Beyond “I Agree”: Are Consent-Based Data Protection Laws Really Protecting Our Privacy?

Author: Sujana B. Urs
Student, Bharati Vidyapeeth New Law College, Pune.

—————————————————————————————————————

💡 3 Quick Takeaways

  1. Digital consent does not always represent a genuinely informed or voluntary choice, particularly when privacy policies are lengthy and refusing consent may mean losing access to essential services.
  2. India’s Digital Personal Data Protection Act, 2023, and the Digital Personal Data Protection Rules, 2025, establish a framework for consent and data protection, but meaningful privacy requires more than an individual’s agreement.
  3. Data minimisation, purpose limitation, privacy by design, and organisational accountability are essential to ensure that the responsibility for protecting personal information does not fall entirely on individuals.

Abstract

In the digital age, privacy has increasingly become something individuals are expected to exchange for convenience. Every day, people click “I agree” to privacy policies, allow applications to access personal information, accept cookies, and share data without necessarily understanding how that information will be collected, processed, stored, or shared. Consent is therefore treated as one of the central safeguards of data protection. But can consent genuinely protect privacy when users often have limited knowledge, limited time, and little meaningful choice?

This article examines whether a consent-based approach to data protection is sufficient to protect informational privacy in India. It focuses on the practical limitations of digital consent, including lengthy privacy policies, consent fatigue, unequal bargaining power between individuals and organisations, and the difficulty of controlling information after it has been disclosed. The article analyses these concerns in the context of the constitutional right to privacy and India’s Digital Personal Data Protection Act, 2023. It also considers the Digital Personal Data Protection Rules, 2025, which seek to strengthen notice and consent mechanisms. The article argues that while consent remains an important expression of individual autonomy, privacy protection cannot depend on individual choice alone. Stronger duties relating to accountability, purpose limitation, data minimisation, transparency, and responsible processing are necessary to make the constitutional promise of privacy meaningful in everyday digital life.

Keywords: Privacy; Data Protection; Consent; Informational Privacy; Digital Personal Data

I. Introduction

“I agree” has become one of the most frequently clicked buttons in modern life. It appears when an individual creates an account, downloads an application, shops online, watches a video, signs up for a service, or visits a website. The action takes only a second. The consequences, however, can last considerably longer.

Behind that single click may lie the collection and processing of names, phone numbers, email addresses, locations, preferences, browsing patterns, photographs, financial information, and other personal details. In many cases, individuals have little understanding of what happens to this information after it is provided. Yet, legally, clicking “I agree” may be treated as an expression of consent.

This creates an important contradiction. Privacy is recognised as a fundamental right under the Indian Constitution, while the modern digital economy depends heavily on the collection and use of personal information. The more individuals participate in digital life, the more information about them becomes available to organisations. The question, therefore, is not merely whether the law recognises privacy as a right, but whether the mechanisms used to protect that right actually work in practice.

The principle of consent appears attractive because it places the individual at the centre of the decision. If people are informed about the collection and use of their data and freely agree to it, their autonomy is respected. However, digital consent is rarely as simple as this model suggests. Privacy policies can be lengthy and difficult to understand. Consent requests are so frequent that users often accept them automatically. Refusing consent may mean losing access to a service. Furthermore, individuals may have little bargaining power compared with the organisations collecting their information.

These difficulties have become particularly significant in India following the recognition of privacy as a fundamental right and the enactment of the Digital Personal Data Protection Act, 2023 (“DPDP Act”).¹ The statutory framework has since been supplemented by the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”), which were notified on 14 November 2025.²

The legal framework attempts to balance individual privacy with the legitimate need to process personal data. Yet, it raises a broader question: can individual consent alone carry the burden of protecting privacy in a digital environment where individuals may not possess the information or power necessary to make genuinely meaningful choices?

This article argues that consent remains an important component of privacy protection, but a consent-based model is insufficient on its own. Meaningful privacy protection requires the law to place substantive responsibilities on organisations that collect and process personal data, rather than assuming that individuals can protect themselves merely by making informed choices.

II. Privacy in the Digital Age

Privacy was once commonly understood in terms of physical space, secrecy, and freedom from unwanted intrusion. Digital technology has significantly expanded the meaning of privacy. An individual’s privacy can now be affected without anyone physically entering their home or directly observing their actions.

A person’s digital activities can reveal an extraordinary amount about them. Search histories can reveal interests. Location data can reveal movements and routines. Purchasing patterns can indicate financial behaviour. Online interactions can provide insights into relationships, preferences, and personal circumstances. Even information that appears harmless in isolation may become revealing when combined with other datasets.

This is why the concept of informational privacy has become increasingly important.

The Supreme Court’s decision in Justice K.S. Puttaswamy (Retd.) v. Union of India marked a significant development in Indian privacy law. The nine-judge Constitution Bench recognised privacy as a constitutionally protected right and connected it with dignity, autonomy, liberty, and individual choice.³ The Court also recognised informational privacy as one of the dimensions of the fundamental right to privacy.⁴

Justice S.K. Kaul’s opinion in Puttaswamy was particularly significant in identifying informational privacy as concerning an individual’s ability to control the dissemination of personal information.⁵ This understanding is especially relevant to digital environments, where personal information can be collected and processed on a scale that individuals cannot realistically monitor themselves.

The problem is that digital information does not behave like physical property. Once information is shared, it can be copied, analysed, combined with other information, transferred, and used for purposes that the individual may not have anticipated. The individual therefore faces a fundamental difficulty: privacy may be lost long before the individual realises that it has been lost.

This makes the role of consent particularly important—and particularly problematic.

III. Consent as the Foundation of Data Protection

Consent is appealing as a legal mechanism because it appears to respect individual autonomy. Instead of allowing organisations to collect personal information without restriction, the individual is given a choice.

In its ideal form, the process looks straightforward:

Information → Understanding → Choice → Consent → Control

The individual receives sufficient information, understands the proposed processing, makes a voluntary decision, and retains the ability to withdraw that decision.

The DPDP Act reflects this model. Section 4 permits the processing of personal data for a lawful purpose where the Data Principal has given consent or where the processing falls within specified legitimate uses.⁶ Section 6 further provides that consent must be “free, specific, informed, unconditional and unambiguous” and expressed through clear affirmative action.⁷

The Act also requires consent requests to be presented in clear and plain language. It provides a right to withdraw consent, with the ease of withdrawal being comparable to the ease with which consent was given.⁸

The DPDP Rules attempt to strengthen these requirements. They require notices to be clear, standalone, understandable, and written in simple language, while specifying that notices should provide sufficient information for informed consent.⁹ They also establish a framework for Consent Managers through which individuals may manage, review, and withdraw consent.¹⁰

These provisions demonstrate that Indian law does not treat consent as an entirely casual or automatic act. However, the existence of legal requirements surrounding consent does not automatically make consent meaningful.

The real question is whether an individual who clicks “I agree” has actually exercised the kind of informed and autonomous choice that privacy law intends to protect. This is where the gap between legal consent and meaningful consent becomes important.

A person may technically agree to something without genuinely understanding it. A person may agree because refusing is inconvenient. A person may agree because every alternative service requires the same information. A person may agree because the privacy notice is too complicated to read. In each situation, consent exists in a formal sense, but whether it represents a genuinely autonomous decision is far less certain.

IV. Why “I Agree” May Not Mean Meaningful Consent

A. The Problem of Informed Consent

For consent to protect autonomy, the individual must have enough information to make an informed decision.

Digital privacy notices create an obvious difficulty. They are frequently long, technical, and written in language that the average user may not fully understand. Even an individual who wants to make an informed choice may struggle to determine what information is being collected, why it is being collected, how long it will be retained, and whether it will be shared with other entities.

The problem is therefore not necessarily that information is unavailable. Often, too much information is provided in a form that makes meaningful understanding difficult.

The DPDP Rules appear to recognise this concern by requiring notices to be clear, standalone, and understandable, and by requiring an itemised description of personal data and the purposes of processing.¹¹

Yet, even a clearer notice cannot eliminate the underlying problem entirely. Providing information and ensuring that the information is actually understood are two different things.

If meaningful consent depends upon the individual reading and understanding complex legal documents every time they use a digital service, privacy becomes dependent upon a level of time and legal literacy that many users simply do not possess.

Thus, the challenge is not merely one of transparency, but of whether transparency can realistically produce informed decision-making.

B. Consent Fatigue

Digital users encounter consent requests constantly.

Cookies, application permissions, account registrations, newsletters, online purchases, location services, and other digital activities may all require some form of permission or acceptance. Over time, users can become accustomed to clicking through these requests without examining them.

