International Peer-Reviewed JournalOpen AccessISSN 2456-8880
irejournals@gmail.com+91-7433024337

Home / Current Issue / Paper 1718085

1718085PublishedVol 9 · Issue 11

Consent, Control, and the Constitution: Deconstructing India’s Digital Personal Data Protection Act, 2023

Rohan S

Subject area: Science,Engineering and Technology  ·  Area of research: Law

DOI: https://doi.org/10.64388/IREV9I11-1718085

Abstract

The enactment of the Digital Personal Data Protection Act (DPDPA), 2023, marks the culmination of India’s long and contested legislative journey toward a statutory data protection regime. Built upon the constitutional bedrock of the right to privacy affirmed in K.S. Puttaswamy (Retd.) v. Union of India (2017), the Act nominally centres the individual as the sovereign of her personal data. Yet a close doctrinal reading reveals a regime in which consent — the Act’s primary lawful basis for processing — is structurally compromised by broadly drawn “deemed consent” provisions, an absence of genuine withdrawal mechanisms, and a regulatory architecture that subordinates individual control to state and commercial interests. This paper interrogates the DPDPA’s consent framework as a site of constitutional tension, examining whether the Act’s design meets the proportionality standard mandated by Puttaswamy and provides meaningful individual control over personal data in an age of algorithmic surveillance. Through doctrinal analysis and comparative reference to the GDPR and the California Consumer Privacy Act, this paper argues that the DPDPA’s consent framework is constitutionally underspecified and recommends six targeted legislative remedies to restore the individual to the centre of India’s data governance design.

Keywords

DPDPA 2023, Consent, Data Fiduciary, Puttaswamy, Fundamental Rights, GDPR, Informational Privacy

How to cite this paper

Rohan S "Consent, Control, and the Constitution: Deconstructing India’s Digital Personal Data Protection Act, 2023" Iconic Research And Engineering Journals Volume 9 Issue 11 2026 Page 3531-3536 https://doi.org/10.64388/IREV9I11-1718085
Rohan S "Consent, Control, and the Constitution: Deconstructing India’s Digital Personal Data Protection Act, 2023" Iconic Research And Engineering Journals, vol. 9, no. 11, May. 2026, doi: https://doi.org/10.64388/IREV9I11-1718085
Rohan S (2026). Consent, Control, and the Constitution: Deconstructing India’s Digital Personal Data Protection Act, 2023. Iconic Research And Engineering Journals, 9(11). doi: https://doi.org/10.64388/IREV9I11-1718085
Rohan S "Consent, Control, and the Constitution: Deconstructing India’s Digital Personal Data Protection Act, 2023" Iconic Research And Engineering Journals, vol. 9, no. 11, May. 2026. Crossref, https://doi.org/10.64388/IREV9I11-1718085
@article{1718085,
      author = {Rohan S},
      title = {Consent, Control, and the Constitution: Deconstructing India’s Digital Personal Data Protection Act, 2023},
      journal = {Iconic Research And Engineering Journals},
      year = {2026},
      volume = {9},
      number = {11},
      pages = {3531-3536},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1718085.pdf},
      abstract = {The enactment of the Digital Personal Data Protection Act (DPDPA), 2023, marks the culmination of India’s long and contested legislative journey toward a statutory data protection regime. Built upon the constitutional bedrock of the right to privacy affirmed in K.S. Puttaswamy (Retd.) v. Union of India (2017), the Act nominally centres the individual as the sovereign of her personal data. Yet a close doctrinal reading reveals a regime in which consent — the Act’s primary lawful basis for processing — is structurally compromised by broadly drawn “deemed consent” provisions, an absence of genuine withdrawal mechanisms, and a regulatory architecture that subordinates individual control to state and commercial interests. This paper interrogates the DPDPA’s consent framework as a site of constitutional tension, examining whether the Act’s design meets the proportionality standard mandated by Puttaswamy and provides meaningful individual control over personal data in an age of algorithmic surveillance. Through doctrinal analysis and comparative reference to the GDPR and the California Consumer Privacy Act, this paper argues that the DPDPA’s consent framework is constitutionally underspecified and recommends six targeted legislative remedies to restore the individual to the centre of India’s data governance design.},
      keywords = {DPDPA 2023, Consent, Data Fiduciary, Puttaswamy, Fundamental Rights, GDPR, Informational Privacy},
      month = {May},
      doi = {https://doi.org/10.64388/IREV9I11-1718085}
  }