India's Digital Personal Data Protection (DPDP) Act, 2023 changes how businesses collect, use and manage personal data.
The substantive consent requirements under Section 6 of the DPDP Act are scheduled to come into force on 13 May 2027. Businesses should use the period before commencement to prepare the processes, systems and controls needed to meet these requirements.
Obtaining consent is not simply about displaying a privacy policy or adding a checkbox to a registration form. Where processing relies on consent, businesses need to ensure that individuals understand what they are agreeing to, can withdraw their consent and have their preferences respected throughout the data processing lifecycle.
The Digital Personal Data Protection Rules, 2025 were published in the Official Gazette dated 13 November 2025. Certain government online listings and communications reflect 14 November 2025 as the publication or notification listing date; however, the Gazette itself is dated 13 November 2025. For the phased commencement timeline in this article, the Gazette date is used.
Under the phased commencement framework, provisions relating to registered Consent Managers are scheduled to come into force on 13 November 2026, while the broader notice, consent, withdrawal and related substantive requirements are scheduled to take effect on 13 May 2027.
For businesses collecting customer, employee or other personal data, compliance involves more than updating legal documents. Consent must be supported by appropriate processes, technical controls, records and withdrawal mechanisms.
This guide focuses specifically on DPDP consent management: what valid consent means, what businesses need to implement and how to prepare for the applicable commencement dates.
What Is Consent Management Under the DPDP Act?
DPDP consent management is the process through which a business obtains, records, manages and honours an individual's consent for processing personal data.
Under Section 6 of the DPDP Act, consent must be:
Free
Specific
Informed
Unconditional
Unambiguous
It must involve a clear affirmative action and be limited to personal data necessary for the specified purpose.
Individuals must also be able to withdraw consent with ease comparable to the process through which it was given.
In practical terms, an effective consent management process should enable a business to:
Establish what an individual agreed to
Demonstrate that valid consent was obtained
Identify the processing covered by the consent
Track the current status of consent
Respond appropriately when consent is withdrawn
Importantly, consent is not the only permitted basis for processing personal data under the Act.
Section 7 also recognises certain legitimate uses. Businesses should therefore assess the appropriate legal basis for each processing activity rather than assuming that every processing activity requires consent.
Why Consent Management Matters for Businesses
Many organisations collect personal data through multiple channels, including websites, mobile applications, registration forms, marketing campaigns, customer-support systems and third-party platforms.
The challenge is ensuring that consent obtained through these channels remains consistent with how personal data is actually processed.
For example, a customer might agree to receive promotional communications when registering for a service. If that customer later withdraws consent, the withdrawal needs to be reflected in the systems responsible for those communications.
A change recorded in one application is of limited practical value if other connected systems continue processing the data for the withdrawn purpose.
The DPDP Act also places responsibility on the Data Fiduciary to demonstrate that appropriate notice was provided and valid consent was obtained when consent is questioned in a proceeding.
This makes reliable consent records an important part of compliance.
Businesses therefore need a process that connects consent collection with the activities, applications and service providers that rely on it.
What Businesses Need to Implement for DPDP Consent Management
An operational consent management framework should address eight core areas:
Data mapping
Consent notices
Valid consent collection
Consent records
Withdrawal mechanisms
System integration
Existing consent review
Monitoring and testing
1. Identify Where Consent Is Required
Before implementing a consent management system, businesses need to understand which processing activities rely on consent.
Start by identifying:
Where personal data is collected
What personal data is collected
Why it is processed
Which systems use it
Whether it is shared with third parties
Which legal basis applies
For every processing activity, assess whether consent is the appropriate basis or whether a certain legitimate use under Section 7 applies.
Section 7(a): Certain Legitimate Use
Section 7(a) may permit processing where:
The Data Principal voluntarily provides personal data to the Data Fiduciary for a specified purpose; and
The Data Principal has not indicated that they do not consent to the use of the personal data for that specified purpose.
Organisations should assess the specific statutory conditions of Section 7(a) before relying on it for a processing activity. It should not be treated as a general alternative to consent.
For example, if a customer voluntarily provides a mobile number and asks a business to send confirmation of a transaction to that number, the business may process the number for that specified purpose where the conditions of Section 7(a) are satisfied.
However, the fact that an individual voluntarily provided personal data for one purpose does not automatically permit its use for an unrelated purpose. The same mobile number should not automatically be used for promotional marketing merely because it was provided for transaction confirmation.
Each further processing activity should be assessed against the applicable basis under the Act.
