Explainer: The Consent Regime under DPDPA, 2023

Summary:

This article examines India’s Digital Personal Data Protection Act 2023, focusing on the adequacy of its consent-based framework as the primary mechanism for privacy protection. It discusses sensitive data classification, the institutional independence of the Data Protection Board, and the limitations of consent in monopolistic digital markets.

Introduction

The increasing level of dependence on technology has led to consumer data being used as currency for digital platforms. Platforms such as Instagram, WhatsApp and Google which are legally called “Data Fiduciaries” process user data in a myriad of ways ranging from targeted advertising to training Artificial Intelligence. The nexus between collection of data and revenue generation for tech giants continues to be an opaque area. However, with new laws in place i.e. the Digital Data Protection Act 2023 and Digital Data Protection Rules 2025, the question that arises is whether these laws are sufficient to protect people’s privacy in a whirlwind of digital chaos?

In this context, in February of this year, the Supreme Court strongly criticized WhatsApp and Meta regarding their privacy policy. This appeal arises from the National Company Law Appellate Tribunal’s (NCLAT) order that upheld the Rs. 213.14 Cr penalty imposed by Competition Commission of India (CCI). Justice Bagchi and the Chief Justice pressed Meta on tracking consumer behaviour that leads to data monetization through targeted advertising.

The Government has begun phased implementation of India’s new digital data protection framework. The substantive provisions of the DPDP Act and DPDP Rules will come into force by May 2027. The central mechanism of this framework is user consent, whereby users are termed as “Data Principals”. This article examines the capability of the consent regime in protecting privacy. The insufficiency of consent as a mechanism and the complexity of data processing in contemporary times is also analyzed.

Background and history

The historic judgement delivered in Justice K.S. Puttaswamy v Union of India (Puttaswamy) recognized privacy as a fundamental human right under the constitution of India. The Court held that privacy is inseparable from liberty. After this ruling, the Government of India constituted the B.N. Srikrishna Committee of experts to examine issues related to data protection.  After initial deliberation, the committee released a White Paper on Data Protection framework for India (White Paper) identifying certain main themes for fair processing of data. The principal areas were identified as: treating consent as a pre-condition for data processing and classification of data into personal data and sensitive personal data such as caste, religion, sexual orientation of the individual. The committee recommended that more protection should be given to sensitive personal data.

Eventually the Committee’s recommendations were used to draft the  Personal Data Protection Bill, 2019 (PDPB, 2019) which subsequently led to the formation of the Data Protection Bill, 2021 (DPB). However, the DPB, 2021 was withdrawn by the Minister for Communications and Information Technology, Ashwini Vaishnaw on 03 August 2022. A year later, on 07 August 2023, the Digital Personal Data Protection Bill, 2023 (DPDPB, 2023) was passed. The Bill was approved by the President of India and became law as the Digital Personal Data Protection Act, 2023 (DPDP Act) on 11 August 2023.

Processing of digital personal data

The DPDP Act is concerned with the “processing of digital personal data”, which means performing a set of operations on personal data such as collecting, sharing, using, etc. according to s.3 r/w s.2(x) of the Act. Anything that can be traced to you or can be used to identify you is your personal data.

DPDP act is a protectionist legislation based on a notice-and-consent mechanism with one caveat. It does not apply to data that is willingly shared by people for instance, social media posts or publicly available data. This is a broad-exemption at the very outset of this legislation. It can have devastating effects on individuals’ privacy in the age where people’s online data is used for AI training.

The DPDP act does not make any categorization between different kinds of personal data, unlike the European Union’s General Data Protection Regulation (GDPR) which classifies data into General Personal Data and Sensitive Personal Data. This classification offers high levels of protection to sensitive personal data that includes racial or ethnic origin, political opinions, religious beliefs, genetic and medical data, sexual orientation, etc. The lack of classification in the Indian framework puts marginalized communities at risk, depriving them of remedies, apart from approaching the Data Protection Board India. Data collected for employment purposes or sexual orientation collected via dating apps can be used to discriminate against individuals. Facebook was previously criticised for allowing advertisers to target and exclude users on the basis of their caste, religion and economic status. Professor Philip Howard, Director of the Oxford Internet Institute, warns that public opinion is constantly being shaped by “computational propaganda” targeting and using data relating to political beliefs of people. The lack of categorization of data increases this risk. As digital marketing and targeting schemes are opaque, users are left in the dark as to which personal data is being used how and when.

