The Digital Personal Data Protection Act, 2023 (DPDP Act) has introduced a significant shift in the way organisations in India are expected to collect, process, and manage digital personal data. One of the central principles of the Act is consent—ensuring that individuals have meaningful control over how their personal data is processed.
For organisations acting as Data Fiduciaries, obtaining consent is not merely a checkbox exercise. Consent must meet specific legal standards and should be supported by appropriate processes, documentation, and technical controls.
What Is Consent Under the DPDP Act?
Under the DPDP Act, consent means an indication of an individual’s willingness to allow the processing of their personal data for a specified purpose.
For consent to be valid, it must be:
- Free
- Specific
- Informed
- Unconditional
- Unambiguous
The individual must provide consent through clear affirmative action.
This means organisations should avoid relying on silence, inactivity, pre-ticked boxes, or assumptions that an individual has consented merely because they continue to use a service.
1. Consent Must Be Freely Given
Consent should not be obtained through coercion, pressure, or an arrangement where the individual has no meaningful choice.
For example, if a website requires a user to agree to receive promotional emails before allowing the user to purchase a product, the organisation should carefully assess whether such consent is genuinely voluntary.
Businesses should therefore distinguish between:
Consent required for providing the requested service and
Optional consent for additional purposes, such as marketing or personalised advertising.
Where processing is optional, individuals should be given a genuine choice.
2. Consent Must Be Specific
Consent should relate to a clearly identified purpose.
A broad statement such as:
“We may use your personal data for various business purposes.”
is unlikely to provide the level of specificity expected from a meaningful consent mechanism.
Instead, organisations should clearly communicate the purpose, for example:
“We will use your email address to send you promotional offers and updates about our products.”
If an organisation intends to process personal data for multiple independent purposes, the consent mechanism should clearly distinguish those purposes where appropriate.
3. Consent Must Be Informed
An individual should understand what data is being collected, why it is being collected, and how it will be used.
The DPDP framework places importance on providing individuals with appropriate information through a notice.
A good privacy notice should explain, in clear and understandable language:
- The personal data being processed;
- The purpose of processing;
- The manner in which individuals can exercise their rights;
- How consent can be withdrawn; and
- Other information required under the applicable legal framework.
Organisations should avoid unnecessarily complicated legal language where a simpler explanation can communicate the same information.
4. Consent Must Be Unconditional
Consent should not be bundled with unrelated purposes.
For instance, consider an online application that asks a user to provide their phone number to create an account and simultaneously requires the user to consent to receiving marketing communications.
These are potentially separate purposes.
A better approach would be to provide separate choices:
☐ I agree to the processing of my phone number for account creation.
☐ I would like to receive promotional communications.
This allows the individual to make a meaningful choice.
5. Consent Must Be Unambiguous
Consent must involve a clear affirmative action.
Examples of stronger consent mechanisms include:
- Selecting an unchecked checkbox;
- Clicking an “I Agree” button;
- Selecting an explicit preference; or
- Completing another clearly affirmative action.
Organisations should be cautious about mechanisms where consent is inferred from:
- Silence;
- Inactivity;
- Continued browsing;
- Pre-ticked boxes; or
- Ambiguous statements.
The consent interface should make it clear that the individual is actively agreeing to the stated processing.
Consent Is Not the Same as a Privacy Notice
One of the most common compliance mistakes is treating the privacy notice and consent as the same thing.
They serve different purposes.
A privacy notice informs an individual about the processing of their personal data.
Consent is the individual’s affirmative agreement to the specified processing where consent is the applicable legal basis.
For example:
Privacy Notice:
“We collect your name, email address and mobile number to create and manage your account.”
Consent Mechanism:
☐ I consent to the processing of my personal data for the purpose described above.
The notice provides information; the consent mechanism captures the individual’s decision.
Consent Withdrawal: The Other Side of Consent
A valid consent framework must also address withdrawal of consent.
The DPDP Act provides individuals with the right to withdraw consent. Importantly, the process for withdrawing consent should not be unnecessarily difficult compared with providing consent.
For example, if a user can provide consent with one click but has to contact customer support, submit a physical form, and wait several days to withdraw it, the organisation may face compliance concerns.
Businesses should therefore implement easily accessible mechanisms such as:
- Privacy preference centres;
- Account settings;
- Unsubscribe links;
- Consent dashboards; or
- Other appropriate digital mechanisms.
Once consent is withdrawn, the organisation must take appropriate steps in accordance with the Act and applicable rules.
Maintain Records of Consent
From a compliance perspective, simply collecting consent is not enough.
Organisations should be able to demonstrate what consent was obtained and in what circumstances.
A consent record may include:
| Consent Record | Example |
|---|---|
| Individual | Customer/User ID |
| Date & Time | 1 September 2026, 10:30 AM |
| Purpose | Marketing communications |
| Data Category | Email address |
| Consent Version | Privacy Notice v2.1 |
| Consent Status | Granted |
| Method | Website checkbox |
| Withdrawal | Date and method, if applicable |
Maintaining an appropriate audit trail can help organisations demonstrate accountability and manage future disputes.
Consent Management Should Be Built Into Business Processes
DPDP compliance should not be limited to drafting a privacy policy.
Organisations should consider implementing a structured Consent Management Framework covering:
1. Consent Collection
Define where and how consent is collected across websites, mobile applications, forms, customer portals, and other systems.
2. Consent Recording
Maintain appropriate records showing when and how consent was obtained.
3. Consent Classification
Map consent to specific purposes and categories of personal data.
4. Consent Withdrawal
Provide individuals with a simple mechanism to withdraw consent.
5. Consent Propagation
Where personal data is shared with processors or other entities, organisations should ensure that relevant consent-related instructions and processing requirements are appropriately managed.
6. Audit and Monitoring
Periodically review consent records, interfaces, notices, and processing activities to identify gaps.
What Should Businesses Review?
Organisations preparing for DPDP compliance should review their existing consent mechanisms and ask:
1. Are we clearly communicating the purpose of processing?
2. Are we collecting consent through affirmative action?
3. Are optional and mandatory purposes appropriately distinguished?
4. Are we avoiding pre-ticked consent boxes and implied consent?
5. Can individuals easily withdraw consent?
6. Do we maintain evidence of consent?
7. Are our privacy notices aligned with our actual processing activities?
8. Are consent records linked to specific processing purposes?
9. Do our third-party processors and vendors support the required consent-related controls?
10. Have we established an internal process for responding to consent withdrawal requests?
The Road Ahead for Organisations
The DPDP Act represents a move towards a more structured and accountable approach to personal data protection in India.
For businesses, consent should therefore be viewed not simply as a checkbox on a website, but as a complete lifecycle:
Notice → Choice → Consent → Record → Processing → Withdrawal → Action → Audit
Organisations that build this lifecycle into their privacy and data-governance programmes will be better positioned to demonstrate accountability and maintain trust with individuals.
Ultimately, effective consent is about giving individuals a real, informed, and meaningful choice over the processing of their personal data.
As the regulatory framework evolves through the applicable rules and guidance, businesses should periodically review their consent mechanisms and ensure that their privacy practices remain aligned with the latest legal requirements.