The result is often described as consent fatigue: repeated demands for consent may reduce the attention individuals give to each request.

The European Data Protection Board’s guidance on consent under the General Data Protection Regulation (GDPR) emphasises that valid consent must be freely given, specific, informed, and unambiguous.¹² The guidance also recognises that consent should not be reduced to a situation in which an individual has little genuine choice.

This is relevant beyond the European context because it exposes a structural problem with consent-based regulation. If consent becomes a routine digital ritual, the mere existence of an affirmative click tells us less about whether the individual actually considered the privacy consequences.

The user is technically making a decision, but the decision may be automatic rather than considered.

C. The Illusion of Choice

Consent assumes that the individual has a real choice.

But what happens when refusing consent means giving up access to a service that has become practically necessary?

An individual may rely on digital platforms for communication, education, banking, employment, transportation, shopping, or public services. As digital participation becomes increasingly integrated into everyday life, refusing to provide personal data can carry significant practical costs.

This creates a distinction between formal choice and meaningful choice.

A user may technically be able to refuse. However, if refusal means losing access to a service, or if comparable alternatives are unavailable, consent may not represent a genuinely free choice.

The DPDP Act itself recognises the importance of voluntariness by requiring consent to be “free” and “unconditional.”¹³ However, the practical meaning of those terms becomes difficult to determine when the individual has significantly less bargaining power than the organisation requesting the data.

D. The Power Imbalance

The relationship between an individual and a large organisation is rarely equal.

The organisation may possess sophisticated technology, legal expertise, data scientists, security infrastructure, and detailed knowledge of how personal information can be analysed and monetised. The individual generally possesses none of these advantages.

This creates an information asymmetry.

The organisation knows what it wants from the data and may understand its potential value. The individual may simply want to access a service.

This imbalance challenges the assumption that both parties are entering an equal transaction.

If privacy law relies too heavily on consent, the burden of protecting privacy may effectively shift onto the individual. The individual is expected to read the policy, understand the consequences, assess the risks, and make an informed decision.

That expectation is unrealistic for most ordinary digital interactions.

The problem is therefore structural rather than merely individual. Better privacy literacy can certainly help, but it cannot eliminate the imbalance between a single user and an organisation capable of collecting and analysing data on an enormous scale.

V. India’s Data Protection Framework: Is Consent Enough?

India’s move towards a dedicated statutory framework for digital personal data protection represents an important recognition that privacy cannot be left entirely to private contracts and individual caution.

The DPDP Act establishes obligations for Data Fiduciaries and provides rights to Data Principals. It regulates the processing of digital personal data while attempting to balance individuals’ privacy interests against legitimate uses of personal data.¹⁴

The Act’s approach to consent is therefore significant. Consent is neither irrelevant nor meaningless. It reflects the principle that individuals should have a say in how information about them is processed.

However, the effectiveness of consent depends upon the environment in which it is obtained.

If a person does not understand what they are consenting to, the protective value of consent is reduced. If refusing consent is practically impossible, the value of choice is reduced. If withdrawing consent cannot meaningfully undo the consequences of previous processing, individual control remains limited.

The Act itself recognises one part of this problem by providing that withdrawal of consent does not affect the legality of processing carried out before withdrawal.¹⁵ This is understandable from a regulatory and operational perspective: data processing cannot always be reversed simply because consent is later withdrawn.

Nevertheless, it illustrates an important limitation of consent. Withdrawal can stop future processing, but it cannot necessarily recreate the position that existed before the data was disclosed.

This does not mean that the DPDP Act fails as a whole. Rather, it highlights a broader limitation of consent-centred privacy regulation.

Privacy cannot be protected solely by asking individuals to make better choices because many aspects of data processing are beyond an individual’s practical control.

Consider the difference between two questions:

  • “Did the individual consent to the processing?”
  • “Was the processing itself reasonable, necessary, proportionate, and consistent with the purpose for which the information was collected?”

The second question places greater responsibility on the organisation.

This is important because privacy protection should not depend entirely on whether an individual successfully navigated a complex digital environment. The law must also regulate the behaviour of those who possess greater power and information.

VI. Beyond Consent: Rethinking Privacy Protection

If consent is not enough, the solution is not to remove consent altogether.

Consent remains important because individual autonomy matters. People should have a meaningful role in deciding how their personal information is used.

