What Is Consent Under the DPDP Act?
A deep dive into consent under India's DPDP Act: requirements, notice, informed decision-making, withdrawal, and how to implement consent properly.
Executive Summary
Consent is the legal foundation for processing personal data under the DPDP Act. This article explains what consent means, how to obtain it properly, the notice requirements, the distinction between consent and notice, and how to implement consent management operationally.
Consent under the DPDP Act is more than a checkbox—it requires clear information, informed decision-making, and proper record-keeping.
What Is Consent?
Under the DPDP Act, consent is defined as freely given, specific, informed, unambiguous and clearly affirmative action signifying agreement to process personal data for a particular purpose.
This is a high bar. It means:
Freely Given
No coercion, pressure, or undue influence. Individuals must have a genuine choice to consent or refuse.
Specific
Consent is given for particular, defined purposes. Broad, vague purposes don't work.
Informed
The individual understands what they're consenting to, based on a clear notice.
Unambiguous & Clearly Affirmative
There's no doubt that consent was given. Opt-in required; pre-checked boxes don't work.
The Role of Notice
Notice is how you make consent informed. Under Section 5 of the DPDP Act, every consent request must be accompanied or preceded by a notice that includes:
- The personal data category and purpose: Clearly describe what data you're collecting and exactly what you'll do with it
- How individuals can exercise their rights: Explain how to access, correct, delete, or withdraw consent
- How to contact the Grievance Officer: Provide information on filing complaints
- Any other prescribed information: Per the Rules, may include retention period, recipients, etc.
Notice Requirements
The notice must be:
- Independent and understandable: Clear, plain language; not buried in long terms
- Presented before consent: The individual must see it before saying yes
- Granular by purpose: Different notice for marketing, analytics, customer support, etc.
- Accessible: Easy to read on the device being used (website, app, etc.)
Common Mistake: Burying consent in lengthy privacy policies and terms. Instead, the notice must be standalone and clear.
Purpose-Specific Consent
Consent is not a blank check. It must be specific to each purpose.
If you want to use personal data for:
- Marketing emails
- Analytics
- Customer support
- Product recommendations
Each requires separate consent. You cannot obtain consent for "various purposes" and then use it as you see fit.
Example:
"We'll use your email to send you marketing messages." (Specific purpose, clearly stated)
vs. "We'll use your information for business purposes." (Too vague - doesn't work)
Proving Consent
A critical requirement: You must be able to prove that consent was obtained in compliance with the Act. This means:
- Record the consent: Log when it was given, which notice version was used, which purpose
- Timestamp it: Record the exact date and time
- Version control: If you update notices, track which version the person saw
- Maintain the record: Keep consent records for as long as the data is processed
- Make it accessible: Be able to retrieve and produce these records if asked
This has significant operational implications. You need systems to:
- Capture consent at the moment it's given
- Store consent records immutably
- Track consent state (when it was withdrawn)
- Retrieve records quickly for individuals or regulators
Consent vs. Withdrawal
Important Distinction: An individual can withdraw consent at any time. When they do:
- You must stop processing personal data for that purpose going forward
- BUT you can retain data that was lawfully processed while consent was active
- UNLESS you have another legal reason to delete it (e.g., right to erasure)
(Withdrawal vs. erasure is covered in detail in our article on Consent Withdrawal)
How to Implement Consent
Step 1: Define Purposes
List every reason you collect and use personal data:
- Account creation and management
- Service delivery
- Marketing communications
- Analytical insights
- Customer support
- Product improvements
Step 2: Create Purpose-Specific Notices
For each purpose, write a clear, standalone notice explaining:
- What data you need and why
- How you'll use it
- Who has access
- How long you'll keep it
- Their rights
Step 3: Request Consent
Use an explicit opt-in mechanism:
- Checkbox or toggle (not pre-checked)
- Button click (e.g., "I agree")
- Explicit yes/no choice
Step 4: Record Consent
Capture and store:
- User ID / identifier
- Timestamp
- Notice version shown
- Purpose(s) for which consent was given
- Consent state (yes/no/withdrawn)
- Channel (website, app, email, etc.)
- IP address or device ID (if applicable)
Step 5: Respect Consent
Ensure downstream systems only process data according to the consent state. If someone withdraws consent for marketing, don't send marketing emails.
For Children's Data
Special rules apply for individuals under 18:
- Parental/guardian consent required - not the child
- Verification required - verify the guardian is 18+ and authorized to act
- More stringent verification than adult consent
- Cannot use children's data without this verified consent
Key Takeaways
1. Consent is specific to purpose: One purpose = one consent.
2. Notice must be clear and independent: Not buried in terms.
3. Opt-in required: Pre-checked boxes don't work.
4. You must prove it: Record consent with timestamp and notice version.
5. It's operational: Systems must respect consent decisions.
Sources & Further Reading
Digital Personal Data Protection Act, 2023 - Sections 5-7
Parliament of India — Consent and Notice
https://indiacode.gov.in/act/c058fa9f-eaf0-4ca3-98f1-3443b087bca9/sectionsDigital Personal Data Protection Rules, 2025 - Rule 3
Ministry of Electronics and Information Technology — Notice Requirements
https://www.meity.gov.in/Related Articles
What Is the DPDP Act? A Practical Guide for Indian Businesses
Understand India's Digital Personal Data Protection Act 2023: scope, key concepts, obligations, and what compliance means for your business.
DPDP Act Compliance Checklist for Indian Businesses
A practical checklist covering data inventory, consent, notices, rights handling, security, and everything your business needs to operationalize DPDP compliance.
Consent Withdrawal Under the DPDP Act: What Businesses Need to Know
Understand consent withdrawal obligations, the distinction between withdrawal and erasure, and how to operationalize withdrawal workflows.
Building your DPDP compliance infrastructure?
ConsentLog helps Indian businesses operationalize DPDP consent requirements across their systems. Learn how we're approaching consent infrastructure.