Logo

Your trusted compliance partner

Logo

Your trusted compliance partner

From consent to accountability: is India's DPDPA moving towards an accountability-based privacy model?

From consent to accountability: is India's DPDPA moving towards an accountability-based privacy model?

From consent to accountability: is India's DPDPA moving towards an accountability-based privacy model?

Research Team (Tsaaro)

Published

WhatsAppFacebookXLinkedIn
DPDPA

Introduction: 

The digital personal data protection act, 2023 (DPDPA) permits the processing of personal data based on consent or for certain legitimate uses recognised under the act. While consent remains central to this framework, the DPDPA also imposes continuing obligations on data fiduciaries, including obligations relating to security safeguards, processor oversight and data erasure.  

This raises an important question: is India moving from a consent-based privacy model towards an accountability-based one? The answer is both yes and no. The DPDPA represents a meaningful shift towards organisational accountability, but it does not abandon consent as an important part of India's privacy framework. It is better understood as a hybrid model, in which individual consent and institutional responsibility operate together. 

Consent cannot carry the entire privacy framework: the illusion of choice 

Privacy frameworks have traditionally relied on notice and choice doctrine: individuals are informed about how their data will be used and given the choice to accept or refuse processing. Section 6 of DPDPA reflects this approach by requiring consent to be “free, specific, informed, unconditional and unambiguous” given through clear affirmative action. Yet the gap between this statutory standard and the reality of digital consent raises an obvious question: can privacy protection realistically depend on individuals understanding and managing every processing decision? 

The difficulty is that the burden of privacy protection falls heavily on the individual. Privacy policies are lengthy, users encounter multiple consent requests, and they may lack the time or technical literacy to understand every processing term. Even where they do, the absence of meaningful alternatives or the denial of services may leave little practical choice. 

The problem becomes sharper when interfaces are designed to influence rather than inform. India's guidelines for prevention and regulation of dark patterns, 2023 recognise practices such as interface interference, confirmation shaming and forced action that can impair consumer autonomy. 

A model built primarily around notice and consent therefore risks reducing privacy protection to a legally defensible click. This is where accountability becomes important: A consent-based model primarily asks: did the individual agree? An accountability-based model adds another question: what did the organisation do to ensure that the processing remained secure, responsible and appropriately governed? Consent may provide a basis for processing, but it does not exhaust the organisation's obligations once processing begins. 

The foundation of fiduciary accountability: 

Section 8(1) of DPDPA makes the data fiduciary responsible for compliance in respect of processing undertaken by it or by a data processor on its behalf. The provision also imposes obligations that operate independently of whether a data principal has consented to the original processing.  Section 8(2) further requires the engagement of a data processor to be under a valid contract.  Under section 8(5), a data fiduciary must take reasonable security safeguards to prevent personal data breaches.  

Where a personal data breach occurs, the data fiduciary shall notify the data protection board and each affected data principal in the prescribed manner in accordance with section 8(6) of DPDPA. It must also erase personal data when consent is withdrawn or when it is reasonable to assume that the specified purpose is no longer being served, unless retention is necessary for compliance with law [section 8(7)]. The digital personal data protection rules, 2025 add operational substance to these duties, particularly in relation to security safeguards and breach management. 

The accountability framework becomes more demanding for significant data fiduciaries. Under section 10, the central government may designate a data fiduciary as a significant data fiduciary based on factors such as the volume and sensitivity of personal data processed and the risks posed to the rights of data principals. Such entities must appoint a data protection officer and an independent data auditor and undertake periodic data protection impact assessments and audits. 

These requirements move privacy beyond passive notice and choice by requiring higher-risk organisations to establish structures for identifying and managing privacy risks. The act reinforces these duties through substantial financial penalties, including up to ₹250 crore for failure to take reasonable security safeguards. 

Taken together, these obligations indicate that the DPDPA does not assume that privacy is ensured once consent is obtained. Instead, it imposes continuing duties concerning security, processor oversight, breach management, retention, and governance on the organisation.  This is where the DPDPA's accountability-based orientation becomes most apparent: consent may initiate processing, but accountability governs the organisation's responsibilities throughout its lifecycle. 

Where does the accountability model remain incomplete? 

Unlike the GDPR, the act does not impose a general and express obligation of data protection by design and by default on every data fiduciary. More structured governance requirements, such as data protection impact assessments and periodic audits, are primarily associated with significant data fiduciaries, creating a tiered model of accountability. 

Enforcement also remains primarily regulatory. While the act provides for substantial financial penalties, it does not create a general statutory right for affected individuals to claim compensation for every violation. Further, the exemptions under section 17 may limit the application of certain obligations in specified circumstances. 

From consent to accountability, but not beyond consent: 

The DPDPA does not replace consent with accountability. Consent remains a principal basis for processing, alongside certain legitimate uses under section 7. What changes is its legal significance: consent does not remove the data fiduciary's continuing obligations concerning security, processor oversight, breach notification or data erasure. 

