Nitin Pradhan is a fourth year student and Ishwar Kanwar is a second year at Army Law College, Pune.
Introduction – The Friction in a Frictionless System
One of the most dynamically developing spheres in India UPI (Unified Payments Interface) is now a part of our life. Auto payment saves us time and makes full automation of the paying process in our life. We can make money transfer with just one touch and move it across accounts. Consider only for the same payments, we would have to confirm each and every time should the UPI applications have to ask our consent each and every time.
The Digital Personal Data Protection Act 2023 (DPDPA) is aimed at safeguarding the Data Principal the consumer whose personal data is processed against the Data Fiduciary the legal party (e.g. banks or payment apps) that processes such data and protects it, by creating stringent consent requirements to all transactions. This is appropriate in safeguarding their data. Nevertheless, it also possesses several disadvantages, which will make the smooth transactions of UPI slower, making the user experience subpar in case customers are forced to consent to all payments. It is simple to pay through a simple tap today. However, with these high specifications, the users would have to click on every deal. The question is now with fast or privacy. Fast transaction, which UPI has mastered, permits us to conduct transactions without any fuss. The entire intention of the DPDP Act 2023 lies in the security of the data. Speed can mean that privacy is compromised; alternatively, privacy can mean that transactions occur more slowly. It is more than a technical problem; it is a question of balance between policy and efficiency on one hand and fundamental rights on the other.
In August 2025, a group of payment service providers led by the NPCI (National Payments Corporation of India) including other major payment services providers like Google Pay, PhonePe, and Amazon Pay officially surrendered before the ministry of Electronics and IT (MeitY). They had applied to the DPDP Act 2023, Section 17(5) on operating exemption. They desired this relief to be given them that they would restructure their already existing systems in such a way that they would not suffer interruptions in the continuity of the current payments which they deemed necessary in continuity of the UPI services. They also requested permission for category-level consent instead of transaction-by-transaction consent. Category-level consent is where the user gives consent to the processing of a group of actions, like regular payments, as one-time consent. This is contrary to transaction-by-transaction consent whereby the Data Fiduciary has to request express consent to the processing of data, necessitating the payment of each and every transaction.
The Consent Clause Dilemma
The constitutionalism of privacy as a fundamental right in Puttaswamy (2017), set the stage for India’s Digital Personal Data Protection Act, 2023 (DPDPA). While a landmark, it is heavily consent-centric. This rigidity risks undermining financial inclusion and digital payments concerns highlighted by NPCI, which warns of “friction” in user experience. However, the EU’s GDPR comprises several acceptable bases including contractual necessity, legal obligation, public interest, and most importantly, legitimate interest often utilized in fraud detection, cybersecurity, and service enhancement.
NPCI observed that India’s primary focus on consent might result in difficulties in digital payments and fintech operations. A model based on risks or sectors which restricts lawful grounds other than consent would shift the balance of privacy protection and innovation in the right way
NPCI and Payment Platforms’ Case for Exemption
The DPDP Act 2023, under Section 17(5), the Central Government may, before expiry of five years from the date of commencement of this Act, by notification, declare that any provision of this Act shall not apply to such Data Fiduciary or classes of Data Fiduciaries for such period as may be specified in the notification. Payment companies and the NPCI have asked to be given this relief so they have time to upgrade their systems without disrupting the digital payment system.
The challenge arises from the Act’s strict and rigid consent model. Consent must be free, informed, specific, unconditional, and revocable. Within the payment system, however, data flows across multiple entities, including the app, bank, merchant, and NPCI. It remains vague whether one-time consent can cover the entire chain or if each intermediary requires separate user approval. This ambiguity risks complicating user experience and raising compliance costs.

The consequences could be significant. UPI has built on speed and seamlessness, but may lose efficiency if multiple consents slow down payments. Smaller fintech firms, lacking resources for complex compliance systems, could be pushed out of the market. Recurring payments such as insurance premiums and rents would also face disruption, automatically, as each billing round might require fresh approval. Similarly, for small transactions, ₹10–₹50 purchases like tea or snacks will be mandatory, hence repeated consent could shift users back to cash, undermining India’s digital payment push.
NPCI highlights the need for risk-based exemptions and clear guidelines, ensuring that user protection does not come at the cost of financial inclusion and innovation.
