AMLEGALS — Strategic Lawyering

DPDPA Consent Requirements: Consent Is a Contract You Must Prove

DPDPA Consent Requirements: Consent Is a Contract You Must Prove

Consent obtained minus consent understood equals no defence.

The scene

The marketing team had eighty thousand opt-ins. Legal asked a simple question: opt-in to what, shown which notice, on which date, in which language? The answer lived in a vendor's logs that had rotated out months ago. Eighty thousand consents became eighty thousand assertions.

Where the thinking breaks

The unclear thought What it breaks The clearer thought

One checkbox covers everything.

Section 6 requires consent to be specific to a purpose; bundling fails that test.

One purpose, one ask. Let the customer say yes to some and no to others.

Withdrawal is an email to support.

Section 6(4) requires withdrawal to be as easy as giving consent.

Put withdrawal where consent was given, one tap away.

The notice is in the privacy policy.

Section 5 requires a notice at or before the request, in clear language, with options in scheduled languages.

Show the notice at the moment of the ask, not in the footer.

Consent managers

The Act introduces registered consent managers: platforms through which Data Principals give, manage and withdraw consent. Registration opens under the Rules' phased timeline. They will change who holds the record of consent.

Monday morning

01 Screenshot every place you ask for consent today.

02 For each, write the purpose in one sentence. If you cannot, the ask is not specific.

03 Test withdrawal yourself. Time it.

Questions, answered plainly

What makes consent valid under DPDPA? +

Section 6 requires consent to be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to personal data necessary for the specified purpose. It must be as easy to withdraw as to give.

Does DPDPA allow pre-ticked consent boxes? +

Consent must be signified by a clear affirmative action. A pre-ticked box is not an action by the Data Principal and is unlikely to meet the standard.

Who are consent managers under DPDPA? +

Consent managers are entities registered with the Data Protection Board that let Data Principals give, manage, review and withdraw consent through an accessible, interoperable platform. They act on behalf of the Data Principal.

Argument 05 Silence after a breach is the most expensive sound. Read →

Argument 06 You can outsource the processing. You cannot outsource the liability. Read →

Argument 07 Privacy is not a department. It is a board decision. Read →

Tell us where your data sits. We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner →

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).