Consent Beyond Compliance: A Comparative Analysis of the GDPR and India’s Digital Personal Data Protection Act, 2023
Abstract
The rapid expansion of the digital economy has transformed personal data into one of the world’s most valuable resources, making robust data protection laws indispensable for safeguarding individual privacy and fostering public trust. The General Data Protection Regulation (GDPR) of the European Union is widely regarded as the global benchmark for data protection, establishing stringent requirements for lawful processing, informed consent, transparency, accountability, and the protection of data subject rights. Inspired by evolving international privacy standards and the constitutional recognition of privacy as a fundamental right in India through Justice K.S. Puttaswamy v. Union of India, India enacted the Digital Personal Data Protection Act, 2023 to regulate the processing of digital personal data while supporting innovation and the growth of the digital economy.
This paper presents a comparative analysis of the consent frameworks under the GDPR and the Digital Personal Data Protection Act, 2023. It examines the legal standards governing valid consent, the rights of individuals to withdraw consent, obligations imposed upon organizations processing personal data, and the mechanisms designed to ensure transparency and accountability. While both frameworks recognize consent as a cornerstone of lawful data processing and empower individuals with significant control over their personal information, notable differences exist in their legislative philosophy, scope, lawful grounds for processing, enforcement architecture, and compliance obligations.
The study further evaluates the practical implications of these differences for multinational businesses, digital platforms, and privacy professionals operating across jurisdictions. It argues that although India’s DPDP Act reflects global privacy principles and marks a significant advancement in the country’s data protection regime, the GDPR remains comparatively more comprehensive due to its broader regulatory scope, detailed lawful processing grounds, stronger institutional safeguards, and well-developed enforcement mechanisms. At the same time, the DPDP Act adopts a pragmatic and business-oriented approach that seeks to balance individual privacy with India’s rapidly expanding digital ecosystem.
Ultimately, the paper concludes that effective data governance requires more than legislative compliance; it demands a culture of transparency, accountability, privacy-by-design, and ethical stewardship of personal data. As digital technologies continue to evolve, harmonisation of global privacy standards and continuous regulatory adaptation will be essential for protecting fundamental rights while enabling responsible innovation in the digital age.
Keywords:
Data Privacy; General Data Protection Regulation (GDPR); Digital Personal Data Protection Act, 2023 (DPDP Act); Consent; Data Subject; Data Principal; Data Controller; Data Fiduciary; Lawful Processing; Privacy by Design; Accountability; Digital Governance; Cross-Border Data Transfers; Data Protection Compliance; Information Privacy; Comparative Data Protection Law; Personal Data; Privacy Rights; Digital Economy; Regulatory Compliance.
Parameter GDPR (European Union) DPDP Act, 2023 (India) Objective Protect the fundamental rights and freedoms of individuals concerning personal data processing. Protect digital personal data while supporting lawful processing and India’s digital economy. Territorial Scope Applies within the EU and extraterritorially to organizations processing EU residents’ data. Applies to digital personal data processed in India and to entities outside India offering goods or services to individuals in India. Key Individual Data Subject Data Principal Organization Processing Data Data Controller Data Fiduciary Person Processing on Behalf of Controller/Fiduciary Data Processor Data Processor Definition of Consent Freely given, specific, informed, and unambiguous indication of wishes through a clear affirmative action. Free, specific, informed, unconditional, unambiguous, and expressed through a clear affirmative action. Withdrawal of Consent Can be withdrawn at any time, and withdrawal must be as easy as giving consent. Data Principal may withdraw consent at any time through accessible means. Lawful Bases for Processing Six lawful bases including consent, contract, legal obligation, vital interests, public task, and legitimate interests. Primarily consent and specified “legitimate uses” recognized under the Act. Transparency Requirements Detailed privacy notices explaining purpose, legal basis, retention, and individual rights. Notice must clearly describe personal data collected, purpose, rights, and grievance mechanism. Rights of Individuals Access, rectification, erasure, restriction, portability, objection, and protection against automated decision-making. Access information, correction, erasure, grievance redressal, nominate another person, and withdraw consent. Children’s Data Special protections for children; parental consent generally required under prescribed age limits. Verifiable parental consent required for processing children’s personal data; additional restrictions apply. Data Protection Officer (DPO) Mandatory in specified situations such as public authorities or large-scale monitoring. Significant Data Fiduciaries may be required to appoint a Data Protection Officer. Accountability Strong documentation obligations, Records of Processing Activities (RoPA), DPIAs, and Privacy by Design. Accountability obligations primarily apply to Significant Data Fiduciaries, with compliance measures prescribed by the Act. Cross-Border Transfers Permitted only where adequate safeguards or adequacy decisions exist. Transfers allowed except to countries specifically restricted by the Central Government. Breach Notification Supervisory Authority generally within 72 hours; individuals informed when high risk exists. Data breaches must be reported to the Data Protection Board and affected Data Principals as prescribed. Regulatory Authority Independent Supervisory Authorities and the European Data Protection Board (EDPB). Data Protection Board of India. Maximum Penalties Up to €20 million or 4% of global annual turnover, whichever is higher. Monetary penalties can extend up to ₹250 crore for certain violations under the Act. Regulatory Philosophy Rights-based, comprehensive, and principle-driven privacy regulation. Privacy protection balanced with ease of doing business and digital innovation. Critical Analysis
The enactment of the General Data Protection Regulation (GDPR) by the European Union and India’s Digital Personal Data Protection Act, 2023 (DPDP Act) reflects a common recognition that personal data is not merely an economic resource but an extension of individual autonomy, dignity, and identity. Although both legal frameworks seek to empower individuals by placing consent at the centre of data processing, they are shaped by distinct legal philosophies, policy objectives, and socio-economic realities. A comparative assessment reveals that while the two laws share foundational privacy principles, they differ considerably in their approach to implementation, regulatory oversight, and the balance between individual rights and economic development.
