At a glanceConsent-at-capture means asking for consent at the exact moment you collect the data — with the notice right there — rather than relying on a privacy policy the person never opened. Under India’s DPDP Act, valid consent has to be informed and specific, which only works if the person sees what they’re agreeing to as they hand the data over. In practice: pair a plain notice with a specific, unbundled opt-in at every point of collection, and record it. Consent buried elsewhere, or assumed, doesn’t meet the bar.
Educational resource only. This explains consent-at-capture under India’s Digital Personal Data Protection Act, 2023 (DPDP Act); it is not formal legal advice.
The idea in one line
Most consent failures aren’t refusals — they’re consent taken in the wrong place, or assumed. Consent-at-capture fixes that by putting the ask exactly where the data is handed over.
What “consent-at-capture” actually means
It’s consent obtained at the point and moment of collection, with the notice attached — not before, elsewhere, or after. When someone fills your form, uploads a document, or shares details in chat, the request to consent and the notice explaining why sit right there, in that step. The person sees what data you’re taking, for what purpose, and actively agrees — then and there.
This isn’t a nice-to-have flourish; it’s what makes consent informed and specific under the DPDP Act (Sections 5 and 6). Consent only counts if the person understood what they were agreeing to at the time — and the reliable way to ensure that is to show them at the moment they act.
Why consent buried in a policy fails
“By using this service you agree to our privacy policy” is the pattern the Act is designed to stop. A link to a long policy nobody reads doesn’t produce specific, informed consent — it produces a fiction of it. The same goes for assuming consent because someone contacted you, or bundling every purpose into one tick at the end. Under the DPDP Act, consent has to be a clear affirmative action tied to a stated purpose; a buried, blanket, or assumed “agreement” isn’t that.
The practical risk: if consent is ever questioned, you have to prove a valid one was given. A policy link proves nothing about what this person understood and agreed to. Consent captured at the point of collection does.
What it looks like at each collection point
The principle is constant; the implementation shifts with the channel. A few examples:
- Web or intake form: the notice sits on the form; each purpose has its own unticked checkbox; submitting records what was shown and agreed.
- Document / KYC upload: before the upload, a clear line on why the document is needed and a specific consent to collect and store it for that purpose.
- Chat (e.g. WhatsApp): an explicit ask for each purpose — support vs marketing — captured as a recorded yes, not inferred from the person messaging you.
- In person / on paper that gets digitised: the consent and purpose are stated on the form the person signs, not implied by the interaction.
How to build it in
Make the notice and the opt-in part of the collection step itself, and capture the evidence. The moves:
- Put the notice where the data is entered — visible, plain, and specific to that collection.
- Split consent by purpose — separate, unticked opt-ins; never one blanket agree.
- Take a clear affirmative action — an actual tick or tap, not a pre-checked box or “by continuing.”
- Record what was shown and agreed — so you can demonstrate the consent later.
- Offer withdrawal from the same place — as easy to withdraw as it was to give.
Get this pattern right once and it drops into every channel you use — which is exactly why it’s the backbone of compliant collection.
FAQ
What does consent-at-capture mean?
Asking for consent at the moment and point you collect the data, with the notice shown right there — rather than relying on a separate policy or assuming consent.
Isn’t a link to my privacy policy enough?
No. A policy link doesn’t produce specific, informed consent, and it doesn’t prove what this person agreed to. Consent has to be a clear opt-in tied to the stated purpose, captured at collection.
Do I need separate consent for each purpose?
Yes. Consent is per purpose — support and marketing, for instance, are different and each needs its own opt-in.
Why does capturing consent at the point of collection matter for proof?
Because the burden of proving valid consent is yours. A record of the notice shown and the opt-in given at collection is what you can actually rely on if it’s ever questioned.