Back to all posts

October 06, 2026

DPDP Consent Management: What Businesses Need to Implement

India's Digital Personal Data Protection (DPDP) Act, 2023 changes how businesses collect, use and manage personal data. 

The substantive consent requirements under Section 6 of the DPDP Act are scheduled to come into force on 13 May 2027. Businesses should use the period before commencement to prepare the processes, systems and controls needed to meet these requirements. 

Obtaining consent is not simply about displaying a privacy policy or adding a checkbox to a registration form. Where processing relies on consent, businesses need to ensure that individuals understand what they are agreeing to, can withdraw their consent and have their preferences respected throughout the data processing lifecycle. 

The Digital Personal Data Protection Rules, 2025 were published in the Official Gazette dated 13 November 2025. Certain government online listings and communications reflect 14 November 2025 as the publication or notification listing date; however, the Gazette itself is dated 13 November 2025. For the phased commencement timeline in this article, the Gazette date is used. 

Under the phased commencement framework, provisions relating to registered Consent Managers are scheduled to come into force on 13 November 2026, while the broader notice, consent, withdrawal and related substantive requirements are scheduled to take effect on 13 May 2027. 

For businesses collecting customer, employee or other personal data, compliance involves more than updating legal documents. Consent must be supported by appropriate processes, technical controls, records and withdrawal mechanisms. 

This guide focuses specifically on DPDP consent management: what valid consent means, what businesses need to implement and how to prepare for the applicable commencement dates.

What Is Consent Management Under the DPDP Act?   

DPDP consent management is the process through which a business obtains, records, manages and honours an individual's consent for processing personal data. 

Under Section 6 of the DPDP Act, consent must be: 

  • Free 

  • Specific 

  • Informed 

  • Unconditional 

  • Unambiguous 

It must involve a clear affirmative action and be limited to personal data necessary for the specified purpose. 

Individuals must also be able to withdraw consent with ease comparable to the process through which it was given. 

In practical terms, an effective consent management process should enable a business to: 

  • Establish what an individual agreed to 

  • Demonstrate that valid consent was obtained 

  • Identify the processing covered by the consent 

  • Track the current status of consent 

  • Respond appropriately when consent is withdrawn 

Importantly, consent is not the only permitted basis for processing personal data under the Act. 

Section 7 also recognises certain legitimate uses. Businesses should therefore assess the appropriate legal basis for each processing activity rather than assuming that every processing activity requires consent.

Why Consent Management Matters for Businesses 

Many organisations collect personal data through multiple channels, including websites, mobile applications, registration forms, marketing campaigns, customer-support systems and third-party platforms. 

The challenge is ensuring that consent obtained through these channels remains consistent with how personal data is actually processed. 

For example, a customer might agree to receive promotional communications when registering for a service. If that customer later withdraws consent, the withdrawal needs to be reflected in the systems responsible for those communications. 

A change recorded in one application is of limited practical value if other connected systems continue processing the data for the withdrawn purpose. 

The DPDP Act also places responsibility on the Data Fiduciary to demonstrate that appropriate notice was provided and valid consent was obtained when consent is questioned in a proceeding. 

This makes reliable consent records an important part of compliance. 

Businesses therefore need a process that connects consent collection with the activities, applications and service providers that rely on it. 

What Businesses Need to Implement for DPDP Consent Management 

An operational consent management framework should address eight core areas: 

  1. Data mapping 

  2. Consent notices 

  3. Valid consent collection 

  4. Consent records 

  5. Withdrawal mechanisms 

  6. System integration 

  7. Existing consent review 

  8. Monitoring and testing 


1. Identify Where Consent Is Required 

Before implementing a consent management system, businesses need to understand which processing activities rely on consent. 

Start by identifying: 

  • Where personal data is collected 

  • What personal data is collected 

  • Why it is processed 

  • Which systems use it 

  • Whether it is shared with third parties 

  • Which legal basis applies 

For every processing activity, assess whether consent is the appropriate basis or whether a certain legitimate use under Section 7 applies. 