The GDPR adopts a rights-centric approach, treating privacy as a fundamental human right embedded within the constitutional framework of the European Union. Consent under the GDPR is intentionally demanding—it must be freely given, specific, informed, and unambiguous, ensuring that individuals make meaningful and conscious choices about the use of their personal information. Beyond consent, the GDPR also grants a comprehensive set of enforceable rights, including the right to data portability, the right to object to processing, and the right not to be subjected solely to automated decision-making. These provisions demonstrate that the GDPR does not view privacy merely as regulatory compliance; rather, it recognizes privacy as essential to personal freedom, democratic participation, and human dignity.
India’s DPDP Act, 2023, while inspired by global privacy standards, reflects a different legislative philosophy. The Act emerged in response to India’s rapidly expanding digital economy, increasing internet penetration, and the constitutional recognition of privacy as a fundamental right in Justice K.S. Puttaswamy v. Union of India. Instead of replicating the GDPR, the legislature designed a framework that seeks to protect personal data while simultaneously encouraging innovation, digital governance, and economic growth. Consequently, the Act adopts a comparatively pragmatic and business-oriented approach. Its reliance on consent, coupled with the concept of “legitimate uses,” attempts to reduce unnecessary compliance burdens without abandoning core privacy protections.
Despite these similarities, the effectiveness of consent under both frameworks depends not only on legal wording but also on user behaviour. In reality, many individuals routinely click “Accept” on lengthy privacy notices without reading or understanding their contents. This phenomenon, often referred to as “consent fatigue,” raises an important question: can consent truly be regarded as informed when users lack the time, technical knowledge, or practical ability to evaluate complex privacy policies? This challenge is common to both jurisdictions and demonstrates that legal compliance alone cannot guarantee meaningful privacy protection. Genuine transparency requires organizations to communicate with users in simple, accessible, and understandable language rather than relying on lengthy legal disclaimers.
Another significant distinction lies in regulatory maturity. The GDPR has benefited from several years of judicial interpretation, regulatory guidance, and enforcement by independent supervisory authorities. Landmark decisions have clarified complex issues relating to consent, cross-border data transfers, and platform accountability, creating a relatively predictable compliance environment. By contrast, India’s DPDP Act is still in its formative stage. Many practical aspects of implementation—including subordinate rules, enforcement practices, and regulatory interpretation—continue to evolve. Consequently, businesses operating in India may initially face uncertainty regarding compliance expectations until the regulatory framework matures through guidance and precedent.
The treatment of cross-border data transfers further illustrates the different policy priorities of the two regimes. The GDPR establishes stringent safeguards before personal data may leave the European Economic Area, reflecting the European Union’s commitment to maintaining equivalent privacy protections irrespective of geographical location. India’s DPDP Act adopts a comparatively flexible mechanism by permitting international transfers except to jurisdictions specifically restricted by the Central Government. While this flexibility may facilitate international commerce and digital innovation, it also places greater responsibility on policymakers to ensure that commercial efficiency does not compromise the protection of individuals’ personal information.
From a corporate perspective, the GDPR often demands significant investment in governance structures, documentation, impact assessments, employee training, and ongoing compliance monitoring. These obligations may appear burdensome, particularly for small and medium-sized enterprises, yet they also foster organizational accountability and strengthen consumer confidence. The DPDP Act attempts to strike a more balanced approach by imposing enhanced obligations primarily on Significant Data Fiduciaries, thereby reducing regulatory burdens for smaller organizations. Nevertheless, as India’s digital ecosystem becomes increasingly interconnected and data-driven, businesses may voluntarily adopt GDPR-level standards to satisfy global clients, enhance consumer trust, and remain competitive in international markets.
