PRIVACY CHALLENGES IN CLOUD COMPUTING UNDER IT LAW

Main Article Content

Davesh Grover, Dr. Ramveer Singh

Abstract

Cloud computing has become a central part of digital governance, business operations, education, health services, banking, e-commerce and public service delivery. Its technical advantages arise from on-demand access, shared resources, rapid elasticity and measured services, but the same features create serious privacy challenges because personal data may be stored, processed, replicated and accessed across multiple systems, jurisdictions and service providers. In India, these challenges must be examined under the Information Technology Act, 2000, the SPDI Rules, 2011, the Digital Personal Data Protection Act, 2023, the Digital Personal Data Protection Rules, 2025, CERT-In cyber-security obligations, and the constitutional right to privacy recognised in Justice K.S. Puttaswamy v. Union of India. This paper analyses the major privacy risks in cloud computing, including unclear data control, cross-border transfer, breach notification, weak consent management, vendor lock-in, government access, metadata exposure, misconfiguration and accountability gaps. The paper concludes that Indian IT law has moved from a limited compensation-based model under section 43A of the IT Act toward a rights-and-obligations model under the DPDP framework, but cloud-specific governance still requires stronger contractual controls, technical safeguards, auditability, encryption, data minimisation, incident response and risk-based compliance.

Article Details

How to Cite
Davesh Grover, Dr. Ramveer Singh. (2026). PRIVACY CHALLENGES IN CLOUD COMPUTING UNDER IT LAW. Journal of Daoist Studies, 19(S7), 1457–1471. Retrieved from https://journalofdaoiststudies.org/index.php/journal/article/view/1363
Section
Articles