AMLEGALS — Strategic Lawyering
Constitutional Foundation

Puttaswamy and the right to privacy: the constitutional bedrock of the DPDPA

On 24 August 2017, a nine-judge bench of the Supreme Court of India delivered its unanimous verdict in Justice K.S. Puttaswamy (Retd.) v. Union of India: the right to privacy is a fundamental right, protected under Article 21 (right to life and personal liberty), Article 19 (freedom of speech and expression) and Article 14 (right to equality) of the Constitution. That judgment created the constitutional mandate from which the Digital Personal Data Protection Act, 2023, directly descends.

Updated · Checked against the DPDP Act, 2023 and the DPDP Rules, 2025 · 5 min read

Abstract classical pillars merging with geometric data lattice on navy and gold background
Short answer

The Supreme Court in Puttaswamy (2017) held unanimously that the right to privacy is a fundamental right under Articles 21, 19 and 14 of the Constitution. Any state action restricting privacy must satisfy a three-part test: legality (prescribed by law), legitimate aim (a valid state interest) and proportionality (the restriction must be proportionate to the need). The DPDPA is Parliament’s legislative response to this mandate—it provides the “prescribed by law” leg of the test for data processing.

  • Right to Privacy
  • Puttaswamy
  • Article 21
  • Supreme Court
  • Constitutional Law
  • DPDPA
Judgment date
24 August 2017
Bench strength
Nine judges (unanimous)
Core holding
Privacy is a fundamental right
Constitutional basis
Articles 21, 19, 14

Why the case arose: Aadhaar and the privacy question

The litigation began as a challenge to the Aadhaar programme. Petitioners argued that mandatory biometric enrolment violated their right to privacy. The Union of India contended that no fundamental right to privacy existed—relying on two earlier decisions, M.P. Sharma v. Satish Chandra (1954, eight-judge bench) and Kharak Singh v. State of Uttar Pradesh (1962, six-judge bench), which had declined to recognise a standalone privacy right.

A three-judge bench hearing the Aadhaar challenge referred the threshold question—“Is privacy a fundamental right?”—to a larger bench. The Chief Justice of India constituted a nine-judge bench, the largest in decades, to settle the matter.

The holding: privacy as a fundamental right

All nine judges agreed that the right to privacy is constitutionally protected. The majority opinion (by Justice D.Y. Chandrachud, concurred in by the Chief Justice and Justices Agrawal, Nazeer and Sapre) located privacy in the concept of personal liberty under Article 21, with intersections in the freedoms guaranteed by Article 19(1)(a) (speech) and the equality protection of Article 14.

The judgment overruled M.P. Sharma and Kharak Singh to the extent they held that no right to privacy existed. Justice Chelameswar, Justice Bobde, Justice Nariman and Justice Kaul each wrote concurring opinions that expanded on different dimensions—informational privacy, bodily autonomy, the privacy of choice—but all converged on the conclusion that privacy is a fundamental right.

  • Article 21: privacy inheres in the right to life and personal liberty
  • Article 19(1)(a): privacy protects informational self-determination and freedom of thought
  • Article 14: state surveillance applied unequally violates the right to equality
  • Overruled: M.P. Sharma (1954) and Kharak Singh (1962) to the extent they denied a privacy right

The three-part test for restricting privacy

A fundamental right is not absolute. The judgment established that any state restriction on the right to privacy must satisfy three requirements:

  1. 01

    Legality

    The restriction must be prescribed by law—an existing statute, not an executive order or administrative practice. The DPDPA serves precisely this function: it is the “law” that authorises and constrains data processing by Data Fiduciaries.

  2. 02

    Legitimate aim

    The law must serve a legitimate state interest—national security, prevention of crime, public health or another recognised purpose. Section 7 of the DPDPA lists the “legitimate uses” that justify processing without consent.

  3. 03

    Proportionality

    The means adopted must be proportionate to the need. The DPDPA’s purpose-limitation principle (Section 4), data-minimisation requirement and time-bound retention (Section 8(7)) are proportionality mechanisms.

Informational privacy and data protection

Justice Sanjay Kishan Kaul’s concurrence identified informational privacy as a distinct facet of the right to privacy. Informational privacy concerns the individual’s ability to control what data about them is collected, who holds it and how it is used.

This dimension is the direct constitutional anchor for the DPDPA. Section 6 (consent), Section 5 (notice), Sections 11–14 (Data Principal rights) and Section 8(7) (erasure upon purpose completion) are legislative implementations of informational privacy as articulated in Puttaswamy.

The judgment also noted that a data-protection framework was an “essential facet” of personal liberty—effectively mandating Parliament to enact comprehensive data-protection legislation.

From Puttaswamy to the DPDPA: the legislative journey

The judgment triggered a sequence of legislative efforts. Justice B.N. Srikrishna was appointed to chair a committee on data protection. The committee’s report (“A Free and Fair Digital Economy”, July 2018) accompanied a draft Personal Data Protection Bill, 2018. That Bill was revised and introduced in Parliament as the Personal Data Protection Bill, 2019, referred to a Joint Parliamentary Committee, and finally withdrawn in 2022.

