The consent that was not: Paradox of digital world

In 2017, the Supreme Court’s judgment in KS Puttaswamy v. Union of India established that privacy was not a privilege granted by the State, but rather an intrinsic dimension of human dignity. The enactment of the Digital Personal Data Protection Act, 2023 was held as a deliverance to that constitutional promise. At its core lay consent; an idea that individuals should meaningfully decide how their personal data is collected, processed, and used.
Yet a closer reading of the Act reveals an uncomfortable question: if consent is truly the cornerstone of this framework, why does the law spend so much of its architecture dismantling it?
This is not merely a question of legislative drafting. It concerns the very nature of autonomy, and the relationship between citizens, corporations, and the State in an increasingly surveilled digital republic.
The Act’s consent framework, on paper, is commendable. Consent must be free, informed, specific, and unambiguous, and such requirements are consistent with the constitutional vision articulated in Puttaswamy, where the nine-judge bench recognised that informational privacy entails the individual’s right to control the narrative of their own data. Consent, in this sense, is not a procedural checkbox, but rather a legal expression of personal autonomy, as well as dignity.
Yet the Act simultaneously introduces “certain legitimate uses”, which is a category of situations under which personal data may be processed entirely without consent.
Employment purposes, State welfare functions, legal obligations, medical emergencies, voluntarily disclosed information — the list is broad, and deliberately so. Individually, each exception appears defensible. Collectively, they raise a more structural concern: when exceptions are wide enough to swallow the rule, the rule ceases to function as one.
This is not hyperbole — it is a principle well established in constitutional jurisprudence. The Puttaswamy judgment did not merely recognise privacy as a fundamental right; it prescribed that any restriction upon it must satisfy a three-part test of legality, necessity, and proportionality, drawing from the standards articulated in Modern Dental College v. State of Madhya Pradesh (2016). The question the DPDPA invites, therefore, is whether its “legitimate uses” carve-outs survive proportionality scrutiny — or whether they represent administrative convenience dressed in constitutional clothing.
Defenders of the Act will rightly argue that no modern privacy framework can function on consent alone. Hospitals cannot pause emergency care to obtain authorisation. Governments cannot administer welfare schemes if every data transaction requires individual sign-off. These are not hypothetical concerns - they are operational realities. The DPDPA’s exceptions, in this reading, are not concessions to power but concessions to practicality.
This argument has merit, and it deserves acknowledgement. The Act does represent a meaningful step forward — for a country that, until recently, had no comprehensive data protection legislation, the DPDPA’s baseline requirements around transparency, purpose limitation, and data fiduciary obligations are not insignificant. The framework is imperfect, but it is not inconsequential.
The concern, however, is not that exceptions exist — it is that the Act offers limited mechanisms to scrutinise whether those exceptions are being invoked appropriately. There is no independent regulatory body insulated from executive influence; the Data Protection Board operates under conditions that raise legitimate questions about its autonomy. There is no robust proportionality review built into the exception-triggering process. The result is a framework that places considerable institutional discretion in the hands of data fiduciaries and State agencies, with the individual left to trust that this discretion will be exercised responsibly.
This is the deeper philosophical problem. Privacy is ultimately about agency — the capacity of individuals to exercise meaningful control over information about themselves. When legal frameworks migrate from individual choice toward institutional discretion, they risk a subtle but consequential transformation: citizens cease to be active participants in data governance and become, instead, its passive subjects. The shift is rarely announced. It happens incrementally, exception by exception, until consent - once the cornerstone — becomes largely ceremonial. The DPDPA is, without question, a significant milestone in India’s evolving data protection landscape. But its treatment of consent reveals an unresolved tension between individual autonomy and administrative practicality — a tension that the Act acknowledges without adequately resolving. As India’s privacy framework matures through legislative revision and judicial interpretation, the task for lawmakers and courts alike will be to ensure that consent does not calcify into symbolism.
A privacy law should not merely inform citizens that they possess control over their data. It must guarantee that such control remains substantive, enforceable, and constitutionally proportionate - not just in the preamble, but in practice. The DPDPA’s success will ultimately be measured not by how prominently it enshrines consent, but by how meaningfully it protects the individual’s right to say no.
The writer is a class XII student. Views expressed are based on her research and analysis; Views presented are personal.















