Post

Navigating Consent: DPDPA Section 6 vs. GDPR Article 7

Navigating Consent: DPDPA Section 6 vs. GDPR Article 7

As India’s Digital Personal Data Protection Act, 2023 (DPDPA) solidifies its regulatory landscape, understanding its nuances, particularly around the cornerstone of consent, is crucial for businesses operating in or with India. A comparative lens against global benchmarks like the European Union’s General Data Protection Regulation (GDPR) offers valuable insights into the expected standards and potential compliance challenges. This analysis focuses on three critical aspects of consent: granularity, withdrawal, and the onus of proof, comparing DPDPA Section 6 with GDPR Article 7.

Both the DPDPA and GDPR underscore the need for specific and informed consent, moving away from broad, catch-all agreements. Under DPDPA Section 6(1)(a), consent must be “free, specific, informed, unconditional and unambiguous,” and given through an affirmative action. The emphasis on “specific” implies that Data Fiduciaries must clearly delineate the purposes for which personal data is being processed. This aligns with the spirit of the erstwhile IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, which, under Rule 5(3), required data collection for a “lawful purpose.” Furthermore, sectoral regulations, such as those from the Reserve Bank of India (RBI) for digital lending or payment aggregators, often reinforce the need for granular consent for different data uses, particularly in financial contexts.

GDPR Article 7(1) similarly mandates consent to be “freely given, specific, informed and unambiguous.” Article 7(2) further clarifies that if a data subject’s consent is sought in the context of a written declaration which also concerns other matters, the request for consent must be “clearly distinguishable from the other matters, in an intelligible and easily accessible form using clear and plain language.” This explicitly pushes for granular options, ensuring individuals can consent to specific processing activities without being forced to accept others. While DPDPA’s text on granularity is strong, GDPR’s explicit mention of distinguishing consent from other matters within a declaration might be interpreted as a slightly stricter requirement for presentation and separation of consent options. However, in practice, DPDPA’s “specific” and “unambiguous” criteria will likely lead to similar granular consent mechanisms.

Ease and Impact of Withdrawal

The right to withdraw consent is a fundamental principle in both regimes. DPDPA Section 6(4) explicitly grants a Data Principal the right to withdraw consent at any time, stipulating that the mechanism for withdrawal must be “as easy as it is to give consent.” This provision is robust and clear. It also clarifies that “the consequences of such withdrawal shall be borne by such Data Principal,” providing practical clarity to businesses regarding service cessation or functionality limitations post-withdrawal. A unique aspect of DPDPA is the provision for a “Consent Manager” under Section 6(6), an entity registered with the Data Protection Board of India, which can enable Data Principals to give, manage, review, and withdraw consent. This institutionalized approach to consent management could potentially make the withdrawal process more streamlined and effective in India.

GDPR Article 7(3) mirrors DPDPA’s stance, stating that the data subject “shall have the right to withdraw his or her consent at any time,” and that “it shall be as easy to withdraw as to give consent.” GDPR also clarifies that the withdrawal “shall not affect the lawfulness of processing based on consent before its withdrawal,” a point implicitly covered by DPDPA’s “consequences borne by the Data Principal.” Both frameworks are equally stringent on the ease of withdrawal, ensuring that individuals retain control over their personal data. The DPDPA’s Consent Manager concept, however, presents a potentially more structured and enforceable mechanism for withdrawal compared to GDPR, which relies more on individual controllers to implement easy withdrawal methods.

A crucial aspect of accountability in data protection is determining who bears the responsibility of proving valid consent. Both DPDPA and GDPR place this burden squarely on the data processing entity. DPDPA Section 6(5) unequivocally states that “the onus of proving that consent was obtained in accordance with the provisions of this Act shall be on the Data Fiduciary.” This clear articulation ensures that Data Fiduciaries must maintain meticulous records and robust consent management systems.

Similarly, GDPR Article 7(1) mandates that “where processing is based on consent, the controller shall be able to demonstrate that the data subject has consented to processing of his or her personal data.” This “accountability principle” is central to GDPR and requires controllers to not only comply with the regulation but also to be able to demonstrate that compliance. In this regard, both the DPDPA and GDPR are equally stringent, imposing a significant burden on businesses to maintain comprehensive audit trails of consent acquisition, including timestamps, methods, and the specific information provided to the Data Principal/data subject.

Practical takeaway

For Indian businesses, General Counsels, and Data Protection Officers, the DPDPA’s provisions on consent demand immediate and thorough review of existing data processing practices. While DPDPA Section 6 shares many similarities with GDPR Article 7, particularly in placing the onus of proof on the Data Fiduciary and ensuring easy withdrawal, the explicit mention of a Consent Manager in India could reshape consent management. Businesses should focus on implementing granular consent mechanisms, ensuring clear, unambiguous language, and making withdrawal as effortless as giving consent. Robust record-keeping of consent acquisition is not merely good practice but a statutory requirement to meet the onus of proof. Aligning with these principles will not only ensure DPDPA compliance but also position Indian entities favorably in the global privacy landscape.

This post is licensed under CC BY 4.0 by the author.