[Nehal Paliwal is a third-year B.A. LL.B. (Hons.) student at the National Law University, Jodhpur. In this piece, the author examines why users increasingly perceive algorithmically curated platforms as a form of surveillance. It attributes this perception to the exploitation of cognitive biases and the Digital Personal Data Protection Act, 2023’s failure to regulate inferred data. The piece argues that formalistic “notice-and-choice” consent cannot legitimize manipulative data practices. It contends that Indian privacy law must recognize inferred data as personal data and adopt an “environment of consent” approach that addresses how platforms shape user behaviour.]
Almost everyone has a story about their phones listening to their conversations, and almost everyone is wrong. And that is exactly the point. You mention needing new running shoes in a voice message. Hours later, Instagram shows you shopping haul reels displaying Nike shoes. You discuss wedding venues with your partner over dinner. The next morning, Facebook suggests event planning services. You think about buying a particular book but never search for it. Amazon recommends it two days later.
The first time this happens, it feels coincidental. The second time, curious. By the third, you are convinced: they are listening. Except they are not; at least, not in the acoustic way you fear.
This eerie sensation of constant ambient eavesdropping is not an accident or an uneducated user error. Rather, it is the highly predictable outcome of an attention economy, explicitly engineered to manipulate human cognition, trigger latent pattern recognition, and intensify an invasive perception of being known.
This raises a deeper question for privacy law. If platforms can predictably shape how users perceive and respond to their digital environment, can consent still be treated as a reliable indicator of autonomous choice? Most modern data protection regimes answer this question through what privacy scholars describe as the “Notice-and-Choice” model. The assumption is simple: once a platform clearly discloses its data practices and obtains consent, users are capable of evaluating the associated risks and deciding whether to proceed.
This article argues that Indian privacy law must decisively reject this legal fiction of the hyper-rational user. This assumption becomes impossible to sustain when platforms deploy a predatory feedback loop where they leverage manipulative interfaces to extract behavioral metrics, transform those metrics into deep psychological inferences, and then weaponize those inferences to manipulate user behavior, all while hiding behind a formalistic checkbox as a shield against liability.
How Platforms Design for Distortion
Platforms do not need to eavesdrop acoustically. Instead, they harvest a relentless stream of behavioral data generated during every second of digital interaction, which includes, content viewed, scroll acceleration patterns, notification responses, precise location points, granular device telemetry. Machine-learning models ingest this at scale to predict, with increasing accuracy, what will capture a user’s attention next.
But modern analytics does not stop at prediction. Instead, platforms use these basic data points to generate deep behavioral inferences, constructing psychological profiles that the user never explicitly consented to disclose. Platforms actively engineer the digital environment to maximize engagement, timing notifications and content deliveries to coincide with mapped moments of peak psychological receptivity, making targeted patterns hyper-visible while rendering alternatives invisible.
The result is not a neutral bulletin board. It is an active, engagement-driven environment that shapes behavioral curation. Platforms act as algorithmic arbiters of information, directly influencing the user’s attention patterns and engineering massive attentional cascades that systematically bypass conscious, rational thought. The platform functions as a customized reality, architecturally designed to exploit what tech policy scholars describe as sociological concepts of trust to extract data, making data protection a structural system design problem rather than an individual choice.
This is where the frequency illusion becomes legally significant. Also known as the Baader-Meinhof phenomenon, it describes the human tendency to perceive a concept as suddenly ubiquitous the moment we become aware of it. You consider buying a red car; you immediately notice red cars everywhere. External reality has not changed. Only the deliberate direction of your attention has. In algorithmically curated environments, this neurocognitive vulnerability is not a bug; it is a monetized feature. Confirmation bias compounds it as users vividly remember the five eerily targeted ads while forgetting the fifty irrelevant ones, constructing an internal narrative of perpetual surveillance that grows more convincing with each reinforcement.
The platform benefits twice from this cognitive capture: once from the immediate ad-revenue generated by precise targeting, and again from the user’s subsequent heightened, defensive attention, which itself produces cleaner behavioral data for future profiling. Users who feel surveilled do not disengage. They scroll more obsessively, interact more defensively, and surrender exactly the behavioral data platforms need to deepen the loop.
Global regulators have begun to recognize this architecture for what it is. The European Commission’s April 2024 enforcement action against TikTok under the DSA explicitly targeted its reward-driven engagement framework as designed to induce addictive behavior through behavioral profiling. The underlying regulatory insight is precise: platform design does not merely influence users. It engineers a state of “algorithmic anxiety” that traps individuals in opaque, asymmetrical feedback loops and alters their real-world behavior just to navigate an online interface.