Section 7(a): Certain Legitimate Use 

Section 7(a) may permit processing where: 

  • The Data Principal voluntarily provides personal data to the Data Fiduciary for a specified purpose; and 

  • The Data Principal has not indicated that they do not consent to the use of the personal data for that specified purpose. 

Organisations should assess the specific statutory conditions of Section 7(a) before relying on it for a processing activity. It should not be treated as a general alternative to consent. 

For example, if a customer voluntarily provides a mobile number and asks a business to send confirmation of a transaction to that number, the business may process the number for that specified purpose where the conditions of Section 7(a) are satisfied. 

However, the fact that an individual voluntarily provided personal data for one purpose does not automatically permit its use for an unrelated purpose. The same mobile number should not automatically be used for promotional marketing merely because it was provided for transaction confirmation. 

Each further processing activity should be assessed against the applicable basis under the Act. 

The outcome of this exercise should be a data inventory connecting personal data categories, processing purposes, applicable legal bases, responsible teams, supporting systems and relevant Data Processors. 

This helps businesses avoid requesting unnecessary consent while identifying where consent collection and withdrawal mechanisms must be implemented. 


2. Provide Clear and Purpose-Specific Consent Notices 

A privacy policy alone is not a substitute for a compliant consent notice. 

Section 5 of the Act and Rule 3 of the DPDP Rules establish requirements relating to information provided to individuals when consent is sought. 

A consent notice should be understandable independently of other information supplied by the organisation and should use clear and plain language. 

It should identify: 

  • The personal data being processed 

  • The specified purpose or purposes 

  • Relevant goods, services or uses enabled by the processing 

  • How consent may be withdrawn 

  • How Data Principal rights may be exercised 

  • How complaints may be made to the Data Protection Board 

Businesses must also provide individuals with the option to access notices and consent requests in English or a language specified in the Eighth Schedule to the Constitution. 

In practice, organisations should review every relevant touchpoint where consent is requested, including account registration, application onboarding, marketing preferences, subscription forms, optional communication preferences and other data-collection processes. 

The objective is to ensure that individuals can understand the processing activity before deciding whether to consent. 

3. Implement Valid Consent Collection 

Businesses relying on consent must ensure that their consent collection mechanisms meet the requirements of Section 6 once the applicable provisions come into force. 

Consent must result from a clear affirmative action. 

It should not be inferred from: 

  • Silence 

  • Inactivity 

  • Pre-selected options 

  • Ambiguous behaviour 

Consent requests should clearly identify the specified purpose or purposes for which personal data will be processed and should enable the Data Principal to understand what they are agreeing to. 

Where distinct, unrelated or optional processing purposes are involved, businesses should avoid combining them in a manner that makes the scope of consent unclear or prevents an informed and meaningful choice. 

Does Every Purpose Need a Separate Checkbox? 

Not necessarily. 

The DPDP Act does not prescribe a separate checkbox for every individual processing purpose in all cases. However, consent must clearly identify the specified purpose or purposes and enable the Data Principal to make an informed and unambiguous choice. 

Where purposes are distinct or optional, organisations should present them clearly so that individuals understand what they are agreeing to and can make a meaningful choice. 

Consent for one purpose should not automatically be treated as consent for an unrelated purpose. 

Example: Optional Marketing Consent 

Consider a business that asks a customer to register for an online service and separately offers promotional communications. 

The consent interface could state: 

Communication Preferences 

We would like to send you product updates and promotional offers by email. You can withdraw your consent at any time through your account settings. 


☐ I agree to receive promotional emails. 


This gives the customer a clear choice about the optional marketing activity without automatically treating registration as agreement to receive marketing communications. 

Businesses should also review whether the personal data requested under each consent is necessary for the stated purpose. 

Consent does not authorise collecting additional personal data unrelated to that specified purpose. 

4. Maintain Reliable Consent Records 

Collecting consent is only one part of compliance. 

Businesses must also be able to demonstrate that valid consent was obtained in accordance with the Act. 

A practical consent management system should retain sufficient evidence to reconstruct the consent transaction when necessary. 

