DPDP Wiki Talk to us

/Guides · Product & compliance teams

Consent, notice and Consent Managers under the DPDP Act

How consent must be obtained, what the notice must say, how consent is withdrawn, and what a registered Consent Manager does.

Interpretation · not legal adviceUpdated 9 September 20268 min read
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation. Every statement links to the official provision it rests on.

Consent is one of only two grounds on which personal data may be processed under the DPDP Act. The Act says what a valid consent looks like, what has to be told to the person first, and how she can take it back; the Rules add the shape of the notice and the registration regime for Consent Managers.

Two grounds, and nothing else#

Personal data of a Data Principal, the individual the data is about, may be processed only in accordance with the Act and for a lawful purpose, and only with her consent or for one of the "certain legitimate uses" (section 4(1)). A lawful purpose is defined negatively: any purpose not expressly forbidden by law (section 4(2)).

Every consent request must be accompanied or preceded by a notice from the Data Fiduciary, the person who decides the purpose and means of processing. It must state the personal data and the purpose of the proposed processing, how she may exercise her right to withdraw consent and her right of grievance redressal, and how she may complain to the Board (section 5(1)).

Rule 3 sets the standard for the notice itself. It must be understandable independently of any other information the Data Fiduciary has made available, so it cannot be folded into a long terms-of-service document. In clear and plain language it must give a fair account of the details needed for specific and informed consent: at a minimum an itemised description of the personal data, the specified purpose or purposes, and a specific description of the goods or services to be provided or uses to be enabled. It must also give the particular communication link, and describe any other means, by which she may withdraw consent, exercise her rights and complain to the Board.

Where consent was given before the Act commenced, the same three items must be given as soon as reasonably practicable, and processing may continue until she withdraws consent (section 5(2)). Either notice must be available in English or any language in the Eighth Schedule to the Constitution (section 5(3)).

Consent must be "free, specific, informed, unconditional and unambiguous with a clear affirmative action", must signify agreement to processing for the specified purpose, and is limited to the personal data necessary for that purpose (section 6(1)). In the Act's illustration, a telemedicine app asks for both service data and the user's contact list; the contact list is not necessary, so consent is read down to the service data alone.

Any part of a consent that infringes the Act, the Rules or another law is invalid to that extent (section 6(2)), as in the Act's illustration of an insurance form that also purports to waive the right to complain to the Board. Every consent request must be in clear and plain language, offer the same choice of language, and carry the contact details of a Data Protection Officer where applicable, or of another authorised person (section 6(3)).

Withdrawal#

Where consent is the basis of processing, the Data Principal may withdraw it at any time, "with the ease of doing so being comparable to the ease with which such consent was given" (section 6(4)). She bears the consequences, and withdrawal does not make earlier processing unlawful (section 6(5)): a marketplace may stop accepting new orders, but must still supply goods already ordered and paid for.

The Data Fiduciary must then, within a reasonable time, cease processing and cause its Data Processors to cease, unless processing without consent is required or authorised under the Act, the Rules or another law in force in India (section 6(6)).

Certain legitimate uses#

Section 7 lists the uses that need no consent: data voluntarily provided for a specified purpose and not objected to; a prescribed subsidy, benefit, service, certificate, licence or permit provided by the State on the conditions set out there; a State function under law, or the interests of sovereignty and integrity of India or security of the State; a legal obligation to disclose information to the State; compliance with a judgment, decree or order; a medical emergency; treatment or health services during an epidemic or other threat to public health; safety and assistance during a disaster or breakdown of public order; and employment purposes, including safeguarding the employer from loss or liability.

The first is narrower than it looks. A pharmacy given a mobile number so it can send a payment receipt may use it for that. A broker asked to find rented accommodation may process the data for that search, but must cease once the customer says she no longer needs help.

A Consent Manager is "a person registered with the Board, who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw her consent through an accessible, transparent and interoperable platform" (section 2(g)). A Data Principal may give, manage, review or withdraw her consent through one (section 6(7)). The Consent Manager is accountable to her and acts on her behalf (section 6(8)), and must be registered with the Board (section 6(9)).

Getting registered#

An applicant meeting the conditions in Part A of the First Schedule may apply to the Board with the particulars and documents the Board publishes on its website. The Board may inquire as it thinks fit, then register the applicant and publish its particulars, or reject the application with reasons (rule 4).

Part A sets nine conditions: a company incorporated in India; sufficient technical, operational and financial capacity; sound finances and management character; net worth of not less than two crore rupees; adequate business volume, capital structure and earning prospects; directors, key managerial personnel and senior management of fair reputation and integrity; constitutional documents requiring adherence to items 9 and 10 of Part B, amendable only with the Board's approval; operations in the interests of Data Principals; and independent certification that the platform matches the standards the Board publishes.

The thirteen obligations#

Part B of the First Schedule applies once registered.

#Obligation
1Let a Data Principal consent to processing by an onboarded Data Fiduciary, directly or routed through another onboarded Data Fiduciary that holds her data
2Share or make data available in a form whose contents the Consent Manager cannot read
3Record consents given, denied or withdrawn, the notices with those requests, and sharing with a transferee Data Fiduciary
4Give the Data Principal access to that record, supply it machine-readable on request, and keep it at least seven years
5Maintain a website or app, or both, as the primary means of access
6Do not sub-contract or assign any obligation under the Act or the Rules
7Take reasonable security safeguards against a personal data breach
8Act in a fiduciary capacity towards the Data Principal
9Avoid conflict of interest with Data Fiduciaries, their promoters and key managerial personnel
10Guard against conflicts from its own people's directorships, financial interests, employment or beneficial ownership in Data Fiduciaries
11Publish its promoters, directors, key managerial personnel, senior management, shareholders above two per cent, bodies corporate where those people hold above two per cent, and anything the Board directs
12Run audit mechanisms over controls, registration conditions and adherence, reporting outcomes to the Board periodically
13Do not transfer control by sale, merger or otherwise without the Board's previous approval

After a hearing, the Board may direct a non-adhering Consent Manager to fix the problem, and may suspend or cancel registration and issue protective directions for recorded reasons (rule 4).

Who has to prove it#

If consent is questioned in a proceeding, the Data Fiduciary must prove that a notice was given and that consent was given in accordance with the Act and the Rules (section 6(10)). That makes a durable record of notices and consents an operational requirement.

When this starts to apply#

ProvisionIn force from
Definitions, including "Consent Manager" (section 2)13 November 2025
Consent Manager registration (section 6(9)) and rule 413 November 2026
Sections 4, 5, 6 except sub-section (9), 7, and rule 313 May 2027

Those are the date of publication, one year later and eighteen months later, fixed by G.S.R. 843(E) for the Act and rule 1 for the Rules.

Key provisions#

/MYND · DPDP practice

Want help applying this?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.