The outcome of this exercise should be a data inventory connecting personal data categories, processing purposes, applicable legal bases, responsible teams, supporting systems and relevant Data Processors.
This helps businesses avoid requesting unnecessary consent while identifying where consent collection and withdrawal mechanisms must be implemented.
2. Provide Clear and Purpose-Specific Consent Notices
A privacy policy alone is not a substitute for a compliant consent notice.
Section 5 of the Act and Rule 3 of the DPDP Rules establish requirements relating to information provided to individuals when consent is sought.
A consent notice should be understandable independently of other information supplied by the organisation and should use clear and plain language.
It should identify:
The personal data being processed
The specified purpose or purposes
Relevant goods, services or uses enabled by the processing
How consent may be withdrawn
How Data Principal rights may be exercised
How complaints may be made to the Data Protection Board
Businesses must also provide individuals with the option to access notices and consent requests in English or a language specified in the Eighth Schedule to the Constitution.
In practice, organisations should review every relevant touchpoint where consent is requested, including account registration, application onboarding, marketing preferences, subscription forms, optional communication preferences and other data-collection processes.
The objective is to ensure that individuals can understand the processing activity before deciding whether to consent.
3. Implement Valid Consent Collection
Businesses relying on consent must ensure that their consent collection mechanisms meet the requirements of Section 6 once the applicable provisions come into force.
Consent must result from a clear affirmative action.
It should not be inferred from:
Silence
Inactivity
Pre-selected options
Ambiguous behaviour
Consent requests should clearly identify the specified purpose or purposes for which personal data will be processed and should enable the Data Principal to understand what they are agreeing to.
Where distinct, unrelated or optional processing purposes are involved, businesses should avoid combining them in a manner that makes the scope of consent unclear or prevents an informed and meaningful choice.
Does Every Purpose Need a Separate Checkbox?
Not necessarily.
The DPDP Act does not prescribe a separate checkbox for every individual processing purpose in all cases. However, consent must clearly identify the specified purpose or purposes and enable the Data Principal to make an informed and unambiguous choice.
Where purposes are distinct or optional, organisations should present them clearly so that individuals understand what they are agreeing to and can make a meaningful choice.
Consent for one purpose should not automatically be treated as consent for an unrelated purpose.
Example: Optional Marketing Consent
Consider a business that asks a customer to register for an online service and separately offers promotional communications.
The consent interface could state:
Communication Preferences
We would like to send you product updates and promotional offers by email. You can withdraw your consent at any time through your account settings.
☐ I agree to receive promotional emails.
This gives the customer a clear choice about the optional marketing activity without automatically treating registration as agreement to receive marketing communications.
Businesses should also review whether the personal data requested under each consent is necessary for the stated purpose.
Consent does not authorise collecting additional personal data unrelated to that specified purpose.
4. Maintain Reliable Consent Records
Collecting consent is only one part of compliance.
Businesses must also be able to demonstrate that valid consent was obtained in accordance with the Act.
A practical consent management system should retain sufficient evidence to reconstruct the consent transaction when necessary.
Recommended implementation records may include:
The individual or account associated with the consent
The specific processing purpose
The personal data covered by the consent
The version of the notice presented
The version of the consent request
The date and time of consent
The method or channel through which consent was provided
The affirmative action taken
The current consent status
Relevant withdrawal history
These are recommended implementation fields. They should not be interpreted as a separately prescribed statutory consent-record format that every Data Fiduciary must use.
Businesses should establish appropriate retention and access controls for consent records based on applicable legal requirements and operational needs.
Maintaining an accurate consent history can help internal teams investigate complaints, confirm individual preferences, demonstrate consent history, verify withdrawal implementation and support internal compliance assessments.
5. Make Consent Withdrawal Easy
Under Section 6(4), a Data Principal must be able to withdraw consent at any time, with ease comparable to the process through which consent was given.
Businesses should therefore review whether their withdrawal mechanisms are genuinely accessible and straightforward.
For example, if a customer provides consent through an online account, requiring the individual to complete a complicated offline process merely to withdraw consent may not align with the requirement.
When consent is withdrawn, the Data Fiduciary must, within a reasonable time, cease the relevant consent-based processing and cause its Data Processors to cease that processing, unless continued processing is otherwise required or authorised under the Act or another applicable law.
In other words, withdrawal ends processing that depends on that consent. Any continued processing must be supported by another applicable legal authorisation.
Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Businesses should establish a clear process to:
Receive the withdrawal request
Record the request
Identify the affected processing activity
Identify affected applications and systems
Notify relevant Data Processors
Stop the relevant consent-based processing
Record completion of the withdrawal action
A withdrawal process should be tested end to end rather than considered complete merely because a user interface shows that the preference has changed.
