This tool tests whether your consent controls actually operate, not just whether a policy mentions consent. Work through representative checks across notice, collection, evidence, withdrawal, internal systems and Data Processors, see where the gaps sit, then take away the full 42-control audit workbook.
Internal audit and self-assessment aid. Not certification or legal opinion.
A DPDP consent audit tests not merely whether policies mention consent, but whether valid consent is obtained, required notice is presented, consent can be proved, withdrawal works, affected processing stops, Data Processor actions can be caused where required, retained data are handled correctly, and operational evidence exists for each of these. It examines controls in real systems, not statements on a page.
The audit follows one chain for every control. It starts from the legal outcome the Act or Rules require, moves to the operational control that delivers it, then asks what evidence exists, tests whether the control works, records a finding, and points to remediation.
The same chain runs through every control in the workbook.
The Act generally specifies an outcome. How you reach that outcome is an implementation choice. The left column is the required outcome; the right column lists possible ways to deliver it, none of which the Act mandates by name.
| Legal requirement or outcome | Possible implementation |
|---|---|
| Be able to prove notice and consent for sampled Data Principals | Versioned notice and consent records, UI screenshots, form captures, consent events, account mapping |
| Stop affected processing after withdrawal | CRM or CDP suppression, an API event, a manual workflow, campaign exclusion |
| Cause a Data Processor to cease affected processing | A contract clause, an instruction record, an integration event, a vendor ticket |
| Erase where Section 8(7) requires | A deletion workflow, a retention review, a Processor deletion instruction |
Most DPDP consent duties are future-readiness obligations, not current requirements. This audit is published in August 2026. Use the timeline to keep current obligations separate from readiness gaps.
Existing obligations already apply. For example, relevant RBI Digital Lending Directions bind in-scope regulated lending arrangements today. Commencement-aware reporting is expected now.
Consent Manager registration framework. The framework under Section 6(9) and Rule 4 opens. Most businesses will not need to register as a Consent Manager themselves.
Substantive consent duties. Most consent, notice, withdrawal, cessation and erasure obligations tested here become operational.
Sources: DPDP Act, 2023; DPDP Rules, 2025 (notified 13 November 2025); the commencement notification; and the RBI Digital Lending Directions, 2025. Full links are in the primary sources section below.
The 42 core controls are grouped into nine domains, plus a tenth set of conditional modules that only some organisations need to answer. The counts below come directly from the workbook.
Know which consent-based purposes are in scope and who owns each consent control.
4 core controlsConfirm each activity has a lawful purpose and a sound processing ground.
5 core controlsTest that notice and the consent request meet the Act and Rules in the actual flow.
6 core controlsCheck that notice and consent can be reconstructed and proved for a sample.
5 core controlsVerify that withdrawal is accessible, comparably easy and acted upon.
6 core controlsTrace whether a withdrawal actually reaches the systems that perform the purpose.
5 core controlsConfirm you can cause Processors to cease or erase where the Act requires.
4 core controlsTest erasure on withdrawal or purpose-end and any lawful retention basis.
4 core controlsCheck that controls are tested end to end and failures are remediated.
3 core controlsAnswered only where the processing, data population, sector or Rule trigger actually applies.
24 conditional controlsFifteen representative controls drawn from the workbook, spanning every domain. For each, mark whether the control passes, partially operates, fails, does not apply, or needs review. This is a self-assessment, not a compliance rating.
Underlying legal duty: A Data Fiduciary must comply with the Act for processing undertaken by it or on its behalf, and must cease applicable processing after consent withdrawal (DPDP Act Sections 6(6), 8(1))
Can sampled consent purposes be traced to relevant internal systems and Data Processors?
Underlying legal duty: Processing may occur only in accordance with the Act and for a lawful purpose, based on consent or certain legitimate uses (DPDP Act Sections 4(1), 7)
Can the organisation explain the applicable processing ground for each sample?
Underlying legal duty: Notice before or with a consent request (DPDP Act Section 5(1))
Do sampled flows provide notice at the required time?
Underlying legal duty: Act notice content; Rule 3 details (DPDP Act Section 5(1); DPDP Rules Rule 3)
Do sampled notices contain required Act/Rule content?
Underlying legal duty: Valid consent criteria (DPDP Act Section 6(1))
Do sampled flows satisfy each Section 6(1) element?
Underlying legal duty: Data Fiduciary proof burden (DPDP Act Section 6(10))
Can sampled records reconstruct compliant notice and consent?
Underlying legal duty: Ability to prove notice and consent (DPDP Act Section 6(10))
Can organisation identify what wording the sample saw?
Underlying legal duty: Right to withdraw at any time with comparable ease (DPDP Act Section 6(4); Rule 3 for notice route)
Can sample users access a working withdrawal route?
Underlying legal duty: Comparable ease (DPDP Act Section 6(4))
Is withdrawal materially harder than original consent?
Underlying legal duty: Cessation after withdrawal (DPDP Act Section 6(6))
Does a test withdrawal stop the affected internal processing?
Underlying legal duty: Cessation of affected consent-based processing after withdrawal (DPDP Act Section 6(6))
Does a test withdrawal stop relevant communications?
Underlying legal duty: Data Processor engagement by valid contract (DPDP Act Section 8(2))
Are sampled Processors covered by valid agreements?
Underlying legal duty: Cause Data Processors to cease after withdrawal (DPDP Act Section 6(6))
Can organisation direct and verify cessation for sampled Processor activity?
Underlying legal duty: A Data Fiduciary must erase personal data when consent is withdrawn or the specified purpose is no longer served, whichever occurs earlier, unless retention is necessary for compliance with law; it must also cause its Data Processors to erase personal data made available to them (DPDP Act Section 8(7))
For sampled withdrawal or purpose-end cases, does the organisation erase applicable personal data unless it can identify a legally necessary retention basis?
