Recently, the parliament enacted the DPDPA to secure the personal digital rights of individual (i.e., Data Principal)

Consent Management under the provisions of the Digital Personal Data Protection Act (DPDPA), 2023

Recently, the parliament enacted the DPDPA to secure the personal digital rights of individual (i.e., Data Principal). Under this Act, it is mandatory that before processing the personal data of an individual for a particular purpose, the service provider (i.e., Data Fiduciary, Consent Manager) adhere to the following:

  • To establish the consent management processes for obtaining specific consent from the individual (data principal) before the processing of her personal data for specific purposes.
  • It may be noted these statutory provisions give individuals more control over their personal data and how it is used by service providers.2 (It is pertinent to note that the consent management process is based on the general principle of consensus ad idem in the contract; otherwise, the said agreement/request would be treated as invalid)
  • Established the consent manager, who is a single point person and registered with the Data Protection Board (i.e., Adjudicatory body under the Act), and who acts as a facilitator to enable data protection to give, manage, review, and withdraw consent through an accessible, interoperable platform.
  • Under the Act, there is a mandate that consent obtained from data principal be subject to adherence to the following principles:
    • The said consent should be free/unconditional.
    • It shall be specific.
    • It shall be unambiguous, with a clear affirmative. (It may be noted that these principles are also spirited by the general principles contract.)
  • Every request for consent should be in clear and simple language, giving the data principal the option to access such a request in English or any other language specified in the Eighth Schedule of the Indian Constitution.
  • The data principal has the right to give, manage, review, or withdraw her consent to the Data Fiduciary through the Consent Manager.
  • The consent manager shall be accountable to the data principal and execute its statutory obligations as per the defined rule.
  • It is also mandatory that the additional burden lie on the data fiduciary to prove that consent was obtained from the data principal as per the provisions of the Act.
Views: 42
Related Posts
Balancing the Current Account: A Legal Analysis of India’s Trade and Payment Framework

The fact that India's economy is among the fastest-growing in the world has attracted a lot of attention from around Read more

Cinematic Evolution of Film Financing in India

The Indian film industry has witnessed a remarkable journey over the decades, evolving from a nascent, struggling entity Introduction The Read more

Exploring the Shifts in Aviation MRO Economics: Insights from the MRO Conference in Delhi

The MRO Conference in Delhi emerges as a pivotal event in the realm of Maintenance, Repair, and Overhaul (MRO) within Read more

Big Data and Competition Law in Telecom: India vs. Europe
Association of big data and Competition Law

India's Competition Act of 2002, aimed at fostering fair competition and protecting consumers, plays a critical role in regulating the Read more

Ransomware – The Most Dangerous Cyber Threat
Ransomware

Ransomware is a form of malware that locks and encrypts the data, files, devices, or systems of a victim, discarding Read more

FOCC Regulations: Navigating India’s Financial Services Landscape
FOCC Regulations

India's banking system is diverse and growing rapidly. It comprises commercial banks, insurance firms, non-banking financial institutions, unions India's banking Read more

Provident Fund (PF) for International Employees in India: A Guide to Post-Termination Procedures

For international employees who have completed their service in India, the process of claiming their Employees' Provident Fund (EPF) benefits Read more

Digital Inheritance – Law that Secures the Future of Your Digital Assets 
Digital Inheritance

In our rapidly changing digital environment, the implementation of the Digital Personal Data Protection Act in 2023 marks a major Read more

Validity of Differential Treatment of Operational and Financial Creditors: The Swiss Ribbons Case

The Swiss Ribbons case addressed the validity of the differential treatment between operational and financial creditors under the Insolvency and Read more

The Importance of Protecting Your Intellectual Property

In today's knowledge-based economy, intellectual property (IP) is one of the most valuable assets a company or individual can have. Read more

Need help with legal issues?
Call Back Request

Leave a Reply

Your email address will not be published. Required fields are marked *