Consent As A Legal Fiction: Rethinking Data Fiduciaries, Algorithmic Power, And Informational Self-Determination In India
- Nikitha K
- Jul 5
- 10 min read
Abstract
The Digital Personal Data Protection Act 2023 arrives at a peculiar historical juncture[1], one where India's digital population has outpaced its legal literacy[2], and where internet architecture has rendered meaningful consent structurally improbable for ordinary users[3]. This blog argues that the statutory consent framework, while formally progressive[4], reproduces a sociological fallacy: that individuals possess equal bargaining capacity when encountering data fiduciaries[5]. Drawing on Zuboff's surveillance capitalism thesis, constitutional privacy jurisprudence post-Puttaswamy[6], and a critical reading of the Act's exemptions architecture[7], it contends that consent in the data economy has become a legal fiction, a procedural artefact laundering commercial extraction as autonomy[8]. It concludes by proposing a fiduciary reorientation of data law, displacing the burden of protection from the individual onto institutional duty-bearers[9].
Introduction: The Tyranny of the Tick-Box
On any given morning, an Indian smartphone user will have, before finishing her first cup of tea, nominally consented to the collection, processing, and onward transfer of her location data, biometric identifiers, browsing behaviour, and purchasing preferences.[10] These consents are buried within terms-of-service agreements that legal scholars estimate would require eleven full working days per year to read in their entirety.[11] The click-through consent model, which forms the operative heart of the Digital Personal Data Protection Act 2023, proceeds on an assumption that is empirically false and sociologically naive: that the user is a rational, informed, and freely choosing agent.[12]
What this blog seeks to do is something more uncomfortable than rehearsing familiar critiques it interrogates whether 'consent,' as a legal category, is capable of doing the normative work data protection law assigns to it, particularly within India's stratified social structure.[13] In a country where digital literacy remains deeply uneven, where platform monopolies face no meaningful competitive check, and where the state itself is the most ambitious data collector, the consent paradigm may function less as a shield for individuals and more as an indemnity for fiduciaries.[14] The Supreme Court's recognition in Puttaswamy of privacy as a fundamental right inhering in Articles 14, 19, and 21 promises informational self-determination;[15] the current consent architecture delivers something considerably thinner.[16]
Surveillance Capitalism and the Structural Impossibility of Consent
The Behavioral Surplus Problem
Shoshana Zuboff's surveillance capitalism thesis offers an indispensable sociological vocabulary for understanding why consent frameworks fail.[17] The dominant business model of digital platforms rests not merely on data collection but on extracting behavioral surplus data generated as a by-product of human activity, processed into prediction products sold in behavioral futures markets.[18] The user's awareness of, let alone consent to, this extraction is structurally irrelevant.[19] Consent frameworks assume a dyadic relationship between data subject and fiduciary; the actual architecture involves dozens of invisible processors, brokers, and advertising intermediaries.[20]
The law has responded through notice-and-choice models.[21] The GDPR mandates disclosure of processing purposes at collection;[22] India's DPDPA 2023 requires itemized notices and affirmative specific consent.[23] These are not without value, but they are structurally insufficient.[24] Information asymmetry between a platform employing hundreds of data scientists and a user with no technical training is not bridged by a longer privacy notice.[25] As Wachter, Mittelstadt, and Floridi have argued, the right to information cannot substitute for genuine comprehension or power.[26]
India-Specific Asymmetries
India's approximately 850 million internet users span enormous gradients of digital literacy, linguistic diversity, and economic vulnerability.[27] For a first-generation smartphone user navigating a welfare portal in a language not her own, 'informed consent' to data processing is not merely theoretical it is practically unintelligible.[28] This is not a failure of individual capability but a consequence of structural conditions.[29] Caste and class inequalities shape access to digital infrastructure and the cognitive resources necessary to exercise meaningful data choices.[30] Virginia Eubanks has documented how automated systems disproportionately harm marginalized communities in ways they cannot anticipate or contest;[31] the Indian analogue is visible in the Aadhaar ecosystem, where biometric collection became a condition of welfare entitlement, eliminating voluntariness from 'consent' altogether.[32]
The DPDPA 2023: Progressive Architecture, Conservative Concessions
The Statutory Framework
The DPDPA 2023 represents a genuine legislative advance.[33] The Act mandates that personal data may be processed only for a lawful purpose upon obtaining free, specific, informed, and unambiguous consent.[34] It introduces the 'Data Fiduciary' concept and imposes obligations of accuracy, storage limitation, and security.[35] The Consent Manager mechanism, permitting individuals to grant and revoke consent through registered intermediaries, is an innovative institutional design that acknowledges the coordination problems inherent in individual data management.[36] These provisions are philosophically coherent with the Puttaswamy framework.[37]
Where the Promise Frays: The Exemptions Architecture