Privacy Advocates’ Concerns
Data privacy is a fundamental right in our country, and preserving this right is a constitutional obligation that ensures personal information remains safeguarded from misuse and undue interference. If an exemption is granted to certain fiduciaries, there is a potential risk that companies could collect information for payments and later sell it to third-party entities for marketing, profiling, or monetizing insights. This would constitute a breach of citizens’ fundamental rights, and in matters of privacy, consent prompts keep users informed about how their data is being used, enabling them to decide how it should be used and, in cases of misuse, to withdraw such access. Sometimes, a minor inconvenience serves as a safeguard, preventing companies from exploiting our data without our knowledge. The likelihood of misuse of users’ data will diminish if such protections remain. However, if exemptions were to reduce consent prompts, data collection could become invisible and unrestrained, potentially leading to misuse without the user’s awareness, and undermining the very intent of data protection laws designed to protect citizens’ data. Two major considerations emerge: whether we prioritise faster, frictionless payments that enhance convenience and stimulate economic activity, or robust privacy safeguards that reinforce data protection and restrain fiduciary overreach. The debate ultimately rests on whether we are willing to sacrifice a measure of convenience to preserve long-term authority over our personal information.
Global Lessons and Possible Middle-Ground Solutions
Countries around the world and even India have been confronted with the same challenge of how to have seamless, fast payments without compromise on privacy. However, they counter with certain provisions according to the GDPR. The European Union allows some processing without consent to be under an established principle of legitimate interest (e.g., fraud prevention), but this must be narrowly identified both in terms of its extent and scale and in terms of its purpose. This will protect against over-collection or misuse of data by companies. In the case of recurring transactions (like subscriptions), the PDPA of Singapore, balances fair use of data under Section 15(3)a to perform under the contract reasonably necessary and under Section 15a to give notice of such usage, which must involve a risk assessment and stated opt-out. This framework minimises repeated approvals and makes online transactions efficient and accountable, simple to withdraw consent, and gives control over its users. , Australia’s version of CPS 234 is an Information Security Prudential Standard that provides the operational resilience and demands the fact that the systems should be secure and reliable. The guideline defining the collection, usage, and disclosure of personal information, including the authorisation of personalised consent requirements on payments, is defined by the Australian Privacy Principles (APPs). Such strategies have assisted the countries in finding a balance between safeguarding information and ensuring the smooth operations of transactions. India would have to exercise such safeguard mechanisms so that the exemptions do not become loopholes. We should only consider exemptions on low-risk recurring payments (e.g., OTT subscriptions), and this should be temporary, with a required review provision. We could save one-time consent that can be revoked anytime by the users immediately, and fiduciaries are to be allowed to collect only the data that is strictly required to carry out the particular transaction. There should be no collection of unnecessary (irrelevant) data.
Weaker firms need to have more time to adapt to changing technologies. There is also the ability to introduce the public transparency dashboards, where people are able to observe the ways and reasons that their data is being utilised. Misused, they must have the possibility of either editing or clearing such data on the platform. There should be measures to spread the exemptions offered to fiduciaries, which should have a timeline to end, after which a formal review should be carried out by the regulators to decide whether it should be continued. At this, it is possible to protect data and have a smooth transaction.
The Stakes and Conclusion
UPI is not simply a means of payment; as a system, it is the backbone of the digital economy in India: more than 18 billion transactions per month are carried out on UPI at negligible expense. It has taken a very short time to become almost a cash replacement and a representation of digital innovation in the country. UPI has also helped people trust the digital economic system through their ease of payment that all people can comfortably use online payment system in India. It is not just in India, but UPI has spread all over the world too, reflecting Indian leadership in digital payments. Such countries as France, and the UAE have implemented the systems based on UPI. UPI shows that it is easy to make online payments as low as sums as 10 rupees or 20 rupees. Yet, when there is a need to obtain a new consent each time to proceed with the payments, it will limit the digital payments in India.
Consequently, a calculated policy adjustment is what the current situation demands, a move that protects privacy while not getting in the way of usability. India should be the first to set up a tiered consent framework that would be the case when small recurring payments and those made through a verified account can be exempted from repeated approvals whereas (high-value) or (sensitive) transactions should ask for explicit consent and verification. These practices should be accompanied by data retention rules bound by time, independent checks, and transparency dashboards made available in real time to ensure accountability.
India can exemplify the world how to embrace the privacy-first digital governance by preferring a structured and flexible model. It shows the world that the technological convenience and data protection are not competitive to each other, and they can coexist in a transparent and trustworthy regulatory system.
