Consent is the most visible aspect of privacy law. It shows up as a pop-up, checkbox, privacy notice or “I agree” button, but at the same time it is one of the concepts most misunderstood. In the case of India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and the European Union’s General Data Protection Regulation (GDPR), consent is not the thing you just casually grant. It is a legal ground that has to be conceptualized, documented, obeyed, and be reversible.
On paper, the two laws sound alike. Both want consent to be free, specific, informed, unambiguous, and affirmative. Both abhor vague or hidden permissions and put the ball on court to prove valid consent. But, underneath the words, the two systems reveal different characters. The GDPR sees consent as only one lawful basis out of several. The DPDP Act sees consent as the main element of its structure, at the same time it is going to prepare a shorter list of non-consent grounds called “certain legitimate uses”.
1. The Basic Meaning of Consent
The DPDP Act provides a very concise,
but stringent definition of consent. When a Data Principal grants consent, it
has to be "free, specific, informed, unconditional and unambiguous"
accompanied by a clear affirmative action. Besides, it should be for a certain
purpose only and personal data collected must be limited to that necessary for
that purpose.
Now, the term "unconditional" is very significant. It implies that
consent must not be turned into a situation where one party has no real
alternative but to agree
GDPR, on the other hand, gives a
definition that is quite similar, although with a slightly more inclusive
structure. Article 4(11) defines consent as a freely given, specific, informed
and unambiguous indication of the will of the data subject, expressed by a
statement or by a clear affirmative action.
Then Article 7 states the DSGVO working rules:
- the controller has to prove consent,
- the consent request must be distinct from other matters,
- the data subject has to be given the ability to withdraw consent, and
- withdrawal has to be as simple as giving consent.
2. Consent - central under DPDP, but only one option under GDPR
Consent is the major structural differentiator when it comes to the overall legal design between the two systems. Under the DPDP Act, personal data may be processed only for a lawful purpose and only either with consent or for certain legitimate uses. These legitimate uses include situations such as voluntary provision of data for a specified purpose, state benefits and services, medical emergencies, disaster management, employment-related purposes, compliance with judgments, or legal requirements.[4]
The GDPR has a wider selection of legitimate
grounds. Article 6 permits processing based on the individual's consent,
contract, legal obligation, vital interests, public task, or legitimate
interests. This means that a European data controller should not request
consent if another legal ground is more suitable.
For example, if the processing is necessary to fulfil a contract with a
customer, the legal basis may be that contract and not consent.
3. Notice and Language - the user must actually understand
How can consent be one that is in an informed manner? If the user is not able to understand the given notice. DPDP Act requires the notice to be given before or along with the consent request. It must explain the personal data, the reason for processing, and also how the Data Principal can exercise his rights and file a complaint to the Data Protection Board. Moreover, it allows users to choose to access the notice and consent request in English or in a language listed in the Eighth Schedule of the Constitution. The rules issued under the DPDP further specify that the notice should be capable of being understood by the recipient without reference to other information and that it should be written in clear and plain language. The notice should also have a clear breakdown of the personal data and the purposes for which it is being collected.
The GDPR achieves a large part of this goal through its transparency framework. Articles 12-14 list clear, concise, transparent and easy-to-understand information- using plain and clear language. Article 7 says that for consent, the consent request should be easily distinguishable from other matters. Recital 32 also explains that silence, pre-ticked boxes and inactivity do no constitute consent.
4. The Question of Free Consent
The GDPR has issued extensive commentary on the issue of consent being a truly "freely given". One of the points made by the European Data Protection Board is that persons lacking a real choice or feeling obliged to give consent or persons who are threatened with negative consequences for refusal or withdrawal of consent would not give a valid consent. It also points out granularity. This means that in case of multiple purposes, separate consent should be given by users. A single button labelled "accept everything" that relates to different purposes is only safe provided that the user gets genuine alternatives.
The DPDP Act is not the GDPR with respect to enforcement record, but the wording of the Act is in fact pointing to the very same direction. The phrases "free", "unconditional", "specified purpose" and "necessary" used together in a sentence make a strong case for anti-bundling rule. If it is the case that an app requires unrelated permissions from the users in exchange of service then in that case the consent given would be questionable.
