Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment
Share this section
Chapter II · Obligations of Data Fiduciary

Section 6: Consent

Section 6 of the Digital Personal Data Protection Act, 2023 sets the conditions for valid consent. Consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action for a specified purpose, and limited to the personal data necessary for that purpose. A Data Principal may withdraw consent at any time, and the Data Fiduciary must be able to prove that valid consent was obtained.

Official Act text
Provision
Section 6, DPDP Act 2023
Chapter
II · Obligations of Data Fiduciary
Applies to
Data Fiduciaries relying on consent
Status (7 Sep 2026)
Notified, not yet in force
Core commencement — 6(1) to (8), (10)
Comes into force 13 May 2027
Consent Manager registration — 6(9)
Comes into force 13 Nov 2026
Official citation
DPDP Act 2023, s.6; DPDP Rules 2025 (G.S.R. 846(E))
Reviewed
7 September 2026

Section 6 at a glance

The provision has three moving parts: what makes consent valid, how it can be withdrawn, and who must prove it.

Valid consentFree, specific, informed, unconditional, unambiguous, by clear affirmative action.
WithdrawableWithdrawal must be as easy as giving consent; processing then stops.
ProvableThe Data Fiduciary carries the burden of proving notice and consent [6(10)].
Optional channelA registered Consent Manager can manage consent on the individual's behalf.

Section 6: key takeaways

  • Consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action.
  • It must be tied to a specified purpose and limited to the personal data necessary for that purpose.
  • Consent is one lawful basis. Some processing may instead rest on a Section 7 certain legitimate use, which has its own tests.
  • A Data Principal may withdraw consent at any time, with ease comparable to the ease of giving it.
  • On withdrawal, the Data Fiduciary must, within a reasonable time, stop processing and cause its Data Processors to stop, unless another law authorises it.
  • If consent is challenged, the Data Fiduciary must prove a notice was given and valid consent obtained [Section 6(10)].
  • A statutory Consent Manager is an optional, Board-registered intermediary, not a cookie banner, CMP or CRM field.

Who Section 6 applies to

Section 6 governs processing where consent is the lawful basis. It binds any Data Fiduciary that asks a Data Principal to agree to processing. It does not follow that consent is required for every activity: where a Section 7 certain legitimate use applies, that basis is tested on its own terms rather than on Section 6.

FoundersLegal / DPOComplianceProduct / EngineeringMarketing

Section 6 explained clause by clause

All ten subsections, with the statutory effect and what it means operationally. The middle column states the Law; the right column is Practice, our operational reading, not statutory wording.

Scroll the table sideways on a narrow screen.

ProvisionWhat the law doesWhat it means operationally
6(1)Consent must be free, specific, informed, unconditional and unambiguous, with a clear affirmative action; it signifies agreement to processing for a specified purpose and is limited to the personal data necessary for that purpose.Ask per purpose. No pre-ticked boxes, no consent buried in terms. Collect only the fields the stated purpose needs.
6(2)Any part of the consent that infringes the Act, the Rules or any other law is invalid to the extent of that infringement.Consent cannot validate an unlawful term. A bad clause is void to that extent, even if the person clicked yes.
6(3)A request for consent must be in clear and plain language, available in English or a language in the Eighth Schedule, and give the contact details of the DPO (where applicable) or another person authorised to answer rights requests.Write the request plainly, offer the required language options, and name a real contact route for rights.
6(4)The Data Principal may withdraw consent at any time, with the ease of doing so comparable to the ease with which consent was given.Provide a withdrawal route that is as easy to reach and use as the original opt-in.
6(5)The Data Principal bears the consequences of withdrawal, and withdrawal does not affect the legality of processing carried out before it.Withdrawal is prospective. Processing done while consent was valid stays lawful; you may explain what the person loses.
6(6)On withdrawal, the Data Fiduciary shall within a reasonable time cease, and cause its Data Processors to cease, processing, unless required or authorised by law.Propagate withdrawal to your own systems and to processors. Keep only what another legal basis requires.
6(7)The Data Principal may give, manage, review or withdraw consent through a Consent Manager.A Consent Manager is an optional channel the individual may use; it is not something you impose.
6(8)The Consent Manager is accountable to the Data Principal and acts on her behalf, in the manner and subject to obligations as prescribed.The Consent Manager's accountability runs to the individual, not to you as Data Fiduciary.
6(9)Every Consent Manager must be registered with the Board, subject to technical, operational, financial and other conditions as prescribed (Rule 4 and the First Schedule of the DPDP Rules 2025).Only a Board-registered entity is a statutory Consent Manager. Registration opens 13 November 2026.
6(10)Where consent is the basis of processing and a question arises in a proceeding, the Data Fiduciary must prove that a notice was given and that valid consent was obtained in accordance with the Act and the Rules.Keep evidence of both the notice and the consent. The burden of proof sits with you.

