New Delhi, India  
Breaking News
Know The Law

Consent in Form, Surveillance in Substance: A Constitutional Critique of India’s Data Protection Regime

By Udit Arora      2 hours ago      0 Comments
Consent in Form Surveillance in Substance A Constitutional Critique of Indias Data Protection Regime

Abstract 

This article examines the constitutional validity of the exemption architecture under the Digital Personal Data Protection Act, 2023 (DPDP Act). While the statute adopts a consent-centric framework for processing personal data, it simultaneously vests the executive with broad powers to exempt State instrumentalities from its application. The Article evaluates whether such exemptions withstand the proportionality standard as laid down in K.S. Puttaswamy v. Union of India, (2017) 10 SCC 1. It argues that the Act marks a shift from a rights-based privacy regime to a governance-oriented data framework, wherein informational autonomy is subordinate to State interests. By analysing the scope of delegated discretion, the absence of independent oversight and comparative international standards, the article proposes doctrinal safeguards to align the Act with constitutional guarantees.

Introduction 

The rapid expansion of digital governance has fundamentally altered the relationship between the individual and the State. The increasing reliance on data-driven decision-making, digital identity infrastructures and platform-mediated service delivery has significantly enhanced the State’s capacity to collect, process and utilise personal data. Globally, concerns surrounding data harvesting and platform dominance came into sharp focus following disclosures such as the Cambridge Analytica scandal involving Facebook, where users data was allegedly utilised for targeted political advertising without adequate consent. These concerns found judicial expression in India as well. In Karmanya Singh Sareen v. Union of India, (2017) SCC OnLine Del 10801, a writ petition was instituted before the Delhi High Court challenging WhatsApp’s updated privacy policy on the ground that it enabled extensive data sharing with Facebook, thereby compromising user privacy.

Similar concerns resurfaced in Facebook Inc. v. Union of India, (2019) 3 SCC 593, where issues relating to traceability of messages on WhatsApp and the extent of intermediary obligations came under scrutiny before the Supreme Court. The proceedings highlighted the tension between user privacy, platform accountability and State interests in investigation. 

Further, controversies surrounding WhatsApp’s 2021 privacy policy update once again raised questions regarding data sharing with its parent entity, Facebook and the extent of meaningful user consent in digital ecosystems.

In India, these developments intersected with constitutional discourse on privacy, culminating in the recognition of privacy as a fundamental right. Against this backdrop, the enactment of the Digital Personal Data Protection Act, 2023 (DPDP Act) represents India’s first comprehensive legislative attempt to regulate personal data processing.

At a structural level, the DPDP Act adopts a consent-based model. However, it simultaneously enables the Central Government to exempt state instrumentalities from its application under broadly framed conditions. This dual architecture gives rise to a critical constitutional question: whether a regime that recognises informational privacy as a right in form, while permitting wide-ranging executive exemptions in substance, can withstand scrutiny under the proportionality standard.

Informational Privacy and Constitutional Doctrine 

The recognition of privacy as a fundamental right under Article 21 of the Constitution marked a transformative moment in Indian constitutional jurisprudence. In K.S. Puttaswamy v. Union of India, (2017) 10 SCC 1, a nine-judge bench of the Supreme Court unanimously affirmed that the right to privacy is intrinsic to life and personal liberty

The judgment arose in the context of challenges to the Aadhaar programme, which involved large-scale collection of biometric and demographic data by the State. The Court held that privacy includes informational self-determination and autonomy over personal data.

Crucially, the Court adopted the proportionality standard as the governing test for evaluating restrictions on privacy. This requires that any limitation on a fundamental right must satisfy: (i) legality; (ii) legitimate aim; (iii) necessity; and (iv) proportionality in the strict sense. The Court also emphasised the need for procedural safeguards against abuse of State power.

Subsequently, in Justice K.S. Puttaswamy v. Union of India, (2019) 1 SCC 1(Aadhaar-5J.), the Court applied these principles to assess the validity of the Aadhaar framework, further reinforcing the centrality of proportionality and safeguards in data governance.