The Indian companies still rely on GDPR practice to
an extent:
a) Consents given for the different purposes separately;
b) To refrain from dark patterns;
c) Non-essential permissions should be optional;
d) Do not make the user dependent on the collection of their unrelated data for
the enjoyment of the service.
5. Withdrawal - consent must be reversible
Both legislations make it clear that consent cannot be considered a one-time agreement permitting indefinite use of personal data. The DPDP Act stipulates that a Data Principal can at any moment decide to revoke the consent given, and doing so should be as simple as giving consent. After consent is withdrawn, the Data Fiduciary should stop processing the data within a reasonable period and must also enforce the Data Processors to stop, unless the law permits or requires processing to continue. The DPDP Rules support this by mandating notices with a link or other facilitation for withdrawal.
The GDPR is aligned with this view in that withdrawal should be allowed any time and it should be as easy as consent-giving. However, withdrawal will not invalidate the processing done lawfully until the time of withdrawal, but any future processing has to be discontinued unless there is a different lawful basis for it. If consent gets withdrawn and no other ground is legally available, then the right to erasure may come into play as well.
Practically, the message is quite clear, don't make giving consent very convenient and withdrawing consent difficult.
6. Accountability and Proof
Consent adherence is a matter of proof too. If the Data Fiduciary is asked to prove consent in legal proceedings, then under the DPDP Act they need to show that the notice was given and the consent was obtained compliant with the Act and Rules. The GDPR requires the controller equally to be able to demonstrate consent.
7. Children's Consent - India is stricter on age
According to the DPDP Act, a child is anyone under eighteen years of age. When it comes to processing the personal data of a child, the Data Fiduciary still needs to obtain the parent's consent; the latter being verifiable. This is in addition to the Data Fiduciary's obligation not to process the child's data in a way that may cause the child harm, and not to perform tracking, behavioural monitoring, or targeted advertising to children, except in cases of prescribed exceptions. DPDP Rules also elaborate on verifiable parental consent and making efforts to verify if the identifying parent is an adult.
On the other hand, GDPR offers a more adaptable framework for online child services. Art 8 has sixteen as the default age for digital consent but allows Member States to lower it as long as it isn't below thirteen. Hence GDPR creates a norm where a person whose age lies anywhere between 13 and 16, given that the national law may differ, while the DPDP Act considers the age from 18 upwards unless exemptions or notified relaxations are in place.
8. Special Categories and Explicit Consent
Another important difference is the GDPR's treatment of special category data. Data such as racial or ethnic origins, political views, religious/philosophical beliefs, union membership, genetic, biometric data used for identification, health data, and sex life or sexual orientation data is targeted under Article 9 for a stricter protective measure. "Explicit consent, " in a few instances, may be allowed as an exception, but it should be much clearer and stronger than ordinary consent.[14]
DPDP Act, however, has not designated "sensitive personal data" as a separate legal category as the Indian privacy discourse had done quite often. It generally applies the consent level widely, whereas one of the main areas for extra attention, specially coming out from children's data, Significant Data Fiduciary roles, security measures, and sectoral obligations.
9. Consent Managers - an Indian innovation
One of the features that sets the DPDP Act apart is the Consent Manager. A Data Principal will be able to give, manage, review or withdraw consent through a Consent Manager that is registered with the Data Protection Board. The objective is to establish a formal layer that can serve as a permission management tool for individuals engaging with various services. The DPDP Rules stipulate the registration and duties of Consent Managers, where Rule 4 is to be implemented one year after the publication of the Rules.
Conclusion
Consent under the DPDP Act and GDPR has one thing in common the moral foundation, nobody should give up control over their personal data due to confusion, pressure or deceptive design. Both regulations call for consent that is given willingly, is well-informed and is limited to a specific purpose. Both provide for withdrawal of consent. Both shift the burden of proof on to the organisation.
However, the distinctions do matter. GDPR is more extensive in its lawful-basis framework, has a richer interpretive history, special-category provisions and different child-consent-age limits. DPDP Act, on the other hand, is built around consent, has an "unconditional" consent standard, language-access requirements, the eighteen-year standard for children and the model of the Consent Manager.
Subscribe now to keep reading and get access to the full archive.
