Protection of Personal Data on Social Media in India: A Study of the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025
Main Article Content
Abstract
The transformations brought about by social media in personal information have an economic value and are utilized for the purposes of behavioural advertising, personalization of content, audience measurement, predictive analytics, and algorithmic decision-making. The users share their names, pictures, locations, relationships, opinions, and professional details with the platforms. At the same time, the platforms gather both observed and inferred personal information from users’ clicks, searches, relationships, and actions. The Digital Personal Data Protection Act (2023) in combination with the Digital Personal Data Protection Rules (2025) is India’s first complete regulatory data framework for digital personal data. This paper assesses if the framework provides sufficient protection to social media users. The research involves doctrinal and analytical methods, including statutory interpretation, principles of privacy under the constitution, and the previous literature, approved by DOI. The analysis revolves around data security obligations, notification of breaches, erasure of personal data, children’s data, cross-border data transfers, as well as institutional enforcement in relation to social media use. It is concluded that the legislation establishes an effective regulatory framework in terms of purpose-based consent, rights to withdrawal, security safeguards, breach notifications, user rights, as well as regulating the activities of Significant Data Fiduciaries. The lack of protection of voluntarily announced personal information, the absence of a separate category for vulnerable personal data, limited rights in the context of profiling and decision-making procedures performed by computer technologies, wide exemptions from the rules for the government, and the absence of a compensation mechanism for the Data Protection Board negatively affect the capacity of the above-mentioned legislation to enhance user protection. It is also possible to see that the requirement for verified parental control creates a conflict between the protection of children and the requirement for constant identification. The paper states that ensuring privacy on social media does not have to rely primarily on formality, since users do not have enough power in negotiations as well as not enough information on how the platforms operate. It is proposed to impose some restrictions to the reuse of publicly available data, to provide people with rights to avoid negative results of profiling, to implement privacy-preserving systems for age verification, to provide better transparency of targeting advertising, to achieve faster processing of complaints, and to enhance independence of regulatory authorities.
Article Details
Section

This work is licensed under a Creative Commons Attribution 4.0 International License.
All authors publishing in The Nation State: A Journal of National Security and Geopolitics retain copyright to their work without restriction and grant the journal the right of first publication. Articles are simultaneously distributed under the terms of the Creative Commons Attribution-ShareAlike 4.0 International (CC BY-SA 4.0) license.
Under CC BY-SA 4.0, you are free to:
- Share – copy and redistribute the material in any medium or format
- Adapt – remix, transform, and build upon the material for any purpose, even commercially
provided that you comply with the following terms:
- Attribution – you must give appropriate credit, provide a link to the license, and indicate if changes were made. You may do so in any reasonable manner, but not in any way that suggests the licensor endorses you or your use.
- ShareAlike – if you remix, transform, or build upon the material, you must distribute your contributions under the same license as the original.
- No additional restrictions – you may not apply legal terms or technological measures that legally restrict others from doing anything the license permits.
Authors remain free to enter into additional non-exclusive agreements for distribution (e.g., posting to institutional repositories or websites), provided that such agreements acknowledge initial publication in The Nation State: Journal of National Security and Geopolitics and maintain the CC BY-SA 4.0 license on the journal’s version of record.
For full license details, please visit https://creativecommons.org/licenses/by-sa/4.0/.
How to Cite
References
1. Alessandro Acquisti, Laura Brandimarte & George Loewenstein, Privacy and Human Behavior in the Age of Information, **347 Science 509, 509–14 (2015)**, [https://doi.org/10.1126/science.aaa1465](https://doi.org/10.1126/science.aaa1465).
2. Mike Ananny & Kate Crawford, Seeing Without Knowing: Limitations of the Transparency Ideal and Its Application to Algorithmic Accountability, **20 New Media & Soc'y 973, 973–89 (2018)**, [https://doi.org/10.1177/1461444816676645](https://doi.org/10.1177/1461444816676645).
