DPDP Act consent requirements: what valid consent looks like
4 min read · Updated 30 September 2026
Consent is the main legal ground for processing personal data under India's Digital Personal Data Protection Act, 2023 (DPDP Act). If your organisation decides why and how personal data is processed, you are a Data Fiduciary, and the Act puts the burden on you to get consent right and to prove it.
This guide summarises what the Act asks for.
When you need consent
Section 4 allows processing of personal data only for a lawful purpose, and only:
- with the consent of the Data Principal (the person the data is about), or
- for one of the legitimate uses listed in Section 7.
Legitimate uses are narrow. They include data a person voluntarily gives for a specified purpose without objecting to its use, certain functions of the State, legal obligations, medical emergencies, disasters and some employment purposes. For most product, marketing and analytics processing, consent is the ground you will rely on.
The five conditions for valid consent
Section 6(1) says consent must be:
- Free — not forced or bundled with something unrelated.
- Specific — given for a specified purpose, not a blanket "any purpose".
- Informed — given after the person received a proper notice.
- Unconditional — not tied to accepting unrelated terms.
- Unambiguous, with a clear affirmative action — a positive act such as ticking an unticked box or pressing an "I agree" button. Silence, pre-ticked boxes and inactivity do not count.
Consent must also be limited to the personal data necessary for the specified purpose. Section 6(2) makes any part of a consent that infringes the Act invalid to that extent.
The notice that must come with the request
Under Section 5, every request for consent must be accompanied or preceded by a notice that tells the Data Principal:
- the personal data you will process and the purpose;
- how they can withdraw consent and exercise their rights, including grievance redressal; and
- how they can complain to the Data Protection Board of India.
The request must be in clear and plain language, and the person must be able to read it in English or any of the 22 languages in the Eighth Schedule of the Constitution (Section 6(3)). The DPDP Rules, 2025 add detail on what the notice must contain. See our consent notice checklist.
For personal data you already hold from before the Act took effect, Section 5(2) requires you to send a notice as soon as reasonably practicable.
Withdrawal must be as easy as giving consent
Section 6(4) lets a Data Principal withdraw consent at any time, and the ease of withdrawing must be comparable to the ease of giving consent. If consent takes one click, withdrawal cannot require an email to a support desk.
After withdrawal you must, within a reasonable time, stop processing that data and cause your Data Processors to stop too (Section 6(6)), unless the Act or another law allows you to keep processing. Withdrawal does not make earlier processing unlawful.
You must be able to prove consent
Section 6(10) puts the burden of proof on the Data Fiduciary. If there is a dispute, you have to show that a notice was given and consent was given, for that purpose, by that person. In practice that means keeping a reliable record of:
- which notice version the person saw;
- what they agreed to, when, and through which channel;
- every later change: renewal, update or withdrawal.
Children and persons with disabilities
Under the Act a child is anyone under 18. Section 9 requires verifiable consent of a parent or lawful guardian before processing a child's personal data, and prohibits processing that is likely to harm a child, as well as tracking, behavioural monitoring and targeted advertising directed at children. The same guardian consent applies to a person with a disability who has a lawful guardian.
Consent Managers
Section 6(7) lets a Data Principal give, manage, review and withdraw consent through a Consent Manager, a platform registered with the Data Protection Board. See what a Consent Manager is under the DPDP Act.
Penalties
The Schedule to the Act sets maximum penalties per instance, including:
| Breach | Maximum penalty |
|---|---|
| Failure to take reasonable security safeguards to prevent a personal data breach | ₹250 crore |
| Failure to notify the Board and affected persons of a breach | ₹200 crore |
| Breach of obligations for children's data | ₹200 crore |
| Breach of additional obligations of Significant Data Fiduciaries | ₹150 crore |
| Any other breach of the Act or Rules | ₹50 crore |
A practical checklist
- Map each processing activity to a specified purpose and the data it needs.
- Show a notice before or with every consent request, in the user's language.
- Collect consent with a clear affirmative action, never pre-ticked.
- Offer withdrawal as easy as giving consent, and propagate it to processors.
- Keep a tamper-evident record of notices shown and consents given and changed.
- Handle children's data with verifiable parental consent.
- Give people a way to access, correct and erase their data and to raise grievances.
Consentrio covers each item on this list: versioned notices, consent capture SDKs, one-click withdrawal with processor notifications, rights and grievance handling, and a hash-chained audit trail that serves as proof.
This guide is general information, not legal advice. Check the Act and the Rules, or ask your counsel, for decisions about your organisation.