KryptoMindz Technologies

KryptoMindz Insight · DPDP Act

DPDP Act Consent Requirements

Under India's DPDP Act, consent must be free, specific, informed, unconditional and unambiguous — given through a clear affirmative action and easy to withdraw. Here is what that means for product design.

By 11 min read Reviewed August 7, 2026

Key takeaways

  • Consent must be free, specific, informed, unconditional and unambiguous — pre-ticked boxes and silence do not qualify.
  • Every consent request must be preceded by an itemized notice; under the Rules, notices must also be available in English and the scheduled Indian languages.
  • Withdrawal must be as easy as giving consent, and from Phase 2 (November 2026), registered Consent Managers will let users manage consent across fiduciaries.

Consent is the engine of the DPDP regime

Unlike frameworks built on a menu of lawful bases, the DPDP Act is consent-led. Processing of personal data requires either consent or one of the limited lawful purposes the Act recognises. That makes consent quality a first-class product requirement: if your consent flows are weak, your entire processing posture is weak.

The five qualities of valid consent

Section 6 of the DPDP Act requires consent to be:

Notice before consent

Section 5 requires that a request for consent be preceded by a notice. That notice must be itemized and easy to understand, stating the personal data being collected, the purpose of processing, how to exercise rights and how to contact the fiduciary. The DPDP Rules, 2025 add a practical requirement: notices must be made available in English and all 22 scheduled Indian languages.

Notice text is not static. When you change what you collect or why, the notice version changes — and the consent tied to it should be revisited. Versioned, traceable notice records are exactly the kind of evidence that matters if the Data Protection Board or an auditor ever asks which notice was live when consent was captured.

Designing consent flows that survive scrutiny

Consent should be designed as a state, not a one-time event:

Dark patterns are a compliance risk

Interfaces that bury consent, make withdrawal difficult, use confusing toggles or bundle unrelated processing undermine the statutory qualities of consent. Beyond reputational risk, they create exactly the kind of evidence a regulator would examine. The Rules and the Act's principles point the same direction: consent screens should be clear, balanced and truthful.

Review your consent architecture before Phase 2

KryptoMindz designs consent and notice architecture, withdrawal workflows and Consent Manager readiness for global and India-facing products.

Discuss Your Consent Design

Go deeper