The problem arises when consent is treated as the primary answer to every privacy concern.

A stronger framework should combine consent with substantive obligations on Data Fiduciaries.

A. Data Minimisation

Organisations should collect only the information reasonably necessary for a legitimate purpose.

The basic principle is simple: data that does not need to be collected cannot later be misused, leaked, or exploited.

This reduces the burden placed on individuals because privacy protection begins before information reaches the organisation.

The DPDP Act reflects this principle in the requirement that consent be limited to personal data necessary for the specified purpose.¹⁶

B. Purpose Limitation

Information collected for one purpose should not automatically become available for unrelated purposes.

Individuals should be able to understand why their data is being collected and should not have to anticipate every possible future use.

Purpose limitation is important because it places boundaries on an organisation’s discretion. It ensures that consent for one activity does not become a blank cheque for every subsequent use of the data.

C. Privacy by Design

Privacy should be incorporated into digital products and services from the beginning rather than added later as a legal formality.

This changes the philosophy of privacy protection.

Instead of asking, “How can users protect themselves?”, the question becomes, “How can organisations design systems that minimise unnecessary intrusion in the first place?”

This approach reduces reliance on individual vigilance and places responsibility on the entities that design and operate data-processing systems.

D. Greater Accountability

The organisation processing personal data should bear a significant share of the responsibility for protecting it.

This is particularly important because organisations generally have greater technical capacity and greater control over the data environment. The DPDP framework already places several duties on Data Fiduciaries, including obligations relating to reasonable security safeguards and erasure in specified circumstances.¹⁷

The broader principle should be that organisations cannot satisfy their privacy responsibilities merely by demonstrating that an individual once clicked “I agree”.

A genuine accountability framework asks whether the organisation acted responsibly throughout the data lifecycle.

VII. Conclusion

The phrase “I agree” has become almost synonymous with participation in digital life. Yet, agreeing to a privacy policy does not necessarily mean that an individual has understood the consequences, had a meaningful choice, or retained genuine control over their information.

Consent remains an important principle because privacy is fundamentally connected with autonomy. Individuals should not be excluded from decisions concerning their personal information. However, consent alone cannot solve the structural problems created by the modern digital economy.

The difficulties of informed consent, consent fatigue, unequal bargaining power, information asymmetry, and the persistence of data after disclosure demonstrate that privacy cannot realistically be protected by placing the entire burden on individuals.

India’s recognition of privacy as a fundamental right provides a strong constitutional foundation for protecting informational autonomy. Puttaswamy made clear that informational privacy is a constitutionally protected interest connected with dignity and individual autonomy.¹⁸ The DPDP Act and the DPDP Rules represent significant steps towards translating that constitutional commitment into a statutory framework.

However, the effectiveness of privacy protection ultimately depends on whether the law goes beyond the question of whether an individual clicked “I agree”.

The more meaningful question is whether organisations are collecting only what they need, using it for legitimate purposes, protecting it responsibly, and remaining accountable for its processing.

The future of privacy law should therefore not be about teaching users to become better readers of privacy policies. It should be about creating a system in which individuals do not have to surrender meaningful control over their personal information simply to participate in modern life.

Consent should remain part of privacy protection. It should not become an excuse for avoiding responsibility.

References

  1. Digital Personal Data Protection Act, 2023, No. 22 of 2023, India Code.
  2. Ministry of Electronics and Information Technology, Government of India, Digital Personal Data Protection Rules, 2025.
  3. Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1.
  4. Ibid.
  5. Ibid., opinion of Justice S.K. Kaul.
  6. Digital Personal Data Protection Act, 2023, § 4.
  7. Ibid., § 6.
  8. Ibid., § 6.
  9. Digital Personal Data Protection Rules, 2025.
  10. Ibid.
  11. Ibid.
  12. European Data Protection Board, Guidelines 05/2020 on Consent Under Regulation 2016/679 (4 May 2020).
  13. Digital Personal Data Protection Act, 2023, § 6.
  14. Ibid.
  15. Ibid., § 6.
  16. Ibid.
  17. Ibid.
  18. Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1.

Disclaimer: The views expressed in this article are those of the author and do not necessarily reflect the views of The Lawscape.


The Lawscape — clear, practical legal insight for students and future lawyers.

Leave a Comment

Your email address will not be published. Required fields are marked *