Written by Prerna Kumari and Alok Pratap Singh students at Law Centre 2, Faculty of Law, University of Delhi
Most WhatsApp users in India would have, at some point, been faced with a dilemma that presented no alternative but to accept the updated privacy policy or lose access to the application. The Delhi High Court, however, did not consider this a mere privacy issue. Its observations assumed renewed significance with the introduction of the Digital Personal Data Protection Act, 2023 (“DPDPA”) and the Digital Personal Data Protection Rules, 2025 (“Rules”), both of which effectively strengthen the individual’s fundamental right to privacy. The pertinent question thus arises: do the DPDPA and the Rules address the issue raised by the Delhi High Court, or do they merely reiterate the same ‘take it or leave it’ scenario under a different legal framework?
Background: The Case
The dispute began in 2021 when WhatsApp announced a privacy policy that would see it share more personal data with Facebook (WhatsApp’s parent company). However, those who rejected the new privacy policy terms were warned that they would soon be unable to access essential WhatsApp services. The competition law angle arose out of the fact that WhatsApp enjoyed a near-monopoly over communication services in India. There was little reason for an average WhatsApp user to switch to another messaging service so long as their contacts remained on WhatsApp. It was, therefore, entirely reasonable for the Competition Commission of India (“CCI”) to take note of WhatsApp’s alleged abuse of its dominant position by forcing users to accept the revised privacy policy.
WhatsApp and Meta (WhatsApp’s parent company) challenged the CCI’s jurisdiction on the grounds that the dispute pertained to privacy and personal data, a matter that only the Data Protection Authority could adjudicate. The Delhi High Court, however, disagreed and in 2021, the Single Judge dismissed WhatsApp’s plea and upheld the CCI’s authority to probe WhatsApp’s alleged abuse of its dominant position. WhatsApp and Meta were thus not unduly pleased with the ruling and moved the Division Bench of the Delhi High Court.
The Division Bench, too, ruled against WhatsApp and Meta, observing that the 2021 WhatsApp privacy policy indeed placed its users in a ‘take it or leave it’ position. However, it was also noted that the Single Judge was correct in ruling that the Competition Act, and not the privacy laws, was the appropriate law to adjudicate the dispute. The division bench thus dismissed WhatsApp and Meta’s appeals for lack of jurisdiction.
While the dispute did involve WhatsApp’s alleged unilateral decision to change its privacy policy. This is important to note because it raises an intriguing question in regard to the DPDPA and the Rules
The Gap: Why Competition Law Needed to Step In
The privacy policy dispute that began in 2021 first involved WhatsApp’s unilateral decision to share more data with Facebook and Meta. It also involved WhatsApp forcing its users to accept the revised privacy policy. However, India did not have a comprehensive data protection law at the time, with the Information Technology Act, 2000 and the Sensitive Personal Data or Information (SPDI) Rules, 2011 providing only limited privacy and data protection.
It is also pertinent to note that prior to the introduction of the DPDPA, India did not have an independent data protection authority tasked with investigating whether the consent of the data principal was free from coercion, among other factors. This was particularly important in light of the Supreme Court’s ruling in K.S. Puttaswamy v. Union of India, which acknowledged the Right to Privacy as a Fundamental Right and, by extension, necessitated a detailed evaluation of the concept of consent.
The CCI, therefore, was tasked to investigate a dispute that primarily pertained to personal data and privacy. It must be noted that the CCI did not determine whether the consent of the data principals (WhatsApp users) was free from coercion or not. It only observed that WhatsApp’s unilateral decision to bind its users to the new privacy policy terms constituted an anti-competitive practice since it placed users in a ‘take it or leave it’ situation. In many ways, therefore, the CCI was fulfilling a jurisdictional vacuum created by the lack of a comprehensive data protection law.
Current Scenario: Where Does the DPDPA Stand Now?
India ratified the Digital Personal Data Protection Act, 2023 (“DPDPA”) in August 2023. However, most of its provisions were not immediately effective. They came into force on a phased basis, beginning with the Rules notified on 13 November 2025. Even then, the government opted to adopt a gradual approach, with the second phase coming into force in November 2026. The first phase, which commenced upon the Rules’ notification in November 2025, was primarily institutional in nature, focusing on the Data Protection Board, India’s data protection authority, and certain definitions. The second phase is expected to come into force in November 2026 and will deal with matters relating to the registration of the Consent Managers. These managers are essentially designed to make consent management easier for the average digital consumer.