Statutory Architecture of the DPDP Act 

The Digital Personal Data Protection Act, 2023 (DPDP Act) establishes a framework governing the processing of digital personal data by "data fiduciaries." It is premised on consent as the primary ground for processing, supplemented by certain "legitimate uses" where consent may not be required.

The Act imposes obligations on data fiduciaries, including purpose limitation, data minimisation, and implementation of reasonable security safeguards. It also confers rights on "data principals," such as the right to access information, seek correction and withdraw consent.

However, the enactment of the DPDP Act must be viewed against the backdrop of increasing State reliance on digital infrastructure and data-driven governance. While the statute appears to adopt a rights-based structure, its architecture is significantly shaped by provisions that enable executive discretion, particularly in relation to exemptions granted to State entities.

Executive Exemptions: Scope and Constitutional Concerns 

The DPDP Act empowers the Central Government to exempt any instrumentality of the State from the application of the Act on grounds such as sovereignty, integrity, security of the State, and public order. The breadth of these grounds, coupled with the absence of narrowly tailored statutory limitations, raises serious constitutional concerns.

First, the delegation of such wide-ranging exemption powers raises questions under the doctrine of excessive delegation. While delegated legislation is permissible, it must be guided by clear legislative policy and adequate safeguards. The absence of defined standards risks conferring unguided discretion upon the executive.

Second, the exemption framework lacks procedural safeguards. There is no requirement for prior judicial approval, independent oversight, or periodic review. This omission is particularly significant in light of the Supreme Court’s emphasis on procedural guarantees as safeguards against arbitrary State action.

Third, the exemption mechanism does not explicitly incorporate the proportionality standard. There is no requirement that exemptions be necessary or represent the least restrictive means of achieving the stated objective. As a result, the statutory framework permits broad exemptions that may not withstand constitutional scrutiny.

Surveillance Implications within a Consent Framework 

A notable feature of the DPDP Act is the coexistence of a consent-based regime with the possibility of extensive State access to data. This creates a distinction between formal consent and substantive autonomy.

While individuals may formally consent to the processing of their data, the existence of broad State exemptions undermines their ability to exercise meaningful control. The aggregation of data across multiple platforms and State databases enhances the potential for surveillance, even in the absence of explicit surveillance provisions.

These concerns are not merely theoretical. The rise of cyber frauds in India, particularly those involving so-called “mule accounts”, illustrates the real-world consequences of weak data protection and enforcement. Mule accounts, bank accounts opened or operated using compromised or fraudulently obtained personal data are increasingly being used as conduits for siphoning funds in digital fraud schemes.

Such frauds often involve unauthorised access to sensitive personal and financial data, including banking credentials, identity information, and transactional details. The misuse of this data points to systemic vulnerabilities in data handling practices across both private entities and financial institutions. In many instances, personal data is not only inadequately protected but is also repurposed and circulated within illicit networks.

From a data protection perspective, these developments highlight two critical gaps. First, the absence of stringent enforcement mechanisms allows for continued misuse of personal data without meaningful accountability. Second, the lack of clear liability frameworks for data breaches and downstream misuse creates ambiguity regarding institutional responsibility.

Consequently, cyber frauds involving mule accounts underscore a broader structural issue: the inability of the existing legal and regulatory framework to ensure substantive data protection. This further reinforces the distinction between formal statutory rights and their practical realisation. 

Comparative Analysis

A comparative perspective highlights the divergence between the Indian framework and international standards. The European Union’s General Data Protection Regulation (GDPR) permits restrictions on data protection rights only where they are necessary and proportionate, and subject to statutory safeguards and independent oversight.

Similarly, jurisdictions such as the United Kingdom and Canada require restrictions on privacy rights in the interests of national security to remain subject to statutory safeguards and varying degrees of independent oversight, reflecting the principle that security-based exemptions cannot operate as blanket exclusions from accountability.

