Chapter II · Obligations of Data Fiduciary
Section 6: Consent
Section 6 sets the standard for valid consent under the DPDP Act: it must be free, specific, informed, unambiguous, and as easy to withdraw as it was to give.
- Chapter
- Chapter II · Obligations of Data Fiduciary
- Status
- Enacted · phased commencement
- Full compliance
- 13 May 2027 (s.6(9): 13 Nov 2026)
- Applies to
- Data Fiduciaries
- Official citation
- DPDP Act, 2023, s.6
- Reading time
- 6 min
- Updated
- August 2026
At a glance
Section 6 requires that consent under the DPDP Act be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action and limited to the personal data necessary for the specified purpose [6(1)]. Requests for consent must be in clear and plain language, offered in English or an Eighth Schedule language, with the contact details of a Data Protection Officer or authorised person [6(3)]. A Data Principal may withdraw consent at any time, with the same ease as giving it [6(4)], after which the Data Fiduciary must stop processing and cause its processors to stop, unless another law requires otherwise [6(6)]. Consent can be managed through a registered Consent Manager [6(7)-(9)], and in any proceeding the burden of proving valid consent rests on the Data Fiduciary [6(10)]. Most of Section 6 takes effect on 13 May 2027, but sub-section 6(9), on the accountability of Consent Managers, comes into force earlier, on 13 November 2026.
Key takeaways
- Consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action [6(1)].
- It must be limited to the data necessary for the specified purpose, no bundling in data you do not need.
- The request must be in clear, plain language, available in English or an Eighth Schedule language, with a DPO or contact for exercising rights [6(3)].
- A person can withdraw at any time, as easily as they consented [6(4)]; you then stop processing and make your processors stop [6(6)].
- Withdrawal does not undo lawful processing done before it, and the person bears the consequences of withdrawing [6(5)].
- In a dispute the burden of proving valid notice and consent is on you [6(10)]; consent may run through a registered Consent Manager [6(7)-(9)].
Who should read this
Read this if you rely on consent to process personal data, because Section 6 decides whether that consent actually counts, and puts the burden of proving it on you.
In plain language
Consent under the DPDP Act is a high bar. It has to be a genuine, informed yes: free, specific to a purpose, unambiguous, and given by a clear affirmative action, not a pre-ticked box or something buried in your terms. And it must be limited to the data you actually need for that purpose.
Withdrawal has to be as easy as giving consent. If someone can opt in with one tap, they must be able to opt out just as easily, and once they do, you have to stop processing and make your vendors stop too, unless a law says otherwise.
The accountability sits with you. If a dispute reaches the Board, you must be able to prove you gave a proper notice and obtained valid consent. Consent can be collected through a registered Consent Manager, but that does not shift your responsibility.
The text of the law
Section 6: Consent
6(1) Consent shall be free, specific, informed, unconditional and unambiguous with a clear affirmative action, signifying agreement to processing for the specified purpose and limited to the personal data necessary for that purpose.
6(3) Every request for consent shall be in clear and plain language, with the option to access it in English or a language in the Eighth Schedule, and shall provide the contact details of a Data Protection Officer or an authorised person.
6(4) Where consent is the basis of processing, the Data Principal has the right to withdraw it at any time, with ease comparable to how it was given.
6(6) On withdrawal, the Data Fiduciary shall within a reasonable time cease, and cause its Data Processors to cease, processing, unless required or authorised by law.
6(10) Where consent is the basis and a question arises in a proceeding, the Data Fiduciary must prove that a valid notice was given and consent obtained in accordance with the Act.
Wording summarised from the enacted Act. Always confirm against the official Gazette text for authoritative language.
What this means for you
- Use unbundled, purpose-specific consent with a clear affirmative action, no pre-ticked boxes, no consent bundled with unrelated purposes.
- Collect only the data necessary for the stated purpose, and pair the ask with a proper Section 5 notice.
- Present the request in plain language and the required languages, with a DPO or contact route for exercising rights.
- Build a one-tap withdrawal as easy as opt-in, wired to stop processing across your systems and processors.
- Keep consent records: what was shown, when, the version and the affirmative action, because the burden of proof is on you [6(10)].
- Using a Consent Manager? Confirm it is registered with the Board, and remember your responsibility remains. Not sure your flow qualifies? Take the readiness assessment or find a specialist.
Frequently asked questions
What makes consent valid under Section 6?
Can I bundle consent for several purposes together?
How easy does withdrawing consent have to be?
Who has to prove that consent was valid?
When does Section 6 take effect?
Sources
- Digital Personal Data Protection Act, 2023Ministry of Electronics and IT (MeitY)
- DPDP Rules, 2025Notified 13–14 November 2025
This is an educational explanation, not legal advice. dpdpactindia.in is an independent resource and is not affiliated with the Government of India.