There are some advantages of the Digital Personal Data Protection Act (DPDPA), 2023. For instance, for the first time, personal data belonging to or identifying children will have to be classified separately, with such data carrying a greater degree of security and privacy. The law also seeks to reduce the rate and impact of data breaches targeting Indian businesses.
The Digital Personal Data Protection law, however, goes a step beyond by imposing penalties for cases where data is breached as a result of a lack of implementation of adequate security controls. However, it could be said that the law isn’t balanced, because it provides wide exemptions to the processing of personal data to the government. For instance, data can be processed “in the interest of prevention, detection, investigation or prosecution of any offence ... in India.” These kinds of exemptions are dangerous as they stand to legitimise widespread and unwarranted collection of data under the guise that such collection and processing may ultimately be useful for preventing or deterring a crime.
Security agencies will have significant authority to collect and retain any data whatsoever, as is typically the case with exemptions relating to the maintenance of sovereignty, integrity, security of the state, preservation of public order, prevention of offences, and incitement to commit offences. The law also exempts processing of personal data held outside of India. The government is also exempt from being required to delete any data that it possesses, regardless of the purpose it may have been collected for, on the request of an individual, or by way of a prescribed data retention period.
The government is not bound by purpose limitations, allowing data collected for one specified purpose to be used for a new, incompatible purpose, which stands in contrast to the regulations imposed on businesses.
In which of the following cases, the access to personal data shall be granted and the person whose data is accessed and processed cannot claim personal data protection?
Correct Answer :
Both (A) and (B).
Solution :
Correct Answer: Both (A) and (B).
Explanation:
The provided text outlines key provisions and exemptions under the Digital Personal Data Protection Act (DPDPA), 2023. Specifically, it highlights that the government is granted wide exemptions from standard data protection rules for processing personal data under specific conditions.
According to the passage:
1. Data can be processed without standard restrictions "in the interest of prevention, detection, investigation or prosecution of any offence ... in India."
2. Security agencies and law enforcement have significant authority to collect and retain data for reasons relating to the "preservation of public order, prevention of offences, and incitement to commit offences."
Now, let's analyze the given cases:
• Case (A): Police accessing the Aadhaar details and fingerprint data of Mr. Z to trace him because he committed multiple robberies falls directly under the "investigation or prosecution of an offence." Therefore, government access is granted and Mr. Z cannot claim personal data protection in this context.
• Case (B): Police using the mobile number and personal details of Mr. G to prevent him from spreading hatred and causing riots falls under the "prevention of offences" and "preservation of public order." Thus, personal data access is granted, and data protection claims do not apply.
Since both situations (A) and (B) fall under the legally exempted government processing purposes mentioned in the passage, the correct choice is Both (A) and (B).
Access expert-curated educational resources and study materials—completely free.
Create, conduct, and manage professional online assessments with Mindyard. Perfect for teachers and institutes.
Copyright © 2026 Mindyard. All Rights Reserved.