Invisible Markets, Visible Harms: Rethinking Data Brokerage In India

Shalini Singh

1 Sept 2026 11:00 AM IST

  • Invisible Markets, Visible Harms: Rethinking Data Brokerage In India
    Listen to this Article

    In the year 2012, The New York Times reported that an incident which involved a disturbing new reality of digital economy where father complained to retailer after his teenage daughter received advertisement for maternity product. This is because Target's system had inferred from her purchasing behaviour that she was pregnant and the most concerning fact is that platform knew before her father. This coverage became a symbol of data mining which reveals that data gathered through ordinary transaction does not just only records what we have done but it also predicts who we actually are. Whenever a person buys a product he provides telephone number, for accessing an app requires location permission, similarly whenever you search something on one app about a product it appears everywhere on your phone, also to navigate internet browsing history is asked. This in isolation seems minor disclosures however, if these fragmented pieces connected together then this would lead to disclosing “SELF”. The capacity of personal date to store insight into human behavior, guide predictions about that behavior, and optimize strategies to guide and change human behavior is what that drives companies to collect the data use the data in the way that they do. The advancement of technology in this digital economy has made individuals more visible and less informed where businesses now know what one buys, where they going to purchase next, about all these individual remain unaware about who possesses all that knowledge, how that assembled and most important with whom it is going to be share and what value it will generate. This is what invisible market of data brokerage is, now it encompasses chain of collection, aggregation, inference and onward disclosures. This advancement reveals limitation in traditional privacy discussion. Privacy laws in India conventionally deals with whether data was collected lawfully, whether free consent was obtained and whether such data was revealed appropriately. Although, in practicality the data economy extracts value from what happens after the collection of data like combining of data, generating predictions and using those predictions to influence the personal or commercial decisions. In India, the Digital Personal Data Protection Act, 2023 provides a comprehensive legal framework for the governance of digital personal data that includes notice, consent, individual rights and regulatory enforcement and Digital Personal Data Protection Rules, 2025 lays down implementation framework. However, one important question that remain unaddressed is- what happens when personal data of an individual that appeared to be just information becomes monetary asset for making decisions about the individuals?

    THE MARKET THAT THE DATA PROTECTION LAW CANNOT SEE

    Data brokerage is a multi-billion-dollar ecosystem of companies collecting, aggregating, analysing, buying, selling, and sharing data on individuals, ranging from demographic information to political affiliations to income data, health conditions, and GPS locations. Its monetary value arises not just from gathering data but also from the ability to combine the data and then generating commercially useful information about people. In India Digital Personal Data Protection Act, 2023 (“DPDP Act”) establishes a clear legal framework for the collection, processing, storage, and sharing of personal data in India which balances innovation and economic growth with individual privacy. It controls the digital personal data under the ambit of Data Principals, Data Fiduciaries and Data Processors, this covers collection, storage, use, sharing and other activities done using digital personal data which means data brokers are not outside the purview of this statutory framework. However, the major gap in India's emerging data economy is that the present statutory framework recognizes the data though it sometimes struggles to identify the market built around it. Some of the major gaps of this are:

    Firstly, it does not recognize right to Data Portability that allows individuals to obtain and reuse their personal data for their own purposes across different services. Even though it gives individuals certain rights in term of access and information, unlike section 20 of GDPR it does not mandate data portability. However, there is paradox in regulatory structure that is Data Empowerment and Protection Architecture (DEPA) by Niti Ayog provides structured technological infrastructure for data mobility that allows for granular consent for each piece of data, moving away from blanket consent practices. This facilitation cannot be made equivalent with a legally enforceable right which reveals a major gap in legal enforcement and recognition rather in technological capacity. Absence of portability that promotes consumer choice will lead to the creation of data lock-in hampering autonomy of consumer, competition in digital market coupled with domination of particular platform. The data of consumer in the digital economy acts both as an asset as well as anchor. On one hand it is a productive information helping service providers and firms to personalise service coupled with increased efficiency while on the other hand concentration of these data can generate switching cost which can dispirit consumer from switching to competing platform even if they will get better service they cannot. Therefore, Data portability regulations, by reducing the barriers for consumers to switch providers, are widely believed to promote a more competitive market environment.

    Secondly, the absence of explicit and dedicated framework for profiling and automated decision making, as the digital economy is advancing towards its peak, data now does not hold value just from collection, firm deriving its value by converting that particular data into prediction, categorization and inferences about individuals. Automated decision-making means making a decision solely by automated means without any human involvement. Algorithm through search history and pattern will be able to infer that an individual is looking for loan product yet it may not be accurate whether the person is financially distressed or not, such inaccurate inference can transform into a disadvantage in determining credit access, insurance or employment. The major concern is that when information gathered from multiple sources results construction of profile from inferences drawn that individual may not have given consciously. Data Broker uses browsing behaviour, purchase history, transaction patterns to construct a profile and monetises it by selling it to third parties. This is where a significant regulatory gap has been created in the act exposing invisible market because conventional data protection rights may not be sufficient to address these algorithmic inferences. Law may have given right to correct data under section 12 of the act but it lacks correction of inaccurate inference not made but generated from digital activity.

    The advancement of data brokerage reveals that main challenge of India's emerging digital economy is not limited to just collection of personal data or breach of privacy but it is the conversion of that particular data into an economic and predictive tool for own benefit. The enaction of DPDP Act, 2023 has created a strong as well as an important foundation for the protection of digital personal data through consent, notice, rights and regulatory mistake. However, this invisible market remains outside the scope of this act and beyond moment of collection. The unavailability of right to data portability constitutes the first gap that a person can have control on his personal data but it cannot not safely move it, resulting collected data to become a source of switching cost. Another major gap is that law does regulate collection of data but lacks regulation of inference generated from these data. Together these gaps expose concerning limitation of India's DPDP framework which means regulation should extend beyond individual affair and address more broader data brokerage system.

    Author is a 2nd year B.A.LL.B student at National University of Study and Research in Law. Views are personal.

    Next Story