6. Connect Consent Management to Business Systems
A business may collect consent in one application while processing the associated personal data across several others.
For example, consent collected through a website may affect:
A customer relationship management system
An email marketing platform
An analytics application
A mobile application
A third-party service provider
Businesses should identify these dependencies and establish a process for updating affected systems whenever a consent preference changes.
Depending on the organisation's size and technology environment, this may involve automated integrations, APIs, centralised preference management, workflow automation or controlled manual processes.
The important objective is that the organisation can honour consent and withdrawal across the processing activities concerned.
Technical and operational controls should also prevent consent-based processing from continuing where valid consent has not been obtained or where consent has subsequently been withdrawn.
7. Review Consent Obtained Before Commencement
Businesses should not overlook personal data collected before the relevant DPDP provisions come into force.
Section 5(2) addresses situations where a Data Principal provided consent before commencement of the applicable provision.
In such cases, the Data Fiduciary must provide the prescribed notice as soon as reasonably practicable following commencement.
The Act permits continued processing on the basis of the earlier consent unless and until the individual withdraws it, subject to the applicable provisions.
This does not mean that every existing consent must automatically be collected again.
Organisations should review existing consent practices and records to identify any gaps and prepare to provide the required notices.
This review should include:
Existing consent records
Relevant processing purposes
Incomplete records
Required notices
Outdated or unclear consent practices
Appropriate remediation measures
Where existing consent records are incomplete or the original consent may not meet the applicable requirements, appropriate remediation should be assessed.
The objective is to understand the organisation's existing position and address identified gaps rather than automatically treating every historic consent as invalid or requiring universal re-consent.
8. Establish Consent Monitoring and Internal Controls
Consent management requires ongoing oversight.
Businesses should assign responsibility for:
Maintaining consent notices
Managing consent records
Responding to withdrawals
Reviewing system changes
Monitoring third-party processing
Testing consent controls
Internal reviews should verify that:
Consent is collected for approved purposes
Consent notices remain accurate
Notice versions are controlled
Consent records are complete
Withdrawal requests are processed correctly
Connected systems reflect the Data Principal's current preferences
Data Processors receive relevant updates
Testing should also cover changes to existing processing activities.
If an organisation introduces a new processing purpose requiring consent, its existing consent records should not automatically be treated as authorising that new activity.
Regular review helps organisations identify operational gaps before they become compliance issues.
What Is a Consent Manager Under the DPDP Act?
The DPDP Act gives Consent Manager a specific legal meaning.
A Consent Manager is an intermediary registered with the Data Protection Board that acts on behalf of Data Principals and enables them to give, manage, review and withdraw consent through an interoperable platform.
It is important to distinguish a registered statutory Consent Manager from an ordinary consent management system used internally by a business.
Internal Consent Management System | Registered Consent Manager |
Used by a business to collect and manage consent relating to its own processing activities | Acts on behalf of Data Principals across participating Data Fiduciaries |
Helps the organisation maintain consent records and implement withdrawal | Enables individuals to manage consent through an interoperable platform |
Does not require Consent Manager registration merely because the organisation manages consent internally | Must be registered with the Data Protection Board |
Designed according to the organisation's applicable DPDP obligations | Subject to Rule 4 and the First Schedule |
A business does not automatically become a statutory Consent Manager simply because it uses consent management software or manages consent internally.
Similarly, commencement of the Consent Manager provisions does not mean that every Data Fiduciary must register as, or integrate with, a Consent Manager.
What Must Registered Consent Managers Implement?
Rule 4 and the First Schedule establish specific requirements for organisations intending to operate as registered Consent Managers.
Applicants must satisfy prescribed eligibility requirements relating to matters such as incorporation in India, net worth, technical and operational capability, financial capability, governance and independence.
Registered Consent Managers also have obligations relating to:
Interoperable consent management
Recordkeeping
Security
Independence
Transparency
Audit mechanisms
Among other requirements, they must maintain prescribed records relating to consent given, denied or withdrawn, associated notices and relevant personal-data sharing.
They must provide Data Principals access to relevant records and retain required records for the prescribed period.
Registered Consent Managers must also ensure that the contents of personal data made available or shared through their arrangements are not readable by the Consent Manager itself.
Importantly, these Consent Manager-specific requirements should not automatically be treated as universal recordkeeping or retention requirements for every Data Fiduciary.
Special Considerations for Children's Consent
Organisations processing children's personal data need to address additional consent requirements.
