·PIB·15 marks·250–350 words

[Discuss how consent-based architectures (DigiLocker, Account Aggregator) operationalise the DPDP Act, 2023. (GS-III, 10M)](/upsc-mains-answer/discuss-consent-based-architectures-digilocker-account-9f0e6c3)

In this answer
  1. Consent as the lawful basis of processing
  2. Purpose limitation and data minimisation
  3. Consent managers and accountability
  4. Limitations

The DPDP Act, 2023 rests on seven principles — consent and transparency, purpose limitation, data minimisation, accuracy, storage limitation, security safeguards and accountability [1]. DigiLocker (MeitY, statutorily anchored in Section 9A of the IT Act, 2000) and the RBI-regulated Account Aggregator (AA) framework are the working rails that convert these principles from statutory text into everyday practice.

Consent as the lawful basis of processing

  • Explicit, in-app consent: onboarding Rajasthan's Jan Aadhaar (Family ID) onto DigiLocker lets ~7.5 crore citizens fetch the credential — and even enrol afresh — only after granting consent within the app [2].
  • Revocability: AAs, licensed as NBFCs under RBI's Master Directions, let a customer give, review and withdraw consent at a single point, matching the Act's withdrawal right [3].

Purpose limitation and data minimisation

  • The AA consent artefact codes purpose, data type, duration and frequency; AAs are "data-blind" and cannot store or use the data they route [3].
  • DigiLocker shares only the specific document requested — e.g. demat and mutual fund holdings for SEBI's unclaimed-assets drive [4] — instead of bulk photocopies.

Consent managers and accountability

  • The Act creates a registered Consent Manager; the AA is its closest operating precedent, and the DPDP Rules, 2025 have since notified obligations for such intermediaries [5].
  • Issuer-signed documents and auditable fetch trails give verifiability at scale — over 950 crore documents issued through DigiLocker [6].

Limitations

  • Consent fatigue, low digital literacy and assisted-mode sharing dilute genuine, informed consent; grievance redress remains thin.

Together, DigiLocker and the AA show that privacy-by-design is achievable within India's Digital Public Infrastructure: consent becomes machine-readable, purpose-bound and revocable rather than a formality. Strengthening consent-artefact standardisation, vernacular consent notices and independent audits by the Data Protection Board will let this architecture deliver both welfare convergence and informational privacy — the twin promise the DPDP Act was enacted to secure.

Sources

  1. 1The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), MeitYseven principles; consent, purpose limitation, Consent Manager
  2. 2Jan Aadhaar (Family ID) Now on DigiLocker, PIB/MeitY, 17 June 2026~7.5 crore citizens; in-app consent, fetch and enrol modes
  3. 3Master Direction — NBFC Account Aggregator, Reserve Bank of IndiaAA as consent manager; consent artefact, purpose/usage limitation, data-blind design
  4. 4SEBI partners with DigiLocker to reduce unclaimed assets, PIBholdings statements and CAS fetched on DigiLocker
  5. 5Government notifies DPDP Rules, 2025, PIBoperational obligations for consent managers
  6. 6India's Digital Public Infrastructure, PIB (March 2026)DigiLocker scale: over 950 crore documents issued

More from this note