<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.2 20190208//EN"
  "https://jats.nlm.nih.gov/publishing/1.2/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink"
         xmlns:mml="http://www.w3.org/1998/Math/MathML"
         article-type="research-article"
         dtd-version="1.2">

  <!-- ============================================================ FRONT -->
  <front>
    <journal-meta>
      <journal-id journal-id-type="publisher-id">IJLTEMAS</journal-id>
      <journal-title-group>
        <journal-title>International Journal of Latest Technology in Engineering, Management &amp; Applied Science (IJLTEMAS)</journal-title>
        <abbrev-journal-title abbrev-type="publisher">IJLTEMAS</abbrev-journal-title>
      </journal-title-group>
      <issn pub-type="epub">2278-2540</issn>
      <publisher>
        <publisher-name>IJLTEMAS</publisher-name>
      </publisher>
    </journal-meta>

    <article-meta>
      <!-- IDs -->
      <article-id pub-id-type="publisher-id">160</article-id>
            <article-id pub-id-type="doi">10.51583/IJLTEMAS.2026.150700155</article-id>
      
      <!-- Categories -->
            <article-categories>
        <subj-group subj-group-type="heading">
          <subject>Public Governance</subject>
        </subj-group>
      </article-categories>
      
      <!-- Title -->
      <title-group>
        <article-title>Reader Privacy Under the Digital Personal Data Protection Act, 2023: Contextual Integrity and the Obligations of Indian Academic Libraries</article-title>
      </title-group>

      <!-- Authors -->
      <contrib-group>
                <contrib contrib-type="author">
                    <name>
            <surname>Dheeraj</surname>
            <given-names>Dheeraj</given-names>
          </name>
                              <aff>
            Research Scholar, Department of Library and Information Science, Swami Vivekanand Subharti University, Meerut, Uttar Pradesh, India                        <country>India</country>
                      </aff>
                    
        </contrib>
                <contrib contrib-type="author">
                    <name>
            <surname>Sapna Sharma</surname>
            <given-names>Dr.</given-names>
          </name>
                              <aff>
            Assistant Professor, Department of Library and Information Science, SVSU, Meerut                        <country>India</country>
                      </aff>
                    
        </contrib>
              </contrib-group>

      <!-- Volume / Issue / Pages -->
            <volume>15</volume>
                  <issue>7</issue>
                        <fpage>2017</fpage>
            <lpage>2031</lpage>
            
      <!-- Dates -->
      <history>
                <date date-type="received">
          <day>13</day>
          <month>08</month>
          <year>2026</year>
        </date>
                        <date date-type="accepted">
          <day>19</day>
          <month>08</month>
          <year>2026</year>
        </date>
              </history>

            <pub-date pub-type="epub">
        <day>25</day>
        <month>08</month>
        <year>2026</year>
      </pub-date>
      
      <!-- DOI Self-URI -->
            <self-uri xlink:href="https://doi.org/10.51583/IJLTEMAS.2026.150700155"/>
      
      <!-- Keywords -->
            <kwd-group kwd-group-type="author">
                <kwd>Digital Personal Data Protection Act; reader privacy; contextual integrity; academic libraries; data protection; intellectual freedom; library records; India.</kwd>
              </kwd-group>
      
    </article-meta>
  </front>

  <!-- ============================================================ BODY (Abstract) -->
  <body>
        <sec>
      <title>Abstract</title>
      <p>The Digital Personal Data Protection Rules, 2025, notified in November 2025, brought India’s first comprehensive data protection statute into operation, with full compliance required by May 2027. Every academic library in India is a processor of digital personal data on a substantial scale, and most are constituent units of institutions that will be data fiduciaries under the Act, yet the professional literature contains almost no analysis of what the statute requires of them. This paper provides that analysis. It applies Nissenbaum’s theory of contextual integrity, together with the proportionality standard established in Puttaswamy, to argue that library records are not simply personal data among other categories but records of intellectual inquiry, whose disclosure produces a chilling effect that a consent-based compliance regime does not by itself prevent. The method is documentary policy and legal-instrument analysis, conducted through a transparent selection protocol yielding a corpus of 81 documents. The paper develops a systematic inventory of the personal data processed by a typical Indian academic library across four categories, maps each category against the requirements of the Act, and analyses four hard cases: users under the age of eighteen, where section 9 forbids the tracking and monitoring of behaviour despite consent; federated authentication under the One Nation One Subscription scheme, which hands over institutional identity to commercial publishers; vendor and publisher analytics, where the library asserts it has no control over data it has caused to be created; and closed-circuit television and biometric attendance, where a proportionality analysis is necessary and is not often conducted. It is argued that the Act protects library users less than the professional standards of IFLA and the American Library Association, that its amendment of the Right to Information Act weakens rather than strengthens accountability, and that compliance alone will not discharge the profession’s obligation. Twelve recommendations follow.</p>
    </sec>
      </body>