The Act's most significant jurisprudential weakness lies not in what it includes but in what it excludes.[38] Section 17 grants sweeping exemptions to the Central Government from virtually all substantive obligations when processing is deemed necessary for sovereignty, security, or public order.[39] These grounds drawn from constitutional language with deliberate breadth are self-assessed: there is no independent oversight body, no judicial pre-authorization, and no proportionality test embedded in the statutory text.[40] This is constitutionally suspect.[41] Puttaswamy insists that any limitation on privacy must satisfy legality, legitimate aim, and proportionality.[42] A blanket executive exemption satisfies, at best, only the first.[43] Justice Chandrachud's dissent in the Aadhaar judgment had warned presciently against allowing the state to function as a data fiduciary without corresponding accountability;[44] the DPDPA 2023 risks entrenching precisely that asymmetry.[45]
Consent as Legal Fiction: The Sociological Critique
Legal fictions are useful devices when they preserve substantive justice.[46] They become dangerous when they launder injustice as procedure.[47] Consider a user in rural Rajasthan installing a food delivery application: the consent dialogue arrives in English, spans multiple screens, and cross-references a privacy policy on a separate URL.[48] Refusal means forfeiting access to the service in an increasingly app-mediated economy, a meaningful loss.[49] The consent obtained under these conditions is what sociologists would call manufactured compliance, not autonomous choice.[50]
Frank Pasquale has argued that the black box quality of algorithmic processing renders meaningful consent impossible even in principle.[51] How can one consent to processing whose downstream effects, credit scoring, insurance pricing, employment profiling, cannot be foreseen at the point of collection?[52] The temporal mismatch between consent and harm structurally defeats the protective purpose of consent frameworks.[53] The DPDPA 2023's purpose limitation provision attempts to address this,[54] but as Julie Cohen has noted, purpose limitation is only as strong as the enforcing institution.[55] When the Data Protection Board operates under government superintendence rather than as a constitutionally insulated body, the conditions for effective enforcement are compromised at their foundation.[56]
Towards a Fiduciary Reorientation
The Fiduciary Duty Model
If consent cannot bear the weight data protection law places upon it, the answer lies in a more robust operationalisation of the fiduciary concept the DPDPA 2023 invokes but inadequately develops.[57] In classical doctrine, fiduciaries are bound by duties of loyalty; they must not act in their own interest at the beneficiary's expense.[58] In the data context, a genuine fiduciary obligation would mean a platform collecting health data cannot monetise it through targeted advertising, regardless of nominal user consent.[59] The consent of the weaker party cannot override the structural duty of the stronger one.[60] Comparative frameworks support this: the GDPR embeds proportionality and data minimisation as intrinsic obligations, not merely consent-dependent permissions;[61] India's own Article 21 jurisprudence recognises that state-like powerful private actors carry affirmative duties towards vulnerable populations that cannot be contracted away.[62]
Institutional Design and Differentiated Protection
No data protection framework functions without institutionally credible enforcement.[63] The Srikrishna Committee recommended a structurally independent authority with technical expertise, quasi-judicial powers, and transparent appointments.[64] These recommendations were not carried forward.[65] A Board whose members are appointed and removable by the Central Government creates incentive structures that reward nominal compliance deploying consent interfaces that satisfy the statute's letter while defeating its spirit.[66] The dark patterns literature documents precisely these dynamics.[67]
A final reform deserving attention is disaggregation of the 'data subject' as a legal category.[68] The DPDPA 2023 provides enhanced protection for children's data;[69] social vulnerabilities disabling meaningful consent extend far beyond age.[70] Caste, class, disability, and linguistic minority status each create differential exposure to algorithmic harm.[71] A more sociologically sophisticated framework would impose stricter obligations on fiduciaries processing data from identifiably vulnerable populations and mandate community-level impact assessments for algorithmic systems deployed in welfare delivery.[72]
Conclusion
There is a particular irony in the fact that India, which produced in Puttaswamy one of the world's most philosophically sophisticated elaborations of the right to privacy,[73] has produced in the DPDPA 2023 a statute whose consent framework rests on an empirically questionable sociology of individual rational choice.[74] The law has lagged behind its own constitutional foundations.[75]
The argument here is not that consent is worthless it is that consent has been overburdened.[76] It has been asked to legitimate a data economy whose structural conditions systematically disable autonomous choice.[77] To rescue the project of data protection, the legal framework must shift from individual consent to institutional duty: from the click-through box to the fiduciary obligation, from notice to accountability, from formal equality to substantive protection.[78] Until that reorientation occurs, consent in the Indian data economy will remain what it too often already is: a legal fiction that protects fiduciaries far more effectively than the individuals whose data they hold.[79]
This blog has been authored by Nikitha K student at SRM Universtiy, Odisha (Winner of the 1st RGNUL National Socio-Legal Blog Writing Competition)
REFERENCES
[1] Digital Personal Data Protection Act 2023 (India).
