The Supreme Court has held that privacy is a fundamental right under Article 21. If the government has violated it, you can go to court directly; if a private company has misused your personal data, a newer, separate law applies -- though its own complaint mechanism is not fully working yet.
1. Know what this right actually protects
In K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1, a 9-judge Constitution Bench unanimously held that the right to privacy is a fundamental right protected under Article 21 (and more broadly under Part III) of the Constitution, overruling earlier contrary observations in M.P. Sharma v. Satish Chandra (1954) and Kharak Singh v. State of U.P. (1962). It covers informational privacy (control over your personal data), bodily and decisional autonomy, and the freedom to make personal choices.
2. Work out who is actually responsible
The correct route depends entirely on who violated your privacy. If it was the government, the police, or another public authority, a constitutional remedy is generally available directly. If it was a private company, app, or individual, fundamental rights are ordinarily not directly enforceable against them, and a different, specific law applies instead.
3. If it is government or police action -- a writ petition
A writ petition may be filed under Article 32 directly in the Supreme Court, or under Article 226 in the jurisdictional High Court, for enforcement of the right to privacy against State action. Article 226 generally allows broader grounds than Article 32 and is usually the more accessible first option.
4. If it is a private company misusing your personal data -- start with its own grievance channel
Existing rules under the Information Technology Act already require many companies handling sensitive personal data to designate a grievance contact. Once the Digital Personal Data Protection Act, 2023's data-principal-rights provisions are fully in force, a person will generally need to use this internal grievance route with the company (the 'Data Fiduciary') before a complaint can go to the Data Protection Board.
5. Know the real, current status of the Digital Personal Data Protection Act before relying on it
The DPDP Act, 2023 has been notified only in phases. The provisions setting up the Data Protection Board of India came into force on 13 November 2025, but the Act's substantive data-principal rights and the Board's complaint-and-penalty provisions (Chapter II and Sections 27-34) are not yet in force -- these are officially targeted for 13 May 2027. As of now, the Board has been legally constituted but has not yet been staffed with appointed members, so it cannot yet actually receive or decide citizen complaints.
6. Use the route that already works today -- Section 43A of the IT Act
Section 43A of the Information Technology Act, 2000 is already in force and lets a person claim compensation from a company that negligently fails to maintain reasonable security practices while handling sensitive personal data, causing loss to that person. This claim can be pursued before an Adjudicating Officer appointed under the IT Act, or before a civil court, and does not depend on the still-partial DPDP Act.
7. Once the Data Protection Board becomes operational, use it directly
When the Board is fully functional, a person will be able to complain to it against a Data Fiduciary after exhausting the company's own grievance mechanism. The Board can investigate and impose penalties of up to Rs. 250 crore for a serious security-safeguard failure, though these penalties go to the Consolidated Fund of India, not as compensation to the affected person.
8. If you suspect unauthorized phone tapping or interception
In PUCL v. Union of India, (1997) 1 SCC 301, the Supreme Court held that interception under the Indian Telegraph Act's Section 5(2) required real safeguards -- an order only from the Home Secretary (Centre or State), a limited validity period, and periodic review by a Review Committee. This interception power now sits in Section 20 of the Telecommunications Act, 2023 (in force since 26 June 2024), operationalised by the Telecommunications (Procedures and Safeguards for Lawful Interception of Messages) Rules, 2024, which continue a similar authorisation-and-review structure.
9. If someone captured or shared private images or videos without consent
Section 66E of the Information Technology Act, 2000 punishes capturing, publishing, or transmitting the image of a person's private area without consent, with imprisonment up to 3 years and/or a fine up to Rs. 2 lakh. Section 77 of the Bharatiya Nyaya Sanhita, 2023 (the voyeurism provision, successor to IPC Section 354C) separately punishes watching or capturing a person in a private act without consent. Both can be reported to the police or through the National Cyber Crime Reporting Portal.
