The promulgation of the Digital Personal Data Protection Act (DPDP Act), 2023, represents a seismic shift in India’s regulatory landscape, transitioning from a fragmented, sector-specific data protection approach to a comprehensive, principles-based framework. Central to this new architecture is the Consent Manager, a regulatory intermediary specifically designed to alleviate the power asymmetry between Data Principals and Data Fiduciaries. Under Section 2(g) of the Act, the Consent Manager is defined as a registered entity that serves as a single point of contact, enabling individuals to give, manage, review, and withdraw consent through an accessible, transparent, and interoperable platform. Crucially, the legislation and the accompanying Draft Digital Personal Data Protection Rules, 2025, impose a fiduciary capacity upon these managers, requiring them to always act in the best interest of the Data Principal. This paper provides an exhaustive analysis of the dual liability regimes governing Consent Managers: the rigorous statutory duties prescribed by the Act and its associated Rules, and the traditional common law principles of tortious negligence. By deconstructing the landmark judgments, the research delineates the precise contours of fiduciary relationships in Indian jurisprudence and applies these to the burgeoning digital ecosystem. Furthermore, Section 39 of the DPDP Act 2023 bars the jurisdiction of civil courts in matters where the Data Protection Board is empowered, potentially limiting traditional tortious remedies. Through a comparative lens, the paper examines the European Union’s Data Intermediation Services under the Data Governance Act and the United Kingdom’s Data Trusts, arguing that the Indian model prioritizes state-led deterrence over individual restitution.
RAHUL YADAV (Wed,) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: