India proposes new data protection bill requiring companies to garner consent from citizens before collecting and processing users' personal data
India has proposed groundbreaking new rules that would require companies to garner consent from citizens in the country before collecting and processing their personal data.
Context & Ripple Effects
This December 2019 proposal is the opening move in what became a six-year legislative arc: the original consent-first bill was later pulled by the government in 2022 after criticism from both privacy advocates and tech giants, then redrafted to loosen restrictions on cross-border transfers.
A successor cleared parliament in 2023 with penalties up to $30M and child-wellbeing rules, and India finally notified its first data protection law in November 2025, complete with verifiable consent — making this early proposal the template every subsequent version answered to.
First-order effects
- Companies collecting or processing personal data of Indian citizens must build consent-gathering into their collection flows before any processing occurs, shifting compliance cost onto every platform serving the market.
- Privacy advocates and tech giants, who split over the withdrawn 2019 text, gain a formal seat at the consultation table as the government commits to drafting a new framework around consent.
Second-order effects
- How the consent regime treats data localization determines where global firms host Indian user data — the later drafts' move to permit cross-border transfer with certain countries shows that pressure reshaping the bill's economics.
- Compliance tooling for consent management becomes a procurement line for any company with Indian users, favoring platforms that can absorb verification infrastructure over smaller operators.
Third-order effects
- India converging on an enforceable consent-based framework places it among major markets where lawful data processing requires explicit user permission, raising the baseline for how consumer data products are designed globally.
- The withdraw-and-redraft cycle suggests emerging data regimes will iterate through multiple versions as governments balance privacy advocates against tech industry objections — consent architecture becoming a negotiated standard rather than a fixed rulebook.
The trend: Major economies are institutionalizing consent as the legal precondition for data processing, with India's multi-year draft cycle showing these frameworks harden through repeated revision rather than arriving whole.