3. C. K. Bareh, Reviewing the Privacy Implications of India's Digital Personal Data Protection Act (2023) from Library Contexts, **44 DESIDOC J. Libr. & Info. Tech. 50, 50–58 (2024)**, [https://doi.org/10.14429/djlit.44.1.18410](https://doi.org/10.14429/djlit.44.1.18410).
4. Svenja Barth & Menno D. T. de Jong, The Privacy Paradox—Investigating Discrepancies Between Expressed Privacy Concerns and Actual Online Behavior—A Systematic Literature Review, **34 Telematics & Informatics 1038, 1038–58 (2017)**, [https://doi.org/10.1016/j.tele.2017.04.013](https://doi.org/10.1016/j.tele.2017.04.013).
5. Lemi Baruh & Mihaela Popescu, Big Data Analytics and the Limits of Privacy Self-Management, **19 New Media & Soc'y 579, 579–96 (2017)**, [https://doi.org/10.1177/1461444815614001](https://doi.org/10.1177/1461444815614001).
6. S. C. Boerman, S. Kruikemeier & F. J. Zuiderveen Borgesius, Online Behavioral Advertising: A Literature Review and Research Agenda, **46 J. Advert. 363, 363–76 (2017)**, [https://doi.org/10.1080/00913367.2017.1339368](https://doi.org/10.1080/00913367.2017.1339368).
7. Rainer Böhme & Stefan Köpsell, Trained to Accept? A Field Experiment on Consent Dialogs, in **Proceedings of the SIGCHI Conference on Human Factors in Computing Systems 2403, 2403–06 (2010)**, [https://doi.org/10.1145/1753326.1753689](https://doi.org/10.1145/1753326.1753689).
8. N. Criado & J. M. Such, Implicit Contextual Integrity in Online Social Networks, **325 Information Sciences 48, 48–69 (2015)**, [https://doi.org/10.1016/j.ins.2015.07.013](https://doi.org/10.1016/j.ins.2015.07.013).
9. Bart Custers, Simone van der Hof & Bart Schermer, Privacy Expectations of Social Media Users: The Role of Informed Consent in Privacy Policies, **6 Policy & Internet 268, 268–95 (2014)**, [https://doi.org/10.1002/1944-2866.POI366](https://doi.org/10.1002/1944-2866.POI366).
10. N. Gerber, P. Gerber & M. Volkamer, Explaining the Privacy Paradox: A Systematic Review of Literature Investigating Privacy Attitude and Behavior, **77 Computers & Security 226, 226–61 (2018)**, [https://doi.org/10.1016/j.cose.2018.04.002](https://doi.org/10.1016/j.cose.2018.04.002).
11. C. M. Gray, C. Santos, N. Bielova, M. Toth & D. Clifford, Dark Patterns and the Legal Requirements of Consent Banners: An Interaction Criticism Perspective, in **Proceedings of the 2021 CHI Conference on Human Factors in Computing Systems 1, 1–18 (2021)**, [https://doi.org/10.1145/3411764.3445779](https://doi.org/10.1145/3411764.3445779).
12. Spyros Kokolakis, Privacy Attitudes and Privacy Behaviour: A Review of Current Research on the Privacy Paradox Phenomenon, **64 Computers & Security 122, 122–34 (2017)**, [https://doi.org/10.1016/j.cose.2015.07.002](https://doi.org/10.1016/j.cose.2015.07.002).
13. Tuukka Lehtiniemi & Yki Kortesniemi, Can the Obstacles to Privacy Self-Management Be Overcome? Exploring the Consent Intermediary Approach, **4 Big Data & Soc'y, no. 2, at 1 (2017)**, [https://doi.org/10.1177/2053951717721935](https://doi.org/10.1177/2053951717721935).
14. Jamie Luguri & L. J. Strahilevitz, Shining a Light on Dark Patterns, **13 J. Legal Analysis 43, 43–109 (2021)**, [https://doi.org/10.1093/jla/laaa006](https://doi.org/10.1093/jla/laaa006).