Consent

Data processing can be done in two manners u/s 4 and 5, primarily through consent and secondly, if the state requires data to be processed for legitimate uses. All data should be processed for only a “lawful purpose”.

Data Fiduciaries have to obtain consent from the Data principals via a notice. Section 5 provides guidelines to be followed while administering a notice for obtaining consent. It must be in simple and clear language that informs the user of the purposes for the collection of personal data, procedure for withdrawal of consent, grievance redressal mechanism, and complaint mechanism.

The phrase “lawful purpose” is determined by the Act as anything that is not forbidden by the law. This is a negative formulation, meaning fairness of the law is to be understood by what it is not. By defining lawful purpose negatively, Section 4(2) creates a presumption of lawfulness. Unless a specific law expressly forbids a purpose, that purpose is considered lawful for data processing.

Consent under the DPDP framework must be free, specific, informed, unconditional and unambiguous with a clear affirmative action as defined u/s 6 of the act. The validity of consent obtained from a Data Principal exists only for the specific period of time and for the specific purpose for which it was given. This implies that authorities cannot rely on “bundled consent” and infringement by over-reaching authority in the interpretation of consent can constitute an infringement.

A right under this section also covers the right to withdraw consent, after which any processing of data would be illegal. Moreover, the burden of proof lies on the Data Fiduciary that the consent was obtained legally. This is a significant consumer protection measure where individuals are relieved from the burden of proving a breach of their privacy. This section is the bedrock for all the procedural requirements of obtaining consent. Such heavy reliance on consent implies that Data Principals will act as informed users. And only after careful consideration would they autonomously provide their consent. Both the GDPR and DPDP frameworks require consent to be the main factor to decide legality.

McDonald and Cranor have estimated that if data subjects were to read all the privacy policies presented to them, it would take them 244 h annually. This means that the effectiveness of consent as a safeguard against unauthorised data disclosure is reduced, because it is overused.

Research suggests that the current legal framework of consent is based upon the idea of autonomous authorization. This has led to “consent desensitization” and “consent fatigue” stemming from an overload of information. The current legal policy is ineffective as users see consent requirements as a barrier to get past to gain access. The issue of information overload is exacerbated by the fact that data subjects are often confronted with consent decisions while they are involved in a completely different decision-making process. For example, the decision to give consent is often exercised while searching for new jeans. Privacy protection then becomes a trade-off between instant gratification versus the abstract risks associated with misuse or abuse of personal data, which are often not well understood, if at all.

Consent-based mechanisms are necessary but not sufficient at this time in history. There are compelling reasons to provide protections beyond consent in both promoting individual rights around privacy and collective, welfarist goals. This takes us to exploring alternatives in data protection to consent-based mechanisms.

However, consent is the most substantial safeguard that an average user has today. Loopholes in the consent mechanism must be understood before exploring the realm of alternative data protection.

Exceptions to consent.

There are different kinds of exceptions u/s 7, and 17 where the notice and consent principles do not apply. The exception of “certain legitimate uses” u/s 7 has two criteria that exclude Data Fiduciaries from obtaining consent. First is voluntary information provided for a specific purpose. Second is information needed for state instrumentalities to perform their functions. These functions can range from providing subsidies, legal obligations, medical emergencies, etc.

One exception that catches the eye u/s 7 and 17 is the authority given to central government to exempt any state agency on the grounds of sovereignty, integrity of India, public order, and security of the State. These grounds effectually limit the scope of the Act as they grant unquestioned discretion to the executive to suspend privacy protections. This section permits blanket immunities to the State without requiring a demonstrable nexus between the exempted activity and the stated objective.

Implying a complete disregard of the  proportionality test laid out in Puttaswamy. Sovereignty and integrity of the nation are broad and vague terms which can be used by the state to dispense with data security of individuals. It is a disproportionate measure based upon discretion that shifts the Act’s balance towards state surveillance. Broad exemptions under the grounds of state security, render Data principals mere subjects without autonomy and participation in maintaining their digital privacy.

