Despite these challenges, the Act presents opportunities for startups to differentiate themselves through ethical data stewardship, thereby aligning with India’s ambition of achieving a USD 1 trillion digital economy by 2030.

THE REGULATORY CONUNDRUM: A MULTIDIMENSIONAL ANALYSIS OF THE DIGITAL PERSONAL DATA PROTECTION ACT, 2023, AND ITS IMPLICATIONS FOR INDIAN STARTUPS Read More »