Recommended implementation records may include: 

  • The individual or account associated with the consent 

  • The specific processing purpose 

  • The personal data covered by the consent 

  • The version of the notice presented 

  • The version of the consent request 

  • The date and time of consent 

  • The method or channel through which consent was provided 

  • The affirmative action taken 

  • The current consent status 

  • Relevant withdrawal history 

These are recommended implementation fields. They should not be interpreted as a separately prescribed statutory consent-record format that every Data Fiduciary must use. 

Businesses should establish appropriate retention and access controls for consent records based on applicable legal requirements and operational needs. 

Maintaining an accurate consent history can help internal teams investigate complaints, confirm individual preferences, demonstrate consent history, verify withdrawal implementation and support internal compliance assessments. 

5. Make Consent Withdrawal Easy 

Under Section 6(4), a Data Principal must be able to withdraw consent at any time, with ease comparable to the process through which consent was given. 

Businesses should therefore review whether their withdrawal mechanisms are genuinely accessible and straightforward. 

For example, if a customer provides consent through an online account, requiring the individual to complete a complicated offline process merely to withdraw consent may not align with the requirement. 

When consent is withdrawn, the Data Fiduciary must, within a reasonable time, cease the relevant consent-based processing and cause its Data Processors to cease that processing, unless continued processing is otherwise required or authorised under the Act or another applicable law. 

In other words, withdrawal ends processing that depends on that consent. Any continued processing must be supported by another applicable legal authorisation. 

Withdrawal does not affect the lawfulness of processing carried out before the withdrawal. 

Businesses should establish a clear process to: 

  • Receive the withdrawal request 

  • Record the request 

  • Identify the affected processing activity 

  • Identify affected applications and systems 

  • Notify relevant Data Processors 

  • Stop the relevant consent-based processing 

  • Record completion of the withdrawal action 

A withdrawal process should be tested end to end rather than considered complete merely because a user interface shows that the preference has changed. 

6. Connect Consent Management to Business Systems 

A business may collect consent in one application while processing the associated personal data across several others. 

For example, consent collected through a website may affect: 

  • A customer relationship management system 

  • An email marketing platform 

  • An analytics application 

  • A mobile application 

  • A third-party service provider 

Businesses should identify these dependencies and establish a process for updating affected systems whenever a consent preference changes. 

Depending on the organisation's size and technology environment, this may involve automated integrations, APIs, centralised preference management, workflow automation or controlled manual processes. 

The important objective is that the organisation can honour consent and withdrawal across the processing activities concerned. 

Technical and operational controls should also prevent consent-based processing from continuing where valid consent has not been obtained or where consent has subsequently been withdrawn. 

7. Review Consent Obtained Before Commencement 

Businesses should not overlook personal data collected before the relevant DPDP provisions come into force. 

Section 5(2) addresses situations where a Data Principal provided consent before commencement of the applicable provision. 

In such cases, the Data Fiduciary must provide the prescribed notice as soon as reasonably practicable following commencement. 

The Act permits continued processing on the basis of the earlier consent unless and until the individual withdraws it, subject to the applicable provisions. 

This does not mean that every existing consent must automatically be collected again. 

Organisations should review existing consent practices and records to identify any gaps and prepare to provide the required notices. 

This review should include: 

  • Existing consent records 

  • Relevant processing purposes 

  • Incomplete records 

  • Required notices 

  • Outdated or unclear consent practices 

  • Appropriate remediation measures 

Where existing consent records are incomplete or the original consent may not meet the applicable requirements, appropriate remediation should be assessed. 

The objective is to understand the organisation's existing position and address identified gaps rather than automatically treating every historic consent as invalid or requiring universal re-consent. 

8. Establish Consent Monitoring and Internal Controls 

Consent management requires ongoing oversight. 

Businesses should assign responsibility for: 

  • Maintaining consent notices 

  • Managing consent records 

  • Responding to withdrawals 

  • Reviewing system changes 

  • Monitoring third-party processing 

  • Testing consent controls 


Internal reviews should verify that:

  • Consent is collected for approved purposes 

  • Consent notices remain accurate 

  • Notice versions are controlled 

  • Consent records are complete 

  • Withdrawal requests are processed correctly 

  • Connected systems reflect the Data Principal's current preferences 

  • Data Processors receive relevant updates 

Testing should also cover changes to existing processing activities. 