The Fiction of the Rational User in Indian Privacy Law
The structural architecture of India’s Digital Personal Data Protection (DPDP) Act, 2023, is built entirely upon what privacy scholars call the Notice-and-Choice paradigm. The statutory framework presumes that the “Data Principal” is an autonomous, hyper-rational actor who will meticulously read multi-page privacy notices, weigh long-term profiling risks against immediate utility, and make a calculated decision to click “Accept.” This fiction persists for two structural reasons.
First, the Act is a direct response to Justice K.S. Puttaswamy v. Union of India (2017), where the bench held that “Privacy represents the core of the human personality and recognizes the ability of each individual to make choices and to take decisions governing matters intimate and personal at [para 169]. Apart from safeguarding privacy, data protection regimes seek to protect the autonomy of the individual [para 177].”
To operationalize this ideal without forcing the state into a paternalistic role, the legislature anchored data protection entirely around individual consent. However, they mistook consent to track a data point, for consent to manipulate user behavior.
Second, India’s digital economy demands frictionless data flows across FinTech, UPI, and e-commerce. Acknowledging cognitive vulnerability would impose unpredictable burdens on Data Fiduciaries. Instead, once a fiduciary issues a notice under Section 5(1), legal risk shifts entirely to the individual. Clicking “accept” sanitizes the extraction and insulates platforms from any liability over whether a user genuinely understood the algorithmic backend.
The deeper tragedy is that India once possessed the statutory vocabulary to protect the cognitively vulnerable user and deliberately abandoned it. The 2018 Draft defined “harm” to include “mental injury” and “surveillance not reasonably expected by the data principal,” and covered behavioral “characteristics, traits, and attributes” as personal data. The 2019 Draft went further, defining personal data to include “any inference drawn from such data for the purpose of profiling,” directly targeting the asymmetry of big data analytics.
However, the final 2023 Act completely excised the definitions of profiling, inferences, and psychological harm, creating a profound structural loophole regarding “Inferred Data.” By only recognizing narrow, quantifiable commercial loss or physical identity theft as cognizable harms, the law is forced to maintain the fiction of the rational user and it simply has no legal vocabulary left to penalize the actual cognitive exploitation platforms inflict.
This helps explain why users often feel surveilled despite never having disclosed the information that appears to be known about them.
This loophole is reinforced by Section 3, which applies only to personal data that is collected. When a platform uses algorithms to generate behavioral predictions, that inferred data is technically created by the platform, not explicitly provided by the user. A data notice under Section 5(1) can state that a platform collects basic “device interaction metrics”. The rational user assumes they are consenting to basic telemetry tracking; they have no way of knowing that this data will be used to infer deep psychological traits.
By treating inferred data as proprietary analytics rather than personal data, platforms hide behind formalistic consent for the collection of raw data while using inferred data to manipulate user behavior.
The consequence is a profound accountability gap. Profiling systems can derive sensitive information, behavioural tendencies, interests, and personality traits from seemingly innocuous data points, often revealing far more than users consciously provide. The inferences drawn from personal data may pose a greater threat to privacy than the underlying data itself. Users may therefore be profiled, categorised, and behaviourally influenced based on predictions they cannot see, contest, or even know exist. The result is that the law regulates the collection of data while leaving largely untouched the inferential processes that transform that data into a mechanism of algorithmic governance.
Why Existing Doctrine Already Rejects This Fiction
When digital platforms claim that clicking “Accept” sanitizes their operations, they are hiding behind a defense that modern Indian jurisprudence has already dismantled across both fronts; the manipulation of the choice interface and the exploitation of inferential behavioral profiles.
Following upon Puttaswamy, the Supreme Court’s majority opinion in Association for Democratic Reforms v. Union of India (2024) directly confronted the mechanics of big data analytics. The Court acknowledged that behavioral markers as seemingly mundane as past purchases and digital footprints can be processed to infer deep-seated psychological and political traits [para 136]. More critically, it held that the right to privacy must encompass the autonomy to think and develop thoughts freely [para 134]. Platforms that manipulate choice architecture to systematically nudge user attention do not merely breach data law, they attack a constitutional guarantee.
In Samira Kohli v. Dr. Prabha Manchanda (2008) the Supreme Court held that consent is only legally meaningful when disclosure is structured to enable genuine comprehension and autonomous evaluation [para 32(i)].
Modern courts have applied this principle directly to digital architectures. In Anil Kapoor v. Simply Life India (2023), the court formally acknowledged that dark patterns are engineered to subvert or impair decision-making skill, marking a decisive jurisprudential moment by acknowledging that algorithmic interfaces can actively destroy an individual’s legal capacity to consent [para 34].
