Consent is the engine of the DPDP Act — and the place where most Indian organisations are non-compliant today without realising it. The Act doesn't just require consent; it defines precisely what consent must look like. Miss one element and the consent is void, making the processing itself unlawful. Here are the seven requirements, with real-world pass/fail examples.
Consent must be given without coercion, pressure or imbalance being exploited. Fails: "Accept all data uses or you cannot enter the premises." Passes: a genuine choice where refusing non-essential processing doesn't block the core service.
Consent attaches to a specified purpose. One blanket consent covering "services, marketing, analytics, partners and improvements" is not specific — each materially different purpose needs its own consent. Fails: a single checkbox for delivery and marketing and data sharing. Passes: separate, per-purpose choices.
Consent must follow a notice that tells the principal, in clear and plain language: what personal data is collected, the purpose of processing, how to exercise rights, and how to complain to the Board. The notice must be understandable on its own — not buried in a 40-page terms document — and available in English or any of the 22 Eighth Schedule languages.
Access to goods or services cannot be conditioned on consent to processing that isn't necessary for that service. Fails: a food delivery app refusing to work unless you consent to sharing data with "marketing partners". Passes: delivery requires your address (necessary); promotional profiling is a separate, refusable ask.
Silence, inactivity, pre-ticked boxes and "by continuing you agree" banners are all invalid. The principal must do something — tick, click, sign, state — that unambiguously signals agreement. Audit your forms today: every pre-ticked box on a lead form, admission form or app signup is a live violation.
Consent covers only personal data necessary for the specified purpose. Collecting extra fields "while we're at it" — date of birth for a newsletter, Aadhaar for a gym membership — exceeds the consent even if the form was otherwise compliant. Data minimisation is baked into consent validity.
The principal may withdraw consent at any time, and the ease of withdrawal must match the ease of giving. If signup was one click, withdrawal cannot be a phone call, an email to legal and a 30-day wait. On withdrawal, you (and your processors) must stop processing and erase within a reasonable time, unless retention is legally required — withdrawal must propagate to every downstream system.
When a complaint reaches the Data Protection Board, the burden is effectively yours: prove this person consented, to this purpose, after this notice, on this date. That demands consent records — who, when, which notice version, which purposes, and every subsequent change or withdrawal — retained in tamper-evident form. A consent your systems cannot evidence is, for regulatory purposes, a consent that doesn't exist.
This is precisely what a consent management platform automates. Privonta Shield's consent module generates compliant notices, captures per-purpose consent with evidence, and propagates withdrawal — so validity is engineered in, not audited after.
Consent is only as valid as the notice that precedes it. Under the Act and Rules, the notice must be a standalone document, understandable on its own, in clear and plain language, and must set out:
A notice buried inside 40 pages of terms and conditions does not satisfy this, even if every element is technically present somewhere in the document.
This is the question that decides how much work you face. Consent obtained before the Act's obligations bite does not automatically become valid — where you relied on consent that would not meet the Act's standard, the Act contemplates giving data principals a fresh, compliant notice so they can make an informed choice about continued processing.
Practically, that means auditing your existing consent base and sorting it into three buckets: consent that already meets the standard and can be evidenced (keep, with records intact); consent that is defective but where processing can continue under a legitimate use such as employment purposes or legal compliance (re-map the basis, stop calling it consent); and consent that is defective with no alternative basis (serve a fresh notice and re-obtain, or stop the processing). Most organisations discover their marketing database sits squarely in the third bucket.
Step 5 is where most audits produce their sharpest findings, because withdrawal is the requirement organisations design last and test never.
Privonta Shield helps Companies, Government, SMEs and Education Institutes meet every DPDP obligation — data discovery, consent management, rights workflows and audit trails, deployed inside your own boundary. Book a free DPDP assessment →
Get a personalised compliance assessment — free, no obligation.
Book a Free Assessment →