DPDP Wiki Talk to us

/Glossary · Defined term

verifiable consent

Defined in rule 2(1)(d) of the Rules.

Official definition

Official definition

Verbatim

Rules, rule 2(1)(d)

(d) “verifiable consent” means a consent as specified in rule 10 or 11.

Interpretation in plain English

Interpretation · not legal advice
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.
Data FiduciaryData Principal

The Digital Personal Data Protection Rules, 2025 define the term "verifiable consent" simply by referencing other specific rules. According to the text, verifiable consent means a consent that is specified in either rule 10 or rule 11. The definition does not list any independent conditions, methods, or technical standards on its own.

Instead, this definition acts as a direct pointer. To understand exactly what steps must be taken or what standards must be met for consent to be considered verifiable, a reader must look directly at the text of rule 10 and rule 11.

This means that for a Data Fiduciary (the person or entity determining the purpose and means of processing personal data) to obtain verifiable consent from a Data Principal (the individual to whom the data relates), they must follow the exact specifications laid out in those two specific rules.

Key points

  • The term "verifiable consent" is defined strictly by reference to rule 10 or rule 11. (Rule 2(1)(d))
  • The definition does not contain its own separate requirements or methods for how consent is verified. (Rule 2(1)(d))

Common misreadings

  • A reader might expect the definitions section to explain how to verify consent, but the text only points to rule 10 and rule 11 for those details.

Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.

/MYND · DPDP practice

Putting this into practice?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.