Last updated: 6 August 2026
Consent is central to the Digital Personal Data Protection Act, 2023. As a general rule, an organisation (a “Data Fiduciary”) must obtain a person’s consent before processing their personal data, unless the processing falls within one of the “certain legitimate uses” recognised by the Act.
Under the Act, consent must be:
In practice, this means consent cannot be inferred from pre-ticked boxes, inaction, or bundling unrelated purposes together. It must be a clear, positive choice for a specific purpose.
Before or at the time of seeking consent, the Data Fiduciary must give the person a notice that describes the personal data to be collected and the purpose of processing, and tells them how they may exercise their rights and how to complain to the Data Protection Board.
Where consent is the basis of processing, the person may withdraw it at any time. Importantly, withdrawing consent must be as easy as giving it was. After withdrawal, the Data Fiduciary must stop processing the personal data within a reasonable time, unless some other lawful basis applies.
The Act provides for “Consent Managers” — entities registered with the Data Protection Board that give individuals a single, accessible platform to give, manage, review, and withdraw their consent across different organisations.
For organisations, building consent flows that meet these requirements — clear notices, specific purposes, and easy withdrawal — is a practical first step toward compliance.