Guardianship And Digital Personnel Data Protection Act, 2023: Why India’s DPDP Act Undermines The Rights Of Disabled Individuals

The DPDP Act,2023 was enacted and is set to get implemented across three phases in India after years of debate surrounding privacy and individual autonomy. Section 9 of the DPDP Act,2023 read along with Rule 11 of the corresponding DPDP Rules, 2025 mandates guardian consent for processing data of persons with disabilities (PwDs) who have a legal guardian. These particular provisions of the DPDP Act, 2023 and the DPDP Rules, 2025 has drawn sharp criticism from disability rights groups as they are being treated much like children and are being subjected to the same process for obtaining consent for processing of their data. Critics argue that PwDs cannot be treated alike children as the process regarding guardian consent undermines the autonomy granted to the PwDs under India’s own legal mechanism and international obligations. A joint report prepared by Chitta Initiative and Saksham Disability focuses on the principle of a supported decision making rather than granting an absolute guardian consent. The PwDs must themselves act as the primary decision maker with the guardians acting as a support.

This blog intends to raise two key issues: Firstly, the DPDP Act, 2023 presumes that each and every PwD having a guardian lacks the capacity to make their own independent decision. Disability is a wide term as many PwDs can make their own independent decisions despite having sensory, physical or cognitive disabilities. This approach to classify all PwDs under the same “umbrella” raises stereotypical notions and further clashes with the Right of Persons with Disabilities Act, 2016 (RPwD Act) and the UN Convention on the Rights of Persons with Disabilities (UNCRPD) both of which focuses on equality and autonomy for PwDs. Secondly, the mechanism of substituted consent can lead to conflict with the actual decision which a PwD would wish. The legal guardian can have their own interests and agendas and moreover India’s legal mechanism provides limited regulation of guardian’s action in the digital realm. The RPwD Act provides for limited guardianship only where required and emphasizes on mutual decision-making. DPDP Framework lacks the safeguards and offers no standards for guardianship consent and raises concerns about potential compromised autonomy.

Section 9(1) of the DPDP Act, 2023 and Rule 11 of DPDP Rules, 2025 creates a conflict with the autonomy focused model of the RPwD Act and the UNCRPD. PwDs are heterogeneous with differing capabilities, providing a blanket guardian consent rule undermines their privacy rights. Substituted consent creates the potential for abuse. This blog puts forward the notion that DPDP provisions should be reformed to align with the contemporary disability rights framework.

Conflict with the Rights of Persons with Disabilities Act, 2016 and commitment under UN Convention on the Rights of Persons with Disabilities

India’s RPwD Act, 2016 and their international commitment under UNCRPD grants the rights to PwD to enjoy independent legal capacity and autonomy. RPwD Act,2016 grants limited guardianship under Section 14 only where necessary. Section 14 of the RPwD Act, 2016 emphasizes how a PwD requiring support plays the role of a central decision maker in choices affecting their lives. However, in contrast to Section 14 of the RPwD Act, 2016 the DPDP Act, 2023 has an absolute rule that whenever a PwD having a legal guardian undergoes any activity requiring data consent or processing requires verifiable consent from their legal guardian. This equal treatment of PwDs ignores the capacity which they possess to make their own independent decision. Section 9(1) of the DPDP Act, 2023 and the DPDP Rules, 2025 treat persons with disabilities and children alike. Grouping of PwDs with children undermines the agency of PwDs and assumes that PwDs are dependents. This perpetuates stereotypes and categorises PwDs as ‘eternal children’ despite them possessing cognitive decision- making abilities. For example: a person with mobility impairment or cognitive disabilities maybe fully able to manage their own digital transactions and decisions concerning personal data. The absolute rule under DPDP Act, 2023 overlooks this wide spectrum of PwD. There cannot be a blanket presumption about any person with disabilities regarding their capacity. Article 12 of UNCRPD affirms legal capacity upon the PwDs on an equal footing with other individuals.

The Saksham Disability Report puts this starkly: the Act “compels persons with disabilities who have a guardian to provide consent through the guardian only,” creating a “denial of autonomy and personhood.” That is the practical cost of the equal-treatment rule discussed above, and it sits uneasily against the RPwD Act, 2016 and the UNCRPD which emphasises on independent decision making.

Whose consent is required?

Beyond the treatment of PwDS which undermines their autonomy is the question of whose consent is actually required to protect the PwDs. Substituted consent is a fraught method to obtain consent, as the guardian’s interests may not align with the PwD’s. The DPDP Act, 2023 has no mechanism to check how a data principal’s guardian actually behaves. It has no way of verifying how close, or how strained, the relationship between a data principal and their legal guardian really is. Left unchecked, a guardian acting in a malicious or neglectful manner could misuse personal data with nothing in place to catch it. The RPwD Act, 2016 provides for safeguards such as appointed guardians must report to the court and can be eliminated from guardianship for reasons such as abuse. These safeguard mechanisms have not been adopted by the DPDP. A recommended solution to counter the problem is ‘dual consent’ which requires not just the approval of the legal guardian but also the informed consent of the data principal who is also a PwD. The rules could mandate that the processing of data by a guardian grants some level of consent from the PwD, this process is similar to how medical trials mandate the requirement of assents from the patient and the guardian. A policy brief from Centre for communication governance at National University Delhi suggests granting joint roles to PwD and their legal guardian. This reflects a mutual decision making with the PwD having the capacity of a primary decision maker with support from their legal guardian. The policy brief also suggests empowering the Data Protection Board to revoke the guardian’s consent giving capacity if they find any evidence concerning abuse or undue influence. Similar to the power of courts under the RPwD Act, 2016 which authorises the court to remove guardians who abuse their power, the DPDP Framework must regulate the activities of the guardian.

