This article is written by Varshni Krishnan, Legal Content Manager at Lawctopus
You may have heard of the DPDP Act and the new DPDP Rules. But before we dive into knowing all those things, let’s take a pause and just think of how much personal information we give away while scrolling through the different apps in our smartphones!
You unlock your phone with your face. Order breakfast on Zomato. Book a cab and share your live location. Shop online. And somewhere between all of this, you probably click “I Agree” on a privacy notice without reading beyond the first line.
For years, most of us have treated this as the price of being online. We give the information, click the button and move on.

India’s Digital Personal Data Protection Rules, 2025 may begin to change that relationship.
If you are wondering how the DPDP Rules affect internet users in India, you do not need to understand every definition in the law. What matters is much simpler:
- What information can an app ask from you?
- What must it tell you?
- What can you ask it to do with your data?
- And, what happens when something goes wrong?
So before you click on ‘I agree’, read through the post below to understand the new framework and what it could mean for a daily smartphone user:
What Exactly Are the DPDP Rules?
The Digital Personal Data Protection Act, 2023 laid down the basic rules for how personal data should be handled in India. The DPDP Rules 2025 provide the practical implementation of the Act by laying down the requirements for collection, processing, security, retention and deletion of personal data.1
In simple terms, a Data Principal is the individual to whom the personal data relates, while a Data Fiduciary is the person or organisation that decides why and how that personal data will be processed.2

The Act is like the goal. The Rules are like the steps to get to the goal. Or the details of how you achieve the goal.
The changes brought by the DPDP Rules will not be seen overnight. But when applicable and well understood, it will make everyday interactions different.
Changes to privacy notices in apps and on the web
You load an application. You’re shown a privacy notice long enough to qualify as weekend reading, before you can use it. And then you click ‘Yes’ without even reading it all.
Any company that collects your personal data must give you a notice that is easily understandable on its own and in clear and plain language, under Rule 3 of the DPDP Rules.3

The notice must specify the personal data being collected, and the particular purpose for which it will be processed. There will also be a simple way to withdraw your consent on any app or website and exercise your right to protect your data.
Keep your personal data ‘Personal’
Let’s take an example to understand this. Imagine having an account in an e-commerce website for more than 5 years but not using the app anymore. But the e-commerce app will still have the data or permissions that you signed up for 5 years back. What can be the possible options to know what they will do with it?
Under the DPDP Rules, You can ask for information about the personal data being processed and certain details about how it has been handled. If your information is incorrect or not valid anymore, you can ask for it to be corrected or updated.
You can also request deletion of your personal data, subject to situations where the company is legally required to retain it.4
The Rules also require companies to clearly publish how users can exercise their rights and how they can raise grievances.5
In practical terms, your relationship with an app does not have to end with the “I Agree” button. You can come back and ask: What information do you have about me? Is this correct? Do you still need it? And can I have it deleted?
This may seem as a small, irrelevant change. But for the services that we are not using, why should the data be still present?
The Other Side of Your Data Rights
We always tend to miss an important point while discussing data protection: the law never gives user rights without expecting something in return. Even the Indian Constitution has Fundamental Rights but followed by Fundamental Duties!
Think about the personal information you may provide while applying for an internship, registering for a moot court competition, submitting a paper to a journal, enrolling in an online course or creating a profile on a recruitment portal.
Your CV alone may contain your phone number, email address, university, educational history and sometimes even your home address.
The DPDP framework gives you greater control over how such personal data is handled. But exercising those rights responsibly is equally important.
For a law student, therefore, data protection is no longer something that belongs only in a cyber law textbook. It begins with something much more ordinary: knowing what information you are sharing, why you are sharing it and what rights you have after you click “Submit.”
What if your data leaks?
Imagine you register on an internship portal and upload your CV. A few weeks later, you receive an email saying that the platform has suffered a data breach. You will not sit and wonder what provision of DPDP applies but what will first come to mind is: Has my data been leaked?
Under the DPDP Act, organisations are required to take reasonable security safeguards to prevent personal data breaches. The Rules give examples of such safeguards, including encryption, access controls, backups, monitoring and measures to detect unauthorised access.6
If your personal data is affected, the organisation must inform you without delay. The communication should explain what happened, the nature and extent of the breach, its possible consequences and the steps being taken to reduce the risk. Importantly, it should also tell you what you can do to protect yourself.
For law students, this is particularly relevant because personal data is shared across numerous platforms.
Next Time You Apply for an Opportunity Online, Pause for 10 Seconds
If you are reading this on Lawctopus, chances are you have applied for an internship, competition, course or job online at least once.
Your CV, phone number, email address, college details and academic record often travel with that one “Submit” click.

The DPDP framework gives us a good reason to pause before doing so. Ask three simple questions: What data am I sharing? Why is it needed? And what happens to it afterwards?
If something goes wrong, use the platform’s grievance mechanism and exercise the rights available to you under the law.
For young lawyers, understanding data protection is no longer useful only for an exam or a cyber law practice but it is becoming part of being a more careful internet user and perhaps, a better lawyer too.
DPDP in your Phone
| You open… | You want to… | Meanwhile, think about… |
| Zomato | Order dinner | Your name, phone number and delivery location |
| Google Maps | Find your way | Your location data |
| Amazon/Myntra | Shop | Your contact, address and transaction-related information |
| Instagram/Facebook | Scroll for “five minutes” | Personal data associated with your account and activity |
| Lawctopus | Finally get that internship! | Your CV, email, phone number and academic details |
The DPDP Rules are not really about apps. They are about the personal data travelling through them.
The Bottom Line
For years, clicking ‘I Agree’ without reading has become a practice. The DPDP framework may not stop us from clicking it quickly. But it gives us a reason to understand what happens after we do.
For law students especially, that is perhaps the bigger lesson. Knowing your data rights is useful. Knowing when and how to use them is even better.
So, the next time “I Agree” appears on your screen, maybe give it those extra ten seconds.
Want to turn your interest in digital rights into a legal career? Our counsellors can help you explore whether Technology, Privacy and Data Protection Law could be the right path for you.
Call us at +91 91409 92838 for a free counselling call or write to us at courses@lawctopus.com for personalised career advice.
Explore Lawctopus Law School’s 4-Month Certificate Course on Mastering IPR and TMT Laws & Freelancing, with a dedicated Privacy and Data Protection module and practical learning in Technology and Media laws.
References
- The Digital Personal Data Protection Act, 2023, No. 22 of 2023; Digital Personal Data Protection Rules, 2025, Ministry of Electronics and Information Technology, Government of India. ↩︎
- The Digital Personal Data Protection Act, 2023, section 2(i)-(j). ↩︎
- The Digital Personal Data Protection Act, 2023, sections 5–6; Digital Personal Data Protection Rules, 2025, r. 3. ↩︎
- The Digital Personal Data Protection Act, 2023, sections 11–12. ↩︎
- The Digital Personal Data Protection Act, 2023, section 13; Digital Personal Data Protection Rules, 2025. ↩︎
- The Digital Personal Data Protection Act, 2023, section 8; Digital Personal Data Protection Rules, 2025 (provisions relating to reasonable security safeguards and intimation of personal data breaches). ↩︎
About the Author
Ms. Varshni Krishnan holds a B.A. LL.B. and LL.M. from Amity University, Noida. She is a recipient of the prestigious Goolam E. Vahanvati Award, 2018 and currently works as a Legal Content Manager at Lawctopus.