There are some advantages of the Digital Personal Data Protection Act (DPDPA), 2023. For instance, for the first time, personal data belonging to or identifying children will have to be classified separately, with such data carrying a greater degree of security and privacy. The law also seeks to reduce the rate and impact of data breaches targeting Indian businesses.
The Digital Personal Data Protection law, however, goes a step beyond by imposing penalties for cases where data is breached as a result of a lack of implementation of adequate security controls. However, it could be said that the law isn’t balanced, because it provides wide exemptions to the processing of personal data to the government. For instance, data can be processed “in the interest of prevention, detection, investigation or prosecution of any offence ... in India.” These kinds of exemptions are dangerous as they stand to legitimise widespread and unwarranted collection of data under the guise that such collection and processing may ultimately be useful for preventing or deterring a crime.
Security agencies will have significant authority to collect and retain any data whatsoever, as is typically the case with exemptions relating to the maintenance of sovereignty, integrity, security of the state, preservation of public order, prevention of offences, and incitement to commit offences. The law also exempts processing of personal data held outside of India. The government is also exempt from being required to delete any data that it possesses, regardless of the purpose it may have been collected for, on the request of an individual, or by way of a prescribed data retention period.
The government is not bound by purpose limitations, allowing data collected for one specified purpose to be used for a new, incompatible purpose, which stands in contrast to the regulations imposed on businesses.
Suppose Mr. Y, a citizen of India, is working in an MNC in New Zealand since 2021. The MNC has obtained personal details of the employee for the purpose of recovering the amount of indemnity bond if Mr. Y left the job within three years of joining.
Correct Answer :
The DPDPA 2023 is not applicable since the data is held outside India.
Solution :
Correct Answer: The DPDPA 2023 is not applicable since the data is held outside India.
Step-by-Step Explanation:
1. Understanding the Core Scenario:
Mr. Y is working in a Multinational Corporation (MNC) located in New Zealand. The MNC collected his personal details and holds this data outside of India for employment contract purposes (indemnity bond recovery).
2. Analyzing the Passage Details regarding DPDPA Applicability:
According to the third paragraph of the provided text, the Digital Personal Data Protection Act (DPDPA), 2023 contains explicit provisions regarding geographic scope and exemptions. Specifically, the text notes: "The law also exempts processing of personal data held outside of India."
3. Applying the Rule to Mr. Y's Case:
Since Mr. Y's personal data is collected and held by an MNC located in New Zealand (outside the territory of India), the processing of this data falls directly under the statutory exemption mentioned in the law. Consequently, the protection provisions of DPDPA 2023 do not apply to this specific data held outside of India.
Conclusion:
Therefore, the statement "The DPDPA 2023 is not applicable since the data is held outside India" accurately reflects the provisions outlined in the passage.
Access expert-curated educational resources and study materials—completely free.
Create, conduct, and manage professional online assessments with Mindyard. Perfect for teachers and institutes.
Copyright © 2026 Mindyard. All Rights Reserved.