The Digital Personal Data Protection Act, 2023, was introduced as a fresh Bill, passed by Parliament on 9 August 2023, and received Presidential assent on 11 August 2023. The DPDP Rules were notified in November 2025. Core obligations take effect from May 2027.

Timeline from Puttaswamy to full DPDPA enforcement
DateEventSignificance
24 Aug 2017Puttaswamy judgmentRight to privacy declared fundamental; data-protection law mandated
Jul 2018Srikrishna Committee reportFirst comprehensive data-protection Bill drafted
Dec 2019PDP Bill introduced in Lok SabhaReferred to Joint Parliamentary Committee
Aug 2022PDP Bill withdrawnGovernment opted for a fresh approach
11 Aug 2023DPDPA receives Presidential assentIndia’s first comprehensive data-protection statute enacted
Nov 2025DPDP Rules 2025 notifiedProcedural framework for compliance set
May 2027Core obligations take effectFull enforcement begins

Why Puttaswamy still matters for compliance

The judgment is not merely historical. Any challenge to DPDPA provisions—or to government processing under Section 17 exemptions—will be tested against the Puttaswamy three-part framework. If a Section 17 notification fails the proportionality test, it can be struck down.

For Data Fiduciaries, Puttaswamy provides the interpretive lens through which courts will read the DPDPA. Purpose limitation, data minimisation and time-bound retention are not just statutory obligations—they are constitutional expectations. A compliance programme that meets the statutory letter but ignores the proportionality spirit risks judicial scrutiny.

How AMLEGALS advises on constitutional data privacy

AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder and Managing Partner, with Rohit Lalwani, Associate Partner, working on DPDPA compliance. The firm assists organisations in understanding how the Puttaswamy framework shapes their DPDPA obligations, advises on proportionality-aligned compliance programmes, and represents parties in Data Protection Board proceedings where constitutional questions arise.

Bottom line

Puttaswamy is not a historical footnote—it is the active constitutional standard against which every DPDPA provision, exemption and enforcement action will be judged.

Key terms
Three-part test (Puttaswamy)
Any restriction on the right to privacy must satisfy legality (prescribed by law), legitimate aim (valid state interest) and proportionality (means proportionate to need).
Informational privacy
The facet of the right to privacy concerning an individual’s control over personal data—what is collected, who holds it and how it is used.
Article 21
Article 21 of the Constitution of India: “No person shall be deprived of his life or personal liberty except according to procedure established by law.” The Supreme Court located the right to privacy within this article.
Questions and answers

Puttaswamy & Right to Privacy: common questions

Is the right to privacy absolute under Indian law?

No. The right to privacy is a fundamental right but can be restricted if the restriction passes the three-part test: it must be prescribed by law, serve a legitimate aim and be proportionate to the need. The DPDPA provides the “prescribed by law” framework for data processing.

Did Puttaswamy directly create the DPDPA?

The judgment mandated that Parliament enact a data-protection law. The legislative journey went through the Srikrishna Committee (2018), the Personal Data Protection Bill (2019), its withdrawal (2022), and the fresh DPDPA (2023). The judgment created the constitutional obligation; Parliament fulfilled it.

Can the DPDPA itself be challenged as unconstitutional?

In principle, yes. Any DPDPA provision that fails the Puttaswamy proportionality test could be challenged. Government exemptions under Section 17 are the most likely targets—if a notification exempts the state from obligations without a proportionate justification, it is vulnerable.

How does Puttaswamy affect everyday compliance?

It requires Data Fiduciaries to treat purpose limitation, data minimisation and proportionality not just as statutory boxes to tick but as constitutional expectations. Courts interpreting the DPDPA will use the Puttaswamy framework as the guiding lens.

Contact

Questions on constitutional data privacy?

Send a question about how the Puttaswamy framework shapes your DPDPA obligations.

Or write to [email protected]

Your details

Name and email are enough to start. The reply comes from [email protected].

Your information is handled in accordance with our privacy obligations. No spam, ever.

Puttaswamy & Right to Privacy: questions and answers

What is the legal framework for data protection in India?

India's framework is the Digital Personal Data Protection Act, 2023 (Presidential assent 11 August 2023; 44 sections) read with the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 (G.S.R. 846(E)) with 23 Rules and 7 Schedules.

When do DPDPA obligations apply to businesses?

The Act and Rules follow phased commencement. Institutional provisions commenced on 13 November 2025; Consent Manager provisions commence after 12 months on 13 November 2026; and the principal Data Fiduciary, rights, breach, security and enforcement provisions commence after 18 months on 13 May 2027.

What is the maximum penalty under DPDPA?

Highest listed maximum for a specified contravention: ₹250 crore under the Schedule to the Act. Penalties are imposed by the Data Protection Board of India after an inquiry, and Section 33(2) requires the Board to consider factors such as the nature, gravity and duration of the breach, the type of personal data affected, repetition, mitigation steps and proportionality.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to Puttaswamy & Right to Privacy?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on Puttaswamy & Right to Privacy under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on Puttaswamy & Right to Privacy under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on Puttaswamy & Right to Privacy?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for Puttaswamy & Right to Privacy rather than a generic checklist.

How do I get a first view of my DPDPA exposure on Puttaswamy & Right to Privacy?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about Puttaswamy & Right to Privacy · DPDPA Exposure Assessment