I applied for an online MBA at ABC University. Pretty straightforward, right?

Then the calls started. And they didn’t stop.

At least ten different universities called me multiple times over the next three months — universities I’d never even applied to. Each one somehow had my phone number.

I was curious (and, honestly, annoyed), so I asked one of the callers:

“Where did you get my number? I only applied at ABC.”

His answer:

“When you apply at one university, the information gets shared across the university network.”

That seemed normal back then. But this may have to change with the introduction of the Digital Personal Data Protection Act, 2023 — the DPDP Act.

Why We Needed This Act

For years, we relied on the Information Technology Act, 2000 and its privacy rules. The IT Act addressed certain privacy and data-security concerns, but its scope and applicability were limited.

To address this gap, the government introduced the DPDP Act, providing a framework for the protection of digital personal data.

The rollout began in November 2025, with mandatory implementation scheduled by May 2027.

Here’s How It Works

In this example, ABC University is the Data Fiduciary, and I am the Data Principal.

The organisation processes personal data such as my phone number and email address for the purpose for which that information was collected, subject to the lawful grounds and requirements provided under the Act.

The important question is what happens when that information is subsequently shared or used for another purpose.

If my information is being shared across a network of universities, the organisation needs to consider whether it has the appropriate basis to do so and whether the required notice and consent obligations have been met.

What Control Does the Individual Have?

The DPDP framework gives individuals mechanisms to exercise greater control over their personal data.

These include the ability to:

  • Withdraw consent — where processing is based on consent, an individual can withdraw that consent.
  • Raise a grievance — individuals can use the organisation’s grievance-redressal mechanism.
  • Escalate unresolved grievances — where applicable, matters can ultimately be taken before the Data Protection Board.

The larger shift is one of accountability: individuals gain enforceable rights relating to their personal data, while Data Fiduciaries operate under defined obligations concerning how that data is collected, processed and managed.

A Familiar Situation With a New Question

Unexpected marketing calls and emails after filling out a single online form have become almost routine.

The DPDP framework makes organisations ask a more fundamental question:

What did the individual actually agree to when they shared their information?

That question has implications far beyond universities — from financial services and healthcare to e-commerce, recruitment and virtually any organisation collecting personal information digitally.


This resource is intended for general informational and educational purposes and should not be treated as legal advice. Applicability may depend on the specific processing activity and circumstances involved.