DPDP Wiki Talk to us

/The Act · Chapter II · Obligations of Data Fiduciary

Section 6: Consent

DPDP Act, 2023 (No. 22 of 2023). Comes into force on 13 November 2026.

UpcomingOfficial textComes into force on 13 November 2026 (phase 2) G.S.R. 843(E)Chapter II: Obligations of Data Fiduciary
Provision
Section 6 of The Digital Personal Data Protection Act, 2023
Status
Comes into force on 13 November 2026 (phase 2) G.S.R. 843(E)
Rules made under it
Rule 4
Source
Ministry of Law and Justice (Legislative Department) · 11 August 2023 · Official PDF

Section 6. Consent

Verbatim from the Gazette of India
(1)

The consent given by the Data Principal shall be free, specific, informed, unconditional and unambiguous with a clear affirmative action, and shall signify an agreement to the processing of her personal data for the specified purpose and be limited to such personal data as is necessary for such specified purpose.

(2)

Any part of consent referred in sub-section (1) which constitutes an infringement of the provisions of this Act or the rules made thereunder or any other law for the time being in force shall be invalid to the extent of such infringement.

(3)

Every request for consent under the provisions of this Act or the rules made thereunder shall be presented to the Data Principal in a clear and plain language, giving her the option to access such request in English or any language specified in the Eighth Schedule to the Constitution and providing the contact details of a Data Protection Officer, where applicable, or of any other person authorised by the Data Fiduciary to respond to any communication from the Data Principal for the purpose of exercise of her rights under the provisions of this Act.

(4)

Where consent given by the Data Principal is the basis of processing of personal data, such Data Principal shall have the right to withdraw her consent at any time, with the ease of doing so being comparable to the ease with which such consent was given.

(5)

The consequences of the withdrawal referred to in sub-section (4) shall be borne by the Data Principal, and such withdrawal shall not affect the legality of processing of the personal data based on consent before its withdrawal.

(6)

If a Data Principal withdraws her consent to the processing of personal data under sub-section (5), the Data Fiduciary shall, within a reasonable time, cease and cause its Data Processors to cease processing the personal data of such Data Principal unless such processing without her consent is required or authorised under the provisions of this Act or the rules made thereunder or any other law for the time being in force in India.

(7)

The Data Principal may give, manage, review or withdraw her consent to the Data Fiduciary through a Consent Manager.

(8)

The Consent Manager shall be accountable to the Data Principal and shall act on her behalf in such manner and subject to such obligations as may be prescribed.

(9)

Every Consent Manager shall be registered with the Board in such manner and subject to such technical, operational, financial and other conditions as may be prescribed.

(10)

Where a consent given by the Data Principal is the basis of processing of personal data and a question arises in this regard in a proceeding, the Data Fiduciary shall be obliged to prove that a notice was given by her to the Data Principal and consent was given by such Data Principal to the Data Fiduciary in accordance with the provisions of this Act and the rules made thereunder.

Interpretation in plain English

Interpretation · not legal advice
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.
Data PrincipalData FiduciaryData ProcessorConsent ManagerBoard

Under Section 6, when a Data Fiduciary (the entity determining the purpose and means of processing data) relies on consent to process personal data, that consent must be free, specific, informed, unconditional, and unambiguous. The Data Principal (the individual to whom the data relates) must take a clear affirmative action to agree. Importantly, consent is strictly limited to the personal data that is actually necessary for the specified purpose. Any part of the consent agreement that violates this Act or other laws is automatically invalid.

Requests for consent must be presented in clear and plain language. The Data Fiduciary must give the Data Principal the option to view the request in English or any language listed in the Eighth Schedule to the Constitution. The request must also include the contact details of a Data Protection Officer or another authorized person who can respond to the Data Principal's communications regarding their rights.

A Data Principal has the right to withdraw their consent at any time, and doing so must be as easy as giving it. While the Data Principal bears the consequences of withdrawing consent, the withdrawal does not make past data processing illegal. Once consent is withdrawn, the Data Fiduciary must stop processing the data within a reasonable time and ensure its Data Processors (entities processing data on its behalf) stop as well, unless another law requires the processing to continue.

Data Principals can choose to give, manage, review, or withdraw their consent through a Consent Manager. A Consent Manager is accountable directly to the Data Principal and must be registered with the Board (the Data Protection Board of India) under conditions that may be prescribed by rules. Finally, if a dispute arises, the Data Fiduciary bears the burden of proving that it provided proper notice and obtained valid consent.

Key points

  • Consent must be free, specific, informed, unconditional, unambiguous, and limited only to the data necessary for the specified purpose (1).
  • Any part of a consent agreement that violates the Act or other laws is invalid (2).
  • Consent requests must be in clear language, offer options for English or Eighth Schedule languages, and provide contact details for a Data Protection Officer or authorized person (3).
  • Data Principals can withdraw consent at any time, and the process must be as easy as giving consent (4).
  • Upon withdrawal, the Data Fiduciary and its Data Processors must stop processing the data within a reasonable time, unless another law requires it (6).
  • If challenged in a proceeding, the Data Fiduciary must prove that it gave notice and obtained valid consent (10).

Common misreadings

  • Assuming a Data Fiduciary can process any data as long as the Data Principal clicks 'I agree'; the law limits consent only to data strictly necessary for the specified purpose.
  • Believing that withdrawing consent makes the previous processing of data illegal; the text states withdrawal does not affect the legality of processing done before the withdrawal.

Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.

/MYND · DPDP practice

Putting this into practice?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.