If an organisation introduces a new processing purpose requiring consent, its existing consent records should not automatically be treated as authorising that new activity. 

Regular review helps organisations identify operational gaps before they become compliance issues. 

What Is a Consent Manager Under the DPDP Act? 

The DPDP Act gives Consent Manager a specific legal meaning. 

A Consent Manager is an intermediary registered with the Data Protection Board that acts on behalf of Data Principals and enables them to give, manage, review and withdraw consent through an interoperable platform. 

It is important to distinguish a registered statutory Consent Manager from an ordinary consent management system used internally by a business. 


Internal Consent Management System 

Registered Consent Manager 

Used by a business to collect and manage consent relating to its own processing activities 

Acts on behalf of Data Principals across participating Data Fiduciaries 

Helps the organisation maintain consent records and implement withdrawal 

Enables individuals to manage consent through an interoperable platform 

Does not require Consent Manager registration merely because the organisation manages consent internally 

Must be registered with the Data Protection Board 

Designed according to the organisation's applicable DPDP obligations 

Subject to Rule 4 and the First Schedule 


A business does not automatically become a statutory Consent Manager simply because it uses consent management software or manages consent internally. 

Similarly, commencement of the Consent Manager provisions does not mean that every Data Fiduciary must register as, or integrate with, a Consent Manager. 

What Must Registered Consent Managers Implement? 

Rule 4 and the First Schedule establish specific requirements for organisations intending to operate as registered Consent Managers. 

Applicants must satisfy prescribed eligibility requirements relating to matters such as incorporation in India, net worth, technical and operational capability, financial capability, governance and independence. 

Registered Consent Managers also have obligations relating to: 

  • Interoperable consent management 

  • Recordkeeping 

  • Security 

  • Independence 

  • Transparency 

  • Audit mechanisms 

Among other requirements, they must maintain prescribed records relating to consent given, denied or withdrawn, associated notices and relevant personal-data sharing. 

They must provide Data Principals access to relevant records and retain required records for the prescribed period. 

Registered Consent Managers must also ensure that the contents of personal data made available or shared through their arrangements are not readable by the Consent Manager itself. 

Importantly, these Consent Manager-specific requirements should not automatically be treated as universal recordkeeping or retention requirements for every Data Fiduciary.

Special Considerations for Children's Consent 

Organisations processing children's personal data need to address additional consent requirements. 

Under the DPDP Act, a child is an individual who has not completed 18 years of age. 

Subject to applicable exemptions, Data Fiduciaries must obtain verifiable parental consent before processing children's personal data. 

Rule 10 specifies relevant technical and organisational measures and due-diligence requirements relating to verification of the parent or lawful guardian, as applicable. 

Businesses operating platforms used by children should therefore assess how these requirements affect: 

  • Account registration 

  • Age verification 

  • Parental authorisation 

  • Identity verification 

  • Consent collection 

  • Consent records 

The appropriate implementation will depend on the processing activity, applicable provisions and any available exemptions. 

When Must Businesses Implement DPDP Consent Management? 

The consent-related provisions follow a phased commencement timeline. 


Date 

Consent-related milestone 

13 November 2025 

Gazette publication date. Certain initial provisions and the framework relating to establishment and administration of the Data Protection Board came into force. 

13 November 2026 

Consent Manager registration and associated Rule 4 provisions are scheduled to come into force, based on the one-year commencement period measured from the Gazette date. 

13 May 2027 

Broader notice, consent, withdrawal and related substantive provisions, including the substantive consent requirements under Section 6, are scheduled to come into force, based on the eighteen-month commencement period. 


Date clarification: The relevant Official Gazette is dated 13 November 2025. Some Government online materials/listings refer to 14 November 2025 in connection with publication or notification. This article uses the date appearing in the Official Gazette when describing the phased commencement timeline. Businesses should nevertheless check the latest official notifications when finalising their compliance timelines. 