The convergence of these concerns is perhaps most visible in the recent WhatsApp privacy policy litigation. In 2021, WhatsApp updated its privacy policy to facilitate broader data sharing within Meta’s ecosystem. Users were presented with a binary choice: accept the updated terms or lose access to a service that had become integral to everyday communication. Rejecting WhatsApp’s defence that users had voluntarily consented, the Competition Appellate Tribunal held that consent was “not freely given” because users were “coerced into a binary choice of accepting invasive terms or forfeiting a vital communication tool” (para 73).
The Tribunal further observed that the removal of opt-out rights and expanded data collection enhanced Meta’s ability to obtain “a wider reach and a deeper understanding of user behaviour” (para 223.2). It recognised that behavioural data constitutes the foundation of targeted advertising and that extensive data accumulation enables a “self-reinforcing cycle” that consolidates platform power (para 223.5). Ultimately, the Tribunal upheld the Commission’s finding that WhatsApp had abused its dominant position and sustained the penalty imposed upon Meta (paras 264-265).
The decision is significant not merely because it concerns privacy, but because the Tribunal examined the structural conditions under which consent was obtained and recognised how behavioural data extraction, market power, and constrained choice interact within digital ecosystems.
The DPDP Act’s own text betrays the rational user fiction. Section 9(3) imposes a blanket prohibition on behavioral tracking of children, regardless of whether parental consent exists, because the legislature implicitly accepted that certain profiling is so inherently invasive that no disclosure can legitimize it.
This logic does not disappear once a user turns eighteen. Bounded rationality, confirmation bias, and the frequency illusion operate in the adult brain just as predictably in engagement-driven environments. If the Indian state accepts that cognitive vulnerability renders consent legally infirm for one demographic, it has no principled basis to treat adults differently when the same vulnerabilities are being systematically mapped and weaponized by the same platforms.
The Doctrinal Path Forward
To bridge the gap between formal compliance and meaningful autonomy, Indian privacy law must move beyond a notice-and-choice model and address the realities of algorithmic profiling.
First, the DPDP Act should expressly recognize inferred data as personal data. Modern profiling systems derive sensitive conclusions from seemingly innocuous behavioural signals such as browsing habits, typing patterns, and location history. Without regulating these inferences, platforms can comply with disclosure requirements while concealing the most consequential aspects of data processing.
Second, courts should adopt an “environment of consent” standard under Section 6(1) of the DPDP Act. Consent should not be assessed solely by the existence of a privacy notice but by the broader context in which it was obtained. Where platforms deploy design features that predictably exploit cognitive biases and distort user understanding, consent cannot be regarded as truly informed.
Third, the Data Protection Board of India should issue guidance addressing manipulative interface design and profiling practices. Drawing from emerging international approaches, the Board should encourage privacy-by-design measures, contextual consent mechanisms, and meaningful opportunities for users to revisit or withdraw consent.
Fourth, behavioural profiling should be subject to heightened safeguards akin to those applied to children’s data under Section 9(3). Where profiling relies on cognitive vulnerabilities and produces significant behavioural influence, platforms should be required to offer genuine, unbundled, and non-punitive opt-outs.
Conclusion
The persistence of perceived digital surveillance is not merely a user education problem; it is a design accountability problem. Platforms that exploit cognitive biases while relying on formalistic consent expose the limits of a privacy framework built on the assumption of a perfectly rational user. As Justice K.S. Puttaswamy recognized, privacy is ultimately concerned with autonomy, dignity, and meaningful control. That promise becomes difficult to realise when the very conditions under which consent is obtained are capable of shaping perception and behaviour.
Yet this debate raises a broader question. Why does data protection law continue to place the burden of managing privacy primarily on individuals when platforms possess vastly superior behavioural insights and technological power? If users can be profiled, predicted, and influenced through inferences drawn from ordinary behavioural data, is the problem really one of inadequate disclosure, or a deeper imbalance of power embedded within digital ecosystems?
The challenge becomes even more pressing as platforms increasingly rely not on what users disclose, but on what they infer. If inferred data can shape opportunities, preferences, and future behaviour, should privacy law continue to focus primarily on regulating data collection, or should it also regulate the inferences themselves? More fundamentally, can consent remain the central organising principle of data protection when the technologies seeking consent are also capable of influencing how that consent is given?
The frontier for Indian privacy law is no longer just about regulating data collection. It is about dismantling a self-reinforcing loop designed to predict, shape, and govern human behavior itself.