News Analysis4 minutes

Analyzing Consent Under DPDP Act 2023 Following the Puttaswamy Precedent

An evaluation of how the 2017 Puttaswamy privacy ruling informs consent obligations under the DPDP Act 2023 and the DPDP Rules 2025 for large BFSI enterprises.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

What Happened

A recent article in The Daily Pioneer titled DPDPA 2023: Is Consent Truly the Cornerstone of India's Privacy Law evaluates the role of consent within the current legislative framework. The piece contextualizes the Digital Personal Data Protection Act, 2023 against the landmark 2017 Supreme Court judgment in KS Puttaswamy v. Union of India. The article highlights that the 2017 ruling established a fundamental constitutional premise that privacy is not a privilege merely granted by the State, but an intrinsic right. The publication questions how this jurisprudential foundation translates into operational reality for data fiduciaries managing consent under the new law.

Does The DPDP Act Apply Here

Yes, the foundational principles discussed directly shape the interpretation of the DPDP Act, 2023. Per Section 3, the Act applies to the processing of digital personal data within India, as well as processing outside India if connected to offering goods or services to Data Principals in India. For large enterprises, especially in the BFSI sector, this means every collection of customer KYC or financial data must align with these constitutional and statutory mandates. The Act does not apply to personal data processed by an individual for personal purposes or data made publicly available by the Data Principal.

Legal Implications Under DPDP

Under Section 4 of the DPDP Act, consent is the primary basis for processing, except where Section 7 legitimate uses apply. The Puttaswamy ruling underscores that because privacy is a fundamental right, any waiver via consent must be explicitly informed, free, and specific. The DPDP Rules, 2025 mandate itemised notices and verifiable consent records, removing the viability of pre-ticked boxes or buried terms in legacy banking platforms. A data fiduciary must maintain an immutable audit trail of these consent artefacts to prove compliance to the Data Protection Board of India.

Could This Happen To You

For a Chief Compliance Officer at a bank or NBFC, relying on legacy consent frameworks creates severe regulatory exposure. If a data principal challenges a data processing activity, the DPBI will demand an evidence pack demonstrating valid, itemised consent. If your current systems cannot produce regulator-ready consent records mapped to specific data points, your board faces significant penalty risks under the Act, which cap at rupees 250 crore per breach instance. Furthermore, if improper consent leads to unauthorised processing or a breach, the Rules, 2025 require intimation to affected Data Principals without delay and a detailed report to the DPBI within 72 hours.

What Companies Should Do In The Next 30 Days

First, the compliance head must initiate a full RoPA update across all core banking and insurance systems to identify where consent is the basis for processing versus Section 7 legitimate uses. Second, control owners must map existing customer journeys against the itemised notice requirements of the DPDP Rules, 2025. Third, IT and compliance teams need to evaluate their capability to generate and store immutable consent artefacts that can be instantly retrieved for DPBI audits. Fourth, update your incident response playbooks to ensure the 72-hour DPBI reporting workflow is fully documented, tested, and aligned with your evidence collection systems.

What To Watch

Enterprises must monitor the DPBI's upcoming guidance on formatting itemised notices and managing verifiable parental consent mechanics under the Rules, 2025. With exactly 282 days remaining until the 13 May 2027 hard compliance deadline, BFSI compliance teams cannot wait to overhaul their consent architectures. To see how your current evidence trails and consent mechanisms measure up against DPDP requirements, check your exposure at freescan.complydp.com before an audit forces the issue.

Sources

Frequently asked questions

Does the DPDP Act require consent for all data processing?

No, consent is the primary basis for processing under Section 4 of the DPDP Act 2023, except where Section 7 legitimate uses apply. Financial institutions must map their processing activities to ensure the correct legal basis is documented in their RoPA.

What did the 2017 Puttaswamy judgment establish regarding privacy?

The 2017 Supreme Court judgment in KS Puttaswamy v. Union of India established that privacy is a fundamental, intrinsic right, not a privilege granted by the State. This foundational principle informs how valid, informed consent must be collected and managed under current Indian law.

What are the DPDP Rules 2025 requirements for a data breach?

In the event of a personal data breach, the DPDP Rules 2025 require data fiduciaries to provide intimation to affected Data Principals without delay. Additionally, a detailed breach report must be submitted to the Data Protection Board of India within 72 hours.

What penalties do banks face for non-compliance under the DPDP Act?

Non-compliance, such as failing to secure valid consent or failing to implement reasonable security safeguards, carries significant financial risk. The DPDP Act specifies penalty ceilings up to rupees 250 crore per breach instance, highlighting the need for robust audit trails.

When is the final deadline for DPDP Act compliance?

The hard compliance deadline for the DPDP Act 2023 is 13 May 2027. Large enterprises must ensure their consent artefacts and incident response frameworks are fully aligned with the DPDP Rules 2025 before this date to avoid regulatory scrutiny.