10. Gather your evidence before approaching any forum
Keep screenshots, correspondence with the company or authority, any data-breach notification received, call/message records if interception is suspected, and identity proof. Clear, dated evidence matters more for a privacy complaint than for many other kinds of disputes, since the violation itself is often intangible.
11. Choose the right forum and file
File a writ petition through an advocate for State action; approach the company's grievance officer first for private data misuse, escalating to an IT Act Section 43A claim or, once operational, the Data Protection Board; and file a police complaint or FIR for image-based or interception-related criminal conduct.
Handled by: Supreme Court / High Court (State action); Data Protection Board of India (private data misuse, not yet operational); Police / Cybercrime Portal (criminal conduct)
Who can use this: Any person in India whose privacy -- personal data, bodily autonomy, personal choices, or private communications -- has been violated by the government or by a private party.
This does not cover: Does not cover general online harassment or stalking (see cyberstalking_harassment), general defamation (see defamation_remedies), or an ongoing safety emergency involving image-based abuse, which Aadhrix's own safety triage handles separately and immediately.
Time limit: No fixed limitation period applies to a writ petition, though unreasonable delay can weaken it. No limitation period has yet been prescribed for a Data Protection Board complaint, since that mechanism is not yet operational. (General writ jurisdiction principles (delay and laches); Digital Personal Data Protection Act, 2023)
Cost: Writ petitions carry court fees plus advocate fees if one is engaged; filing an FIR is free; a Data Protection Board fee structure has not yet been prescribed.
You'll need:- Who violated your privacy -- a government authority or a private party
- What kind of privacy was affected -- personal data, communications, bodily autonomy, or a personal choice
- The date(s) the violation occurred or was discovered
- Whether the government or a company was directly involved, or whether it was another individual
- Any response already received from the company or authority, if you have already complained
Documents that help:- Identity proof
- Screenshots or copies of the material or data in question
- Any data-breach notification received from a company
- Correspondence with the company's grievance officer, if already contacted
- Call detail records or other evidence, if interception is suspected
- A copy of any FIR or police complaint already filed
What happens after: A writ petition is listed for hearing and the court may issue directions, including compensation in some cases. An IT Act Section 43A claim before an Adjudicating Officer proceeds like a compensation claim, with both sides heard before an order is passed. A police complaint leads to an FIR and investigation. A future Data Protection Board complaint would be examined online, with the Data Fiduciary given a chance to respond before any penalty is imposed.
These are the remedies Indian law provides for this kind of situation -- not a recommendation, and not every remedy will apply to your own facts.
Writ petition under Article 32
Supreme Court of India
Article 32 allows a person to approach the Supreme Court directly for enforcement of a fundamental right, including the right to privacy, when the violation is by the State or a state instrumentality.
Writ petition under Article 226
Jurisdictional High Court
Article 226 allows a person to approach the High Court of the relevant state for enforcement of a fundamental right or any other legal right, on broader grounds than Article 32, primarily against State action.
Compensation claim under IT Act Section 43A
Adjudicating Officer under the IT Act, or a civil court
Section 43A of the Information Technology Act, 2000 allows a person to claim compensation from a body corporate that negligently fails to maintain reasonable security practices while handling sensitive personal data, causing loss to that person.
Complaint to the Data Protection Board of India
Data Protection Board of India (not yet operational)
The Digital Personal Data Protection Act, 2023 provides for a Data Principal to complain to the Data Protection Board against a Data Fiduciary once the Act's data-principal-rights provisions and the Board's complaint-handling function are brought fully into force.
Criminal complaint for non-consensual image capture or sharing
Police / National Cyber Crime Reporting Portal
Section 66E of the Information Technology Act, 2000 and Section 77 of the Bharatiya Nyaya Sanhita, 2023 allow a criminal complaint to be filed against a person who captures, publishes, or transmits an image of a person's private area, or observes a person in a private act, without consent.
Review of an interception order
Review Committee (Home Ministry, Centre or State) / High Court
The procedural safeguards from People's Union for Civil Liberties v. Union of India, (1997) 1 SCC 301, now reflected in the Telecommunications Act, 2023 and its 2024 interception rules, allow the lawfulness of an interception order to be examined through the Review Committee mechanism, or a High Court to be approached where those safeguards appear to have been breached.
