Illusory Consent and Digital Privacy under the DPDP Act, 2023

Abstract

Every day, millions of people install mobile applications for various purposes, such as shopping, food delivery, education, entertainment, and social networking. Before they can use these applications, they are required to accept lengthy privacy policies and terms of service by clicking a button marked “I Agree.” Most users do not read these documents, yet that single click allows companies to collect, store, use, and process large amounts of personal data.

At first glance, this may seem like a voluntary choice because the user has given consent. However, it raises an important question: Is consent truly voluntary when refusing to accept the terms means the application cannot be used at all? Can users negotiate the terms, refuse unnecessary permissions, or choose how much personal data they want to share? In most cases, the answer is no.

This situation gives rise to the concept of illusory consent, where consent appears to be freely given but, in reality, users have very little choice. This article examines how the Digital Personal Data Protection Act, 2023 addresses such “take-it-or-leave-it” terms used by mobile applications and whether it provides meaningful protection to users’ digital privacy rights.

 

What is Illusory Consent?

Illusory consent means a situation where a person appears to have given consent, but in reality does not have a genuine choice. The person technically agrees to the terms, because they don’t have choice to refuse, if they refuse them it mean losing access to the service. As a result, the consent may look voluntary, even though it is given because there is no practical alternative.

For example, suppose you download a food delivery or shopping app. Before you can place your first order, the app asks you to accept its Privacy Policy and Terms of Service. You cannot change these terms or reject only some permissions. If you choose not to click “I Agree,” you cannot use the app at all. This is something that millions of users experience every day. Although users click “I Agree,” they often do so because they have no other option if they want to use the service. This is what is commonly referred to as illusory consent.

 

What are “Take-It-or-Leave-It” Terms?

“Take-it-or-leave-it” terms are conditions that are already prepared by the company. The user cannot change, negotiate, or remove any of these terms. They have only two choices—either accept all the terms and continue using the app or reject them and stop using the service.

For example, when you install a mobile app, it usually asks you to accept its Privacy Policy and Terms & Conditions before you can create an account or use its features. If you do not click “I Agree,” the app will not let you continue. This means the user is not given a real opportunity to choose or discuss the terms.

Such agreements are widely used because they are convenient for companies. However, they place users in a weaker position, as they must accept the company’s conditions even if they are uncomfortable with some of them. This lack of real choice is one of the main reasons why consent on many mobile apps is questioned.

 

The DPDP Act, 2023

Earlier, India did not have a comprehensive data protection law. With the rapid growth of smartphones, online shopping, social media, digital payments, and personal data became extremely valuable. This increased the risk of misuse, making legal protection necessary. This created the need for a law that could protect people’s personal information.

A major step in this direction came with the Supreme Court’s judgment in Justice K.S. Puttaswamy v. Union of India. The Court held that the right to privacy is a fundamental right under Article 21 of the Constitution. It also recognised that people have a right to control their personal information and decide how it is used. This judgment became the foundation for India’s data protection law.

To protect personal data and regulate how it is collected and used, Parliament enacted the Digital Personal Data Protection Act (DPDP), 2023. The Act aims to protect the privacy of individuals while also allowing organisations to process personal data for lawful purposes. It gives certain rights to individuals and places responsibilities on organisations that collect and use personal data.

 

Main Analysis & Case Studies

1.     Justice K.S. Puttaswamy (Retd.) v. Union of India (2017) – In this landmark case, the Supreme Court held that the Right to Privacy is a fundamental right under Article 21 of the Constitution. The Court observed that privacy is closely connected to an individual’s dignity, autonomy, and freedom to make personal choices. It also recognised informational privacy which means that individuals should have control over their personal data. This judgment laid the constitutional foundation for data protection laws like the DPDP Act and supports the idea that consent for processing personal data must be real, informed, and meaningful.

2.     Justice K.S. Puttaswamy v. Union of India(2018) – In this case, the Supreme Court looked at the Aadhaar system and how it was being used. The Court allowed Aadhaar in principle, but it clearly said that people cannot be forced to share their personal or biometric information with private companies just to access services. The Court was concerned that if private companies start making Aadhaar mandatory, then individuals would have no real choice but to give away sensitive personal data in order to use everyday services. This, according to the Court, affects a person’s freedom and control over their own information.

3.     Venkatesh Nayak v. Union of India (W.P. (C) No. 177/2026) – In this case, the petitioner challenged Section 17 of the DPDP Act, arguing that it gives the Government broad powers to process personal data without the user’s consent in certain situations such as National security, public order etc. According to the petitioner, if consent can be bypassed so easily, then a person’s control over their own data becomes only a formality. Therefore, the petition argues that the consent promised by the Act becomes “illusory” rather than meaningful.

4.     The Reporters Collective Trust v. Union of India (W.P.(C) 211/2026) – In this case, the journalists have questioned the impact of the DPDP Act on the Right to Information framework. The concern raised is that the broad restriction on disclosure of “personal data” could, in practice, limit access to information that would otherwise be available under the RTI Act. This has led to apprehensions that public authorities may increasingly rely on privacy protections to deny disclosure of information involving public interest. The matter is currently pending consideration before a larger Bench of the Supreme Court.

 

Critical Analysis and Evaluation

The DPDP Act, 2023 is an important step towards protecting people’s personal data, but it does not completely solve the problem of “take-it-or-leave-it” consent. Even today, many mobile apps require users to accept all terms and permissions before they can use the app. This means users often do not have a real choice.

Although the Act gives users rights like receiving clear information and withdrawing their consent, many people still accept privacy policies without reading or understanding them. This is because the terms are long, complicated, and refusing them usually means they cannot use the service.

Therefore, while the DPDP Act has improved digital privacy protection, stronger rules and simpler consent processes are still needed to make consent truly free and meaningful.

 

Conclusion

The Digital Personal Data Protection Act, 2023 marks a significant step towards strengthening digital privacy and protecting the personal data of individuals in India. By introducing provisions for informed consent, clear notice, withdrawal of consent, and the rights of Data Principals, the Act aims to give users greater control over their personal information. However, the problem of “take-it-or-leave-it” terms used by many mobile applications continues to raise concerns about whether consent is truly free and informed. In many cases, users have no practical choice but to accept the terms if they wish to access the service.

Therefore, while the DPDP Act provides a strong legal framework, its true effectiveness will depend on proper implementation, stricter enforcement, and greater awareness among users about their digital privacy rights. Companies must also adopt transparent and user-friendly privacy practices. Only when users are able to make genuine and informed choices can consent become meaningful rather than merely illusory, ensuring stronger protection of privacy in the digital age.

 

Reference

  1. Constitution of India, 1950.
  2. Digital Personal Data Protection Act, 2023.
  3. Justice K.S. Puttaswamy (Retd.) v. Union of India – (2017) 10 SCC 1 (Right to Privacy declared a Fundamental Right).
  4. K.S. Puttaswamy (Aadhaar-5J.) v. Union of India – (2019) 1 SCC 1 (Aadhaar judgment; proportionality, privacy, and data protection).
  5. Venkatesh Nayak v. Union of India (W.P. (C) No. 177/2026)
  6. The Reporters Collective Trust v. Union of India (W.P.(C) 211/2026)
  7. Information Technology Act, 2000.

 

 

 

 

 

 

 

 

 

Suhani Sharma
Author: Suhani Sharma