Word of the Day
Loading... Fetching today's legal term...
DPDP Act 2023 & Media Law

DPDP Act 2023 & Intersecting Laws for the Press

Navigating Compliance, Journalistic Exposure & High-Stakes Liabilities | Client Advisory
(Author’s Outlook)
DPDP Act 2023 & Intersecting Laws for the Press
CRITICAL STATUTORY PENALTY WARNING:

Non-compliance under the Digital Personal Data Protection Act, 2023 carries statutory penalties of up to ₹250 Crore per violation. Media organisations face severe exposure due to high-volume subscriber databases, print-to-digital workflows, and investigative editorial practices.

1. Statutory Scope & The Absence of Journalistic Carve-Out

Unlike global privacy legislation such as the EU GDPR or previous legislative drafts in India, the Digital Personal Data Protection (DPDP) Act, 2023 contains no statutory exemption for journalistic or media activities.

Scope of Coverage [Section 3(a)]: The Act applies to the processing of personal data within India that is collected in digital form OR collected non-digitally and subsequently digitized. This is particularly critical for print publishers, whose paper subscriber forms, offline event registries, or legacy physical archives become subject to DPDP mandates the moment they are scanned, entered into databases, or processed electronically.

Data Fiduciary Classification: Media houses—spanning print, broadcast, and digital platforms—are classified as Data Fiduciaries under Section 2(i) wherever they determine the purpose and means of data processing.

2. Operationalizing DPDP Across Media Verticals

A. Editorial & Journalistic Data (The Newsroom)

Publicly Available Data Exemption [Section 3(c)(ii)]: The Act does not apply to personal data that the Data Principal herself has made publicly available (e.g., public social media posts, speeches) or that is required by law to be public. This forms the primary legal basis for daily news reporting.

Investigative Journalism & Non-Public Data: If journalists obtain private digital data (e.g., leaked documents, private chats, sting operation logs) that the subject did not make public, processing without consent sits in a grey zone. Newsrooms must rely on constitutional free speech rights (Article 19(1)(a)) and rigorous public interest justification until judicial precedent or statutory rules clarify editorial processing.

B. Commercial & Subscriber Data (Circulation & Digital Media)

For paywalls, newsletters, targeted ads, and app analytics, full Data Fiduciary obligations apply. Processing requires specific, informed, and unconditional consent [Section 6(1)] preceded by standalone notices [Section 5(1)], with an equally easy consent withdrawal mechanism [Section 6(4)].

C. Workforce Data: Employees vs. Stringers & Freelancers

Full-Time Employees [Section 7(i)]: Employers may process employee personal data without explicit consent under 'certain legitimate uses' for employment purposes, payroll, corporate security, or safeguarding against liability/espionage.

Stringers, Freelancers & Columnists (Independent Contractors):

  • Section 7(i) specifically applies to a Data Principal who is an employee.
  • Independent journalists, retainers, and stringers fall outside Section 7(i).
  • Media houses cannot rely on employment legitimate use for freelancer data and must instead establish contract necessity, voluntary provision [Section 7(a)], or explicit consent.

3. Phased Implementation Timeline (DPDP Rules, 2025)

The DPDP Rules, 2025 were notified on 13 November 2025 (G.S.R. 846(E)). Substantive obligations are subject to a staggered commencement schedule, allowing entities time to build technical capabilities:

Effective Date Rules in Force Operational Mandates & Scope
13 Nov 2025
(In Force)
Rules 1, 2, 17–21 Board establishment machinery, Search-cum-Selection Committee, Digital Office rules, Appellate Tribunal (TDSAT) appeal procedures.
13 Nov 2026 Rule 4 Consent Manager registration framework opens before the Data Protection Board.
~13 May 2027
(+18 Months)
Rules 3, 5–16,
22, 23
Full Enforcement: Notice, consent mechanics, breach intimation, erasure rules, children's verifiable consent, SDF duties, Data Principal rights, and cross-border transfer requirements.

4. The Intersecting Legal Web: Harmonizing Parallel Statutes

A. IT Act, 2000 & CERT-In Dual-Clock Incident Reporting

Personal data breaches trigger two distinct, parallel statutory reporting mechanisms:

  • CERT-In Reporting (IT Act S.70B): Mandatory reporting of cybersecurity incidents to CERT-In within 6 hours of detection.
  • DPDP Breach Reporting (Section 8(6) & Rule 7): A two-stage process requiring initial notification to the Board and affected Data Principals without delay [Rule 7(1), Rule 7(2)(a)], followed by a detailed, updated report to the Board within 72 hours [Rule 7(2)(b)].

B. RTI Act, 2005 (Section 8(1)(j) & Section 8(2))

Section 44(3) of the DPDP Act amends Section 8(1)(j) of the RTI Act to remove the former 'public interest' balancing exception for personal information. In practice, this creates a major barrier for investigative reporters seeking personal records from public authorities. However, legally, the discretionary public-interest override under Section 8(2) of the RTI Act remains structurally intact, though public authorities rarely invoke it to grant access to personal data.

