As India digitizes banking, healthcare, education, government services, shopping, travel, and everyday communication, it collects and processes enormous amounts of personal information.
A citizen may have provided their identity, address, phone number, financial information, or other personal data to dozens—or hundreds—of organizations over many years.
But most people cannot easily answer basic questions:
Who has my data?
What information do they have?
Why are they using it?
Who have they shared it with?
How long will they keep it?
What did I consent to?
How do I withdraw that consent?
Without this visibility, “consent” can become little more than clicking I Agree on a lengthy notice.
India’s Digital Personal Data Protection Act establishes rights and obligations around processing digital personal data, while the 2025 Rules require consent notices to explain the personal data collected and the purposes for which it will be used. The framework also provides for registered Consent Managers through which individuals can give, manage, review, and withdraw consent.
The opportunity is to turn these principles into a simple citizen-facing system of control.

Leave a Reply