AMLEGALS — Strategic Lawyering
Consent

How to Implement Consent Management Under DPDPA

Building consent architecture that satisfies legal requirements while maintaining user experience

Updated 18 January 2025

Executive Summary

Consent under the DPDPA must be free, specific, informed, unconditional, and unambiguous. These requirements demand more than a terms acceptance checkbox. This guide addresses the legal, technical, and operational dimensions of consent management that organisations must navigate.

Key Takeaways

  • 1
    Design consent requests that are genuinely informative rather than legally comprehensive but incomprehensible
  • 2
    Implement granular consent for distinct processing purposes rather than bundled permissions
  • 3
    Ensure withdrawal mechanisms are as accessible as consent collection
  • 4
    Maintain auditable records of consent including version, timestamp, and scope
  • 5
    Plan for consent refresh when processing purposes expand

1Understanding Section 6 Requirements

Section 6 establishes that consent must accompany or precede any processing of personal data. The consent must relate to specified data for a specified purpose. This specificity requirement precludes broad, catch-all consent that attempts to cover future, undefined uses. Importantly, consent cannot be a condition for providing goods or services unless necessary for performance.

Important Warnings

  • •Pre-ticked checkboxes do not constitute valid consent
  • •Consent obtained through deceptive dark patterns is voidable

2Designing the Consent Request

The consent request is the interface between legal requirements and user understanding. It must communicate processing purposes clearly without overwhelming users with legal terminology.

1

Identify Distinct Purposes

Separate processing purposes that require independent consent. Marketing communications, analytics, and service delivery should not be combined into a single consent request.

2

Draft Plain Language Descriptions

Explain each processing purpose in language a reasonable person without legal training would understand. Avoid technical jargon and defined terms where simpler alternatives exist.

3

Specify Data Categories

Identify what personal data will be processed for each purpose. Users should understand what they are consenting to share.

4

Disclose Recipients

Where data will be shared with third parties, identify them by name or category with sufficient specificity.

5

State Retention Periods

Communicate how long data will be retained for each purpose.

Practical Tips

  • •Test consent language with actual users before deployment
  • •Consider localisation for audiences whose primary language is not English

3Technical Implementation

Consent management requires technical infrastructure to collect, record, honour, and demonstrate consent. Many organisations implement a Consent Management Platform integrated with their data processing systems.

1

Consent Collection Interface

Build or configure interfaces that present consent requests at appropriate points in the user journey. Ensure consent is collected before any non-essential processing begins.

2

Consent Record Storage

Maintain immutable records of each consent interaction including the exact language presented, user response, timestamp, and method of collection.

3

Consent Status Propagation

Ensure consent decisions are communicated to all systems that process the relevant data. A withdrawal in one channel must take effect across all processing.

4

Consent Enforcement

Implement technical controls that prevent processing absent valid consent. Do not rely solely on policy compliance.

4Withdrawal Mechanisms

Section 6(4) requires that withdrawal of consent be as easy as giving consent. This seemingly simple requirement has significant operational implications. If users can consent with a single tap, they must be able to withdraw with equivalent ease.

1

Accessible Withdrawal Options

Provide withdrawal mechanisms through the same channels used for collection. A consent given through a mobile app should be withdrawable through that app.

2

Clear Withdrawal Process

Users should not need to navigate complex menus or contact support to withdraw consent. Provide direct, obvious options.

3

Confirmation and Acknowledgment

Confirm withdrawal receipt and communicate the effective timeline. Explain any processing that will continue on other legal bases.

4

Technical Effectuation

Ensure withdrawal triggers actual cessation of processing within reasonable timeframes. Document the technical mechanisms that enforce withdrawal.

Important Warnings

  • •Requiring users to email support or call a helpline to withdraw consent likely fails the accessibility requirement
  • •Partial withdrawal may be complex to implement but must be supported for granular consents

5Record Keeping for Accountability

Demonstrating valid consent requires comprehensive records. The burden of proving consent rests with the Data Fiduciary, making record keeping essential for both compliance and dispute resolution.

1

Consent Receipt Generation

Generate and store a complete record of each consent interaction including identity verification method, exact notice presented, user action, and timestamp.

2

Version Control

Maintain historical versions of consent notices. When notices change, record which version each user consented to.

3

Audit Trail

Log all consent related events including grants, withdrawals, and modifications with timestamps and attribution.

6Special Considerations for Children's Data

Processing children's personal data requires verifiable consent from a parent or lawful guardian. This introduces additional complexity in consent collection and verification.

1

Age Verification

Implement mechanisms to identify users below the threshold age. While DPDPA does not specify the threshold, organisations should adopt a reasonable approach pending Rule clarification.

2

Guardian Identification

Establish procedures to identify and verify parents or lawful guardians before collecting their consent.

3

Consent Verification

Implement verification measures proportionate to the risk. Low risk processing may require less stringent verification than sensitive data collection.

Frequently Asked Questions

Need Implementation Support?

Our data protection team can help translate these guidelines into organisation-specific policies, procedures, and technical implementations.

Get Expert Guidance

Implement Consent Management: questions and answers

When do DPDPA obligations apply to businesses?

The Act and Rules follow phased commencement. Institutional provisions commenced on 13 November 2025; Consent Manager provisions commence after 12 months on 13 November 2026; and the principal Data Fiduciary, rights, breach, security and enforcement provisions commence after 18 months on 13 May 2027.

What must a DPDPA privacy notice contain?

Section 5 read with Rule 3 requires a notice, understandable independently of other information, that itemises the personal data and the specified purpose, and explains how the Data Principal may withdraw consent, exercise rights and complain to the Board. A Data Principal has the right to access the notice in English or any language specified in the Eighth Schedule to the Constitution. The design of translation operations is an implementation matter.

When must personal data be erased under DPDPA?

Section 8(7) requires erasure once the specified purpose is no longer served or consent is withdrawn, unless retention is required by law. Rule 8 and the Third Schedule prescribe time periods for specified classes of Data Fiduciaries, with prior intimation to the Data Principal before erasure.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to Implement Consent Management?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on Implement Consent Management under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on Implement Consent Management under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on Implement Consent Management?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for Implement Consent Management rather than a generic checklist.

How do I get a first view of my DPDPA exposure on Implement Consent Management?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about Implement Consent Management · DPDPA Exposure Assessment