With the core substantive provisions of the act, including sections 3 to 17, scheduled to come into force in may 2027, organisations are now in a critical implementation period. For organisations, the remaining period is not merely about updating notices or consent forms, but about establishing the governance structures necessary to meet these continuing obligations. 

Conclusion: 

Privacy, therefore, is no longer concerned only with whether the individual agreed, but also with how responsibly the organisation acts once processing begins. Consent continues to give the individual a role in deciding whether certain processing may take place. Accountability determines what the organisation must do throughout the lifecycle of that data. 

India is therefore not moving entirely from consent to accountability. It is moving towards a framework in which privacy protection is no longer expected to rest on either one alone. The DPDPA's more significant conceptual shift may thus be a redistribution of responsibility: from privacy as a choice made solely by the individual to privacy as a responsibility increasingly shared with the institution that processes their data. 

Want to stay ahead?     

Reach out to the experts at tsaaro today. 


 

We Help You to Grow Your Business Faster & Easier

Our mission is to redefine Digital Trust — helping businesses stay compliant and secure across data privacy, cybersecurity, AI governance, and risk. With 150+ clients across 6 global regions and 50+ regulations covered, we've partnered with leading brands like Airtel, Adani, Titan, Godrej, Booking.com, Paytm, CRED, Nykaa, IKEA, and Flipkart & more.


  • Specialist Talent, On Demand – Privacy, Cyber, AI & GRC experts via staff augmentation, expert pods, and SME-on-demand.

  • Leadership as a Service – Fractional DPO, CISO, and AI Officer leadership, without the cost of a full-time hire.

  • Proven Results – Trusted by top brands including Adani, CRED, and Flipkart.

  • Responsible AI Governance – Build and run AI programmes aligned to ISO/IEC 42001, the EU AI Act, and NIST AI RMF.

  • Cybersecurity Expertise – Protect your business from evolving threats with vCISO-led strategy and assessments.

  • Global Standards & Regulations – Stay ready for GDPR, DPDPA, PDPL, HIPAA, and ISO frameworks across markets.

  • Flexible & Cost-Effective – The right expertise at the right time, without permanent-hiring overhead.

  • Trusted Advisory – Led by certified privacy and security professionals.

We Help You to Grow Your Business Faster & Easier

Our mission is to redefine Digital Trust — helping businesses stay compliant and secure across data privacy, cybersecurity, AI governance, and risk. With 150+ clients across 6 global regions and 50+ regulations covered, we've partnered with leading brands like Airtel, Adani, Titan, Godrej, Booking.com, Paytm, CRED, Nykaa, IKEA, and Flipkart & more.


  • Specialist Talent, On Demand – Privacy, Cyber, AI & GRC experts via staff augmentation, expert pods, and SME-on-demand.

  • Leadership as a Service – Fractional DPO, CISO, and AI Officer leadership, without the cost of a full-time hire.

  • Proven Results – Trusted by top brands including Adani, CRED, and Flipkart.

  • Responsible AI Governance – Build and run AI programmes aligned to ISO/IEC 42001, the EU AI Act, and NIST AI RMF.

  • Cybersecurity Expertise – Protect your business from evolving threats with vCISO-led strategy and assessments.

  • Global Standards & Regulations – Stay ready for GDPR, DPDPA, PDPL, HIPAA, and ISO frameworks across markets.

  • Flexible & Cost-Effective – The right expertise at the right time, without permanent-hiring overhead.

  • Trusted Advisory – Led by certified privacy and security professionals.

We Help You to Grow Your Business Faster & Easier

Our mission is to redefine Digital Trust — helping businesses stay compliant and secure across data privacy, cybersecurity, AI governance, and risk. With 150+ clients across 6 global regions and 50+ regulations covered, we've partnered with leading brands like Airtel, Adani, Titan, Godrej, Booking.com, Paytm, CRED, Nykaa, IKEA, and Flipkart & more.


  • Specialist Talent, On Demand – Privacy, Cyber, AI & GRC experts via staff augmentation, expert pods, and SME-on-demand.

  • Leadership as a Service – Fractional DPO, CISO, and AI Officer leadership, without the cost of a full-time hire.

  • Proven Results – Trusted by top brands including Adani, CRED, and Flipkart.

  • Responsible AI Governance – Build and run AI programmes aligned to ISO/IEC 42001, the EU AI Act, and NIST AI RMF.

  • Cybersecurity Expertise – Protect your business from evolving threats with vCISO-led strategy and assessments.

  • Global Standards & Regulations – Stay ready for GDPR, DPDPA, PDPL, HIPAA, and ISO frameworks across markets.

  • Flexible & Cost-Effective – The right expertise at the right time, without permanent-hiring overhead.

  • Trusted Advisory – Led by certified privacy and security professionals.