What counts as valid consent under DPDP?
By dpdprules.org editorial team · Reviewed by dpdprules.org source verificationPublished · Last reviewed
The short answer
Consent must be free, specific, informed, unconditional and unambiguous, given with a clear affirmative action, and it covers only the personal data necessary for the specified purpose. Any part of consent infringing the Act or another law is invalid to that extent. Withdrawal must be as easy as giving consent, and after withdrawal the Data Fiduciary must stop processing and cause its processors to stop, within a reasonable time, unless another basis allows it. In a proceeding, the Data Fiduciary carries the burden of proving notice was given and consent taken.
Consent is the framework's default basis for processing, and section 6 defines it tightly enough that most legacy consent flows need rework.
Five qualities plus an action
"The consent given by the Data Principal shall be free, specific, informed, unconditional and unambiguous with a clear affirmative action, and shall signify an agreement to the processing of her personal data for the specified purpose and be limited to such personal data as is necessary for such specified purpose."
Two consequences follow directly. Pre ticked boxes and silence fail the clear affirmative action requirement. And bundled scope fails the necessity limit: the section's own illustration invalidates a telemedicine app's grab of a phone contact list, because the contact list is not necessary for telemedicine.
Invalid parts fall away
Any part of consent that infringes the Act or another law is invalid to that extent. The section illustrates it with a consent purporting to waive the right to complain to the Board: that part simply does not count.
Withdrawal is a design requirement
Withdrawal must be possible at any time with ease comparable to how consent was given, its consequences fall on the individual, and it does not undo the legality of processing already done. After withdrawal, the Data Fiduciary must within a reasonable time stop processing and cause its Data Processors to stop, unless processing without consent is otherwise authorised.
You carry the proof
Where consent is the basis and a question arises in a proceeding, the Data Fiduciary must prove notice was given and consent was taken as required. Dated records of every consent screen version stop being nice to have.
What to do
The notice that precedes consent has its own requirement list under Rule 3; check yours against it element by element.
Sources cited on this page
- [1]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 6, p. 5. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026Section 6 begins on Gazette page 5 and concludes on page 6.