International Peer-Reviewed JournalOpen AccessISSN 2456-8880
irejournals@gmail.com+91-7433024337

Home / Current Issue / Paper 1718085

1718085 Vol 9 · Issue 11 Download Paper

Consent, Control, and the Constitution: Deconstructing India’s Digital Personal Data Protection Act, 2023

Rohan S

Subject area: Science,Engineering and Technology  ·  Area of research: Law

DOI: https://doi.org/10.64388/IREV9I11-1718085

Abstract

The enactment of the Digital Personal Data Protection Act (DPDPA), 2023, marks the culmination of India’s long and contested legislative journey toward a statutory data protection regime. Built upon the constitutional bedrock of the right to privacy affirmed in K.S. Puttaswamy (Retd.) v. Union of India (2017), the Act nominally centres the individual as the sovereign of her personal data. Yet a close doctrinal reading reveals a regime in which consent — the Act’s primary lawful basis for processing — is structurally compromised by broadly drawn “deemed consent” provisions, an absence of genuine withdrawal mechanisms, and a regulatory architecture that subordinates individual control to state and commercial interests. This paper interrogates the DPDPA’s consent framework as a site of constitutional tension, examining whether the Act’s design meets the proportionality standard mandated by Puttaswamy and provides meaningful individual control over personal data in an age of algorithmic surveillance. Through doctrinal analysis and comparative reference to the GDPR and the California Consumer Privacy Act, this paper argues that the DPDPA’s consent framework is constitutionally underspecified and recommends six targeted legislative remedies to restore the individual to the centre of India’s data governance design.

Keywords

DPDPA 2023, Consent, Data Fiduciary, Puttaswamy, Fundamental Rights, GDPR, Informational Privacy

References

[1] K.S. Puttaswamy (Retd.) & Anr. v. Union of India & Ors., (2017) 10 SCC 1 [Nine-Judge Privacy Bench].

[2] K.S. Puttaswamy v. Union of India, (2019) 1 SCC 1 [Aadhaar Five-Judge Bench].

[3] Anuradha Bhasin v. Union of India, (2020) 3 SCC 637.

[4] M.P. Sharma v. Satish Chandra, District Magistrate, Delhi, AIR 1954 SC 300.

[5] Kharak Singh v. State of U.P., AIR 1963 SC 1295.

[6] Shreya Singhal v. Union of India, (2015) 5 SCC 1.

[7] Case C-518/07, Commission v. Germany [2010] ECR I-1885 (CJEU) [DPA Independence].

[8] Case C-311/18, Data Protection Commissioner v. Facebook Ireland (Schrems II), ECLI:EU:C:2020:559 (CJEU 2020).

[9] Case C-673/17, Planet49 GmbH v. Bundesverband der Verbraucherzentralen, ECLI:EU:C:2019:801 (CJEU 2019).

[10] Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) (India).

[11] Information Technology Act, 2000 (Act No. 21 of 2000) (India).

[12] Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 (India).

[13] Regulation (EU) 2016/679 (General Data Protection Regulation) [2016] OJ L119/1.

[14] California Consumer Privacy Act, Cal. Civ. Code §§ 1798.100–1798.199.100 (2018, as amended by CPRA 2020).

[15] UK Data Protection Act 2018 (c.12); Age Appropriate Design Code (Children’s Code), ICO (UK, 2020).

[16] Justice B.N. Srikrishna Committee, ‘A Free and Fair Digital Economy: Protecting Privacy, Empowering Indians’ (MeitY, Government of India, July 2018).

[17] Joint Parliamentary Committee on the Personal Data Protection Bill, 2019, Report (Lok Sabha Secretariat, December 2021).

[18] European Data Protection Board, ‘Guidelines 05/2020 on Consent under Regulation 2016/679’ (EDPB, Version 1.1, 4 May 2020).

[19] Article 29 Working Party, ‘Guidelines on Consent under Regulation 2016/679’ (WP259 rev.01, April 2018).

[20] Graham Greenleaf, Asian Data Privacy Laws: Trade and Human Rights Perspectives (OUP, 2014).

