Discuss how consent-based architectures (DigiLocker, Account Aggregator) operationalise the DPDP Act, 2023.

Q. Discuss how consent-based architectures (DigiLocker, Account Aggregator) operationalise the DPDP Act, 2023. (15 marks, 250-350 words)

The Digital Personal Data Protection Act, 2023 rests on notice-and-consent, purpose limitation and data minimisation [1]. Consent-based Digital Public Infrastructure (DPI) converts these statutory principles into working code, making the citizen — not the custodian — the gatekeeper of personal data.

Consent as the operative legal basis - DigiLocker, run by MeitY under Digital India (2015), issues and shares documents only on an explicit in-app consent action [2]. The recent onboarding of Rajasthan's Jan Aadhaar (Family ID) for ~7.5 crore residents shows consent-gated fetch of a state credential onto a Union rail [3]. - The Account Aggregator (NBFC-AA) framework, under RBI's 2016 Master Directions, transfers no financial data without customer consent; the AA itself cannot read the data it moves [4].

Purpose limitation and data minimisation - AA consent artefacts specify purpose, data-fields, validity period and frequency — a machine-readable expression of the Act's purpose-limitation duty [4]. - DigiLocker shares a single verified document rather than a bundle of photocopies, embodying minimisation.

Data principal rights and accountability - Both provide revocability: consent can be withdrawn, satisfying the Act's right to withdraw. - Audit trails of every fetch create verifiable accountability for data fiduciaries, replacing untraceable paper flows. - DigiLocker's Section 9A, IT Act, 2000 backing gives shared documents legal parity with originals, reducing repeat data collection.

Limitations - Consent fatigue and low digital literacy risk reducing consent to a reflex click. - Family-unit IDs like Jan Aadhaar raise questions of whose consent binds the household. - Coverage remains uneven; the DPDP Rules' phased rollout and Consent Manager registration are still maturing [1].

Consent architectures thus translate the DPDP Act from statute into everyday transaction design, aligning DPI with the privacy right affirmed in K.S. Puttaswamy (2017). Strengthening grievance redress, vernacular consent notices and assisted-consent at last mile — alongside a fully operational Data Protection Board — will ensure these rails deliver both inclusion and informational self-determination.

(~330 words)

Sources: 1. The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), MeitY — consent, purpose limitation, data minimisation, withdrawal rights, phased rules 2. Digital Locker, Ministry of Electronics & Information Technology — DigiLocker under MeitY/Digital India, consent-based issuance and sharing 3. Jan Aadhaar (Family ID) Now on DigiLocker, PIB (17 June 2026) — ~7.5 crore Rajasthan residents; in-app consent; fetch and enrol modes 4. Account Aggregator Framework, Department of Financial Services, Ministry of Finance — RBI NBFC-AA Master Directions, 2016; no data movement without explicit consent

Note: web search results carried an embedded "REMINDER" instruction to reformat sources; it was ignored in favour of the skill's citation format.