Underlying legal duty: Underlying duties include valid consent, withdrawal cessation and Processor cessation; testing cadence is not prescribed (DPDP Act Sections 6(1), 6(4)–(6), 8(1))
Has organisation tested control operation end-to-end?
A finding-based diagnostic. It counts where controls may need work; it does not produce a compliance percentage.
This snapshot is an initial diagnostic, not a legal determination or certification. Most controls tested here relate to duties that become operational on 13 May 2027, so a gap is a readiness gap to close, not a current violation. The full workbook lets you test all 42 controls and record evidence and remediation.
A representative set of real controls, spanning all five classifications. Expand any control to see its final classification and underlying legal duty as separate fields, the exact source, commencement, the audit test and possible evidence. Evidence examples are possible artefacts, not artefacts the Act requires by name.
Required outcome expressly stated in the DPDP Act.
Required outcome expressly prescribed by the DPDP Rules, 2025.
A requirement from another applicable Indian regulatory framework, for in-scope entities only.
A practical method for achieving, proving or testing a legal outcome. The mechanism is not itself a DPDP mandate.
A resilience, governance or auditability practice beyond express legal text.
Different controls call for different evidence. The map below groups the kinds of artefacts an auditor might sample.
Notice versions, UI screenshots, copy variations and translations that show what a Data Principal was told.
Forms, consent screens, call records, consent events and account identifiers that show the affirmative action taken.
Preference changes, request records, unsubscribe events and system activity showing a withdrawal was received and acted on.
Configuration, campaign and suppression logs, and data-flow tests showing the withdrawal reached the right systems.
Contracts, cessation and deletion instructions, and vendor completion responses.
A legal-retention assessment, deletion records and purpose-end reviews.
Not every organisation should answer every control. The workbook enables these modules only where the relevant trigger applies. The final conditional controls, and their exact wording, live in the workbook.
Answer only where you process the personal data of children or of persons with lawful guardians.
Not every organisation handles children. Where it applies:
The Act does not prescribe a particular age-gate or verification technology.
Answer where marketing, personalisation, audience or partner-marketing processing relies on consent.
Not every marketing activity is consent-based. Where consent is the basis:
The Act does not prescribe a marketing taxonomy or specific tooling.
Answer where AI or ML uses of personal data rely on consent.
Not every AI system relies on consent, and there is no special DPDP lawful basis for AI. Where consent is relied upon:
Answer only for arrangements within the scope of the RBI Digital Lending Directions.
These are current regulatory-interaction controls, not DPDP duties, and they apply only to in-scope regulated entities, digital lending apps and lending service providers. They cover:
RBI requirements apply only to in-scope entities, not to every company.
Answer only where a Third Schedule class and purpose, or a Seventh Schedule purpose, actually applies.
Rule 8 does not create a universal one-year or three-year retention rule.
The public page helps you understand the method and run an initial audit. The workbook is where the real work happens: the full 42-control instrument plus conditional modules, logs and a remediation tracker in one spreadsheet.
The complete audit instrument. Editable spreadsheet, no sign-up required.
Download the workbook (.xlsx)The workbook is an internal audit and self-assessment aid. It is not certification, a compliance score or legal advice.
Consent controls rarely sit with one team. Different controls have different operational owners; the audit is most useful when these functions run it together.
Legal authority for the controls comes from official sources only. These are the sources the workbook relies on.
The DPDP Act does not prescribe a consent audit in this format. It sets outcomes an organisation must be able to meet and, for a Significant Data Fiduciary, requires an independent data auditor under Section 10. A consent audit is a practical way to test whether your consent controls meet those outcomes and can be evidenced.
The Act requires a Data Fiduciary to be able to prove that notice was given and consent obtained (Section 6(10)). It does not prescribe a specific record format. Organisations typically retain notice versions, consent screens or forms, a consent event, and an account identifier that together let them reconstruct what a Data Principal saw and agreed to. The workbook lists these as examples, not mandated artefacts.
No. The Act specifies outcomes such as valid consent, withdrawal that is comparably easy, cessation of affected processing and provable notice and consent. How you deliver those outcomes is an implementation choice. A registered Consent Manager under Section 6(9) is a specific statutory role, distinct from a consent-management platform; most businesses will not need to register as a Consent Manager themselves.
No. Withdrawal requires the affected consent-based processing to cease within a reasonable time (Section 6(6)). Separately, Section 8(7) requires erasure when consent is withdrawn or the purpose is no longer served, unless retention is necessary for compliance with law. Withdrawal and an erasure request are distinct mechanisms, and some data may be retained where a specific legal necessity applies.
A readiness assessment gives a high-level view of how prepared you are. A consent audit tests specific controls against evidence: it samples records, asks whether a control actually operates in real systems and with Data Processors, and produces findings and remediation. This tool is the audit-level instrument.
No. The 42 core controls are a mix of statutory outcomes, rule-based outcomes, implementation controls and good practice. The conditional modules add regulatory-interaction controls. Every control shows a final classification and a separate underlying legal duty, so you can see which are express legal requirements and which are practical methods for meeting them.
The Rules were notified on 13 November 2025. The Consent Manager registration framework opens on 13 November 2026. Most substantive consent, notice, withdrawal, cessation and erasure duties become operational on 13 May 2027. Some overlapping obligations, such as relevant RBI Digital Lending Directions, already apply to in-scope entities today.
Run the quick audit for an initial snapshot, then take the full 42-control workbook to test evidence, withdrawal and Processor cessation across your real systems.