Introduction:
The Right to Privacy has emerged as a cornerstone of constitutional jurisprudence in India following the landmark judgement in Justice K.S. Puttaswamy v Union of India (2017). The Supreme Court unanimously recognised privacy as a fundamental right inherent in Article 21 and other freedoms guaranteed under Part III of the Constitution. The judgement overruled earlier precedents and redefined the relationship between the individual and the State in the era of rapid technological advancement. This paper argues that the DPDP Act’s deemed-consent mechanism and its broad government exemptions dilute the proportionality test laid down in Puttaswamy, leaving individual informational autonomy weaker in statute than in constitutional doctrine.
The key features of the Digital Personal Data Protection Act, 2023:
● Data fiduciary duties: Emphasizes purpose limitation, data minimization, and storage limitation.
● Consent-based regime: Data can only be processed with clear and informed consent.
● Rights of Data Principals: Includes the right to access, connection, erasure, and grievance redress.
The Legal Framework:
Article 21 of the Constitution guarantees that no person shall be deprived of personal liberty except by procedure established by law. In Puttaswamy, a nine-judge bench held that privacy is not a freestanding right but flows from the guarantee of life and personal liberty, along with the freedoms in Part III more broadly. Any state measure impacting privacy must satisfy: (i) legality, meaning the existence of law; (ii) legitimate state claim; (iii) proportionality between the means adopted and the object sought; and (iv) adequate procedural safeguards against abuse.
The DPDP Act, enacted six years later establishes a framework for processing “personal date” and creates obligations for “data fiduciaries”. Two provisions are important here. Section 7 permits processing without specific consent where consent is “deemed”- including for purposes the fiduciary considers the individual would reasonably expect. Second, the Section 17 exempts government agencies from most obligations under the Act, including purpose limitation and storage limitation, where processing is deemed necessary in the interests of sovereignty, security of State or public order.
After the Puttaswamy judgement, the Information Technology Act, 2000, particularly Sections 43A and 72A, provides civil and criminal liability for misuse for personal data and breach of confidentiality. The Aadhar Act 2016 was read subject to privacy safeguards by the Supreme Court.
Case Law Analysis:
It is a line of cases and not the 2017 judgement alone that defines the doctrinal benchmark against which the DPDP Act must be measured.
In the Aadhaar judgment, a five-judge bench applied the Puttaswamy test directly to a legislative scheme mandating biometric identification for access to welfare benefits. The majority held the core Aadhar scheme as satisfying legitimate state aim and proportionality in the context of targeted subsidy delivery, but struck down section 57 of the Aadhar Act, which had permitted private bodies to seek Aadhaar based authentication, holding that this extension lacked adequate legal backing and proportionate justification. This case is significant as it shows that the proportionality test has real teeth- the Court was willing to sever a statutory provision it found excessive and it demonstrates that even a facially legitimate government purpose does not immunise every element of an implementing scheme from scrutiny.
The proportionality standard was extended further in Anuradha Bhasin v Union Of India, where the Court considered internet shutdowns imposed in Jammu and Kashmir. The bench held that restrictions on internet access, even when framed as measures of public order, must satisfy the same proportionality analysis as any other restriction on a fundamental freedom, and must be temporary, subject to periodic review, and proportionate to the specific threat identified rather than imposed as a blanket measure. Read alongside the Aadhar Judgement, Anuradha Bhasin signals the courts expect proportionality to function as a continuing, reviewable constraint on state action and not a final and binding law enactment.
Critical Analysis: Where the Statute departs from the Doctrine
Deemed consent and erosion of legality through specificity: Puttaswamy’s legality requirement contemplates not merely the existence of a law, but a law that is precise enough to constrain discretion. Section 7’s deemed consent categories, particularly the “reasonable expectation” standard, transfer the determination of what counts as consent from the individual to the data fiduciary itself. This inverts the logic of informed consent that data protection frameworks are typically built around, and arguably fails the specificity that legality demands: an individual cannot meaningfully anticipate, ex ante, what a fiduciary will later characterise as within their reasonable expectation.
Government exemptions and the missing procedural safeguard: The fourth pillar of the Puttaswamy test- procedural safeguards against abuse and this was precisely what led the Court to strike down Section 57 in the Aadhar case. Section 17 of the DPDP Act exempts government processing from core obligations on broadly worded grounds such as security of the state, without requiring the same judicial or independent oversight mechanisms that the Court has repeatedly emphasised as necessary companions to any privacy-limiting measure. Unlike the internet shutdown scrutinised in Anuradha Bhasin, which the Court subjected to a requirement of periodic review, the DPDP’s exemption contains no comparable review mechanism, leaving the executive largely self-certifying when the exemption applies.
Institutional independence of the Data Protection Board: Procedural safeguards are only as strong as the body enforcing them. The Data Protection Board established under the Act is constituted, with its members appointed by the Central Government, and their tenure and removal also governed by executive rule-making power. An adjudicatory body whose composition and continuation depend on the very executive it may need to check sits uneasily with the Puttaswamy Court’s insistence that safeguards must be capable of checking state overreach, not merely administering it.
Conclusion:
Puttaswamy did not merely constitutionalise privacy; it established a continuing standard of review that later cases have applied with increasing rigour. Measured against standard, the DPDP Act’s deemed-consent provisions and government exemptions represent a retreat from rather than a fulfilment of, the constitutional promise. Two reforms would narrow this gap: first, replacing open-ended “reasonable expectation” deemed consent with a closed, enumerated list of processing purposes; and second, subjecting Section 17 government exemptions to periodic judicial or independent review, modelled on the safeguard the Court itself imposed in Anuradha Bhasin. In the absence of such a reform, India’s data protection regime risks becoming a statute that pays doctrinal homage to Puttaswamy while structurally departing from it.
Bibliography: