India’s Two-Tier Consent Architecture
Internal Consent Systems and Statutory Consent Managers under the DPDP Act 2023 and Rules 2025
DOI:
https://doi.org/10.32674/gyty6375Keywords:
DPDP Act, Data Protection., Consent Governance,, Data Fiduciary,, Consent Manager,Abstract
India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and the DPDP Rules, 2025 create a new two-level consent system for personal data protection in India. This paper examines both the internal consent systems used by Data Fiduciaries and the external statutory Consent Manager. It explains how these mechanisms improve transparency, accountability, and user control over personal data. Unlike the GDPR and similar laws, the DPDP framework mainly focuses on clear and informed consent while also providing certain exemptions and protections for children and persons with disabilities. The paper studies legal provisions related to consent notices, withdrawal of consent, data security, record keeping, and data erasure. It also discusses the role of Consent Managers as independent intermediaries that help users manage consent without accessing personal data. The paper compares the DPDP model with global privacy laws and highlights its strengths, challenges, and enforcement framework, including heavy penalties for non-compliance.