C. Sectoral Data Retention: Statutory Carve-Out under Section 8(7)

Section 8(7) of the DPDP Act mandates erasing personal data when the specified purpose is served or consent is withdrawn. However, Section 8(7) explicitly carves out cases where retention is necessary for compliance with any law for the time being in force:

  • Tax & Corporate Laws: Income Tax Act and Companies Act, 2013 mandate retaining financial and transaction records for 7–8 years.
  • RBI Payment Guidelines: Financial subscriber records must be retained per RBI norms, overriding DPDP erasure requests for that specific data.
  • Press & Registration of Periodicals (PRP) Act, 2023: Publisher and subscriber registries maintained for statutory compliance are protected under the Section 8(7) retention exception.

5. Contingent Obligations, Transfers & Special Classifications

A. Significant Data Fiduciary (SDF) Status [Section 10] — Contingent Basis

Entities are designated as SDFs only upon specific notification by the Central Government based on factors like data volume, sensitivity, public order, or risk to electoral democracy. As of mid-2026, no news organization or digital platform has been formally notified as an SDF, nor have numerical thresholds been set. If and when notified, an SDF must appoint an India-based DPO, an independent auditor, and conduct annual DPIAs [Rule 13].

B. Cross-Border Data Transfers

The DPDP Act allows for the transfer of personal data outside India by default, taking a 'blacklist' approach where the Central Government may notify specific countries to which transfers are restricted. However, media platforms utilizing foreign cloud services must ensure any transfers comply with these restrictions and establish contracts that uphold Indian data protection standards.

C. Large Platform 3-Year Erasure Rules [Rule 8 & Third Schedule]

Regardless of SDF status, e-commerce entities and social media platforms with ≥ 2 crore users, or online gaming platforms with ≥ 50 lakh users, face a mandatory 3-year data erasure timeline from last user interaction (excluding account access and stored virtual tokens).

D. Children's Data Restrictions [Section 9 & Rule 10]

Youth portals processing data of individuals under 18 must obtain verifiable parental consent and are strictly barred from targeted advertising or behavioral tracking, unless covered by Fourth Schedule exemptions (e.g., educational institution safety/monitoring).

6. Actionable Implementation Roadmap

Step 1. Data Classification & Digitization Audit:
Audit physical-to-digital workflows (print subscriber forms) under Section 3(a).
Separate workforce data into Employees (Section 7(i)) and Freelancers/Stringers (requiring contract/consent grounds).

Step 2. Dual-Track Incident Response Playbook:
Establish an internal SOC playbook addressing both the 6-hour CERT-In deadline and the two-stage DPDP Board notification ('without delay' initial, 72-hour detailed report).

Step 3. Statutory Retention Matrix:
Document specific statutory laws (Tax, Companies Act, RBI) relied upon under Section 8(7) to justify retaining data post-consent withdrawal or account closure.

Step 4. Newsroom & Editorial Legal Briefing:
Train journalists on the scope of the Publicly Available Data exemption [Section 3(c)(ii)] and establish legal protocols for non-public digital evidence.

Step 5. Phase-In Preparation (~May 2027 Deadline):
Utilize the 18-month window to implement consent management solutions, update cloud vendor contracts regarding cross-border transfers, and establish DPO contact publishing mechanics.

7. How JTS Lex Can Assist Your Organization, if needed?

At JTS Lex, we provide end-to-end legal advisory and compliance structuring to help media houses, digital publishers, and corporate entities seamlessly navigate the DPDP Act, 2023 framework without interrupting core operations.

  • DPDP Compliance Audit & Data Mapping: Conducting comprehensive audits of physical and digital data pipelines, subscription workflows, and legacy archives to map statutory coverage under Section 3(a).
  • Contractual Restructuring & Freelancer DPAs: Drafting specialized Data Processing Agreements (DPAs), non-disclosure covenants, and consent frameworks tailored for stringers, columnists, and independent contractors to bridge the Section 7(i) exclusion.
  • Editorial & Investigative Protocol Drafting: Structuring legal protocols and compliance guidelines for editorial desks to balance Section 3(c)(ii) public domain exemptions with constitutional protections under Article 19(1)(a).
  • Dual-Track Incident Response & SOC Integration: Designing customized breach management playbooks to satisfy both CERT-In 6-hour requirements and DPDP Board 72-hour filing mandates.
  • Statutory Retention Matrix & Notice Architecture: Developing retention schedules under Section 8(7) harmonized with tax, corporate, and RBI rules, alongside standalone Section 5(1) consent notices for paywalls and digital platforms.
Sachin Tulsi, Advocate — JTS Lex

About the Author:

Sachin Tulsi, former under-secretary to the Government of India with 20 years of unblemished service, a key member of JTS Lex since 2020. Now a lawyer and social activist, he dedicated himself to public awareness, music, and theatre. His mission focuses on disseminating information on consumer rights, environmental responsibility, and fundamental duties to empower people-centric decision-making.

Disclaimer: The insights shared in this article represent the personal viewpoint/interpretation and professional outlook of the author and do not necessarily reflect the official position of the firm, JTS Lex.
← Back to Legal Insights