Skip to content

Concerns of Consent under the DPDPB: Compliance Requirements

Article by Tsaaro

7 min read

Introduction:

Data protection requires a comprehensive system design strategy incorporating administrative, legal, and technical safeguards. To safeguard user rights, personal information, and privacy, the Ministry of Electronics & Information Technology (Meity) has released the draft of the Digital Personal Data Protection Bill 2022 (DPDPB). The bill covers the processing of digital personal data in India, obtained online or collected offline and digitized. It also applies to processing conducted outside India if it involves promoting products/services to Indian citizens or profiling Indian citizens.

The DPDPB mandates that personal data can only be processed with the individual’s consent for a lawful purpose. In some cases, consent may be deemed given. Analysing the provisions related to consent under the Act, this article explores its intricacies in relation to privacy regulation in India.

Evolution of the concept of ‘consent’ under various existing laws in India vs. DPDPB:

When the IT Act was enacted way back in 2000, its primary objective was to establish fundamental aspects of technology law, such as digital signatures and granting legal validity to electronic documents, among other similar provisions. However, the Information Technology (Amendment) Act of 2008 brought significant changes to the IT Act, and it came into effect on October 27, 2009. It introduced Section 43A, requiring corporate entities handling sensitive personal data to adopt reasonable security practices. It also included provisions for compensation in case of inadequate data protection. The inclusion of Section 72A, which enforced fines for intentional breaches of personal data, was also made. But the amendment did not provide specific definitions for personal data or sensitive personal data. The determination of “sensitive personal data or information” was left to the Central Government in consultation with professional groups. Subsequently, the 2011 Rules were established, marking India’s first legal framework for data privacy, effective from March 28, 2012.

Rule-5(1) of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“2011 Rules”) states that:

Body corporate or any person on its behalf shall obtain consent in writing through letter or Fax or email from the provider of the sensitive personal data or information regarding purpose of usage before collection of such information.”

Therefore, consent is crucial for collecting and using sensitive personal data. While the 2011 Rules emphasize the need for consent, they lack specific guidelines or requirements for obtaining valid consent or addressing its specifics.

In 2017, the Supreme Court of India declared the right to privacy as a fundamental right in the case of K.S. Puttaswamy v. UOI.[1] This led to the formation of a committee led by B.N. Srikrishna to address data privacy in India. Recognizing the changing market dynamics and the increasing reliance on data in the digital economy, the committee recommended the adoption of a data protection law. As a result, the Personal Data Protection Bill 2019 was initially proposed but later withdrawn. Subsequently, a revised bill called the Digital Personal Data Protection Bill 2022 was introduced.

In comparison, the DPDPB of 2022 introduces a robust framework for consent, emphasizing informed, clear, and affirmative consent for personal data processing. It incorporates explicit consent principles, requiring specific and separate consent for each purpose. The bill mandates clear communication of consent requests in plain language, along with contact details of the Data Privacy Officer or authorized personnel. The new law defines the consent framework clearly, extending its scope to all personal data and providing detailed provisions for both sensitive and non-sensitive data. It prioritizes individual autonomy, transparency, and control over personal data, setting higher standards for obtaining and maintaining consent in data protection.

Ensuring consent compliance: DPDPB 2022 Requirement

Sections 7 and 8 of the bill outline requirements for ‘consent’ and ‘deemed consent,’ binding data fiduciaries to comply with them. Section 7(1) mandates ‘free,’ ‘specific,’ and ‘informed’ consent, ensuring voluntary agreement is limited to the stated purpose and not extended to undisclosed purposes. However, consent must not violate the provisions of the Act.

Section 7(3) obligates data fiduciaries to present consent requests in clear and plain language, providing the option for the data principal to access them in English or any language specified in the Eighth Schedule to the Indian Constitution. This inclusion aims to promote inclusivity and protect the rights of individuals who prefer their native language. However, compliance with these measures may present challenges for data fiduciaries, such as recruiting language-fluent staff, managing translations, and allocating additional resources. Maintaining consistency and timely updates across translations can be complex and time-consuming.

Section 8 of the bill deals with ‘deemed consent’. It lays down several conditions, and if the data principal acts in that manner, it is assumed that the data principal has given consent for the processing of their personal data. These conditions include the following:

i. When the data principal voluntarily provides personal data, and it is reasonably expected.

ii. For legal functions, services benefiting the data principal, or issuance of certificates, licenses, or permits.

iii. Compliance with an order or judgment under the law.

iv. Providing healthcare during epidemics or other emergencies.

v. Assisting in disasters or maintaining public order.

vi. Responding to medical emergencies for threats to life or health.

vii. Workplace-related goals like preventing espionage, protecting trade secrets, and managing employees.

viii. Processing for the public interest, including fraud prevention, mergers, security, and debt.

ix. Processing for fair and reasonable purposes, considering the data controller’s interests, public interest, and data subject’s expectations.

