AMLEGALS — Strategic Lawyering
Consent

How to Design Consent Collection Mechanisms

Creating user interfaces that obtain valid, informed consent

Updated 9 January 2025

Executive Summary

The manner in which consent is requested significantly impacts its validity. Dark patterns, manipulative design, and obscured choices undermine consent quality regardless of what users click. This guide addresses how to design consent interfaces that are both legally compliant and genuinely informative.

Key Takeaways

  • 1
    Present choices clearly without manipulative design elements
  • 2
    Make accepting and declining equally accessible
  • 3
    Provide information before requesting the consent action
  • 4
    Test designs with actual users to verify comprehension
  • 5
    Document design decisions to demonstrate good faith

1Principles of Consent Interface Design

Effective consent interfaces balance legal requirements, user experience, and genuine informed choice. The goal is not merely to obtain clicks but to enable users to make meaningful decisions about their data.

2Avoiding Dark Patterns

Dark patterns are design choices that manipulate users toward outcomes they would not choose if presented fairly. DPDPA prohibits deceptive practices that undermine consent quality.

1

Reject Confirmshaming

Do not use emotionally manipulative language like 'No thanks, I don't care about my privacy' for decline options.

2

Avoid Hidden Options

Do not make decline or customisation options harder to find than accept options.

3

Eliminate Misdirection

Do not use visual hierarchy, colour, or positioning to push users toward a particular choice.

4

Remove Obstacles

Do not require more steps to decline than to accept. Consent and refusal should be equally accessible.

5

Stop Nagging

Do not repeatedly prompt users who have declined until they relent. Respect their choice.

Important Warnings

  • •Consent obtained through dark patterns is voidable under Section 6
  • •Regulatory enforcement increasingly focuses on consent interface design

3Information Architecture

Users need relevant information before making consent decisions. How this information is structured affects comprehension.

1

Layered Disclosure

Provide essential information prominently with additional detail available on request. Users should not need to read lengthy documents to understand basic choices.

2

Purpose-Centric Organisation

Organise information around processing purposes rather than legal categories. Users understand 'We want to send you marketing emails' better than 'legitimate interest processing under Section 7'.

3

Just-In-Time Information

Provide information at the moment it is relevant. Explain location tracking when requesting location permission, not buried in a privacy policy.

4

Visual Aids

Consider icons, illustrations, or diagrams that communicate concepts quickly. Visual communication can be more effective than text for some audiences.

4Choice Architecture

How choices are presented influences decisions. Ethical design presents choices neutrally.

1

Equal Prominence

Give accept and decline options equal visual weight. Same size, same colours, same position treatment.

2

Clear Labels

Use unambiguous labels that tell users exactly what each option does. 'Accept all cookies' is clearer than 'Continue'.

3

Granular Options

Where appropriate, allow users to accept some processing while declining others. Forced all-or-nothing choices may not satisfy specificity requirements.

4

Sensible Defaults

Default settings should be privacy protective. Users who do not engage should not find themselves opted into extensive data processing.

5Mobile Considerations

Mobile interfaces present particular challenges for consent collection.

1

Screen Real Estate

Limited space requires careful prioritisation. Focus on essential information with clear paths to detail.

2

Touch Targets

Ensure all options have adequate touch target size. Small decline buttons that are hard to tap fail the accessibility requirement.

3

Scroll Behaviour

Do not hide key information or options below the fold where users might not scroll. Critical elements should be immediately visible.

4

Operating System Integration

Leverage operating system permission dialogues where appropriate. Users are familiar with these patterns.

6Testing and Iteration

Good intentions do not guarantee good outcomes. Testing reveals whether designs actually work.

1

User Comprehension Testing

Test whether users understand what they are consenting to. Ask them to explain in their own words.

2

A/B Testing Ethically

If testing variations, do not optimise solely for consent rates. Consider comprehension and satisfaction alongside acceptance.

3

Accessibility Testing

Verify that consent interfaces work for users with disabilities, including screen reader users and those with motor impairments.

4

Iterate Based on Feedback

Use testing insights to improve designs. Consent interfaces should evolve with user understanding and regulatory guidance.

7Documentation

Document design decisions to demonstrate good faith compliance.

1

Design Rationale

Record why specific design choices were made, particularly where alternatives were considered and rejected.

2

Testing Results

Maintain records of user testing and how results informed design.

3

Version History

Keep records of interface versions and when they were deployed. This supports demonstrating what users saw at specific times.

Frequently Asked Questions

Need Implementation Support?

Our data protection team can help translate these guidelines into organisation-specific policies, procedures, and technical implementations.

Get Expert Guidance

Design Consent Collection Mechanisms: questions and answers

When do DPDPA obligations apply to businesses?

The Act and Rules follow phased commencement. Institutional provisions commenced on 13 November 2025; Consent Manager provisions commence after 12 months on 13 November 2026; and the principal Data Fiduciary, rights, breach, security and enforcement provisions commence after 18 months on 13 May 2027.

What must a DPDPA privacy notice contain?

Section 5 read with Rule 3 requires a notice, understandable independently of other information, that itemises the personal data and the specified purpose, and explains how the Data Principal may withdraw consent, exercise rights and complain to the Board. A Data Principal has the right to access the notice in English or any language specified in the Eighth Schedule to the Constitution. The design of translation operations is an implementation matter.

When must personal data be erased under DPDPA?

Section 8(7) requires erasure once the specified purpose is no longer served or consent is withdrawn, unless retention is required by law. Rule 8 and the Third Schedule prescribe time periods for specified classes of Data Fiduciaries, with prior intimation to the Data Principal before erasure.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to Design Consent Collection Mechanisms?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on Design Consent Collection Mechanisms under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on Design Consent Collection Mechanisms under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on Design Consent Collection Mechanisms?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for Design Consent Collection Mechanisms rather than a generic checklist.

How do I get a first view of my DPDPA exposure on Design Consent Collection Mechanisms?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about Design Consent Collection Mechanisms · DPDPA Exposure Assessment