---
title: "Consent and notice"
url: https://dpdp.myndsolution.com/wiki/faq/consent-and-notice/
description: "What valid consent looks like, what a notice must contain under rule 3, how withdrawal works, legitimate uses, Consent Managers and existing customers."
kind: faq
updated: 2026-09-09
text_type: analysis
publisher: MYND Integrated Solutions
license: Official Government of India texts are reproduced verbatim (public domain / open government data). Interpretation is CC BY 4.0, MYND Integrated Solutions.
disclaimer: Not legal advice. Official text prevails over any interpretation.
html_version: https://dpdp.myndsolution.com/wiki/faq/consent-and-notice/
---
# Consent and notice

> This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.

## What counts as valid consent under the DPDP Act?

Consent must be "free, specific, informed, unconditional and unambiguous with a clear affirmative action", it must signify agreement to processing for the specified purpose, and it is limited to the personal data necessary for that purpose ([section 6(1)](/wiki/act/section-6/)). Anything bundled in beyond that is not covered: the Act's illustration is a telemedicine app that asks for both health processing and the phone contact list, where consent is read down to the telemedicine purpose alone. Any part of a consent that infringes the Act, the Rules or another law is invalid to that extent ([section 6(2)](/wiki/act/section-6/)). The request itself must be in clear and plain language, offered in English or any language in the Eighth Schedule to the Constitution, and must carry the contact details of the Data Protection Officer or another authorised person ([section 6(3)](/wiki/act/section-6/)).

## What must a privacy notice contain?

The Act requires a notice with or before every consent request, telling the person the personal data and the purpose, how to exercise her rights under section 6(4) and section 13, and how to complain to the Board ([section 5(1)](/wiki/act/section-5/)). [Rule 3](/wiki/rules/rule-3/) adds the detail. The notice must be understandable on its own, independently of any other information the Data Fiduciary makes available. In clear and plain language it must give a fair account of what is needed for specific and informed consent, including at the minimum "an itemised description of such personal data" and the specified purposes with a specific description of the goods or services to be provided. It must also give the particular communication link for the website or app, and describe other means, for withdrawing consent, exercising rights and complaining to the Board.

## Can consent be withdrawn, and how easy must that be?

Yes, at any time. Where consent is the basis of processing, the Data Principal has the right to withdraw it "at any time, with the ease of doing so being comparable to the ease with which such consent was given" ([section 6(4)](/wiki/act/section-6/)). [Rule 3](/wiki/rules/rule-3/) reinforces this by requiring the notice itself to point to the communication link and other means for withdrawal, again with comparable ease. A consent that took two taps to give cannot take a written letter to undo.

## What happens after someone withdraws consent?

Three things follow. The consequences of withdrawal are borne by the Data Principal, and withdrawal does not affect the legality of processing done before it ([section 6(5)](/wiki/act/section-6/)). The Data Fiduciary must then, within a reasonable time, cease and cause its Data Processors to cease processing, unless that processing without consent is required or authorised by the Act, the Rules or another law in force in India ([section 6(6)](/wiki/act/section-6/)). And unless retention is necessary for compliance with a law, the Data Fiduciary must erase the personal data and cause its Data Processor to erase it ([section 8(7)](/wiki/act/section-8/)). The Act's own illustration allows an e-commerce seller to finish supplying goods already ordered and paid for.

## Do I need consent to process employee data?

Not always. Processing is lawful either with consent or for "certain legitimate uses" ([section 4(1)](/wiki/act/section-4/)), and one of those uses is employment. [Section 7(i)](/wiki/act/section-7/) covers processing "for the purposes of employment or those related to safeguarding the employer from loss or liability, such as prevention of corporate espionage, maintenance of confidentiality of trade secrets, intellectual property, classified information or provision of any service or benefit sought by a Data Principal who is an employee". Note what this does not do: it does not switch off the rest of the Act. Security safeguards ([section 8(5)](/wiki/act/section-8/)), breach intimation ([section 8(6)](/wiki/act/section-8/)), accuracy, erasure and grievance redressal still apply to employee data.

## What are "certain legitimate uses"?

They are the nine uses listed in [section 7](/wiki/act/section-7/), and the phrase is defined as exactly those uses ([section 2(d)](/wiki/act/section-2/)). They are: data voluntarily provided for a specified purpose where the person has not indicated she objects; provision of a prescribed subsidy, benefit, service, certificate, licence or permit by the State; performance of a State function under law or in the interest of sovereignty, integrity or security; complying with a legal disclosure obligation to the State; complying with a judgment, decree or order; a medical emergency; medical treatment or health services during an epidemic or other threat to public health; safety and assistance during a disaster or breakdown of public order; and employment purposes. [Rule 5](/wiki/rules/rule-5/) and the [Second Schedule](/wiki/rules/schedule-2/) set the standards the State must follow for the subsidy and benefit ground.

## What is a Consent Manager?

A Consent Manager is "a person registered with the Board, who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw her consent through an accessible, transparent and interoperable platform" ([section 2(g)](/wiki/act/section-2/)). A Data Principal may route her consent through one ([section 6(7)](/wiki/act/section-6/)), the Consent Manager is accountable to her and acts on her behalf ([section 6(8)](/wiki/act/section-6/)), and it must be registered with the Board ([section 6(9)](/wiki/act/section-6/)). [Rule 4](/wiki/rules/rule-4/) and the [First Schedule](/wiki/rules/schedule-1/) set the conditions: a company incorporated in India, net worth "not less than two crore rupees", independent certification of its platform, records kept for at least seven years, contents it shares kept unreadable by it, and no sub-contracting of its obligations.

## Do I need fresh consent from customers who signed up before the Act?

No fresh consent, but you do owe them a notice. Where consent was given before the Act commenced, the Data Fiduciary must, "as soon as it is reasonably practicable", give the Data Principal a notice covering the personal data and the purpose it has been processed for, how she may exercise her rights under section 6(4) and section 13, and how she may complain to the Board ([section 5(2)](/wiki/act/section-5/)). Processing may continue "until and unless the Data Principal withdraws her consent". The Act's illustration contemplates an e-commerce operator sending this by email, in-app notification or another effective method.

## Who has to prove that consent was actually obtained?

The Data Fiduciary. Where consent is the basis of processing and a question about it arises in a proceeding, the Data Fiduciary "shall be obliged to prove" that it gave the notice and that the Data Principal gave consent in accordance with the Act and the Rules ([section 6(10)](/wiki/act/section-6/)). In practice that means keeping a record of the notice text shown, the consent captured and the time it was captured. Neither the Act nor the Rules prescribe a format or a retention period for a Data Fiduciary's own consent records, although a Consent Manager must keep its records for at least seven years under the [First Schedule](/wiki/rules/schedule-1/).
