At a glanceUnder India’s DPDP Act the burden of proving valid consent sits with you, the business — so if the Data Protection Board ever asks, you must be able to show it. That means keeping a durable record of what notice was shown, the specific purpose consented to, the clear action the person took, when, and any later withdrawal — not just the data itself. A spreadsheet of answers isn’t proof of consent; a record of the notice-and-opt-in, tied to the person and moment, is.
Educational resource only. This explains the consent-record and proof obligations under India’s Digital Personal Data Protection Act, 2023 (DPDP Act); it is not formal legal advice.
The situation
Most businesses can show that they hold someone’s data. Far fewer can show what that person agreed to, and when — which is the thing the law actually asks for if consent is ever questioned. Closing that gap is mostly about capturing the right record at the moment of collection, not reconstructing it later.
Why the burden of proof is yours
If a consent is challenged, you have to demonstrate a valid one was given — the individual doesn’t have to disprove it. The DPDP Act makes the Data Fiduciary accountable for its processing (Section 8), and in practice that means being able to show that valid notice was given and consent properly obtained. So consent isn’t something you take and forget; it’s something you must be able to evidence — to the Data Protection Board, or to the person, at any time. Without a record, “they agreed” is just an assertion.
What a consent record must capture
A useful consent record ties a specific person to a specific agreement at a specific moment. At minimum, keep:
- The notice shown — the exact wording (or version) of the notice presented at collection.
- The purpose(s) consented to — which specific purposes, kept separate where consent was per purpose.
- The affirmative action — evidence the person actively opted in (not a pre-ticked box).
- Identity and timing — who consented and when.
- Scope of data — what data the consent covered.
- Withdrawal history — if and when consent was later withdrawn, and that you acted on it.
The theme: record the agreement, not just the data the agreement produced.
“We have their data” isn’t “we can prove consent”
The most common gap is mistaking stored data for stored consent. A CRM row, a form response, or a chat message shows you have the data — it doesn’t show what notice the person saw or what they agreed to. If the notice later changed, or consent was bundled, or the opt-in was assumed, the data alone won’t save you. This is why a durable, purpose-linked consent record — captured at the point of collection and hard to alter after the fact — is worth building deliberately, rather than hoping the raw data will stand in for it.
How to keep records that hold up
Capture the record at collection, keep it tamper-resistant, and keep it as long as you rely on the consent. Practically:
- Log consent at the point of capture — notice version, purposes, the opt-in action, identity, timestamp — automatically, as part of the collection step.
- Keep it hard to alter — a record you can quietly edit later is weak evidence; prefer append-only or otherwise tamper-evident storage.
- Link it to the data — so you can answer “what did this person agree to?” for any record you hold.
- Track withdrawals — record when consent ends and that processing stopped.
- Retain it for as long as you rely on that consent, and align it with your retention policy.
FAQ
Who has to prove consent was given — me or the customer?
You do. The burden of demonstrating valid notice and consent sits with the Data Fiduciary, not the individual.
Is storing the customer’s data enough to prove consent?
No. Data shows you hold it, not what the person was told or agreed to. You need a record of the notice and the specific opt-in.
What exactly should a consent record contain?
The notice shown, the purposes consented to, evidence of the affirmative action, who consented and when, the data covered, and any later withdrawal.
How long should I keep consent records?
For as long as you rely on that consent to process the data, aligned with your retention policy — so you can evidence it whenever it’s relied on.