India’s Two-Tier Consent Architecture

Internal Consent Systems and Statutory Consent Managers under the DPDP Act 2023 and Rules 2025

Authors

  • Prashant Kumar Chauhan Faculty of Law, University of Lucknow Author

DOI:

https://doi.org/10.32674/gyty6375

Keywords:

DPDP Act, Data Protection., Consent Governance,, Data Fiduciary,, Consent Manager,

Abstract

India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and the DPDP Rules, 2025 create a new two-level consent system for personal data protection in India. This paper examines both the internal consent systems used by Data Fiduciaries and the external statutory Consent Manager. It explains how these mechanisms improve transparency, accountability, and user control over personal data. Unlike the GDPR and similar laws, the DPDP framework mainly focuses on clear and informed consent while also providing certain exemptions and protections for children and persons with disabilities. The paper studies legal provisions related to consent notices, withdrawal of consent, data security, record keeping, and data erasure. It also discusses the role of Consent Managers as independent intermediaries that help users manage consent without accessing personal data. The paper compares the DPDP model with global privacy laws and highlights its strengths, challenges, and enforcement framework, including heavy penalties for non-compliance.

Published

2026-09-06

Issue

Section

Law, Technology, and Society

How to Cite

India’s Two-Tier Consent Architecture: Internal Consent Systems and Statutory Consent Managers under the DPDP Act 2023 and Rules 2025. (2026). STAR Journal of Law, Policy and Society, 2. https://doi.org/10.32674/gyty6375

Similar Articles

11-15 of 15

You may also start an advanced similarity search for this article.