There are some advantages of the Digital Personal Data Protection Act (DPDPA), 2023. For instance, for the first time, personal data belonging to or identifying children will have to be classified separately, with such data carrying a greater degree of security and privacy. The law also seeks to reduce the rate and impact of data breaches targeting Indian businesses.
The Digital Personal Data Protection law, however, goes a step beyond by imposing penalties for cases where data is breached as a result of a lack of implementation of adequate security controls. However, it could be said that the law isn’t balanced, because it provides wide exemptions to the processing of personal data to the government. For instance, data can be processed “in the interest of prevention, detection, investigation or prosecution of any offence ... in India.” These kinds of exemptions are dangerous as they stand to legitimise widespread and unwarranted collection of data under the guise that such collection and processing may ultimately be useful for preventing or deterring a crime.
Security agencies will have significant authority to collect and retain any data whatsoever, as is typically the case with exemptions relating to the maintenance of sovereignty, integrity, security of the state, preservation of public order, prevention of offences, and incitement to commit offences. The law also exempts processing of personal data held outside of India. The government is also exempt from being required to delete any data that it possesses, regardless of the purpose it may have been collected for, on the request of an individual, or by way of a prescribed data retention period.
The government is not bound by purpose limitations, allowing data collected for one specified purpose to be used for a new, incompatible purpose, which stands in contrast to the regulations imposed on businesses.
Suppose the DPDPA, 2023 provided exemption for the processing of personal data for the purpose of ascertaining the financial position of any person who has defaulted in payment of amount due on loan taken from a nationalised bank. Mr. X commits a default in repayment of EMI of loan taken from a nationalised bank.
Correct Answer :
The bank can process the data of Mr. X for the purpose of ascertaining the assets and liabilities of the defaulter.
Solution :
The correct answer is: The bank can process the data of Mr. X for the purpose of ascertaining the assets and liabilities of the defaulter.
Step-by-Step Explanation:
1. Analyze the Premise and Scope of the Exemption:
The prompt specifies a hypothetical situation where the DPDPA, 2023 provides an exemption for processing personal data specifically for the purpose of ascertaining the financial position of a person who has defaulted on a loan from a nationalised bank.
2. Evaluate the Relevance of Data Types:
Since Mr. X has defaulted on his loan EMI, the bank is permitted to utilize the exemption strictly within its stated purpose: ascertaining his financial position.
- Data regarding family history of medical ailments is unrelated to financial standing and privacy rights would protect such sensitive information.
- Particulars of extended family members (wife, children, brothers, etc.) are irrelevant to determining Mr. X's individual financial default unless directly tied to financial assets or guarantees.
- Data regarding assets and liabilities directly reflects an individual's financial position and capacity to satisfy debt obligations.
3. Conclusion:
Therefore, the bank can only process personal data of Mr. X that relates specifically to evaluating his financial status, namely his assets and liabilities.
Access expert-curated educational resources and study materials—completely free.
Create, conduct, and manage professional online assessments with Mindyard. Perfect for teachers and institutes.
Copyright © 2026 Mindyard. All Rights Reserved.