Consent Under the DPDP Act, 2023

Last updated: 6 August 2026

Consent is central to the Digital Personal Data Protection Act, 2023. As a general rule, an organisation (a “Data Fiduciary”) must obtain a person’s consent before processing their personal data, unless the processing falls within one of the “certain legitimate uses” recognised by the Act.

What valid consent must be

Under the Act, consent must be:

In practice, this means consent cannot be inferred from pre-ticked boxes, inaction, or bundling unrelated purposes together. It must be a clear, positive choice for a specific purpose.

The notice that must accompany consent

Before or at the time of seeking consent, the Data Fiduciary must give the person a notice that describes the personal data to be collected and the purpose of processing, and tells them how they may exercise their rights and how to complain to the Data Protection Board.

The right to withdraw consent

Where consent is the basis of processing, the person may withdraw it at any time. Importantly, withdrawing consent must be as easy as giving it was. After withdrawal, the Data Fiduciary must stop processing the personal data within a reasonable time, unless some other lawful basis applies.

Consent Managers

The Act provides for “Consent Managers” — entities registered with the Data Protection Board that give individuals a single, accessible platform to give, manage, review, and withdraw their consent across different organisations.

For organisations, building consent flows that meet these requirements — clear notices, specific purposes, and easy withdrawal — is a practical first step toward compliance.