
The privacy consent model assumes a person who reads the notice, understands it, and chooses. For the hundreds of millions of people coming online for the first time, that person does not exist.
For two decades, our fix for weak privacy protection in emerging markets has been the same: better notice. Make the consent screen shorter, clearer, translated into the local language, and the user will make an informed choice.
India just wrote that theory into binding law.
The Digital Personal Data Protection Rules, notified in November 2025 with an 18-month phased compliance window, require every company processing personal data to issue a separate consent notice in clear and plain language, available in English or any of the 22 languages in the Constitution’s Eighth Schedule. The Principles for Digital Development say much the same thing in Principle 8. It is a reasonable theory.
A new peer-reviewed study of 50 first-time smartphone users in urban India shows that, for this population, it is mostly beside the point.
The study, “I Just Press Allow”: Understanding Privacy Practices of New Internet Users in Urban India, interviewed 50 early-stage smartphone users across urban and peri-urban India. Their finding, in their own words, is a mismatch between formal privacy controls and the realities of everyday practice.
This matters at scale. India crossed 886 million active internet users in 2024, with rural users now the majority and 98 percent consuming content in Indic languages rather than English. India is not unique.
The GSMA’s Mobile Gender Gap Report 2025 finds the same barriers, affordability, low digital skills, and safety concerns, at their widest across South Asia and sub-Saharan Africa, where roughly 60 percent of the world’s unconnected women live.
The people the consent model fails are the ones powering smartphone growth.
Sign Up Now for more digital privacy insights
Person Who Clicks Is Often Not the User
The first thing the study breaks is the assumption that there is one user, sitting at the device, making a decision. Again and again, the person who installed the app, granted the permissions, and dismissed the prompts was someone else: a son, a nephew, a neighbor, a shopkeeper.
One woman handed her phone to her son whenever a new prompt appeared. He clicked something, handed it back, and she trusted that he had handled it. Another judged an app safe because her nephew said everyone uses it. A third let the shopkeeper who sold her a loan app grant camera and SMS access because he said it was normal.
The authors call this interdependent privacy, and no amount of training fixes it. It is a structural feature of how phones enter a household.
Skills concentrate in the digitally literate relative, usually a younger man, and everyone else delegates. Translating the consent notice into Telugu does nothing for the 56-year-old whose nephew taps Allow before she ever sees the screen.
The consent UI is built for a decision-maker who, in these homes, is not the data subject. This is the same gap Nithya Sambasivan’s team documented across India, Pakistan, and Bangladesh, where women’s phones are routinely shared and surveilled by family.
Seven years later, our consent design still assumes the lone individual.
When Refusal Is Not an Option
The study’s title comes from a construction worker who tried to deny permissions to a ride app. It refused to open. She tried again, gave up, and allowed everything.
Since then, she presses Allow on every app, because otherwise they do not work. She told the researchers she feels like she is not really choosing.
She is correct.
The authors call this compelled consent, and it is the part of the paper that should end the “better notice” conversation.
When denying a permission breaks the app, and the app is how you book transport or send money, refusal is not a choice the interface offers. A clearer notice changes nothing about that. The user already understood the trade. She had no alternative.
This is a sharper version of the digital resignation that privacy scholars have described in Western markets, except here it is compounded by dependency and the fact that the essential service and the data grab are bundled into the same button.
Permission-gating of core functionality, where the app holds itself hostage until you consent, is a coercive design.
Independent research suggests apps routinely ask for more than they need: NordVPN’s analysis of top apps found roughly a fifth of requested permissions were not required for the app to function, with nearly half of apps requesting access tied to activity outside the app itself.
Treat that as directional rather than precise, since it is a vendor study, not peer-reviewed. The point holds: the consent screen is the thinnest possible cover for a demand the user cannot refuse.
DPDP Act Framework
India’s DPDP framework is a genuine advance, built on the Indian constitutional right to privacy the Supreme Court recognized in 2017. Plain-language notices, multilingual access, consent withdrawal links, and a Data Protection Board are all worth having.
But every one of those provisions optimizes for comprehension. The study shows comprehension was not the thing standing between these users and protection.
The binding constraints were two: someone else made the decision, and refusal was not possible. Neither is addressed by a clearer notice in a 22nd language.
If you fix readability and leave delegation and compulsion untouched, you will have built a more legible version of the same trap, and you will be able to say consent was obtained. That is the risk: a compliance regime that measures notice quality and declares victory while the woman handing her phone to her nephew is exactly as exposed as before.
The Threat Model Is Social
We treat privacy as a question of data flows: who collects what, stored how long, shared with whom. The users in this study do not experience it that way.
The harms they named were a ride driver who saved a passenger’s number and called at odd hours, a woman whose photo was lifted from Facebook onto a fake profile, a relative tricked into entering her Aadhaar number into a fake government form.
For women especially, a breach means harassment, blackmail, and reputational damage with physical consequences.
This is why notice-and-consent protects against the wrong threat. The same lesson surfaced when researchers found that Facebook’s privacy concepts did not translate into Khmer for Cambodian users, and it sits at the center of the long-running question of data justice for the next billion users.
A consent model imported from a context where the feared adversary is a corporate data broker will keep missing the adversary these users fear, who is often a stranger, a relative, or a repair technician.
Users Already Build Workarounds.
The most useful finding is that these users are not passive. Denied real controls, they built their own.
- They swap personal photos for flowers and cartoons.
- They post poems and festival greetings instead of selfies.
- They run second accounts to wall off relatives, lock apps behind patterns, hide folders, and clear browser history.
One 19-year-old learned app-locking from a YouTube video. The authors call this pragmatic privacy and tactical agency, and it is real expertise, invisible to the designers who never asked.
That is the design brief, and it is the opposite of where most of our informed consent thinking points. Stop trying to turn these users into the rational individual the consent screen imagines.
Build for the user who is already there: who shares a device, delegates setup, and fears social exposure more than data brokers.
What Informed Consent Demands
MeitY and the Data Protection Board of India should not stop at notice quality.
They should require shared-device and delegation-aware consent, including guest modes, role-based profiles, and re-consent prompts when a device changes hands, and they should treat permission-gating of core functionality as a consent-defeating dark pattern, not a developer’s prerogative.
India’s consent notices can now be served in any of 22 official languages. The woman whose nephew taps Allow before handing the phone back will still never read one.


Solid read. I’d never considered the next billion users will angle in this light, so the walkthrough genuinely helped. Thanks for sharing.