15. Monika Macenaite & Eleni Kosta, Consent for Processing Children's Personal Data in the EU: Following in U.S. Footsteps?, **26 Info. & Commc'n Tech. L. 146, 146–97 (2017)**, [https://doi.org/10.1080/13600834.2017.1321096](https://doi.org/10.1080/13600834.2017.1321096).
16. Chetan Malhotra & Umesh Malhotra, Putting Interests of Digital Nagriks First: Digital Personal Data Protection (DPDP) Act 2023 of India, **70 Indian J. Pub. Admin. 516, 516–31 (2024)**, [https://doi.org/10.1177/00195561241271575](https://doi.org/10.1177/00195561241271575).
17. Arunesh Mathur, Gunes Acar, Michael J. Friedman, Elena Lucherini, Jonathan Mayer, Marshini Chetty & Arvind Narayanan, Dark Patterns at Scale: Findings from a Crawl of 11K Shopping Websites, **3 Proc. ACM on Hum.-Comput. Interaction, no. CSCW, at 81 (2019)**, [https://doi.org/10.1145/3359183](https://doi.org/10.1145/3359183).
18. Brent D. Mittelstadt, Patrick Allo, Mariarosaria Taddeo, Sandra Wachter & Luciano Floridi, The Ethics of Algorithms: Mapping the Debate, **3 Big Data & Soc'y, no. 2, at 1 (2016)**, [https://doi.org/10.1177/2053951716679679](https://doi.org/10.1177/2053951716679679).
19. P. Naithani, Analysis of India's Digital Personal Data Protection Act, 2023, **67 Int'l J.L. & Mgmt. 543, 543–53 (2025)**, [https://doi.org/10.1108/IJLMA-05-2024-0174](https://doi.org/10.1108/IJLMA-05-2024-0174).
20. Arvind Narayanan, Arunesh Mathur, Marshini Chetty & Mihir Kshirsagar, Dark Patterns: Past, Present, and Future, **63 Commc'ns ACM 42, 42–47 (2020)**, [https://doi.org/10.1145/3397884](https://doi.org/10.1145/3397884).
21. Machteld Nouwens, Ilaria Liccardi, Michael Veale, David Karger & Lalana Kagal, Dark Patterns After the GDPR: Scraping Consent Pop-Ups and Demonstrating Their Influence, in **Proceedings of the 2020 CHI Conference on Human Factors in Computing Systems 1, 1–14 (2020)**, [https://doi.org/10.1145/3313831.3376321](https://doi.org/10.1145/3313831.3376321).
22. Bart W. Schermer, Bart Custers & Simone van der Hof, The Crisis of Consent: How Stronger Legal Protection May Lead to Weaker Consent in Data Protection, **16 Ethics & Info. Tech. 171, 171–82 (2014)**, [https://doi.org/10.1007/s10676-014-9343-8](https://doi.org/10.1007/s10676-014-9343-8).
23. Zoe Stardust, Abeer Obeid, Alastair McKee & Dana Angus, Mandatory Age Verification for Pornography Access: Why It Cannot and Will Not “Save the Children,” **11 Big Data & Soc'y, no. 2, at 1 (2024)**, [https://doi.org/10.1177/20539517241252129](https://doi.org/10.1177/20539517241252129).
24. Daniel Susser, Beate Roessler & Helen Nissenbaum, Technology, Autonomy, and Manipulation, **8 Internet Pol'y Rev., no. 2, at 1 (2019)**, [https://doi.org/10.14763/2019.2.1410](https://doi.org/10.14763/2019.2.1410).
25. Karen Yeung, “Hypernudge”: Big Data as a Mode of Regulation by Design, **20 Info., Commc'n & Soc'y 118, 118–36 (2017)**, [https://doi.org/10.1080/1369118X.2016.1186713](https://doi.org/10.1080/1369118X.2016.1186713).