top of page

Consent or Compulsion? The DPDPA’s Blind Spot on Coerced Consent

by Anwita Mishra


In the modern digital governance system, consent has become the moral and legal foundation for data protection. India's Digital Personal Data Protection Act, 2023 (DPDPA), reflects this approach by making consent the foundation for legal data processing. This sounds wonderful in principle. In reality, however, the issue is much more complicated. When users have few to no choices to begin with, consent starts to feel more like coercion and less like consent.

The Illusion of Choice

Essentially, consent under DPDPA is “free, specific, informed, unconditional and unambiguous”. What does this notion of “free” imply in a world in which a few giants control the market? If a user wishes to make use of a highly popular messaging and/or payment service? The service demands that the user consent to its extensive data collection practices in order to be permitted to make use of the service. What if there is no other service that is as popular and/or has similar features and functionalities? What if the user clicks “I agree”, not because they have freely consented to the service provider's practices, but because they have no other choice if they wish to be a member of the digital world? This is not “free” consent.

This has been termed as “take it or leave it” contracts and has been heavily criticized by legal scholars. The DPDPA does not do much to address this issue. It simply presumes that the availability of consent implies autonomy.

Unlike the General Data Protection Regulation (GDPR) in the EU, which specifically addresses the issue of the “imbalance of power” in the validity of consent (Recital 43, GDPR), the DPDPA fails to directly engage with the problem of consent validity, specifically whether consent is given voluntarily in the face of economic or technological dependencies.

The Structural Nature of Coercion

The lack of reference to coerced consent in the DPDPA is more alarming when one considers that the coercion in question is not apparent but rather inherent in the system. This coercion stems from:

Market concentration – a few companies dominate the provision of key services in the digital space.

Network effects – the more users a service has, the more valuable it becomes.

Digital dependency - access to services like banking, communication, and education requires one to be part of a given system.

In this ecosystem, the lack of choice can be seen as a form of coercion.

Failure to consider consent coercion has profound consequences. For instance, it calls into question the validity of the entire regime of data protection. This is because without voluntary consent, there is no way to prevent the misuse of personal data.

Furthermore, it places the onus on individuals to protect their own privacy, which is often beyond them to do so against corporate entities. This is antithetical to the purpose of data protection law, which is to create balance in power between individuals and data fiduciaries.

Rethinking Consent

In this context of addressing the above-mentioned gap, the following are the changes India must make:

1. “Imbalance of Power”

The DPDPA must recognize the concept of “Imbalance of Power” in the context of consent. This can be done by adopting the GDPR approach of analyzing the situation to determine if the users had any choice in the matter.

2. Decoupling Services and Data Collection

Essential services should not be linked with the excessive data collection process. In this regard, the data protection law must make it mandatory that the data processing of the users must be linked with the essential services provided.

3. Data Fiduciary Responsibility

The data protection law must not focus on the consent of the users and instead make the data fiduciaries liable.

4. Encouraging Market Alternatives

Competition law and data protection law should be integrated. Less concentrated markets can provide users with more choices, thus making their consent more meaningful.

5. Design-Based Interventions

User interfaces should be regulated to prevent “dark patterns,” which are manipulative designs used to pressure users into giving their consent. This can be done by the DPDPA.

Conclusion

DPDPA is an important step in the evolution of data protection in India. However, its focus on consent is flawed because it does not consider the nature of digital power structures.

While consent in a world of limited choice is often not necessarily given freely but is often a result of constraint, to ensure that users are empowered through law, one must go beyond mere compliance and consider the nature of that consent.

Until that is done, one is left to ponder: is the click on “I agree” one of choice or one of compliance?


 
 
 

Comments


Address

2nd & 4th Floor, Maharashtra National Law University Mumbai, MTNL Building, Technology Street, Powai, Mumbai. 

Our Socials

  • LinkedIn
  • Instagram

Contact

Convenor
Revant Sinha -  91 78270 76105

Associate Convenors
Om Dambhare - 91 93072 24566

Ritesh Karale - 91 93593 07137

bottom of page