  <!-- ============================================================ BACK (References) -->
    <back>
    <ref-list>
      <title>References</title>
            <ref id="ref1">
        <label>1</label>
        <mixed-citation>American Library Association. (2019). Privacy: An interpretation of the Library Bill of Rights. Chicago: ALA. https://www.ala.org/advocacy/intfreedom/librarybill/interpretations/privacy (accessed 12 August 2026)</mixed-citation>
      </ref>
            <ref id="ref2">
        <label>2</label>
        <mixed-citation>American Library Association. (2021). Code of ethics of the American Library Association. Chicago: ALA.</mixed-citation>
      </ref>
            <ref id="ref3">
        <label>3</label>
        <mixed-citation>American Library Association. (n.d.). Policy on confidentiality of library records. Chicago: ALA. https://www.ala.org/advocacy/intfreedom/statementspols/otherpolicies/policyconfidentiality (accessed 12 August 2026)</mixed-citation>
      </ref>
            <ref id="ref4">
        <label>4</label>
        <mixed-citation>American Library Association. (n.d.). State privacy laws regarding library records. Chicago: ALA. https://www.ala.org/advocacy/privacy/statelaws (accessed 12 August 2026)</mixed-citation>
      </ref>
            <ref id="ref5">
        <label>5</label>
        <mixed-citation>Ayre, L. B., &amp; Craner, J. (2018). Algorithms: Avoiding the implementation of institutional biases. Public Library Quarterly, 37(3), 341–347.</mixed-citation>
      </ref>
            <ref id="ref6">
        <label>6</label>
        <mixed-citation>Bhattacharya, A. (2024). The Digital Personal Data Protection Act, 2023: An overview of the consent architecture. Indian Journal of Law and Technology.</mixed-citation>
      </ref>
            <ref id="ref7">
        <label>7</label>
        <mixed-citation>Government of India. (2005). The Right to Information Act, 2005. New Delhi: Ministry of Law and Justice.</mixed-citation>
      </ref>
            <ref id="ref8">
        <label>8</label>
        <mixed-citation>Government of India. (2023). The Digital Personal Data Protection Act, 2023 (No. 22 of 2023). New Delhi: Ministry of Law and Justice.</mixed-citation>
      </ref>
            <ref id="ref9">
        <label>9</label>
        <mixed-citation>Government of India. (2025). The Digital Personal Data Protection Rules, 2025. New Delhi: Ministry of Electronics and Information Technology.</mixed-citation>
      </ref>
            <ref id="ref10">
        <label>10</label>
        <mixed-citation>International Federation of Library Associations and Institutions. (2012). IFLA code of ethics for librarians and other information workers. The Hague: IFLA.</mixed-citation>
      </ref>
            <ref id="ref11">
        <label>11</label>
        <mixed-citation>International Federation of Library Associations and Institutions. (2015). IFLA statement on privacy in the library environment. The Hague: IFLA. https://www.ifla.org/publications/ifla-statement-on-privacy-in-the-library-environment/ (accessed 12 August 2026)</mixed-citation>
      </ref>
            <ref id="ref12">
        <label>12</label>
        <mixed-citation>Justice K. S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1.</mixed-citation>
      </ref>
            <ref id="ref13">
        <label>13</label>
        <mixed-citation>Lambert, A. D., Parker, M., &amp; Bashir, M. (2015). Library patron privacy in jeopardy: An analysis of the privacy policies of digital content vendors. Proceedings of the Association for Information Science and Technology, 52(1), 1–9.</mixed-citation>
      </ref>
            <ref id="ref14">
        <label>14</label>
        <mixed-citation>Magi, T. J. (2011). A content analysis of library vendor privacy policies: Do they meet our standards? College &amp; Research Libraries, 71(3), 254–272.</mixed-citation>
      </ref>
            <ref id="ref15">
        <label>15</label>
        <mixed-citation>National Information Standards Organization. (2015). NISO consensus principles on users’ digital privacy in library, publisher, and software-provider systems. Baltimore: NISO.</mixed-citation>
      </ref>
            <ref id="ref16">
        <label>16</label>
        <mixed-citation>Nissenbaum, H. (2004). Privacy as contextual integrity. Washington Law Review, 79(1), 119–157.</mixed-citation>
      </ref>
            <ref id="ref17">
        <label>17</label>
        <mixed-citation>Nissenbaum, H. (2010). Privacy in context: Technology, policy, and the integrity of social life. Stanford: Stanford University Press.</mixed-citation>
      </ref>
            <ref id="ref18">
        <label>18</label>
        <mixed-citation>Press Information Bureau, Government of India. (2025, November 14). Digital Personal Data Protection (DPDP) Rules, 2025 [Press release]. New Delhi: PIB.</mixed-citation>
      </ref>
            <ref id="ref19">
        <label>19</label>
        <mixed-citation>Rubel, A., &amp; Zhang, M. (2015). Four facets of privacy and intellectual freedom in licensing contracts for electronic journals. College &amp; Research Libraries, 76(4), 427–449.</mixed-citation>
      </ref>
            <ref id="ref20">
        <label>20</label>
        <mixed-citation>Scott, J. (1990). A matter of record: Documentary sources in social research. Cambridge: Polity Press.</mixed-citation>
      </ref>
            <ref id="ref21">
        <label>21</label>
        <mixed-citation>Sturges, P., Davies, E., Dearnley, J., Iliffe, U., Oppenheim, C., &amp; Hardy, R. (2003). User privacy in the digital library environment: An investigation of policies and preparedness. Library Management, 24(1–2), 44–50.</mixed-citation>
      </ref>
            <ref id="ref22">
        <label>22</label>
        <mixed-citation>Zimmer, M. (2013). Patron privacy in the ‘2.0’ era: Avoiding the Faustian bargain of library 2.0. Journal of Information Ethics, 22(1), 44–59.</mixed-citation>
      </ref>
            <ref id="ref23">
        <label>23</label>
        <mixed-citation>Zimmer, M., &amp; Tijerina, B. (2018). Library values and privacy in our national digital strategies: Field guides, convenings, and conversations. Milwaukee: University of Wisconsin-Milwaukee.</mixed-citation>
      </ref>
          </ref-list>
  </back>
  
</article>