Ultimately, the comparison demonstrates that neither framework should be viewed as inherently superior; instead, each reflects the unique constitutional values, governance priorities, and economic realities of its jurisdiction. The GDPR represents a mature, rights-oriented model that prioritizes comprehensive individual protection, whereas the DPDP Act represents India’s evolving attempt to reconcile privacy rights with technological innovation and digital inclusion. As artificial intelligence, cross-border cloud computing, biometric technologies, and algorithmic decision-making continue to reshape the digital landscape, both regulatory frameworks will inevitably require continuous adaptation.
In the long term, the true measure of an effective privacy law will not be the number of statutory provisions it contains or the severity of its penalties. Rather, its success will depend on whether individuals genuinely understand how their personal information is collected and used, whether organizations embrace privacy as an ethical responsibility rather than a legal obligation, and whether governments create a regulatory environment that promotes both innovation and respect for fundamental rights. In this sense, data privacy is not merely a legal requirement—it is a cornerstone of digital trust in an increasingly interconnected world.
Conclusion
The digital economy has fundamentally transformed the way personal information is created, shared, and monetised, making effective data protection laws indispensable for preserving individual autonomy and public trust. This comparative analysis demonstrates that both the European Union’s General Data Protection Regulation (GDPR) and India’s Digital Personal Data Protection Act, 2023 (DPDP Act) recognise consent as a central pillar of lawful data processing. However, their approaches reflect different constitutional values, regulatory priorities, and socio-economic contexts.
The GDPR represents a mature and comprehensive privacy framework that places fundamental rights at the forefront of digital governance. Its detailed provisions on consent, accountability, transparency, and data subject rights establish a high standard for organisations processing personal data across jurisdictions. India’s DPDP Act, while comparatively recent, marks a significant milestone in the country’s privacy landscape. By introducing a dedicated statutory framework for digital personal data, the Act strengthens individual control over personal information while acknowledging the practical realities of India’s rapidly expanding digital ecosystem.
Despite these legislative advancements, the effectiveness of either framework ultimately depends upon implementation rather than statutory language alone. Privacy notices remain lengthy and difficult to understand, consent mechanisms often encourage routine acceptance rather than informed choice, and technological innovations such as artificial intelligence, biometric surveillance, and cross-border cloud computing continue to challenge traditional regulatory models. Consequently, meaningful privacy protection requires organisations to move beyond formal compliance and embrace privacy as an ethical responsibility embedded within organisational culture.
For businesses operating internationally, the convergence of global privacy principles presents both a challenge and an opportunity. Organisations that adopt transparent governance practices, minimise unnecessary data collection, strengthen cybersecurity measures, and prioritise user trust will not only achieve regulatory compliance but also establish sustainable competitive advantages in an increasingly data-driven economy.
As India continues to refine its data protection framework through subordinate legislation and regulatory guidance, greater harmonisation with international best practices may further strengthen legal certainty and cross-border digital cooperation. At the same time, policymakers must ensure that innovation and economic growth do not come at the expense of individual dignity and informational self-determination.
Ultimately, privacy is far more than a compliance obligation or a contractual formality. It represents an essential condition for individual freedom, democratic participation, and digital trust. The future of data governance will therefore depend not only upon stronger legislation but also upon responsible institutions, informed citizens, and organisations committed to respecting personal data as an extension of the individual rather than merely another commercial asset.
References
-
General Data Protection Regulation (GDPR), Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.
-
Digital Personal Data Protection Act, 2023.
-
Justice K.S. Puttaswamy (Retd.) v. Union of India.
-
Ministry of Electronics and Information Technology, Digital Personal Data Protection Act, 2023.
-
European Data Protection Board, Guidelines 05/2020 on Consent under Regulation 2016/679.
-
European Commission, Data Protection Rules for the EU Institutions.
-
Information Commissioner’s Office, Guide to the UK GDPR.
-
International Association of Privacy Professionals, India’s Digital Personal Data Protection Act Resource Centre.
-
Organisation for Economic Co-operation and Development, OECD Privacy Guidelines (2013).
-
United Nations Conference on Trade and Development, Data Protection and Privacy Legislation Worldwide.
-
World Economic Forum, Global Risks Report (latest edition).
-
Deloitte, India’s Digital Personal Data Protection Act: A Business Perspective.
-
PwC, Understanding India’s DPDP Act.
-
EY, Digital Personal Data Protection Act – Implications for Businesses.
-
KPMG, Data Privacy and the DPDP Act.
-
Cyril Amarchand Mangaldas, Analysis of the Digital Personal Data Protection Act, 2023.
-
Khaitan & Co, DPDP Act: Key Compliance Considerations.
-
Trilegal, India’s New Data Protection Regime.
-
Shardul Amarchand Mangaldas & Co, Digital Personal Data Protection Act – Legal Analysis.
-
Schrems II.
-
Google Spain SL v AEPD.
-
Fashion ID GmbH & Co KG v Verbraucherzentrale NRW.
-
Harvard Law Review, articles on privacy and data protection.
-
SSRN, scholarly papers on comparative data protection law.
-
HeinOnline, journal articles on GDPR and Indian data protection law.