I. Introduction
One of the primary arguments that is consistently and boldly made against the claim of privacy is —
If one has consented to it, then what is the issue?
This argument posits that an individual’s consent to something that encompasses their privacy is the quintessential solution to managing all privacy concerns. Consent is seen as control, and in the digital age, this control over one’s privacy is presented as a bundle of rights: the right to notice, access, and consent to the sharing, collection, processing, and use of one’s personal data. Daniel Solove calls this “privacy self-management”. This forms the bedrock for the data protection regulatory regimes, including India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”), which, under section 6, enumerates that valid consent must be free, specific, informed, unconditional, and unambiguous, presented through clear affirmative action by the data principal. This consent cannot be bundled, coerced, or implied through silence or pre-ticked boxes. Several online websites, browsers and applications also hinge on such a consent mechanism.
Theoretically, the aim is to ensure that individuals are entirely aware of what they are consenting to and are exercising meaningful consent over their personal information. However, the practical realities of whether consent is actually informed and meaningful differ, especially in India. This article borrows Solove’s discourse on this consent dilemma, analysing both the cognitive and structural issues, to then adopt it within the assertion that this dilemma is worsened in a country such as India, a global south state faced with social, economic and cultural concerns — such as rampant poverty, lack of literacy, and an extensive digital divide.
II. The Consent Dilemma through an Indian Lens
Solove posits that privacy self-management does not provide people with meaningful consent over their data, creating a consent dilemma because of two sets of problems.
A. Individual issues
The first set is that of cognitive problems. This includes the reality of the uninformed individuals who inevitably make skewed decisions about sharing their personal data. In accordance with the DPDP Act, a notice must be served on the data principal detailing the type of data collected, how it is used, and further giving them a choice to accept such processing. However, practically, most people do not read privacy notices that are either presented on websites or within boilerplate privacy terms in contracts. Individuals are often unwilling, ignorant, lazy, or simply unaware, and consequently fail to care about the implications. Even if they were to read these notices, as laypersons not familiar with the law, they lack the expertise to adequately assess the implications of agreeing to certain uses or disclosures of their data or even understand the language.
This issue is worsened in India — a country wherein over 1 billion people fall below the poverty line and are unable to access the education that would help them understand what boxes they click on their phones imply. Furthermore, in India, English is not the first language for a majority of the population, which puts them at an inherent disadvantage in understanding the notices drafted in English, worsened by the complex, lengthy legal jargon.
Emerging technology aims to increase an individual’s convenience but disregards their privacy. In India, platforms such as the Digi Yatra system have become the norm because people prefer the expediency of such technology, despite its privacy implications — Digi Yatra collects and stores facial biometrics, Aadhaar card details, business information, contact data, and videos and images taken at every kiosk. This hoard of data is backed by an insufficient Digi Yatra Biometric Boarding System (“DYBBS”) Policy and weak privacy guidelines, which lack the fundamental privacy principles. For example, the Digi Yatra Foundation, which now owns the person’s data, can share it with government entities without consent based on security reasons and a need basis, which may lead to a potential abuse of access. Additionally, the DPDP Act does not entirely protect the data of a Digi Yatra user, as its obligations can be exempt under section 17 of the Act. The Act also fails to recognise that facial biometrics are “sensitive personal data”, lacking any codification of such a category that requires additional safeguards, further creating a legislative gap. By collecting business information and contact details, information which is not required for the authentication of a passenger against their facial biometric data, this technology also fails essential data privacy principles such as data minimisation.
This status quo largely remains because the benefits, convenience and efficiency of these applications are far better advertised and accepted over awareness of their potential privacy violations. No one is aware of it unless they read in-depth, complicated critiques or articles about it — a practice the average Indian would not be exposed to. In fact, even if people are aware and refrain from using such services, they seem to think that they are put at a disadvantage in comparison to those who use them uninhibitedly or merely don’t weigh such issues to be of greater importance than a short-term relief of not having to stand in line.
B. Structural issues
However, the issue does not remain merely at the individual level — Solove states that structural issues also exacerbate this dilemma.
First is the problem of scale and complexity. He points out that there are simply too many entities that collect, use, and disclose people’s data for any rational person to execute privacy self-management effectively. All data collectors have varied privacy policies, some of which are periodically amended, making it more difficult for the user to keep track. The incomprehension faced from dealing with complicated emerging technology results in a psychological phenomenon of consent fatigue — referring to the exhaustion and disengagement experienced by users who are repeatedly asked to provide consent through the dozens of privacy prompts they face across multiple digital platforms every day. An individual, overwhelmed by such a cognitive overload and faced with repetitive choices to make, resorts to making impulsive decisions based on heuristics — opting for shortcuts that result in quicker, convenient decisions to solve problems.
With the internet being intrinsically intertwined with their life, individuals feel a sense of entitlement to it. Every website or browser has a cookie policy; these cookies are small data files that are stored to remember who you are, save your preferences and track your activity, in the name of improved algorithms. A person using the internet daily would be exhausted being faced with a cookie policy on every website and would accept it merely to enter the website and access what they are entitled to. This leads to another structural issue — that of data aggregation. Once certain data is collected in isolation, ensuring the user’s consent is taken, this individual data has the potential to aggregate, creating culminated datasets that reach conclusions the isolated data wouldn’t have, recognise patterns and trends, and finally create a digital version of a person. This means that even if people agree to share individual pieces of data in isolation, they fail to understand the way data aggregation over time can reveal sensitive facts about a person, invasively track, profile, and de-anonymise a person. This violates a person’s fundamental right to informational privacy, which is established to be an intrinsic part of the Right to Privacy under Article 21 in the case of Justice K.S. Puttaswamy v. Union of India, by taking away the right to control, communicate or retain information about one’s own person.
The understanding to exercise this right would require understanding how the information can be controlled. However, in India, this form of understanding might prove difficult. People in rural areas are increasingly affected by this due to the digital divide and lack of digital literacy. The country faces a significant digital divide, with internet penetration ranging from 24% in rural households to 66% in urban households, restricting access to the internet. Digital literacy is substantially lower; for example, computer literacy among individuals aged 15 years and above stands at 24.7% and the marginalised, women and the elderly face even lower digital literacy in India. Due to this, the population of India are left inept and worse off in managing their privacy by way of their own consent, as this consent can never be truly informed. Herein, individuals become complacent in trading their privacy rights for other economic and welfare rights.
III. Conclusion
The data collectors and their technology lawyers view consent as merely a compliance requirement, and to users, this becomes a box to tick before availing of the services they are promised— thus, the ideal of a rational, informed consent slowly erodes. Those who understand this technology prefer its convenience and efficiency over their privacy, and those without the means to understand the use of technology find it all the more difficult to realise its impact, resorting to it as a necessity and means to improve their life. Ultimately, an individual, whether from a rural or urban area in India, faces a threat to privacy. Therefore, it must be recognised that the regime of consent as control over one’s privacy cannot holistically ensure one’s right to privacy, especially when socio-cultural and economic factors are influencing this issue that ostensibly is presented as solely a legal problem.
Deepshikha Das is a law graduate from Jindal Global Law School. Her areas of interests rest in the intersections between Technology law and socio-economic and cultural justice.

