Key takeaways
- Consent must be free, specific, informed, unconditional and unambiguous — pre-ticked boxes and silence do not qualify.
- Every consent request must be preceded by an itemized notice; under the Rules, notices must also be available in English and the scheduled Indian languages.
- Withdrawal must be as easy as giving consent, and from Phase 2 (November 2026), registered Consent Managers will let users manage consent across fiduciaries.
Consent is the engine of the DPDP regime
Unlike frameworks built on a menu of lawful bases, the DPDP Act is consent-led. Processing of personal data requires either consent or one of the limited lawful purposes the Act recognises. That makes consent quality a first-class product requirement: if your consent flows are weak, your entire processing posture is weak.
The five qualities of valid consent
Section 6 of the DPDP Act requires consent to be:
- Free: no coercion or unfair pressure, and no bundling that forces unnecessary data as a condition of service (Section 7).
- Specific: tied to a particular purpose, not a blanket authorization.
- Informed: the Data Principal knows what data is collected, why and how to exercise rights.
- Unconditional: not made a precondition where the data is not necessary for the purpose.
- Unambiguous: a clear affirmative action — not silence, inaction or a pre-ticked box.
Notice before consent
Section 5 requires that a request for consent be preceded by a notice. That notice must be itemized and easy to understand, stating the personal data being collected, the purpose of processing, how to exercise rights and how to contact the fiduciary. The DPDP Rules, 2025 add a practical requirement: notices must be made available in English and all 22 scheduled Indian languages.
Notice text is not static. When you change what you collect or why, the notice version changes — and the consent tied to it should be revisited. Versioned, traceable notice records are exactly the kind of evidence that matters if the Data Protection Board or an auditor ever asks which notice was live when consent was captured.
Designing consent flows that survive scrutiny
Consent should be designed as a state, not a one-time event:
- Capture: record notice version, timestamp, the affirmative action taken and what the user was shown.
- Withdrawal: make withdrawal as easy as giving consent — ideally in the same interface, with a single clear action.
- Propagation: when consent is withdrawn, downstream processing must stop and processors must be instructed to delete or stop using the data.
- Consent Manager readiness: from Phase 2, users may manage consent through registered Consent Managers. Your systems should be able to honour consent states from those platforms, not only consent captured on your own properties.
Dark patterns are a compliance risk
Interfaces that bury consent, make withdrawal difficult, use confusing toggles or bundle unrelated processing undermine the statutory qualities of consent. Beyond reputational risk, they create exactly the kind of evidence a regulator would examine. The Rules and the Act's principles point the same direction: consent screens should be clear, balanced and truthful.
Review your consent architecture before Phase 2
KryptoMindz designs consent and notice architecture, withdrawal workflows and Consent Manager readiness for global and India-facing products.
Discuss Your Consent Design