Do you need Section 6 consent?

An orientation tool, not a complete lawful-basis determination. Each basis must be tested against its own statutory provision.

Are you processing digital personal data?
↓
For a clearly specified purpose?
↓
Is consent the basis you are relying on?
↓
Yes → apply Section 6
Section 5 notice, then valid consent, then evidence and a withdrawal route.
Maybe a Section 7 basis
Test the exact Section 7 legitimate use on its own terms.

Section 5 vs Section 6 vs Section 7

Three adjacent provisions that people often blur. Notice, consent, and the alternative to consent.

ProvisionCore questionWhat it governsRead next
Section 5What must the person be told?The notice that must accompany or precede a consent request.Section 5
Section 6What makes consent valid and controllable?The conditions for valid consent, its withdrawal, and proof.This page
Section 7When may processing occur without consent?Certain legitimate uses that do not rely on Section 6 consent.Section 7

What valid consent requires

Section 6(1) sets a seven-part test. Each factor must hold; a single failure can invalidate the consent.

FreeNo coercion or forced trade-off for unrelated benefits.
SpecificTied to a defined purpose, not open-ended.
InformedPreceded by a Section 5 notice.
UnconditionalNot bundled with unrelated terms.
UnambiguousA clear yes, not inferred silence.
AffirmativeAn active step, never a pre-ticked box.
Necessary data onlyLimited to what the purpose needs.

The full UI examples, a good-versus-bad walkthrough and the detailed test live in the deep guide. See the complete Valid Consent under Section 6 guide →

A consent journey under Section 6

Practice This is an implementation model showing how the provisions fit together, not statutory wording.

01Purpose identified
02Section 5 notice
03Consent request
04Affirmative action
05Consent evidence
06Processing
07Preference change / withdrawal
08Internal cessation
09Processor cessation
10Retained evidence

Can you prove consent?

Section 6(10) puts the burden on the Data Fiduciary: if consent is questioned in a proceeding, you must show that a notice was given and that valid consent was obtained. In practice this means keeping a reconstructable record of each consent event.

Practice Suggested evidence design. The Act creates the proof burden but does not prescribe this exact schema.

1Identity of the Data Principal
2Purpose consented to
3Notice version shown
4Consent wording / version
5Affirmative action taken
6Timestamp
7Channel
8Current consent state
9Withdrawal history
10Relevant processor state

What happens when consent is withdrawn

Under Sections 6(4) to 6(6), a Data Principal can withdraw at any time with ease comparable to giving consent. Withdrawal is prospective, and on withdrawal you must stop processing and cause your processors to stop within a reasonable time, unless another law authorises retention.

Weak practice

Consent given by a website toggle, but withdrawal only through an email to support, a wait and a manual ticket.

Better practice

A visible preference control, or a digital route as easy to reach as the original opt-in.

Law The Act requires ease comparable to giving consent. It does not prescribe a single click; that is one way to operationalise the standard, not the wording of the Act.

Withdrawal request → identify the affected purpose → stop consent-based processing internally → cause processors to stop → check for any independent legal basis or retention duty → preserve evidence. See the full Consent withdrawal guide →

Consent Manager under Sections 6(7) to 6(9)

A Consent Manager lets a Data Principal give, manage, review or withdraw consent through a single, interoperable point [6(7)]. It is accountable to the individual [6(8)] and must be registered with the Board [6(9)], under Rule 4 and the First Schedule of the DPDP Rules 2025. Using one is not mandatory for every Data Fiduciary.

What it isRoleStatus
Statutory Consent ManagerBoard-registered intermediary acting for the Data Principal.Defined in Section 6(7) to (9); registration from 13 Nov 2026.
CMP / consent softwareA tool a Data Fiduciary uses to capture and store consent.Useful, but not a statutory Consent Manager.
CRM preference fieldAn internal record of a marketing preference.Not consent evidence on its own, and not a Consent Manager.

Common Section 6 mistakes

  • Vague or open-ended purposes. Consent tied to broad language rather than a specified purpose.
  • Bundling unnecessary data. Asking for more than the stated purpose needs.
  • Pre-selected or passive consent. Pre-ticked boxes or inferred agreement instead of a clear affirmative action.
  • Hiding optional processing in terms. Folding unrelated processing into a single accept.
  • Hard withdrawal. An opt-out route far harder to reach than the opt-in.
  • No reconstructable evidence. Being unable to show what was consented to, and when.
  • Withdrawal that stops at your border. Ceasing internally but leaving processors running.
  • Treating CMP software as a statutory Consent Manager. Two different things.

