Mobile phones in India are ubiquitous - over a billion subscribers. They serve as touch points for multiple needs. Consequently attempts to get people to part with their phone number, often through dubious means, are common. One such example is to get customers to share their phone number to bill retail purchases. It's often done by linking it to the billing system even when it serves no purpose in concluding a transaction. Times of India reported that this method of violating personal data privacy may soon end as the consumer affairs ministry is expected to issue an advisory to stop it. It's a much-needed move. But it doesn't solve the core problem. Invasion of data privacy is not limited to consumer transactions. It's far wider in scope. The only way to check it is to legislate a comprehensive personal data protection law. Absent that, any solution is at best a piecemeal effort. India has lagged in this aspect. As a result, the explosion of digital activity has been accompanied by a surge in extracting personal data without consent. Government of India began the ongoing process of enacting a personal data protection law in 2019. It's gone through many iterations. The bill needs to be introduced in the next parliament session. India's data protection framework should strongly emphasise two principles, data minimization and purpose limitation. The former is the first line of defence against abuse as data collection needs to be limited to just what's relevant to conclude a transaction. The principle of purpose limitation then seeks to ensure that data collected is used for only the stated purpose. While the intent of the consumer affairs ministry is positive, it alone can't ensure Indian's data privacy.