Back to Rights of Data Principals

Right to Withdraw Consent

How Data Principals can withdraw consent under the DPDPA - process, consequences, and the ease-of-withdrawal principle.

7 min read

The Ease-of-Withdrawal Principle

Section 6(6) of the DPDPA establishes a critical principle: the ease of withdrawing consent must be comparable to the ease of giving consent. This means that if consent was obtained through a single click, withdrawal should be achievable through an equally simple mechanism. This principle prevents 'dark patterns' where organisations make it easy to consent but deliberately difficult to withdraw. The Rules further operationalise this by requiring that every privacy notice include a clear link or mechanism for consent withdrawal.

Process and Mechanism

Data Principals exercise the right to withdraw consent by communicating their withdrawal to the Data Fiduciary through the mechanism provided. Under Rule 3, every privacy notice must contain a link enabling the Data Principal to withdraw consent. Consent Managers (R.4-5) also provide a centralised mechanism for managing and withdrawing consent across multiple Data Fiduciaries. Upon receiving a withdrawal request, the Data Fiduciary must cease processing the personal data covered by the withdrawn consent and cause its Data Processors to do the same. The processing must stop within the timeframe prescribed by the Rules.

Consequences of Withdrawal

The withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal. This is consistent with the GDPR's approach and provides legal certainty to Data Fiduciaries. However, the Data Fiduciary may inform the Data Principal of the consequences of withdrawal - such as loss of access to a service - before processing the withdrawal. The Data Fiduciary must not make withdrawal conditional upon accepting unfavourable terms or use withdrawal as a basis for discrimination.

Granular and Partial Withdrawal

Where consent has been given for multiple purposes, the Data Principal should be able to withdraw consent for specific purposes while maintaining consent for others. The itemised privacy notice requirement under Rule 3 supports this by ensuring that consent is purpose-specific. Conversely, where a service inherently requires processing for multiple purposes, withdrawal of consent for one purpose may necessitate termination of the entire service. The Data Fiduciary must clearly communicate this to the Data Principal.

Interaction with Legitimate Uses (Section 7)

Consent withdrawal does not affect processing that is based on legitimate uses under Section 7. If a Data Fiduciary processes data both on the basis of consent and legitimate uses, withdrawal of consent only affects the consent-based processing. For example, an employer may process employee data under the employment legitimate use (Section 7(i)) and also collect consent-based marketing preferences. Withdrawal of marketing consent does not affect the employer's ability to process employment-related data.

Frequently Asked Questions

Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.