What Section 6 means for your business

One concrete checkpoint per function.

Legal

Confirm which processing rests on consent and which on a tested Section 7 basis.

Product / UX

Unbundled, purpose-specific requests with a clear affirmative action and no pre-ticked boxes.

Marketing

Separate marketing consent from service terms; keep the opt-out as easy as the opt-in.

Engineering / data

Log consent events and wire withdrawal to stop processing across systems.

Vendor management

Ensure processors can receive and act on withdrawal signals.

Privacy operations

Retain notice and consent evidence so consent can be proved on request.

Not sure your consent flow meets Section 6?

The readiness check maps where consent, notice, withdrawal and evidence stand against the DPDP requirements, and where the gaps are.

Frequently asked questions about Section 6

What makes consent valid under Section 6?

Consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action. It must be tied to a specified purpose and limited to the personal data necessary for that purpose, and it must follow a Section 5 notice. A pre-ticked box or consent buried in terms does not qualify.

Does every business need consent to process personal data?

No. Consent under Section 6 is one lawful basis. Some processing may instead rely on a Section 7 certain legitimate use, which is tested on its own terms. Where you rely on consent, Section 6 applies in full; where you rely on Section 7, you must satisfy that provision.

Can several purposes be bundled into one consent?

No. Consent must be specific and unconditional. Bundling unrelated purposes into a single accept, or making an unrelated benefit conditional on consent, undermines validity. Ask for consent per purpose and collect only the data each purpose needs.

How easy must consent withdrawal be?

Section 6(4) requires the ease of withdrawal to be comparable to the ease with which consent was given. The Act does not mandate a specific mechanism such as one click; a route as easy to reach and use as the original opt-in is the standard.

What happens after consent is withdrawn?

Withdrawal is prospective, so processing done beforehand stays lawful [6(5)]. Going forward, the Data Fiduciary must within a reasonable time stop processing and cause its Data Processors to stop [6(6)], unless another law requires or authorises continued processing.

Who has to prove that consent was valid?

The Data Fiduciary. Under Section 6(10), if consent is questioned in a proceeding, you must prove that a notice was given and that valid consent was obtained in accordance with the Act and the Rules. Keeping evidence of both is essential.

What consent records should a Data Fiduciary keep?

The Act sets the proof burden but does not prescribe a schema. In practice, retain enough to reconstruct each consent event: the identity, purpose, notice version, consent wording, the affirmative action, a timestamp, the channel, the current state, and any withdrawal.

Does a Data Fiduciary have to appoint a Consent Manager?

No. A Consent Manager is an optional channel a Data Principal may use to manage consent [6(7)]. It is a Board-registered intermediary [6(9)], not the same as consent software or a CRM field. Most Data Fiduciaries are not required to use one.

What is the difference between a Section 5 notice and Section 6 consent?

Section 5 governs what the person must be told before or when consent is sought. Section 6 governs what makes the resulting consent valid, how it can be withdrawn, and who must prove it. A valid consent under Section 6 assumes a proper Section 5 notice.

When does Section 6 take effect?

Section 6 is notified but not yet in force. The core consent obligations are scheduled to come into force on 13 May 2027, and Consent Manager registration on 13 November 2026, under the phased commencement of the DPDP Rules 2025. Dates should be confirmed against the current official notification.

Primary sources

Digital Personal Data Protection Act, 2023 — Section 6
Ministry of Electronics and IT (MeitY) · Gazette of India, 2023
Establishes the conditions for valid consent, withdrawal and the proof burden. Official Act text (PDF)
Digital Personal Data Protection Rules, 2025
MeitY · Gazette notification G.S.R. 846(E), 13 November 2025
Operationalises the Act, including Rule 4 and the First Schedule for Consent Managers.
Commencement
Rule 1, DPDP Rules 2025, and companion Act commencement notification
Phased: machinery from 13 Nov 2025; Consent Manager registration from 13 Nov 2026; substantive obligations from 13 May 2027.
Data Protection Board of India
Established under the Act, Chapter V
The adjudicating body before which the Section 6(10) proof burden is tested.

This page is legal information about Section 6 of the DPDP Act, 2023, not legal advice. Statutory provisions and commencement dates should be confirmed against the current official Government of India sources before you rely on them. Reviewed 7 September 2026.

Start readiness assessment