00
Days
00
Hrs
00
Min
00
Sec
Submit Your Paper

Reader Privacy Under the Digital Personal Data Protection Act, 2023: Contextual Integrity and the Obligations of Indian Academic Libraries

Authors

Dheeraj

Research Scholar, Department of Library and Information Science, Swami Vivekanand Subharti University, Meerut, Uttar Pradesh, India (India)

Dr. Sapna Sharma

Assistant Professor, Department of Library and Information Science, SVSU, Meerut (India)

Article Information

DOI: 10.51583/IJLTEMAS.2026.150700155

Subject Category: Public Governance

Volume/Issue: 15/7 | Page No: 2017-2031

Publication Timeline

Submitted: 2026-08-13

Accepted: 2026-08-19

Published: 2026-08-25

Abstract

The Digital Personal Data Protection Rules, 2025, notified in November 2025, brought India’s first comprehensive data protection statute into operation, with full compliance required by May 2027. Every academic library in India is a processor of digital personal data on a substantial scale, and most are constituent units of institutions that will be data fiduciaries under the Act, yet the professional literature contains almost no analysis of what the statute requires of them. This paper provides that analysis. It applies Nissenbaum’s theory of contextual integrity, together with the proportionality standard established in Puttaswamy, to argue that library records are not simply personal data among other categories but records of intellectual inquiry, whose disclosure produces a chilling effect that a consent-based compliance regime does not by itself prevent. The method is documentary policy and legal-instrument analysis, conducted through a transparent selection protocol yielding a corpus of 81 documents. The paper develops a systematic inventory of the personal data processed by a typical Indian academic library across four categories, maps each category against the requirements of the Act, and analyses four hard cases: users under the age of eighteen, where section 9 forbids the tracking and monitoring of behaviour despite consent; federated authentication under the One Nation One Subscription scheme, which hands over institutional identity to commercial publishers; vendor and publisher analytics, where the library asserts it has no control over data it has caused to be created; and closed-circuit television and biometric attendance, where a proportionality analysis is necessary and is not often conducted. It is argued that the Act protects library users less than the professional standards of IFLA and the American Library Association, that its amendment of the Right to Information Act weakens rather than strengthens accountability, and that compliance alone will not discharge the profession’s obligation. Twelve recommendations follow.

Keywords

Digital Personal Data Protection Act; reader privacy; contextual integrity; academic libraries; data protection; intellectual freedom; library records; India.

Downloads

References

1. American Library Association. (2019). Privacy: An interpretation of the Library Bill of Rights. Chicago: ALA. https://www.ala.org/advocacy/intfreedom/librarybill/interpretations/privacy (accessed 12 August 2026) [Google Scholar] [Crossref]

2. American Library Association. (2021). Code of ethics of the American Library Association. Chicago: ALA. [Google Scholar] [Crossref]

3. American Library Association. (n.d.). Policy on confidentiality of library records. Chicago: ALA. https://www.ala.org/advocacy/intfreedom/statementspols/otherpolicies/policyconfidentiality (accessed 12 August 2026) [Google Scholar] [Crossref]

4. American Library Association. (n.d.). State privacy laws regarding library records. Chicago: ALA. https://www.ala.org/advocacy/privacy/statelaws (accessed 12 August 2026) [Google Scholar] [Crossref]

5. Ayre, L. B., & Craner, J. (2018). Algorithms: Avoiding the implementation of institutional biases. Public Library Quarterly, 37(3), 341–347. [Google Scholar] [Crossref]

6. Bhattacharya, A. (2024). The Digital Personal Data Protection Act, 2023: An overview of the consent architecture. Indian Journal of Law and Technology. [Google Scholar] [Crossref]

7. Government of India. (2005). The Right to Information Act, 2005. New Delhi: Ministry of Law and Justice. [Google Scholar] [Crossref]

8. Government of India. (2023). The Digital Personal Data Protection Act, 2023 (No. 22 of 2023). New Delhi: Ministry of Law and Justice. [Google Scholar] [Crossref]

9. Government of India. (2025). The Digital Personal Data Protection Rules, 2025. New Delhi: Ministry of Electronics and Information Technology. [Google Scholar] [Crossref]

10. International Federation of Library Associations and Institutions. (2012). IFLA code of ethics for librarians and other information workers. The Hague: IFLA. [Google Scholar] [Crossref]

11. International Federation of Library Associations and Institutions. (2015). IFLA statement on privacy in the library environment. The Hague: IFLA. https://www.ifla.org/publications/ifla-statement-on-privacy-in-the-library-environment/ (accessed 12 August 2026) [Google Scholar] [Crossref]

12. Justice K. S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1. [Google Scholar] [Crossref]

13. Lambert, A. D., Parker, M., & Bashir, M. (2015). Library patron privacy in jeopardy: An analysis of the privacy policies of digital content vendors. Proceedings of the Association for Information Science and Technology, 52(1), 1–9. [Google Scholar] [Crossref]

14. Magi, T. J. (2011). A content analysis of library vendor privacy policies: Do they meet our standards? College & Research Libraries, 71(3), 254–272. [Google Scholar] [Crossref]

15. National Information Standards Organization. (2015). NISO consensus principles on users’ digital privacy in library, publisher, and software-provider systems. Baltimore: NISO. [Google Scholar] [Crossref]

16. Nissenbaum, H. (2004). Privacy as contextual integrity. Washington Law Review, 79(1), 119–157. [Google Scholar] [Crossref]

17. Nissenbaum, H. (2010). Privacy in context: Technology, policy, and the integrity of social life. Stanford: Stanford University Press. [Google Scholar] [Crossref]

18. Press Information Bureau, Government of India. (2025, November 14). Digital Personal Data Protection (DPDP) Rules, 2025 [Press release]. New Delhi: PIB. [Google Scholar] [Crossref]

19. Rubel, A., & Zhang, M. (2015). Four facets of privacy and intellectual freedom in licensing contracts for electronic journals. College & Research Libraries, 76(4), 427–449. [Google Scholar] [Crossref]

20. Scott, J. (1990). A matter of record: Documentary sources in social research. Cambridge: Polity Press. [Google Scholar] [Crossref]

21. Sturges, P., Davies, E., Dearnley, J., Iliffe, U., Oppenheim, C., & Hardy, R. (2003). User privacy in the digital library environment: An investigation of policies and preparedness. Library Management, 24(1–2), 44–50. [Google Scholar] [Crossref]

22. Zimmer, M. (2013). Patron privacy in the ‘2.0’ era: Avoiding the Faustian bargain of library 2.0. Journal of Information Ethics, 22(1), 44–59. [Google Scholar] [Crossref]

23. Zimmer, M., & Tijerina, B. (2018). Library values and privacy in our national digital strategies: Field guides, convenings, and conversations. Milwaukee: University of Wisconsin-Milwaukee. [Google Scholar] [Crossref]

Metrics

Views & Downloads

Similar Articles

© 2026 IJLTEMAS · RSIS International. All rights reserved. ISSN 2278-2540.