In contrast, the Indian framework vests significant discretion in the executive without equivalent safeguards, raising concerns regarding constitutional alignment. 

Reconciling the DPDP Act with Constitutional Standards 

To better align the DPDP Act with constitutional requirements, the exemption framework should incorporate substantive and procedural safeguards consistent with the proportionality doctrine laid down in K.S. Puttaswamy. First, exemptions under Section 17 should not operate as blanket exclusions but should be supported by a demonstrable proportionality assessment establishing that the exemption is necessary and narrowly tailored to achieve its stated objective. Second, exemptions should remain subject to independent institutional oversight and periodic review to minimise the risk of arbitrary executive action and ensure that they continue only for so long as the underlying justification exists. Third, greater transparency should accompany the exercise of exemption powers by requiring reasoned exemption notifications, subject to legitimate national security limitations, thereby facilitating accountability and meaningful judicial review. Finally, Parliament may consider expressly requiring that exemptions under Section 17 be exercised consistently with the guarantees under Articles 14, 19 and 21 of the Constitution. Collectively, these safeguards would ensure that executive discretion remains constitutionally structured, thereby reinforcing the balance between legitimate State interests and the fundamental right to informational privacy.

Conclusion

The DPDP Act represents a significant step in India’s data protection journey. However, its exemption architecture raises important constitutional concerns. A meaningful commitment to informational privacy requires not only formal recognition but also substantive safeguards against arbitrary State action. The incorporation of doctrinal limitations and oversight mechanisms is essential to ensure that the Act withstands constitutional scrutiny and effectively protects individual autonomy.

Ultimately, the legitimacy of India's data protection framework will not be measured merely by the enactment of legislation, but by the constitutional discipline governing its implementation. A consent-based regime cannot meaningfully protect informational autonomy if broad executive exemptions operate without independent oversight, proportionality review, or effective accountability. Unless these structural concerns are addressed, the DPDP Act risks recognising privacy as a constitutional right in principle while permitting its dilution in practice.

Author Bio 

Udit Arora is an Advocate practising before the Supreme Court of India, the Delhi High Court, and various tribunals. His practice spans constitutional, commercial, and technology law, including advisory work for companies in the space and emerging technology sectors. His research interests include privacy, digital regulation, and technology policy. 9958779393, uditaroraa9@gmail.com

Disclaimer: The views and opinions expressed in this article are solely those of the author and do not necessarily reflect the views of LawStreet Journal, its editors, management, or affiliates.



Share this article:



Leave a feedback about this
Related Posts
View All

Cant put a chip on lawmakers, SC dismisses PIL to digitally monitor all MPs/MLAs Cant put a chip on lawmakers, SC dismisses PIL to digitally monitor all MPs/MLAs

Supreme Court dismisses PIL for digital monitoring of MPs/MLAs, citing privacy rights and inappropriateness of surveillance akin to that for felons.

Digital Personal Data Protection Act 2023 Navigating India's Data Privacy Revolution [Read DPDP Act] Digital Personal Data Protection Act 2023 Navigating India's Data Privacy Revolution [Read DPDP Act]

Overview of India's DPDP Act 2023, focusing on data protection, privacy rights, penalties, and compliance.

What Are The Rights And Duties Of Data Principal Under DPDP Act 2023 What Are The Rights And Duties Of Data Principal Under DPDP Act 2023

Analysis of DPDP Act 2023: Exploring Data Principals' rights, duties, and the balance between individual privacy and regulatory compliance.

What is Forensic Audit: Know India's Legal Framework for Combating Financial Crimes What is Forensic Audit: Know India's Legal Framework for Combating Financial Crimes

Explore forensic audits in India: key laws, processes, and their role in fighting financial fraud to ensure integrity and transparency.

New Release

Senior Citizens Rights Handbook

The Senior Citizen Rights Handbook is a comprehensive guide designed to empower elderly citizens with clear and accessible knowledge of their legal and social rights in India.

Join Group

Signup for Our Newsletter

Get Exclusive access to members only content by email