Consent and Algorithmic Decision-Making under the DPDP Act, 2023: A Regulatory Paradox
DOI:
https://doi.org/10.37591/njcsl.v9i1.2007Keywords:
DPDP Act, 2023, Consent, Algorithmic Decision-Making, Data Protection, Informational AutonAbstract
The Digital Personal Data Protection Act, 2023, also called the DPDP Act, is based on a consent-focused vision of data regulation, where the consent is the default rule of data processing, as well as the main manifestation of informational independence. The paper explores the performance of such an architecture in a situation whereby individual information is persistently embedded within algorithmic systems that categorize, rank, and make predictions on individuals in a manner that influences access to opportunities and services. The paper asserts that, in modern platform space, the consent is frequently manufactured,
instead of meaningfully exercised: interface design, defaults, bundling, and functional dependency structure, choose, and computational inference is increasing the range of that which is actually processed by anything beyond what a user can reasonably anticipate at the time of collection. Consent is therefore more than a processing gateway, it is a decision ecosystem gateway based on inference downstream. Furthering this, the paper finds the source of a temporal discrepancy in the core of consent- based legitimacy: at onboarding, autonomy manifests episodically, whereas algorithmic assessment proceeds continuously in the long term. Although the DPDP Act provides a set of conditions under which valid consent and notice can be given, it does not introduce a broader statutory framework of exclusively automated decision-making, such as rights to explanation, contestation or meaningful human review, which is similar in logic to Article 22 of the GDPR. The article includes a doctrinal and structural criticism of the idea of entry-based accountability and suggests specific reforms, namely, anti-dark-patterns consent rules, profiling/inference transparency requirements, and review-and-contestation protections against significant-effect automated decisions.
References
1. Digital Personal Data Protection Act, 2023, s 6(1).
2. D igital Personal Data Protection Act, 2023, s 5(1).
3. Digital Personal Data Protection Act, 2023, s 7.
4. Solove DJ. Privacy self-management and the consent dilemma. Harv Law Rev. 2013;126:1880.
5. Justice K.S. Puttaswamy (Retd.) v Union of India. (2017) 10 SCC 1.
6. Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation), Art 22.
7. Digital Personal Data Protection Act, 2023, s 4(1)–(2).
8. Digital Personal Data Protection Act, 2023, s 7.
9. Digital Personal Data Protection Act, 2023, s 6(1).
10. Digital Personal Data Protection Act, 2023, s 5(1).
11. Digital Personal Data Protection Act, 2023, s 6(10).
12. Digital Personal Data Protection Act, 2023, s 6(1).
13. Digital Personal Data Protection Act, 2023, s 5(1).
14. Digital Personal Data Protection Act, 2023, s 6(4)–(6).
15. European Data Protection Board. Guidelines 3/2022 on dark patterns in social media platform interfaces. Brussels: EDPB; 2022.
16. Organisation for Economic Co-operation and Development. Dark commercial patterns. OECD Digit Econ Pap. 2022.
17. Mathur A, Acar G, Friedman MJ, Lucherini E, Mayer J, Chetty M, et al. Dark patterns at scale: Findings from a crawl of 11K shopping websites. Proc ACM Hum Comput Interact. 2019.
18. Solove DJ. Privacy self-management and the consent dilemma. Harv Law Rev. 2013;126:1880.
19. Yoo CS. Network effects in action. 2020.
20. Obar JA, Oeldorf-Hirsch A. The biggest lie on the internet: Ignoring the privacy policies and terms of service policies of social networking services. Inf Commun Soc. 2020.
21. McDonald AM, Cranor LF. The cost of reading privacy policies. I/S J Law Policy Inf Soc. 2008.
22. Acquisti A, Brandimarte L, Loewenstein G. Privacy and human behavior in the age of information. Science. 2015.
23. Regulation (EU) 2016/679 (General Data Protection Regulation), Art 4(4).
24. Information Commissioner’s Office. What is automated individual decision-making and profiling? UK GDPR guidance.
25. Digital Personal Data Protection Act, 2023, s 11.
26. Digital Personal Data Protection Act, 2023, s 12.
27. Digital Personal Data Protection Act, 2023, s 13.
28. Digital Personal Data Protection Act, 2023, s 6(4).
29. Latham & Watkins LLP. India’s Digital Personal Data Protection Act 2023 vs the GDPR: A comparison.
30. Digital Personal Data Protection Act, 2023, s 5(1).
31. Digital Personal Data Protection Act, 2023, s 6(1).
32. Digital Personal Data Protection Act, 2023, s 8(1), 8(3), 8(5)–(6).
33. Digital Personal Data Protection Act, 2023, ss 11–13; s 6(4).
34. European Data Protection Board. Guidelines 3/2022 on dark patterns in social media platform interfaces. 2022.
35. Regulation (EU) 2016/679 (General Data Protection Regulation), Art 22.
36. Digital Personal Data Protection Act, 2023, s 8(1), 8(3), 8(5)–(6).
37. Regulation (EU) 2016/679 (General Data Protection Regulation), Art 22; Digital Personal Data Protection Act, 2023, ss 11–13; s 6(4).
