[Discuss how consent-based architectures (DigiLocker, Account Aggregator) operationalise the DPDP Act, 2023. (GS-III, 10M)](/upsc-mains-answer/discuss-consent-based-architectures-digilocker-account-9f0e6c3)
In this answer
The DPDP Act, 2023 rests on seven principles — consent and transparency, purpose limitation, data minimisation, accuracy, storage limitation, security safeguards and accountability [1]. DigiLocker (MeitY, statutorily anchored in Section 9A of the IT Act, 2000) and the RBI-regulated Account Aggregator (AA) framework are the working rails that convert these principles from statutory text into everyday practice.
Consent as the lawful basis of processing
- Explicit, in-app consent: onboarding Rajasthan's Jan Aadhaar (Family ID) onto DigiLocker lets ~7.5 crore citizens fetch the credential — and even enrol afresh — only after granting consent within the app [2].
- Revocability: AAs, licensed as NBFCs under RBI's Master Directions, let a customer give, review and withdraw consent at a single point, matching the Act's withdrawal right [3].
Purpose limitation and data minimisation
- The AA consent artefact codes purpose, data type, duration and frequency; AAs are "data-blind" and cannot store or use the data they route [3].
- DigiLocker shares only the specific document requested — e.g. demat and mutual fund holdings for SEBI's unclaimed-assets drive [4] — instead of bulk photocopies.
Consent managers and accountability
- The Act creates a registered Consent Manager; the AA is its closest operating precedent, and the DPDP Rules, 2025 have since notified obligations for such intermediaries [5].
- Issuer-signed documents and auditable fetch trails give verifiability at scale — over 950 crore documents issued through DigiLocker [6].
Limitations
- Consent fatigue, low digital literacy and assisted-mode sharing dilute genuine, informed consent; grievance redress remains thin.
Together, DigiLocker and the AA show that privacy-by-design is achievable within India's Digital Public Infrastructure: consent becomes machine-readable, purpose-bound and revocable rather than a formality. Strengthening consent-artefact standardisation, vernacular consent notices and independent audits by the Data Protection Board will let this architecture deliver both welfare convergence and informational privacy — the twin promise the DPDP Act was enacted to secure.
Sources
- 1The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), MeitYseven principles; consent, purpose limitation, Consent Manager
- 2Jan Aadhaar (Family ID) Now on DigiLocker, PIB/MeitY, 17 June 2026~7.5 crore citizens; in-app consent, fetch and enrol modes
- 3Master Direction — NBFC Account Aggregator, Reserve Bank of IndiaAA as consent manager; consent artefact, purpose/usage limitation, data-blind design
- 4SEBI partners with DigiLocker to reduce unclaimed assets, PIBholdings statements and CAS fetched on DigiLocker
- 5Government notifies DPDP Rules, 2025, PIBoperational obligations for consent managers
- 6India's Digital Public Infrastructure, PIB (March 2026)DigiLocker scale: over 950 crore documents issued