Operationalising dual consent within India’s existing digital consent architecture is more feasible than it may first appear. The DPDP Rules, 2025 already require Data Fiduciaries to route consent through a Consent Manager registered with the Data Protection Board, and to log consent as a distinct, auditable record rather than a one-time checkbox. A dual consent requirement could be layered onto this same architecture. The Consent Manager interface used to capture the guardian’s consent could carry a parallel prompt directed at the PwD’s own registered account, generating a separate, time-stamped consent record wherever the PwD has a means of responding, whether through text, audio, or assistive technology. Where a PwD genuinely cannot engage with such a prompt, the guardian’s consent alone would suffice, but the burden of establishing that incapacity should sit with the guardian and the Data Fiduciary rather than being presumed by the statute itself. This shifts the default from blanket incapacity to case-by-case verification, in much the same way banks already run a parallel OTP-based confirmation for high-value transactions instead of relying on a single authorising signature. The Data Protection Board would need express rule-making power to prescribe the form of this parallel consent and to audit Data Fiduciaries who bypass it, much as it already oversees Consent Managers under the current Rules. None of this demands new institutional infrastructure. It simply requires the DPDP Rules to extend the consent-logging obligations that already exist for ordinary data principals to the PwD half of a guardian-mediated transaction.

The substituted consent mechanism of DPDP Framework created hurdles for an individual without a legal guardian. For a PwD without a legally appointed guardian, the act skips Section 9 which creates a potential gap. Digital platforms might collect disability status even when there is no requirement to do so. PwDs with legal guardians have guardianship for specific functions and not for an absolute control over all their decisions. The Saksham Report observes that assuming that all PwDs lack capacity to make their own independent decision is conflicting with the legal reality of guardianship which exists to provide partial support whilst majority of the decisions are independent taken by the PwD.

Comparison with International Jurisprudence

Comparative data protection framework demonstrates that recognising disability as requiring higher level of protection does not necessarily justify the removal of decision- making autonomy of PwDs. Rather than equating disability with incapacity, the contemporary legal frameworks distinguish between the need for stricter safeguards and the denial of legal capacity. This distinction is important to understand the limitations of India’s DPDP Framework.

The European Union’s General Data Protection Regulation (GDPR) classifies data concerning health as ‘special category of personal data’ under Article 9, thereby demanding a higher threshold for lawful processing of data which requires explicit consent. However, the GDPR does not create a separate consent model which eliminates the decision-making abilities of an adult having any form of disability with that of a guardian simply because a legal guardian exists. GDPR proceeds on the presumption that adults have legal capacity, thereby protecting sensitive data while also ensuring the autonomy is not undermined.

A similar rights-based approach can also be observed in the UN Convention on the Rights of Persons with Disabilities. Article 12 recognised that individuals having disabilities possess legal capacity to make their own individual decisions. UNCRPD has focused on a supported decision- making model rather than a substituted decision -making model. India’s ratification of this convention and the enactment of RPwD, 2016 reflect this transition, particularly under Section 14 of RPwD, 2016 the concept of limited guardianship is enshrined. The PwD continues to remain the primary decision-maker with support being provided only wherever necessary.

The objective of the DPDP Act, 2023 is to strengthen the protection of personal data in a society which is rapidly digitalising. However, the contemporary framework under Section 9 of the Act and Rule 11 shows how privacy cannot be protected by sacrificing autonomy. The law presumes that every person with a disability lacks the capacity to make their own decision, the Act fails to consider the diverse nature of disabilities and ignores the supported decision-making model present in the RPwD Act, 2016 and Article 12 of the UNCRPD. Simultaneously granting absolute authority to the guardians without provision of any safeguards creates a potential risk of guardian acting in their own interest rather than those individuals whose privacy the law aims to protect. A data protection framework must empower disabled individuals to be the holder of their rights rather than acting as passive beneficiaries. DPDP Framework must be reconsidered by eliminating the absolute guardian consent model or by replacing it with a ‘dual’ consent model which grants the recognition to the PwD as the primary decision maker of their own personal data. Only doing so will ensure that Indias data protection regime protects both informational privacy and autonomy of persons with disabilities.

(This post has been authored by Siddhanth Vinod and Vignesh Menon, 4thYear students at BITS LAW SCHOOL, Mumbai.) 

CITE AS: Siddhanth Vinod and Vignesh Menon, ‘Guardianship And Digital Personnel Data Protection Act, 2023: Why India’s DPDP Act Undermines The Rights Of Disabled Individuals’ (The Contemporary Law Forum, 21 August 2026) <https://tclf.in/2026/08/21/guardianship-and-digital-personnel-data-protection-act-2023-why-indias-dpdp-act-undermines-the-rights-of-disabled-individuals/> date of access.

Leave a Comment

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.