[2] Aleecia M McDonald and Lorrie Faith Cranor, 'The Cost of Reading Privacy Policies' (2008) 4(3) I/S: A Journal of Law and Policy for the Information Society 543.
[3] DPDPA, 2023, ss 5–6.
[4] Shoshana Zuboff, The Age of Surveillance Capitalism: The Fight for a Human Future at the New Frontier of Power (PublicAffairs 2019) 8–12.
[5] Justice K S Puttaswamy (Retd) v Union of India (2017) 10 SCC 1.
[6] Ibid [298]–[326] (Chandrachud J).
[7] DPDPA, 2023, s 17.
[8] Zuboff (n 4) 93–97.
[9] Lina M Khan and David E Pozen, 'A Skeptical View of Information Fiduciaries' (2019) 133(2) Harvard Law Review 497, 514–18.
[10] Zuboff (n 4) 75–82; Yochai Benkler, The Wealth of Networks: How Social Production Transforms Markets and Freedom (Yale University Press 2006) 13–28.
[11] McDonald and Cranor (n 2) 565.
[12] Sandra Wachter, Brent Mittelstadt and Luciano Floridi, 'Why a Right to Explanation of Automated Decision-Making Does Not Exist in the General Data Protection Regulation' (2017) 7(2) International Data Privacy Law 76, 82–87.
[13] Telecom Regulatory Authority of India, Consultation Paper on Privacy, Security and Ownership of the Data in the Telecom Sector (TRAI 2017) paras 2.4–2.9.
[14] Internet and Mobile Association of India, India Internet Report 2023 (IAMAI 2023); Virginia Eubanks, Automating Inequality: How High-Tech Tools Profile, Police, and Punish the Poor (St Martin's Press 2018) 9–13; Reetika Khera (ed), The Battle for Employment Guarantee (Academic Foundation 2011); Unique Identification Authority of India, Annual Report 2022–23 (UIDAI 2023).
[15] Puttaswamy (n 5) [3] (Chelameswar J), [264] (Chandrachud J).
[16] DPDPA, 2023, ss 5–6, 17.
[17] Zuboff (n 4) 63–74; Ministry of Electronics and Information Technology, Report of the Expert Committee on Non-Personal Data Governance Framework (MeitY 2020) paras 3.2–3.4.
[18] Zuboff (n 4) 93–97.
[19] ibid 233–37.
[20] DPDPA, 2023, ss 2(i), 8 (defining 'Data Fiduciary' and 'Data Processor').
[21] Puttaswamy (n 5) [298]–[326] (Chandrachud J).
[22] Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data [2016] OJ L119/1 (GDPR), arts 13–14.
[23] DPDPA, 2023, ss 5–6; cf Justice K S Puttaswamy (Retd) v Union of India (Aadhaar) (2018) 16 SCC 1 [294]–[300].
[24] Shyam Divan and Anjali Sengupta, 'Dismantling the Surveillance Architecture' (2019) 54(1) Economic and Political Weekly 34, 38.
[25] Lon L Fuller, Legal Fictions (Stanford University Press 1967) 9–12.
[26] Wachter, Mittelstadt and Floridi (n 12) 82; see also Peter Birks, 'Equity in the Modern Law: An Exercise in Taxonomy' (1996) 26 University of Western Australia Law Review 1, 18–22.
[27] Amba Kak and Smriti Parsheera, 'The DPDPA 2023 and the Road Ahead' (IT for Change Policy Brief, November 2023) 4–6.
[28] ibid; Usha Ramanathan, 'Immunity and Accountability: A Review of the Aadhaar Ecosystem' (2021) 56(4) Economic and Political Weekly 22, 25–27.
[29] Cass R Sunstein and Richard H Thaler, Nudge: Improving Decisions about Health, Wealth, and Happiness (Yale University Press 2008) 81–88.
[30] Frank Pasquale, The Black Box Society: The Secret Algorithms That Control Money and Information (Harvard University Press 2015) 19–32.
[31] Eubanks (n 14) 174–82; Mireille Hildebrandt, 'Profiling and the Identity of the European Citizen' in Mireille Hildebrandt and Serge Gutwirth (eds), Profiling the European Citizen (Springer 2008) 303.
[32] Puttaswamy (Aadhaar) (n 23) [1448]–[1480] (Chandrachud J, dissenting).
[33] Julie E Cohen, 'The Biopolitical Public Domain: The Legal Construction of the Surveillance Economy' (2017) 31(2) Philosophy and Technology 213, 219–24.
[34] DPDPA, 2023, ss 4–6.
[35] ibid ss 8–10; Cohen (n 33) 226.
[36] DPDPA, 2023, s 6(7)–(9); see Paul D Finn, 'The Fiduciary Principle' in TG Youdan (ed), Equity, Fiduciaries and Trusts (Carswell 1989) 1, 4–9; Bristol and West Building Society v Mothew [1998] Ch 1 (CA) 18 (Millett LJ).
[37] Puttaswamy (n 5) [298]–[326]; cf Khan and Pozen (n 9) 506–10.
[38] Cf GDPR (n 22) art 23 (limited derogations subject to proportionality).
[39] DPDPA 2023 (n 1) s 17(2)(a); see Maneka Gandhi v Union of India AIR 1978 SC 597, [55]–[56].
[40] Srikrishna Committee, A Free and Fair Digital Economy: Protecting Privacy, Empowering Indians (Ministry of Electronics and Information Technology, July 2018) 122–28.
[41] ibid; DPDPA, 2023, s 17 (no proportionality language).
[42] Puttaswamy (n 5) [310]–[325] (Chandrachud J).
[43] DPDPA, 2023, s 17(2).
[44] Puttaswamy (Aadhaar) (n 23) [1448]–[1480] (Chandrachud J, dissenting); see also Eubanks (n 14) 174–82; E Tendayi Achiume, 'Digital Racial Borders' (2020) 115 AJIL Unbound 333, 335–37.
[45] Andrew D Selbst and others, 'Fairness and Abstraction in Sociotechnical Systems' (2019) Proceedings of the ACM Conference on Fairness, Accountability, and Transparency 59, 64–66.
[46] Fuller (n 25) 49–53.
[47] ibid 67–70.
[48] Kak and Parsheera (n 27) 7–9.
[49] Ramanathan (n 28) 26.
[50] Sunstein and Thaler (n 29) 88.
[51] Pasquale (n 30) 14–17, 191–93.
[52] Hildebrandt (n 31) 309–13.
[53] Pasquale (n 30) 191–93.
[54] DPDPA 2023 (n 1) ss 4(2), 8(3).
[55] Cohen (n 33) 230–34.
[56] ibid; see DPDPA, 2023, ss 18–20 (constitution and powers of the Data Protection Board).
[57] DPDPA, 2023, s 2(i); Finn (n 36) 4–9.
[58] Finn (n 36) 27–35; Bristol and West (n 36) 18 (Millett LJ).
[59] Khan and Pozen (n 9) 514–18.
[60] Pasquale (n 30) 192.
[61] GDPR (n 22) art 5(1)(b)–(c).
[62] Maneka Gandhi (n 39) [55]–[56]; see also Olga Tellis v Bombay Municipal Corporation AIR 1986 SC 180, [33].
[63] Cohen (n 33) 230–34.
[64] Srikrishna Committee (n 40) 144–48.
[65] ibid; cf DPDPA 2023 (n 1) ss 18–20.
[66] Arvind Narayanan and others, 'Dark Patterns: Past, Present, and Future' (2020) 18(2) ACM Queue 67, 70–73.
[67] ibid 73–86.
[68] Eubanks (n 14) 174–82.
[69] DPDPA, 2023, s 9.
[70] Achiume (n 44) 335–37.
[71] Eubanks (n 14) 174–82; Achiume (n 44) 335–37; see also Safiya Umoja Noble, Algorithms of Oppression: How Search Engines Reinforce Racism (New York University Press 2018) 64–84.
[72] Puttaswamy (Aadhaar) (n 23) [1448]–[1480] (Chandrachud J, dissenting).
[73] Puttaswamy (n 5); see Gautam Bhatia, The Transformative Constitution: A Radical Biography in Nine Acts (HarperCollins 2019) ch 6.
[74] DPDPA, 2023, ss 5–6; cf Zuboff (n 4) 8–12.
[75] Srikrishna Committee (n 40) 122–28, 144–48.
[76] Khan and Pozen (n 9) 514–18.
[77] Zuboff (n 4) 8–12, 233–37.
[78] Eubanks (n 14) 174–82; Selbst and others (n 45) 64–66.
[79] Fuller (n 25) 67–70.





%20(1).png)

Comments