Consent Governance: What does this mean for the organisation?
The DPDP Bill, 2022, officially became the Digital Personal Data Protection Act after receiving the President's assent on August 11, 2023. This marked a watershed moment in India’s privacy and consumer protection landscape.
As data fiduciaries grapple with trying to comprehend their obligations under the Act and take measures both quick and long-term to avoid penalties, there emerges a need for an enterprise-wide digital transformation.
The pathway to DPDP Act compliance, although complex, provides organizations the opportunity to re-imagine their customer touch points and assess their personal data collection and processing methods. This serves as a means not only to become compliant but also to build user trust and confidence in the brand.
Navigating the Complexity: The Plumbing Problem
Complying with the Act is generally misunderstood.
Organizations may feel that making minor tweaks to their UI screens will suffice, but that is just a surface-level problem. On digging a little deeper, what appears is a complex web of M:N relationships between data fiduciaries and data processors, sitting behind even the simplest of customer interactions.
In the diagram below, we understand this complexity with respect to a popular product offering: a co-branded credit card onboarding experience.
<insert diagram>
As we track the ‘personal data’ being collected and processed across the value chain of data fiduciaries and processors, the problem of managing a user’s consent becomes real.
Rethinking Compliance: Beyond the Checkbox ✅
It is critical for enterprises to think beyond minor UI tweaks and explore how the concept of “Consent Governance” could aid in Act compliance.
In simple words, Consent Governance is the management of user consent across the consent lifecycle, which can be broken down into 4 key themes:
Key Components of Consent Governance:
Challenges Foreseen:
The path to compliance shall involve alignment between multiple stakeholders, including Legal and Compliance, Enterprise Risk, Business, Product and Technology. It would involve orchestrating change management and re-imaging not just customer interactions but also current ways of treating and managing personal data.
Role of Leadership
As DPOs for enterprises who may also qualify as “significant data fiduciaries”, it would be prudent to -
Consent Governance serves as a guiding light for enterprises navigating the compliance landscape. DPOs play a crucial role in ensuring the correct and rigorous illumination of this pathway.