Back to Key Provisions
Consent Framework
Deep dive into the DPDPA's consent requirements - valid consent, notice obligations, withdrawal, and the role of Consent Managers.
11 min read
Consent as the Primary Basis for Processing
Consent is the primary lawful basis for processing personal data under the DPDPA. Section 6 establishes that personal data may only be processed for a lawful purpose for which the Data Principal has given consent, or for certain legitimate uses recognised by the Act.
The DPDPA's consent framework is broadly aligned with global standards but includes unique Indian features, such as the Consent Manager concept and the requirement for consent notices in all Schedule VIII languages.
Requirements for Valid Consent (Section 6)
For consent to be valid under the DPDPA, it must be:
• Free: Given voluntarily without coercion, undue influence, or compulsion
• Specific: Related to a clearly defined purpose
• Informed: Based on a clear notice describing the data and purpose
• Unconditional: Not contingent on the acceptance of terms beyond what is reasonably required
• Unambiguous: Demonstrated through a clear affirmative action
Consent cannot be inferred from silence, pre-ticked boxes, or inactivity. The burden of proving valid consent lies on the Data Fiduciary.
The Consent Notice (Section 5)
Before or at the time of requesting consent, the Data Fiduciary must provide a notice containing:
1. A description of the personal data to be collected
2. The purpose of processing
3. How the Data Principal can exercise their rights under the Act
4. How the Data Principal can make a complaint to the Board
The notice must be presented in clear and plain language. Data Principals must be given the option to access notices in English or any language listed in the Eighth Schedule to the Constitution. This multilingual access requirement is unique to the DPDPA and reflects India's linguistic diversity.
The DPDP Rules (R.3) further detail the form and content of consent notices.
Withdrawal of Consent (Section 6(4)-(6))
The right to withdraw consent is as easy to exercise as the right to give consent. Key principles:
• Withdrawal must be through a process as easy as giving consent
• The Data Fiduciary must cease processing within a reasonable period after withdrawal
• The Fiduciary must erase the personal data (unless retention is required by law)
• Withdrawal does not affect the lawfulness of processing done before withdrawal
Organisations must design their consent mechanisms to include an equally accessible withdrawal process. This may require technical changes to consent management platforms.
Granularity and Bundling
The DPDPA requires consent to be specific to each purpose. While the Act does not explicitly prohibit bundled consent, the requirement for specificity and the prohibition on conditioning services on unnecessary consent effectively discourages blanket consent clauses.
Best practice is to seek separate consent for each distinct purpose of processing, allowing Data Principals to consent to some purposes while declining others. This is particularly relevant for:
• Marketing communications vs. service delivery
• Analytics and profiling vs. core functionality
• Third-party sharing vs. internal use
Consent Obtained Before the Act
Section 5(2) addresses consent that was obtained before the Act's commencement. Where processing was ongoing based on previously obtained consent:
• The Data Fiduciary must provide a notice to the Data Principal as soon as reasonably practicable
• The Data Principal can withdraw consent after receiving this notice
• If consent is not withdrawn, the processing may continue
This transitional provision gives organisations time to align their consent practices without immediately invalidating existing consent arrangements.
Related Resources
Frequently Asked Questions
On This Page
Quick ResourcesDisclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.