Is my right to privacy absolute?
No. The Supreme Court in the 2017 Puttaswamy judgment held that privacy can be restricted, but only by a law, for a legitimate state purpose, and in a proportionate manner -- not on the government's mere say-so.
Can I sue a private company directly using my fundamental rights?
Generally no. Fundamental rights under Part III, including Article 21, are ordinarily enforceable against the State, not directly against a private company. For a private company's misuse of your data, the IT Act's Section 43A or the Digital Personal Data Protection Act are the relevant routes instead.
Has the Digital Personal Data Protection Act, 2023 actually come into force?
Only partially. The sections setting up the Data Protection Board of India took effect on 13 November 2025, but the Act's data-principal rights and complaint/penalty provisions are not yet in force and are officially targeted for 13 May 2027.
Can I file a complaint with the Data Protection Board today?
The Board has been legally constituted, but as of now it has not been staffed with appointed members and cannot yet process complaints in practice. Section 43A of the IT Act remains a real, currently available alternative for a data-misuse claim against a company.
Does phone tapping require a court warrant?
No. Under the safeguards from PUCL v. Union of India and now the Telecommunications Act, 2023, interception is authorised administratively -- typically by the Home Secretary -- rather than by a court warrant, but it must follow a defined procedure and periodic review.
What is the difference between the two Puttaswamy judgments?
K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1 is the 2017 ruling that declared privacy a fundamental right. A separate, later judgment -- also called Puttaswamy, (2019) 1 SCC 1 -- decided in 2018 upheld the Aadhaar Act with modifications. They are two different cases, both commonly shortened to 'Puttaswamy.'
What if someone shares my private photos or videos without my consent?
This can be reported to the police as a criminal offence under Section 66E of the IT Act and/or Section 77 of the Bharatiya Nyaya Sanhita (voyeurism), including through the National Cyber Crime Reporting Portal.
Does the right to privacy cover personal choices like marriage, relationships, or diet?
Yes. The Supreme Court's privacy ruling recognised decisional autonomy as part of privacy, and this reasoning was later applied in Navtej Singh Johar v. Union of India, (2018) 10 SCC 1 (decriminalising consensual same-sex relations) and Joseph Shine v. Union of India, (2019) 3 SCC 39 (striking down the criminal offence of adultery).
What is a 'Data Fiduciary'?
It is the term the DPDP Act uses for any entity -- typically a company or organisation -- that decides the purpose and means of processing a person's personal data, comparable to what is commonly called a data controller elsewhere.
Do I have to complain to the company before going to the Data Protection Board?
Under the Act's design, once its complaint provisions are in force, a person will generally need to first use the Data Fiduciary's own grievance redressal mechanism, and may approach the Board only if that does not resolve the issue.
What can the Data Protection Board actually do to a company?
Once operational, it can investigate a complaint and impose a monetary penalty on the company -- up to Rs. 250 crore for a serious security-safeguard failure -- but this penalty is paid to the government, not as compensation to the affected person.
How much time do I have to file a writ petition?
There is no fixed limitation period, but courts can decline to entertain a writ petition if it is brought after unreasonable, unexplained delay.
Governing law: Constitution of India, Art. 21; Digital Personal Data Protection Act, 2023; IT Act, 2000; Telecommunications Act, 2023
Source: Puttaswamy (privacy), (2017) 10 SCC 1; Puttaswamy (Aadhaar, a separate case), (2019) 1 SCC 1; PUCL, (1997) 1 SCC 301. DPDP Act Board provisions in force from 13 Nov 2025; data-principal-rights/complaint provisions not yet in force (targeted 13 May 2027) -- confirmed live, Sept 2026, that the Board has no appointed members yet.
Aadhrix does not decide which route applies to you. This describes the official process as published — consider an advocate for advice specific to your situation.