The third and final phase of the implementation of the DPDPA is expected to commence in May 2027. It will contain the substantive provisions, including notice and consent, breach notification, retention of personal data, cross-border processing of personal data, and the rights of the data principal (such as the right to access, correct, update, and delete). The penalties under the Act, which may range up to hundreds of crores of rupees, will also apply starting from this phase.
In other words, the competition law issue raised by the Delhi High Court will continue to persist so long as the full text of the DPDPA continues to remain suspended for the time being.
Does the Law Itself, When It Comes into Force, Actually Solve the Problem?
Assuming that the provisions dealing with notice and consent do become effective in May 2027 as currently envisioned, the provisions appear stronger than what existed under the Information Technology Act, 2000 and the SPDI Rules, 2011. Section 6 of the DPDPA requires that the consent of the data principal should be free, specific, informed, unconditional, and unambiguous. It also states that a data fiduciary may only process personal data for the specific purpose for which consent has been provided. In many ways, therefore, the DPDPA’s approach to consent is far stronger than the approach adopted by the EU’s General Data Protection Regulation (“GDPR”).
More importantly, unlike the GDPR, the DPDPA does not permit the “legitimate interest” exception, which sees organizations processing personal data based on their legitimate interests, as opposed to the consent of the data principal. On the surface, therefore, the DPDPA provides enhanced levels of protection to the data principals. The real test, however, lies in determining whether the new law effectively prevents the coercive ‘take it or leave it’ scenario identified by the Delhi High Court.
As previously mentioned, Section 6 of the DPDPA provides that the consent of the data principal must be free from any coercion, undue influence, fraud, or misrepresentation. At first glance, therefore, it appears as if the coercive consent practiced by WhatsApp and placed in front of its users in 2021 would be prohibited by the DPDPA.
Section 6 of the DPDPA does not explicitly bar organizations such as WhatsApp from tying processing of personal data to the supply of essential services. The processing of personal data by Meta, as part of the wider Meta ecosystem, may similarly be considered necessary for enabling the end-to-end encryption and other services offered by WhatsApp. The DPDPA and the Rules do not explicitly prohibit such bundling, which may allow ‘take it or leave it’ consent to persist, even under the new law.
As currently worded, notice and consent provisions do not prevent coercive consent. Users are placed in a position where they must accept a privacy policy or lose access to the service. Functional unbundling will prevent such a scenario by allowing the user to opt out of one or more services or features while continuing to use the rest.
A final concern pertains to the institutional design of the new data protection regime. The Data Protection Board primarily serves the role of adjudicating upon violations of the DPDPA and imposing penalties upon the offending entities. The CCI will therefore continue to play an important role in regulating the ‘take it or leave it’ scenario so long as it continues to investigate such scenarios in light of Section 2(h)(i) of the Competition Act, which prohibits abuse of dominant position.
Future Outlook
The next few years will be telling in regard to whether the competition law gap identified by the Delhi High Court will be bridged. Much will depend upon how the Privacy Consent Managers framework, the early implementation of which is set to commence in November 2026, works.
When the substantive provisions relating to notice and consent come into force in May 2027, much will depend upon the early jurisprudence of the Data Protection Board. Will the ‘unconditional consent’ requirement be interpreted narrowly to only prohibit clearly coercive consent practices? Or will it go as far as preventing bundling of services, thereby preventing coercive ‘take it or leave it’ consent?
Even then, the Rules do not explicitly prohibit bundled consent such as the one employed by WhatsApp in its dispute with the CCI. At this juncture, therefore, the law’s ability to prevent such consent practices remains unclear at best.
For anyone researching this topic, the primary question no longer pertains to whether India has a data protection law but rather to whether it will be able to prevent big tech firms from tying the supply of essential services to the processing of personal data and, by extension, deny individuals any real choice in the matter.
References
- K.S. Puttaswamy v. Union of India, (2017) 10 SCC 1.
- WhatsApp LLC v. Competition Commission of India, Delhi High Court (Division Bench), judgment dismissing the appeals challenging the Competition Commission of India’s investigation into WhatsApp’s 2021 Privacy Policy. See also Deccan Herald’s coverage of the decision. WhatsApp privacy policy places users in ‘take it or leave it’ situation, says Delhi HC
- Digital Personal Data Protection Act, 2023 (India).
- Digital Personal Data Protection Rules, 2025 (India), notified on 13 November 2025. See also the explanatory summary published by Bar and Bench. MeitY notifies final Digital Personal Data Protection Rules 2025
- Privy by IDfy, DPDP Compliance and Phased Implementation Timeline (overview of the implementation roadmap under the Digital Personal Data Protection framework). DPDP Compliance Guide 2026: Requirements & Deadlines


Leave a Reply