Under the DPDP Act, a child is an individual who has not completed 18 years of age.
Subject to applicable exemptions, Data Fiduciaries must obtain verifiable parental consent before processing children's personal data.
Rule 10 specifies relevant technical and organisational measures and due-diligence requirements relating to verification of the parent or lawful guardian, as applicable.
Businesses operating platforms used by children should therefore assess how these requirements affect:
Account registration
Age verification
Parental authorisation
Identity verification
Consent collection
Consent records
The appropriate implementation will depend on the processing activity, applicable provisions and any available exemptions.
When Must Businesses Implement DPDP Consent Management?
The consent-related provisions follow a phased commencement timeline.
Date | Consent-related milestone |
13 November 2025 | Gazette publication date. Certain initial provisions and the framework relating to establishment and administration of the Data Protection Board came into force. |
13 November 2026 | Consent Manager registration and associated Rule 4 provisions are scheduled to come into force, based on the one-year commencement period measured from the Gazette date. |
13 May 2027 | Broader notice, consent, withdrawal and related substantive provisions, including the substantive consent requirements under Section 6, are scheduled to come into force, based on the eighteen-month commencement period. |
Date clarification: The relevant Official Gazette is dated 13 November 2025. Some Government online materials/listings refer to 14 November 2025 in connection with publication or notification. This article uses the date appearing in the Official Gazette when describing the phased commencement timeline. Businesses should nevertheless check the latest official notifications when finalising their compliance timelines.
These dates should not be treated as a single universal compliance deadline.
The requirements applicable to an organisation depend on its activities and the provisions relevant to it.
For ordinary Data Fiduciaries, the practical priority is to prepare consent notices, consent collection mechanisms, consent records, withdrawal processes, data inventories, system integrations and monitoring controls ahead of the applicable commencement dates.
Organisations intending to operate as registered Consent Managers should separately prepare for the Rule 4 registration framework.
A Practical DPDP Consent Management Implementation Plan
Businesses can organise implementation into three stages.
Stage 1: Assess Existing Practices
Identify:
Consent-based processing activities
Relevant personal data
Existing consent notices
Existing consent collection methods
Applicable legal bases
Systems relying on consent
Data Processors relying on consent
Existing withdrawal mechanisms
Stage 2: Implement the Required Controls
Implement or improve:
Consent notices
Consent interfaces
Consent records
Withdrawal processes
System integrations
Processor communication workflows
Responsibility assignments
Stage 3: Test and Verify Readiness
Conduct testing to confirm that:
Consent collection operates as intended
Consent records are accurate
Withdrawal requests are properly processed
Downstream systems receive preference changes
Data Processors respond appropriately
Responsible teams understand the process
Businesses should retain evidence of implementation work, including approved consent notices, consent configurations, test results, internal procedures, review records and relevant training evidence.
These records can support internal assessments and demonstrate how consent management controls operate.
Common DPDP Consent Management Mistakes to Avoid
Several implementation gaps can arise when organisations focus only on the consent collection interface rather than the complete processing lifecycle.
Common mistakes include:
Relying only on a general privacy policy
Using unclear or overly broad consent wording
Combining unrelated processing purposes without adequate clarity
Treating consent for one purpose as consent for an unrelated purpose
Treating silence or inactivity as consent
Failing to preserve evidence of consent
Failing to maintain consent history
Making withdrawal unnecessarily difficult
Failing to update connected systems after withdrawal
Continuing consent-based processing after withdrawal without another applicable legal authorisation
Assuming every processing activity requires consent
Assuming every purpose legally requires a separate checkbox
Assuming every organisation must become a registered Consent Manager
Applying Consent Manager-specific obligations to every Data Fiduciary
An effective implementation should reflect the organisation's actual processing activities and the specific statutory provisions applicable to those activities.
Conclusion
DPDP consent management is an ongoing operational responsibility, not a one-time exercise in updating privacy policies.
Businesses relying on consent need to connect clear notices and valid consent collection with accurate records, accessible withdrawal processes and the systems that process personal data.
They should also distinguish between activities that genuinely require consent and those that may fall within the certain legitimate uses recognised under Section 7, ensuring that the applicable statutory conditions are satisfied before relying on those provisions.
With the substantive consent requirements under Section 6 scheduled to come into force on 13 May 2027, organisations should use the preparation period to assess existing practices and implement the controls relevant to their processing activities.
By identifying processing activities that require consent, implementing appropriate controls and testing their effectiveness ahead of the applicable commencement dates, organisations can establish a consent management programme that supports compliance and gives individuals meaningful control over their personal data.
FAQ