[21] Rahul Matthan, Privacy 3.0: Unlocking Our Data-Driven Future (HarperCollins India, 2018).

[22] Eleni Kosta, Consent in European Data Protection Law (Martinus Nijhoff Publishers, 2013).

[23] Vrinda Bhandari and Renuka Sane, ‘Towards a Privacy Framework for India in the Age of the Internet’ (2018) 14 Journal of Indian Law and Society 1.

[24] Arnav Kumar, ‘The Chimera of Consent: Consent-Based Data Protection Under India’s DPDPA, 2023’ (2024) 9 Indian Journal of Law and Technology 45.

[25] Paul Schwartz and Daniel Solove, ‘The PII Problem’ (2011) 86 New York University Law Review 1814.

[26] Usha Ramanathan, ‘A Unique Identity Bill: Concerns’ (2010) 45(35) Economic and Political Weekly 10.

[27] Apar Gupta, ‘Surveillance Law and Technology in India: An Analysis of the DPDPA’s Section 17 Exemption’ (2024) 11 NUJS Law Review 88.

[28] Rohan Suraj, ‘The Deemed Consent Problem: Structural Deficits in India’s Data Protection Act’ (2025) 9(1) Amity International Journal of Juridical Sciences 45.

How to cite this paper

Rohan S "Consent, Control, and the Constitution: Deconstructing India’s Digital Personal Data Protection Act, 2023" Iconic Research And Engineering Journals Volume 9 Issue 11 2026 Page 3531-3536 https://doi.org/10.64388/IREV9I11-1718085
Rohan S "Consent, Control, and the Constitution: Deconstructing India’s Digital Personal Data Protection Act, 2023" Iconic Research And Engineering Journals, vol. 9, no. 11, May. 2026, doi: https://doi.org/10.64388/IREV9I11-1718085
Rohan S (2026). Consent, Control, and the Constitution: Deconstructing India’s Digital Personal Data Protection Act, 2023. Iconic Research And Engineering Journals, 9(11). doi: https://doi.org/10.64388/IREV9I11-1718085
Rohan S "Consent, Control, and the Constitution: Deconstructing India’s Digital Personal Data Protection Act, 2023" Iconic Research And Engineering Journals, vol. 9, no. 11, May. 2026. Crossref, https://doi.org/10.64388/IREV9I11-1718085
@article{1718085,
      author = {Rohan S},
      title = {Consent, Control, and the Constitution: Deconstructing India’s Digital Personal Data Protection Act, 2023},
      journal = {Iconic Research And Engineering Journals},
      year = {2026},
      volume = {9},
      number = {11},
      pages = {3531-3536},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1718085.pdf},
      abstract = {The enactment of the Digital Personal Data Protection Act (DPDPA), 2023, marks the culmination of India’s long and contested legislative journey toward a statutory data protection regime. Built upon the constitutional bedrock of the right to privacy affirmed in K.S. Puttaswamy (Retd.) v. Union of India (2017), the Act nominally centres the individual as the sovereign of her personal data. Yet a close doctrinal reading reveals a regime in which consent — the Act’s primary lawful basis for processing — is structurally compromised by broadly drawn “deemed consent” provisions, an absence of genuine withdrawal mechanisms, and a regulatory architecture that subordinates individual control to state and commercial interests. This paper interrogates the DPDPA’s consent framework as a site of constitutional tension, examining whether the Act’s design meets the proportionality standard mandated by Puttaswamy and provides meaningful individual control over personal data in an age of algorithmic surveillance. Through doctrinal analysis and comparative reference to the GDPR and the California Consumer Privacy Act, this paper argues that the DPDPA’s consent framework is constitutionally underspecified and recommends six targeted legislative remedies to restore the individual to the centre of India’s data governance design.},
      keywords = {DPDPA 2023, Consent, Data Fiduciary, Puttaswamy, Fundamental Rights, GDPR, Informational Privacy},
      month = {May},
      doi = {https://doi.org/10.64388/IREV9I11-1718085}
  }