These are the conditions mentioned in the bill under which it would be considered that there is deemed consent from the data principal. However, compliance with the bill’s provisions may be challenging, particularly in determining what constitutes “fair and reasonable” purposes under Section 8(9). Assessing whether the data fiduciary’s legitimate interests outweigh the data principal’s rights requires careful evaluation, which can vary based on interpretations and perspectives. In India, with varying digital literacy rates, establishing a “reasonable expectation” regarding data-sharing consequences is complex. Moreover, many people lack an understanding of the implications of data sharing, potentially leading to significant privacy invasions for data principals.

Furthermore, compliance becomes challenging when authorities unreasonably process data in the name of public interest. Establishing and justifying public interest in processing personal data is subjective and can vary among stakeholders. Section 8(7) of the bill deems consent given for employment purposes, enabling employers to collect employee data without explicit consent. This provision allows surveillance technology use without employee consent, compromising privacy. It further empowers employers and exacerbates the power imbalance between employers and employees.

The bill contains a provision that limits the ability to withdraw consent in certain circumstances, which undermines the individual’s right to privacy. While the DPDPB acknowledges the right to withdraw consent, it does not apply in cases of deemed consent, restricting the rights of data principals in those situations.

Exemption for Government:

There are certain kinds of exemptions provided to the government on the basis of some vague ground, and this poses a serious threat to the right to privacy. These exemptions allow the government to process user data without consent and without adhering to the provisions of the Act. Section 18(2)(a) permits the government to process user data for reasons such as national security, maintaining friendly relations with other countries, upholding public order, or preventing the incitement of a “cognisable offence” related to these matters. Furthermore, Section 18(4) enables the government to retain a data principal’s information indefinitely, as the provisions of Section 9(6) do not apply to government instrumentalities. The lack of clarity in these subsections leaves room for varied interpretations and potential misuse of these powers by government agencies.

Conclusion:

While the data protection legislation aims to safeguard individuals’ privacy, certain ambiguous provisions and numerous exceptions, such as those regarding deemed consent in Section 8 and exemptions in Section 18, pose a threat to the bill’s objectives.

The bill includes a provision that exempts government agencies from the limitation on data storage. This exemption allows them to retain personal data indefinitely, even when the original purpose for processing the data is no longer relevant and there is no legal obligation to store it. This exemption contradicts the principles of purpose limitation and data minimization, as it goes against the idea of deleting data once its intended purpose has been fulfilled. Furthermore, more and more obligations have been imposed on the data fiduciary, and this poses certain grave challenges in compliance with those measures.

Also read  DPDPB and GDPR: Obligations of Controllers and Processors to know more about the obligations of Controllers and Processors in data processing. Tsaaro helps in compliance with the privacy laws, with the skilled privacy professionals in the market. Take the first step towards a secure your organization’s data by scheduling a call with our privacy expert team at Tsaaro Solutions today. Get in touch with us at info@tsaaro.com


[1] (2017) 10 SCC 1.

1,322 thoughts on “Concerns of Consent under the DPDPB: Compliance Requirements”

  1. Great V I should definitely pronounce, impressed with your web site. I had no trouble navigating through all the tabs as well as related information ended up being truly simple to do to access. I recently found what I hoped for before you know it at all. Quite unusual. Is likely to appreciate it for those who add forums or something, site theme . a tones way for your client to communicate. Nice task..

  2. A person essentially help to make seriously articles I would state. This is the very first time I frequented your website page and thus far? I amazed with the research you made to make this particular publish incredible. Excellent job!

  3. Thank you for another informative site. The place else may I am getting that type of information written in such a perfect method? I have a venture that I’m simply now working on, and I’ve been at the glance out for such information.

  4. Hey this is kinda of off topic but I was wanting to know if blogs use WYSIWYG editors or if you have to manually code with HTML. I’m starting a blog soon but have no coding expertise so I wanted to get advice from someone with experience. Any help would be enormously appreciated!

  5. Интернет-магазин инструментов https://profimaster58.ru для работы по металлу — ваш эксперт в качественном оборудовании! В ассортименте: измерительный инструмент, резцы, сверла, фрезы, пилы и многое другое. Гарантия точности, надежности и выгодных цен.

