Chat on WhatsApp

India

Consent requirements under the DPDP Act

When a Data Fiduciary relies on consent, the Digital Personal Data Protection Act, 2023 sets a standard for how that consent is asked for, limited, and withdrawn. This page explains that standard in operational language.

What is consent under the DPDP Act?

Consent is a free, specific, informed, unconditional, and unambiguous indication that the Data Principal agrees to the processing of their personal data for a specified purpose. It must be given by a clear affirmative action, and it is limited to the personal data necessary for that purpose.

A bundled accept click does not meet the standard by itself

The Act allows processing with the Data Principal’s consent or for a legitimate use it specifically lists. If you are in the consent path, silence, a pre-ticked box, or a single unavoidable accept for unrelated purposes is not the clear agreement the statute describes.

The request for consent is accompanied or preceded by a notice. The notice should let the person understand the personal data and the purpose, how they can withdraw, how they can exercise their rights, and how they can complain to the Board. The DPDP Rules can specify how that notice is presented. Confirm the current particulars with counsel before you freeze the copy.

Withdrawal has to be as easy as giving consent. Processing that was lawful before withdrawal does not become unlawful because the person later withdraws. After withdrawal, the fiduciary must stop processing that relied on the consent, and cause its processors to stop, unless the Act or another law still requires that processing.

How the requirements show up in a consent workflow

  1. Step 1

    Identify the Data Principal

    The Data Principal is the individual the personal data relates to. For a child, the parent or lawful guardian acts in that role. The same is true for a person with a disability who has a lawful guardian.

  2. Step 2

    Limit the ask

    Ask only for the personal data necessary for the stated purpose. Keep a purpose that is necessary for the service separate from an optional purpose such as advertising.

  3. Step 3

    Take a clear action

    The person does something that indicates agreement. Inactivity is not that action.

  4. Step 4

    Keep the path open

    The same person can review and withdraw the choice later, with no harder steps than the original request.

Key capabilities

Notice and consent under DPDP

Banner and preference-center text can be published in English or a configured Eighth Schedule language, and the consent record points at the version that was live.

Digital consent under DPDP

The choice can be collected in the browser SDK or written from your own application through the consent API. Either way, it is tied to purposes you defined.

Withdrawal of consent under DPDP

The preference center is the returning path. The new decision becomes what enforcement follows. The earlier evidence remains according to retention and any legal hold.

Where a Consent Manager fits

The Act lets a Data Principal give, manage, review, and withdraw consent through a registered Consent Manager. That role is accountable to the Data Principal. A website’s consent platform is not automatically that role.

What teams use it for

  • A shared vocabulary for legal and engineering.
  • Purpose-level choices instead of one site-wide flag.
  • A record of the notice that was actually shown.
  • A public guide teams can read before they open the workspace.

Website notices

Draft purpose copy that matches the processing the site performs, then publish it as the version the SDK serves.

Product and privacy reviews

Check a new vendor or tag against an existing purpose before it is added to the live notice.

Training

Pair this page with the DPDP Act guide and the 30-module course when a team is learning the statute.

Privacy considerations

This is not a restatement of every section, and it is not legal advice. Legitimate uses, children’s data, cross-border transfers, and breach duties sit outside a consent banner.

Do not describe a record as consent if the organization is relying on a different ground.

Questions

1.What is a Data Principal?

The Data Principal is the individual to whom the personal data relates. Where the individual is a child, or a person with a disability who has a lawful guardian, the parent or guardian acts as the Data Principal.

2.What information should a consent notice contain?

With a request for consent, the notice should explain the personal data and the purpose of processing, how the person may withdraw consent, how they may exercise their rights, and how they may complain to the Data Protection Board. Present it in clear language. Check the current Rules for any itemised form the notice must take.

3.How can users withdraw consent?

The Act gives the Data Principal the right to withdraw consent at any time, with ease comparable to giving it. In Consent Guru, that path is the privacy preference center, or an API call from a settings page you operate. Withdrawal updates the current choice.

4.How should consent records be maintained?

Keep the choice together with when it was made, the purposes it covered, and the notice version that was shown. Retain it for the period your policy sets. Do not delete historical evidence merely because the person later withdraws, unless retention rules and legal holds allow that deletion.

5.What is consent evidence?

Consent evidence is the retained proof of what was asked and what was decided. In this product that includes a consent identifier, a policy snapshot, and, when you export a receipt, cryptographic proof of that snapshot. It shows what your system recorded. It does not by itself prove that the underlying processing was lawful.

Related pages

This page describes how Consent Guru supports privacy operations. It is not legal advice, and using the product does not by itself make an organization compliant with GDPR, CCPA, CPRA, the DPDP Act, or any other law.