The story in brief
DEPA is an architectural and institutional idea for consent-based data sharing. Its discussion-paper origins should be kept distinct from the current rules applying to a specific product.
NITI Aayog’s 2020 discussion paper introduced Data Empowerment and Protection Architecture as a framework for consent-based data sharing. It is useful to read DEPA as an architectural and institutional idea in its historical context. The paper is a discussion document, not a substitute for the laws and sector rules that apply to a particular product today.
A permission screen is only one part
Consent has to connect to an actual data flow. The person granting it should be able to understand the intended purpose, while the system needs ways to carry that decision through the process. A well-written button cannot compensate for an unclear relationship between the request and what happens afterward.
Design the whole information journey
Our editorial question is where a user’s understanding can become separated from the system’s behaviour. Consider the request, the recipient, the duration and how someone learns what happened. That perspective can help a startup ask better product questions even before a particular integration is chosen. The practical implementation still needs to follow the current requirements of its domain.
Use the architecture to ask better product questions
A framework can help a team see where permission, information movement and responsibility belong in a service. It does not supply every answer for a particular implementation. Begin with the proposed use of data, then map the organisations and decisions involved. Ask what the person sharing information needs to understand and how that understanding is reflected in the product. Keep historical concepts separate from current legal and sector requirements. This makes an architecture discussion useful without turning it into a copied compliance checklist. The founder benefit is a more explicit design conversation about data use, rather than treating consent as a label added to a finished form.
Put the idea to work
Use these questions to investigate the idea in your own context.
- Describe the proposed data use before choosing an interface.
- Map the roles and permission points in the information flow.
- Check the current requirements relevant to the actual product and sector.
A closer look
Can the DEPA discussion paper replace current data-protection guidance?
No. It explains an architectural direction in a particular historical context. A live product needs to be assessed against the current rules and obligations that apply to it. This article is an ecosystem explanation, not a compliance determination.
Sources & editorial note
This guide draws on the sources below. Our practical questions and analysis are editorial interpretation. Historical documents describe their own period; use current official programme information for availability, terms and applications.
See our editorial standards or request a correction. For another perspective, read A different kind of ambition: the Zerodha story


