From Consent To Control: Reassessing Informational Privacy Under India's Digital Personal Data Protection Framework
- IJLLR Journal
- 3 hours ago
- 1 min read
Pratibha Jha, The Institute of Company Secretaries of India (ICSI)
ABSTRACT
The recognition of privacy as a fundamental right by the Supreme Court of India in Justice K.S. Puttaswamy (Retd.) v. Union of India marked a constitutional transformation in the understanding of individual autonomy, dignity and informational privacy. The Digital Personal Data Protection Act, 2023 (DPDP Act) subsequently sought to establish a statutory framework governing the processing of digital personal data. The notification of the Digital Personal Data Protection Rules, 2025 (DPDP Rules) represents the next stage in this regulatory development. This article examines whether India's emerging data-protection framework adequately transforms the constitutional promise of informational privacy into meaningful individual control over personal data. It particularly analyses consent, the obligations of Data Fiduciaries, rights of Data Principals, governmental processing, security safeguards and the institutional role of the Data Protection Board. It argues that consent, while important, cannot by itself constitute an adequate privacy safeguard in an environment characterised by information asymmetry, technological complexity and unequal bargaining power. The article therefore proposes a shift from a predominantly consent-oriented approach towards an accountability-based model grounded in data minimisation, purpose limitation, transparency, privacy-by-design and effective remedies. The phased commencement of the DPDP framework also creates an opportunity to strengthen institutional safeguards before substantive provisions become operational.
Keywords: Informational Privacy; Digital Personal Data Protection Act; Data Principal; Data Fiduciary; Consent; Article 21; Data Protection; Digital Rights.
