Unlike Europe’s GDPR, which allows organizations to process personal data on multiple legal grounds including ‘legitimate interest’ India’s Digital Personal Data Protection Act, 2023 places consent as the primary legal basis for processing. This means if you are collecting personal data from Indian users and you do not have a clear, valid, and documented consent from them, you are at risk.
This guide breaks down everything you need to know about consent under DPDP.
What Is Consent Under the DPDP Act?
Consent under the DPDP Act means that a person has voluntarily, knowingly, and clearly agreed to let your organization collect and use their personal data for a specific purpose.
For consent to be valid under DPDP, it must be:
- Free — the person must not be forced or pressured. You cannot make consent a condition for accessing your core service unless the data is genuinely needed for that service.
- Specific — tied to one clearly defined purpose, not a vague umbrella.
- Informed — the person must understand what data is being collected and why, in simple language.
- Unambiguous — a clear action like clicking an opt-in button, not a pre-ticked box.
- Revocable — the person must be able to withdraw consent at any time, without any difficulty.
Why Your Old Consent Process Probably Does Not Work Anymore
Most businesses today still rely on one of these outdated practices:
- A long privacy policy buried in the website footer
- A pre-checked ‘I agree to the terms’ checkbox during signup
- A vague cookie banner that says ‘We use cookies for a better experience’
None of these are compliant under the DPDP Act.
The Rules 2025 are clear: your privacy notice must be a standalone document written in plain language. It must list each category of personal data you collect, state the specific purpose for each, and include a direct method for users to withdraw consent or raise a complaint.
What Is a Consent Management Platform and Why Do You Need One?
A Consent Management Platform (CMP) is a software system that helps you collect, store, manage, and audit user consent. Think of it as the operational backbone of your consent process.
If your business processes data for more than a few hundred users, you need one. Here is why:
- You need a time-stamped, tamper-proof record of every consent given.
- You need to honour withdrawal requests immediately not in three days, not next week.
- You need to link consent records to specific purposes, so you can prove what a user agreed to and when.
- When the Data Protection Board audits you, you need documentation, not just assurances.
A proper CMP handles all of this automatically.
The Consent Manager : India’s Unique Innovation
The DPDP Act introduces something called a Consent Manager — a registered intermediary that helps users manage their data permissions across different platforms from one place.
Think of it like a dashboard where a user can see every organization that holds their data, what they agreed to, and revoke any consent with a single click — across multiple companies at once.
Consent Managers must register with the Data Protection Board. Registration opens in November 2026 — 12 months after the Rules were notified. To qualify, a Consent Manager must:
- Have a minimum net worth of at least two crore rupees
- Operate with complete neutrality they cannot use or access the data they manage on behalf of users
- Support large-scale consent management across platforms
This is a uniquely Indian innovation no other data protection law in the world has created this kind of interoperable consent infrastructure at this scale.
How to Collect Valid Consent?
Step 1: Write a Clear Notice Before Collecting Data
Before you collect any personal data, show the user a standalone notice that explains exactly what you are collecting and why. No bundled terms and conditions. No fine print. Plain language, preferably in the language of the user’s choice.
Step 2: Get an Explicit Opt-In
Use a clear, affirmative action a checkbox the user ticks, a button they click, or a confirmation they send. Pre-filled boxes do not count.
Step 3: Record and Timestamp the Consent
Your system must log the consent who gave it, when, for what purpose, and what data was involved. This record must be tamper-proof and retrievable in case of an audit.
Step 4: Make Withdrawal Simple
Provide a clear, accessible method for users to withdraw their consent at any time. When a user withdraws, you must stop processing their data and, in most cases, delete it. This must happen quickly.
What About Children’s Consent?
If your platform is used by anyone under 18, additional rules apply. You must obtain verifiable consent from a parent or legal guardian before processing a child’s data. The DPDP Rules suggest using existing verification systems such as DigiLocker.
You are also not allowed to show targeted advertising to minors or track their behaviour for profiling purposes.
When Can You Process Data Without Consent?
The DPDP Act does allow a limited set of situations where data can be processed without consent called ‘legitimate uses.’ These include:
- Government functions and public interest activities
- Legal obligations the business must comply with
- Medical emergencies
- Employment-related data processing within defined limits
These exceptions are narrow. Most business use cases — marketing, analytics, product improvement, third-party sharing — will still require consent.
How DPDP AI Helps You Get Consent Right
Managing consent manually across thousands of users is not practical. DPDP AI’s platform automates the entire consent lifecycle collecting notices in 22 Indian languages, recording timestamps, handling re-consent when your purpose changes, processing withdrawal requests in real time, and generating audit-ready reports for regulators.
Consent is not a form on your website. It is a continuous system. The right platform makes that system invisible to your team while keeping it fully operational.
The Bottom Line
Consent under the DPDP Act is a new standard — stricter, more user-friendly, and backed by penalties that can reach ₹250 crore. The organizations that get this right are not just avoiding fines. They are building something more valuable: customer trust.
Start by auditing your current consent process. Ask yourself: can I prove, right now, that every user whose data I hold has clearly agreed to the specific purposes I am using it for? If the answer is not a confident yes, it is time to act.