These dates should not be treated as a single universal compliance deadline. 

The requirements applicable to an organisation depend on its activities and the provisions relevant to it. 

For ordinary Data Fiduciaries, the practical priority is to prepare consent notices, consent collection mechanisms, consent records, withdrawal processes, data inventories, system integrations and monitoring controls ahead of the applicable commencement dates. 

Organisations intending to operate as registered Consent Managers should separately prepare for the Rule 4 registration framework.

A Practical DPDP Consent Management Implementation Plan 

Businesses can organise implementation into three stages. 


Stage 1: Assess Existing Practices 

Identify:

  • Consent-based processing activities 

  • Relevant personal data 

  • Existing consent notices 

  • Existing consent collection methods 

  • Applicable legal bases 

  • Systems relying on consent 

  • Data Processors relying on consent 

  • Existing withdrawal mechanisms 


Stage 2: Implement the Required Controls 

Implement or improve: 

  • Consent notices 

  • Consent interfaces 

  • Consent records 

  • Withdrawal processes 

  • System integrations 

  • Processor communication workflows 

  • Responsibility assignments 


Stage 3: Test and Verify Readiness 

Conduct testing to confirm that: 

  • Consent collection operates as intended 

  • Consent records are accurate 

  • Withdrawal requests are properly processed 

  • Downstream systems receive preference changes 

  • Data Processors respond appropriately 

  • Responsible teams understand the process 


Businesses should retain evidence of implementation work, including approved consent notices, consent configurations, test results, internal procedures, review records and relevant training evidence. 

These records can support internal assessments and demonstrate how consent management controls operate. 

Common DPDP Consent Management Mistakes to Avoid 

Several implementation gaps can arise when organisations focus only on the consent collection interface rather than the complete processing lifecycle. 

Common mistakes include: 

  • Relying only on a general privacy policy 

  • Using unclear or overly broad consent wording 

  • Combining unrelated processing purposes without adequate clarity 

  • Treating consent for one purpose as consent for an unrelated purpose 

  • Treating silence or inactivity as consent 

  • Failing to preserve evidence of consent 

  • Failing to maintain consent history 

  • Making withdrawal unnecessarily difficult 

  • Failing to update connected systems after withdrawal 

  • Continuing consent-based processing after withdrawal without another applicable legal authorisation 

  • Assuming every processing activity requires consent 

  • Assuming every purpose legally requires a separate checkbox 

  • Assuming every organisation must become a registered Consent Manager 

  • Applying Consent Manager-specific obligations to every Data Fiduciary 

An effective implementation should reflect the organisation's actual processing activities and the specific statutory provisions applicable to those activities. 


Conclusion 

DPDP consent management is an ongoing operational responsibility, not a one-time exercise in updating privacy policies. 

Businesses relying on consent need to connect clear notices and valid consent collection with accurate records, accessible withdrawal processes and the systems that process personal data.

They should also distinguish between activities that genuinely require consent and those that may fall within the certain legitimate uses recognised under Section 7, ensuring that the applicable statutory conditions are satisfied before relying on those provisions. 

With the substantive consent requirements under Section 6 scheduled to come into force on 13 May 2027, organisations should use the preparation period to assess existing practices and implement the controls relevant to their processing activities. 

By identifying processing activities that require consent, implementing appropriate controls and testing their effectiveness ahead of the applicable commencement dates, organisations can establish a consent management programme that supports compliance and gives individuals meaningful control over their personal data.

FAQ

Got Questions? We've Got Answers

Have questions about DPDP consent management? Explore the FAQs to understand key requirements, consent withdrawal, records, and what your business should prepare before May 2027.

Have questions about DPDP consent management? Explore the FAQs to understand key requirements, consent withdrawal, records, and what your business should prepare before May 2027.

What makes consent valid under the DPDP Act?

Does every processing purpose need a separate checkbox?

What happens when an individual withdraws consent?

Is a registered Consent Manager mandatory for every business?

When do the main DPDP consent requirements take effect?

Related resources

Related resources

Explore More

Explore More