[Discuss how consent-based architectures (DigiLocker, Account Aggregator) operationalise the DPDP Act, 2023. (GS-III, 10M)](/upsc-mains-answer/discuss-consent-based-architectures-digilocker-account-9f0e6c3)

Q. Discuss how consent-based architectures (DigiLocker, Account Aggregator) operationalise the DPDP Act, 2023. (15 marks, 250-350 words)

The DPDP Act, 2023 rests on seven principles — consent and transparency, purpose limitation, data minimisation, accuracy, storage limitation, security safeguards and accountability [1]. DigiLocker (MeitY, statutorily anchored in Section 9A of the IT Act, 2000) and the RBI-regulated Account Aggregator (AA) framework are the working rails that convert these principles from statutory text into everyday practice.

Consent as the lawful basis of processing - Explicit, in-app consent: onboarding Rajasthan's Jan Aadhaar (Family ID) onto DigiLocker lets ~7.5 crore citizens fetch the credential — and even enrol afresh — only after granting consent within the app [2]. - Revocability: AAs, licensed as NBFCs under RBI's Master Directions, let a customer give, review and withdraw consent at a single point, matching the Act's withdrawal right [3].

Purpose limitation and data minimisation - The AA consent artefact codes purpose, data type, duration and frequency; AAs are "data-blind" and cannot store or use the data they route [3]. - DigiLocker shares only the specific document requested — e.g. demat and mutual fund holdings for SEBI's unclaimed-assets drive [4] — instead of bulk photocopies.

Consent managers and accountability - The Act creates a registered Consent Manager; the AA is its closest operating precedent, and the DPDP Rules, 2025 have since notified obligations for such intermediaries [5]. - Issuer-signed documents and auditable fetch trails give verifiability at scale — over 950 crore documents issued through DigiLocker [6].

Limitations - Consent fatigue, low digital literacy and assisted-mode sharing dilute genuine, informed consent; grievance redress remains thin.

Together, DigiLocker and the AA show that privacy-by-design is achievable within India's Digital Public Infrastructure: consent becomes machine-readable, purpose-bound and revocable rather than a formality. Strengthening consent-artefact standardisation, vernacular consent notices and independent audits by the Data Protection Board will let this architecture deliver both welfare convergence and informational privacy — the twin promise the DPDP Act was enacted to secure.

(~320 words)

Sources: 1. The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), MeitY — seven principles; consent, purpose limitation, Consent Manager 2. Jan Aadhaar (Family ID) Now on DigiLocker, PIB/MeitY, 17 June 2026 — ~7.5 crore citizens; in-app consent, fetch and enrol modes 3. Master Direction — NBFC Account Aggregator, Reserve Bank of India — AA as consent manager; consent artefact, purpose/usage limitation, data-blind design 4. SEBI partners with DigiLocker to reduce unclaimed assets, PIB — holdings statements and CAS fetched on DigiLocker 5. Government notifies DPDP Rules, 2025, PIB — operational obligations for consent managers 6. India's Digital Public Infrastructure, PIB (March 2026) — DigiLocker scale: over 950 crore documents issued