---
title: "Section 6: Consent"
url: https://dpdp.myndsolution.com/wiki/act/section-6-consent/
description: "Section 6 of the Digital Personal Data Protection Act, 2023 (Consent). Official text verbatim, comes into force on 13 november 2026, with plain-English…"
kind: act-section
updated: 2026-09-09
official_source: https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
text_type: official-text-plus-interpretation
publisher: MYND Integrated Solutions
license: Official Government of India texts are reproduced verbatim (public domain / open government data). Interpretation is CC BY 4.0, MYND Integrated Solutions.
disclaimer: Not legal advice. Official text prevails over any interpretation.
html_version: https://dpdp.myndsolution.com/wiki/act/section-6-consent/
---
# Section 6: Consent

*The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), Chapter II: OBLIGATIONS OF DATA FIDUCIARY. Comes into force on 13 November 2026.*

## Official text

- **(1)** The consent given by the Data Principal shall be free, specific, informed, unconditional and unambiguous with a clear affirmative action, and shall signify an agreement to the processing of her personal data for the specified purpose and be limited to such personal data as is necessary for such specified purpose.

> **Illustration.** X, an individual, downloads Y, a telemedicine app. Y requests the consent of X for (i) the processing of her personal data for making available telemedicine services, and (ii) accessing her mobile phone contact list, and X signifies her consent to both. Since phone contact list is not necessary for making available telemedicine services, her consent shall be limited to the processing of her personal data for making available telemedicine services.

- **(2)** Any part of consent referred in sub-section (1) which constitutes an infringement of the provisions of this Act or the rules made thereunder or any other law for the time being in force shall be invalid to the extent of such infringement.

> **Illustration.** X, an individual, buys an insurance policy using the mobile app or website of Y, an insurer. She gives to Y her consent for (i) the processing of her personal data by Y for the purpose of issuing the policy, and (ii) waiving her right to file a complaint to the Data Protection Board of India. Part (ii) of the consent, relating to waiver of her right to file a complaint, shall be invalid.

- **(3)** Every request for consent under the provisions of this Act or the rules made thereunder shall be presented to the Data Principal in a clear and plain language, giving her the option to access such request in English or any language specified in the Eighth Schedule to the Constitution and providing the contact details of a Data Protection Officer, where applicable, or of any other person authorised by the Data Fiduciary to respond to any communication from the Data Principal for the purpose of exercise of her rights under the provisions of this Act.

- **(4)** Where consent given by the Data Principal is the basis of processing of personal data, such Data Principal shall have the right to withdraw her consent at any time, with the ease of doing so being comparable to the ease with which such consent was given.

- **(5)** The consequences of the withdrawal referred to in sub-section (4) shall be borne by the Data Principal, and such withdrawal shall not affect the legality of processing of the personal data based on consent before its withdrawal.

> **Illustration.** X, an individual, is the user of an online shopping app or website operated by Y, an e-commerce service provider. X consents to the processing of her personal data by Y for the purpose of fulfilling her supply order and places an order for supply of a good while making payment for the same. If X withdraws her consent, Y may stop enabling X to use the app or website for placing orders, but may not stop the processing for supply of the goods already ordered and paid for by X.

- **(6)** If a Data Principal withdraws her consent to the processing of personal data under sub-section (5), the Data Fiduciary shall, within a reasonable time, cease and cause its Data Processors to cease processing the personal data of such Data Principal unless such processing without her consent is required or authorised under the provisions of this Act or the rules made thereunder or any other law for the time being in force in India.

> **Illustration.** X, a telecom service provider, enters into a contract with Y, a Data Processor, for emailing telephone bills to the customers of X. Z, a customer of X, who had earlier given her consent to X for the processing of her personal data for emailing of bills, downloads the mobile app of X and opts to receive bills only on the app. X shall itself cease, and shall cause Y to cease, the processing of the personal data of Z for emailing bills.

- **(7)** The Data Principal may give, manage, review or withdraw her consent to the Data Fiduciary through a Consent Manager.

- **(8)** The Consent Manager shall be accountable to the Data Principal and shall act on her behalf in such manner and subject to such obligations as may be prescribed.

- **(9)** Every Consent Manager shall be registered with the Board in such manner and subject to such technical, operational, financial and other conditions as may be prescribed.

- **(10)** Where a consent given by the Data Principal is the basis of processing of personal data and a question arises in this regard in a proceeding, the Data Fiduciary shall be obliged to prove that a notice was given by her to the Data Principal and consent was given by such Data Principal to the Data Fiduciary in accordance with the provisions of this Act and the rules made thereunder.


## Rules made under this section

- [Rule 4: Registration and obligations of Consent Manager](https://dpdp.myndsolution.com/wiki/rules/rule-4-registration-and-obligations-of-consent-manager/)

## Interpretation in plain English (not legal advice)

> This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.

Under Section 6, when a Data Fiduciary (the entity determining the purpose and means of processing data) relies on consent to process personal data, that consent must be free, specific, informed, unconditional, and unambiguous. The Data Principal (the individual to whom the data relates) must take a clear affirmative action to agree. Importantly, consent is strictly limited to the personal data that is actually necessary for the specified purpose. Any part of the consent agreement that violates this Act or other laws is automatically invalid.

Requests for consent must be presented in clear and plain language. The Data Fiduciary must give the Data Principal the option to view the request in English or any language listed in the Eighth Schedule to the Constitution. The request must also include the contact details of a Data Protection Officer or another authorized person who can respond to the Data Principal's communications regarding their rights.

A Data Principal has the right to withdraw their consent at any time, and doing so must be as easy as giving it. While the Data Principal bears the consequences of withdrawing consent, the withdrawal does not make past data processing illegal. Once consent is withdrawn, the Data Fiduciary must stop processing the data within a reasonable time and ensure its Data Processors (entities processing data on its behalf) stop as well, unless another law requires the processing to continue.

Data Principals can choose to give, manage, review, or withdraw their consent through a Consent Manager. A Consent Manager is accountable directly to the Data Principal and must be registered with the Board (the Data Protection Board of India) under conditions that may be prescribed by rules. Finally, if a dispute arises, the Data Fiduciary bears the burden of proving that it provided proper notice and obtained valid consent.

### Key points

- Consent must be free, specific, informed, unconditional, unambiguous, and limited only to the data necessary for the specified purpose (1).
- Any part of a consent agreement that violates the Act or other laws is invalid (2).
- Consent requests must be in clear language, offer options for English or Eighth Schedule languages, and provide contact details for a Data Protection Officer or authorized person (3).
- Data Principals can withdraw consent at any time, and the process must be as easy as giving consent (4).
- Upon withdrawal, the Data Fiduciary and its Data Processors must stop processing the data within a reasonable time, unless another law requires it (6).
- If challenged in a proceeding, the Data Fiduciary must prove that it gave notice and obtained valid consent (10).

### Common misreadings

- Assuming a Data Fiduciary can process any data as long as the Data Principal clicks 'I agree'; the law limits consent only to data strictly necessary for the specified purpose.
- Believing that withdrawing consent makes the previous processing of data illegal; the text states withdrawal does not affect the legality of processing done before the withdrawal.

*Interpretation prepared 2026-09-09 from the official text only; the official text prevails.*

---
Cite as: Digital Personal Data Protection Act, 2023, s. 6. Official source: https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