  6. Смотрите аниме онлайн https://studiobanda.net бесплатно и без рекламы. Удобный каталог с популярными тайтлами, новинками и свежими сериями. Высокое качество видео и быстрый плеер обеспечат комфортный просмотр. Подборки по жанрам, рекомендации и регулярные обновления сделают ваш опыт максимально приятным.

  7. Предприниматель и инвестор Святослав Гусев https://spark.ru/startup/gusev специализирующийся на IT, блокчейн-технологиях и венчурном инвестировании. Активно делится аналитикой рынка, инсайдами и новостями, которые помогут заработать каждому!

  8. At Cheap SEO Solutions https://cheap-seo-solutions.com we don’t believe in half-measures. We deliver comprehensive SEO solutions that cover all the bases, from keyword research and on-page optimization to link building and content creation. Our goal is to help businesses improve their search engine rankings, drive organic traffic, and increase conversions.

  9. Ставки на спорт с Vavada https://selfiedumps.com это простота, надежность и высокие шансы на победу. Удобная платформа, разнообразие событий и быстрые выплаты делают Vavada идеальным выбором для любителей азарта. Зарегистрируйтесь сейчас и начните выигрывать вместе с нами!

  10. Смотрите любимые дорамы https://dorama2025.ru онлайн в HD-качестве! Огромный выбор корейских, китайских, японских и тайваньских сериалов с профессиональной озвучкой и субтитрами.

  11. Ищете качественные стероиды для мышц? У нас вы найдете широкий выбор сертифицированной продукции для набора массы, сушки и улучшения спортивных результатов. Только проверенные бренды, доступные цены и быстрая доставка. Ваше здоровье и успех в спорте – наш приоритет! Заказывайте прямо сейчас!”

  12. Строительный портал https://bms-soft.com.ua для тех, кто строит и ремонтирует! Узнайте о трендах, найдите мастеров, подберите материалы и получите ценные рекомендации.

  13. Good – I should definitely pronounce, impressed with your web site. I had no trouble navigating through all the tabs as well as related information ended up being truly easy to do to access. I recently found what I hoped for before you know it at all. Reasonably unusual. Is likely to appreciate it for those who add forums or something, web site theme . a tones way for your client to communicate. Nice task.

  14. Excellent info and straight to the point. I am not sure if this really is in fact the best location to ask but do you folks have any ideea where to hire some skilled writers? Thx

  15. Hey! This is kind of off topic but I need some guidance from an established blog. Is it difficult to set up your own blog? I’m not very techincal but I can figure things out pretty fast. I’m thinking about setting up my own but I’m not sure where to start. Do you have any points or suggestions? Thank you

  16. TaskMy.ru – профессиональная помощь в решении задач любого уровня

    TaskMy.ru – это надежный сервис, который предлагает качественную помощь в выполнении задач любых направлений: от технических расчётов и программирования до написания текстов и аналитики. Мы работаем быстро, эффективно и ориентированы на ваши требования.

    Доверяя TaskMy.ru, вы получаете индивидуальный подход, точное соблюдение сроков и доступные цены. Оставьте свою задачу профессионалам – результат превзойдет ожидания!

  17. “Ищете качественный кирпич напрямую от производителя? https://Muravey61.ru – ваш надежный поставщик строительных материалов в регионе! Мы предлагаем кирпич высшего качества по доступным ценам прямо с завода. Доставка точно в срок, широкий ассортимент, и гарантированное качество – всё, что нужно для вашего строительства. Закажите у нас и убедитесь сами, что с нами строить легко!”

  18. OR Realty — это ваш надежный партнер в мире недвижимости. Мы предлагаем большой выбор квартир, домов и коммерческих объектов по выгодным условиям. Наши специалисты помогут вам найти идеальный вариант, соответствующий вашим потребностям. Надежность, качество и удобство — вот что делает OR Realty лучшим выбором. Обращайтесь!

  19. Ищете промокоды для игр промокод на барабан бонусов ggdrop наш сайт – ваш лучший помощник! Собираем актуальные игровые промокоды для бонусов, скидок и эксклюзивных наград. Наслаждайтесь играми с максимальной выгодой – воспользуйтесь промокодами уже сегодня!

  20. надежный маркетплейс bs2site at где сочетаются безопасность, широкий выбор товаров и удобство использования. Платформа работает с анонимными платежами и гарантирует полную конфиденциальность для всех пользователей.

  21. Reliable and unique bip39 Word List contains 2048 words needed to create seed phrases in crypto wallets. Allows you to safely manage private keys and guarantees the possibility of recovering funds.

  22. I do not even know how I ended up right here, however I thought this put up was good. I don’t recognize who you are but definitely you are going to a well-known blogger when you aren’t already 😉 Cheers!

