Confidential Dispatch

DPDP consent, explained: what counts as valid consent under India's data law

5 min readUpdated 2026-06-30
On this page
  1. 01What does “consent” mean under the DPDP Act?
  2. 02Why isn’t a single blanket “I agree” enough?
  3. 03What counts as a “clear affirmative action”?
  4. 04Can you withdraw consent — and what happens then?
  5. 05When do you not need consent at all?
  6. 06Who has to prove consent was given?
  7. 07FAQ
At a glance

Under India’s DPDP Act, valid consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action — like ticking an unticked box. It has to be taken per purpose, cover only the data that purpose actually needs, and be as easy to withdraw as it was to give. A pre-ticked box, silence, or one blanket “I agree” buried in your terms does not count.

Educational resource only. This explains how consent works under India’s Digital Personal Data Protection Act, 2023 (DPDP Act); it is not formal legal advice.

What does “consent” mean under the DPDP Act?

Consent is a specific, opt-in “yes” to a stated purpose — not a blanket agreement buried in your terms. Section 6 of the DPDP Act sets five qualities that consent must have, all at once:

  • Free — a genuine choice, with no pressure and no penalty for saying no. You can’t be denied a service for refusing to hand over data the service doesn’t actually need.
  • Specific — tied to a particular, named purpose. “To process your loan application” is specific; “for business purposes” is not.
  • Informed — given after a clear notice that says what’s being collected, why, how to withdraw, and how to complain. (That notice is a requirement in its own right.)
  • Unconditional — not bundled with unrelated terms or used as a lever. Agreeing to the service can’t be quietly conditioned on agreeing to extra, unnecessary data use.
  • Unambiguous, by a clear affirmative action — an active, deliberate step that signals agreement. Inaction, silence, or a pre-checked box is not consent.

Consent also has to be limited to the data the purpose needs (data minimisation): if you’re collecting a phone number to send an OTP, the consent — and the collection — stops at the phone number.

Why isn’t a single blanket “I agree” enough?

One “I agree” covering everything fails, because consent under the DPDP Act is per purpose. If a clinic collects your phone number to confirm appointments and wants to use it for promotional offers, those are two purposes — each needs its own clear yes. A single bundled tick can’t stand in for both.

This is why long, catch-all terms-and-conditions checkboxes no longer do the job on their own. The practical pattern that works is granular consent: separate, unticked opt-ins, each naming one purpose, so the person can agree to the thing they came for and decline the rest.

What counts as a “clear affirmative action”?

Consent has to be something the person actively does — never something they fail to undo. That rules out the most common shortcuts:

  • A pre-ticked checkbox.
  • Silence or “by continuing, you agree.”
  • A box bundling several unrelated purposes into one tick.
  • An unticked box the person ticks themselves.
  • A clear, labelled “I agree” action tied to the specific purpose stated in the notice.
  • A signature on a consent line that names the purpose.

The test is simple: could the person have ended up “consenting” without doing anything? If yes, it isn’t valid consent.

Can you withdraw consent — and what happens then?

Yes — withdrawal is a right, and it must be as easy as giving consent was. If someone consented through a one-tap box, you can’t force them through a week of emails to take it back. Withdrawal has to be comparably simple and available at any time.

When consent is withdrawn, you must stop processing that data — and make sure any third parties (data processors) you passed it to stop as well, unless some other lawful basis genuinely applies. People can give, manage, and withdraw consent directly, or through a Consent Manager — an intermediary registered with the Data Protection Board that lets them handle consents across services in one place.

When do you not need consent at all?

Consent is the main route, but not the only one — some processing runs on “legitimate uses” instead. This is the load-bearing caveat: Section 7 lists situations where consent isn’t required — for example, when a person voluntarily shares data for a purpose, or for certain employment purposes. A business shouldn’t assume everything needs a consent box, nor that legitimate use is a free pass — it’s a defined, limited list. Two flags worth holding onto:

  • Children: data of anyone under 18 needs verifiable parental consent, with tighter rules — ordinary consent isn’t enough.
  • “Necessary minimum” isn’t “anything goes”: even where a legal obligation lets you collect something (e.g. KYC), using it for an extra purpose like marketing still needs separate consent.

Where the consent requirement stops and starts is covered in the legitimate-use pillar.

Who has to prove consent was given?

The business does — not the individual. If a consent is ever questioned, the DPDP Act puts the burden on the Data Fiduciary (the organisation deciding why and how the data is used) to show that a valid notice was given and consent was properly obtained. In practice that means consent isn’t something you take and forget; it’s something you must be able to demonstrate later — who agreed, to what, and when. Without a record, you can’t prove it happened.

FAQ

Is a pre-ticked consent box legal under the DPDP Act?

No. Consent needs a clear affirmative action; a pre-ticked box, silence, or “by continuing you agree” doesn’t qualify.

Can a business refuse me service if I don’t consent?

It can require the data genuinely needed to provide the service, but it can’t make you consent to extra, unnecessary uses as a condition of getting it — consent has to be free and unconditional.

Does one “I agree” cover everything a company wants to do with my data?

No. Consent is per purpose. A new or different use generally needs a fresh, specific consent.

Can I take back consent after giving it?

Yes, at any time — and it must be as easy to withdraw as it was to give. After you withdraw, the business must stop processing that data and have its processors stop too.

Reviewed by Confidential Dispatch Editorial Team
Last updated 30 June 2026
Not legal advice.

Collecting personal data from your own customers?

These are the rights your business has to honour. See where you stand with a two-minute self-check — no sign-up, no data stored.

Run the compliance self-check →