The Supreme Court in Anuradha Bhasin v. Union of India has explicitly warned against excessive use of “national security” to justify overarching violations on fundamental rights, holding that national security cannot justify disproportionate restrictions. The Court in Manohar Lal Sharma v. Union of India stated that the “mere invocation of national security by the State does not render the Court a mute spectator”. Holding that protection of citizens’ rights must be paramount and that surveillance technologies cannot be allowed to function without constraints.

The DPDP Act, while undoubtedly essential in addressing contemporary privacy challenges, strays into the realm of excessive discretion. These powers are further amplified, with the lack of effective checks and balances upon the government’s conduct.

Institutional framework

The consent regime under the DPDP Act is only as strong as the body tasked with enforcing it. That body is the Data Protection Board of India (DPB) established u/s 18 of the Act. It is the primary adjudicatory authority empowered to receive complaints, conduct inquiries and also impose penalties in cases of breach. However, the board’s design raises serious questions about whether it can function as independently as it should.

The structural problem begins with appointments. The Board’s Chairperson and Members are appointed by the Central Government, on the recommendation of a Selection Committee that is itself constituted by the Central Government. The Act has given unchecked powers to the Executives to appoint the chairperson and members of the DPBI, thus diluting the independence of the Board. This stands in sharp contrast to the independence requirements built into GDPR-equivalent supervisory authorities, where Article 52 explicitly mandates that supervisory authorities act with “complete independence” and member states are prohibited from influencing their decisions. A set of Writ Petitions challenging the constitutionality of DPDPA are currently pending before the Supreme Court. One of the core issues is lack of institutional independence of the DPB.

There is also the concept of a “Consent Manager” introduced within S. 6(7) to 6(9). Consent Managers are registered with the Data Protection Board. They can enable the Data Principal to give, manage, and withdraw her consent. They are in a fiduciary relationship with the Data Principal.  Only a company can be a consent manager that has a net worth of more than Rs. 2 Cr.  It is not clear why the threshold of Rs. 2 Cr. has been specified. Effectually, only established commercial entities can afford this role which raises an immediate question about whose interests will such entities prioritize.

Conclusion

Over-reliance on consent and vague, broad exemptions to it are two extreme ends of the rope that cannot achieve data privacy meaningfully. Data breaches can have devastating effects when they result in exposing sensitive information which can lead to stigmatization of a person in society.

In 2010, professor Ramchandra Siras was harassed by some journalists who had barged into his flat and filmed him being intimate with his partner, a man. Photographs were taken with the aim to shame him publicly. He was suspended by Aligarh Muslim University  for “bringing disrepute to the institution”. The Allahabad High Court stayed Professor Siras’ suspension but did not stop the departmental enquiry. He died by suicide a few days after the court order.  

Helen Nissenbaum, in her book Privacy in Context , argues that sharing of privacy and personal information differs contextually where societal norms play a huge role. She posits the idea of “contextual integrity”. Warning that privacy concerns should not be limited solely to concern about control over personal information, but on distribution and “flow” of information according to norms governing distinct social contexts. Hence, categorization of data as per the specific context is crucial for legislative policy.  

The new consent regime should be informed by the growing concerns and complexities of data flow in the new age. There should be more user-friendly safeguards built into legislation than consent that derive from current technology-practices employed by people in their daily lives. Independent oversight mechanisms must be put in place, along with mandatory transparency with regards to processing by Data Fiduciaries in order to ensure that information flows appropriately and privately.

Author Bio: Divyanshi Sonkeria is a law student pursuing B.A. LL.B. (Hons.) from University Scool of Law and Legal Studies, GGSIPU. She has a keen interest in constitutional law, criminal law and and contemporary socio-legal developments. She is a CEDE-LAOT mentee.
 
[Editorial Note: This piece was edited by Hansika and published by Tamanna Yadav from the student editorial board.]
İmajbetgrandpashabet girişgrandpashabetGrandPashaBet Şikayetgrandpashabet güncel girişşanlıurfa konteynerbetcio girişHoliganbetHoliganbetHoliganbetGrandpashabetGrandpashabetjojobet girişjojobetgrandpashabetjojobet girişbetcio girişJojobetJojobetJojobetEscort Royalejojobetgrandpashabetcasibom girişjojobetgrandpashabetgrandpashabet