  23. Металличекие двери с завода с установкой за 1 день.
    Любые конфигурации отделок на выбор. Более 3500 моделей на складе: здесь

  24. Сауна очищает организм https://sauna-broadway.ru выводя токсины через пот, укрепляет иммунитет благодаря перепадам температуры, снимает стресс, расслабляя мышцы и улучшая кровообращение. Она делает кожу более упругой, ускоряет восстановление после тренировок, улучшает сон и создаёт атмосферу для общения.

  25. Входные стальные двери с завода с установкой за 1 день.
    Любые конфигурации замков на выбор. Более 3500 моделей на складе: здесь

  26. Ковры для уюта вашего дома, ковровое покрытие.
    Ковры, которые преобразят ваш интерьер, по акции.
    Ковры для стильного интерьера, интересные дизайны.
    Декорируйте пространство с помощью ковров, добавьте.
    Ковры для игровой зоны, функциональность.
    Ковры в восточном стиле, откройте.
    Эстетика ковров в офисе, добавьте.
    Ковры, которые легко чистить, подходящий стиль.
    Как выбрать идеальный ковер?, читайте.
    Ковры для холодных полов, лучший вариант.
    Модные ковры 2025 года, декор.
    Ковры для загородного дома, выбирайте.
    Идеи по использованию ковров, узнайте.
    Разнообразие стилей ковров, найдите.
    Ковры для спальни, мягкие текстуры.
    Премиальные ковры для вашего интерьера, выбирайте.
    Мои любимые ковры для зоолюбителей, найдите.
    Теплые ковры для холодных зим, приобретайте.
    Разделение пространства с помощью ковров, функции.
    классические ковры классические ковры .

  27. Все о компьютерных играх http://lifeforgame.ru обзоры новых проектов, рейтинги, детальные гайды, новости индустрии, анонсы и системные требования. Разбираем особенности геймплея, помогаем с настройками и прохождением. Следите за игровыми трендами, изучайте секреты и погружайтесь в мир гейминга.

  28. Все о недвижимости https://stroyk-wood.ru покупка, аренда, ипотека. Разбираем рыночные тренды, юридические тонкости, лайфхаки для выгодных сделок. Помогаем выбрать квартиру, рассчитать ипотеку, проверить документы и избежать ошибок при сделках с жильем. Актуальные статьи для покупателей, арендаторов и инвесторов.

  29. Все о недвижимости https://doncodom.ru покупка, аренда, ипотека. Разбираем рыночные тренды, юридические тонкости, лайфхаки для выгодных сделок. Помогаем выбрать квартиру, рассчитать ипотеку, проверить документы и избежать ошибок при сделках с жильем. Актуальные статьи для покупателей, арендаторов и инвесторов.

  30. Покупка, аренда, ипотека https://stolbbeton.ru всё о недвижимости в одном блоге! Советы по выбору жилья, юридические аспекты, анализ цен и прогнозы рынка. Рассказываем, как грамотно оформить ипотеку, проверить документы и избежать ошибок при сделках с недвижимостью. Будьте в курсе всех изменений и трендов!

  31. Nice blog here! Also your website loads up very fast! What host are you using? Can I get your affiliate link to your host? I wish my site loaded up as quickly as yours lol

  32. Покупка недвижимости и ипотека https://asksteel.ru что нужно знать? Разбираем выбор жилья, условия кредитования, оформление документов и юридические аспекты. Узнайте, как выгодно купить квартиру и избежать ошибок!

Leave a Reply

Your email address will not be published. Required fields are marked *

Krishna

The evolving digital landscape in the 21st century have placed a challenge for governments and organizations as they attempt to …

Tsaaro Consulting

Introduction  The Digital Personal Data Protection (DPDP) Act, 2023, and the Digital Personal Data Protection Rules, 2025 establish a comprehensive …

Tsaaro Consulting

In today’s interconnected world, cybersecurity plays a crucial role in protecting our digital lives. From protecting personal data to safeguarding …

Tsaaro Consulting

Introduction  A Transfer Impact Assessment (TIA) is a critical evaluation conducted under the General Data Protection Regulation (GDPR) to assess …

Tsaaro Consulting

Introduction The Digital Personal Data Protection Act (DPDPA), 2023 and the Draft DPDP Rules, 2025 have ushered in a new …

Recent Comments

SHARE THIS POST

Would you like to read regular updates from Tsaaro.
Subscribe to our newsletter

Our Latest Blogs

Read what the latest hapennings in the cyber world are and learn what the
experts have to say about them

Call Our Experts:

+91 95577 22103

small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png

We’d love to help your organization achieve your Data Protection goals!

Schedule a complimentary consultation with our Team of Experts.