Section 6: Consent
Section 6 of the Digital Personal Data Protection Act, 2023 sets the conditions for valid consent. Consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action for a specified purpose, and limited to the personal data necessary for that purpose. A Data Principal may withdraw consent at any time, and the Data Fiduciary must be able to prove that valid consent was obtained.
- Provision
- Section 6, DPDP Act 2023
- Chapter
- II · Obligations of Data Fiduciary
- Applies to
- Data Fiduciaries relying on consent
- Status (7 Sep 2026)
- Notified, not yet in force
- Core commencement — 6(1) to (8), (10)
- Comes into force 13 May 2027
- Consent Manager registration — 6(9)
- Comes into force 13 Nov 2026
- Official citation
- DPDP Act 2023, s.6; DPDP Rules 2025 (G.S.R. 846(E))
- Reviewed
- 7 September 2026
On this page
- Section 6 at a glance
- Key takeaways
- Who Section 6 applies to
- Clause by clause: 6(1) to 6(10)
- Do you need Section 6 consent?
- Section 5 vs 6 vs 7
- What valid consent requires
- A consent journey under Section 6
- Can you prove consent?
- When consent is withdrawn
- Consent Manager: 6(7) to 6(9)
- Common Section 6 mistakes
- What it means for your business
- What are you trying to do?
- FAQ
- Primary sources
Section 6 at a glance
The provision has three moving parts: what makes consent valid, how it can be withdrawn, and who must prove it.
Section 6: key takeaways
- Consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action.
- It must be tied to a specified purpose and limited to the personal data necessary for that purpose.
- Consent is one lawful basis. Some processing may instead rest on a Section 7 certain legitimate use, which has its own tests.
- A Data Principal may withdraw consent at any time, with ease comparable to the ease of giving it.
- On withdrawal, the Data Fiduciary must, within a reasonable time, stop processing and cause its Data Processors to stop, unless another law authorises it.
- If consent is challenged, the Data Fiduciary must prove a notice was given and valid consent obtained [Section 6(10)].
- A statutory Consent Manager is an optional, Board-registered intermediary, not a cookie banner, CMP or CRM field.
Who Section 6 applies to
Section 6 governs processing where consent is the lawful basis. It binds any Data Fiduciary that asks a Data Principal to agree to processing. It does not follow that consent is required for every activity: where a Section 7 certain legitimate use applies, that basis is tested on its own terms rather than on Section 6.
Section 6 explained clause by clause
All ten subsections, with the statutory effect and what it means operationally. The middle column states the Law; the right column is Practice, our operational reading, not statutory wording.
Scroll the table sideways on a narrow screen.
| Provision | What the law does | What it means operationally |
|---|---|---|
| 6(1) | Consent must be free, specific, informed, unconditional and unambiguous, with a clear affirmative action; it signifies agreement to processing for a specified purpose and is limited to the personal data necessary for that purpose. | Ask per purpose. No pre-ticked boxes, no consent buried in terms. Collect only the fields the stated purpose needs. |
| 6(2) | Any part of the consent that infringes the Act, the Rules or any other law is invalid to the extent of that infringement. | Consent cannot validate an unlawful term. A bad clause is void to that extent, even if the person clicked yes. |
| 6(3) | A request for consent must be in clear and plain language, available in English or a language in the Eighth Schedule, and give the contact details of the DPO (where applicable) or another person authorised to answer rights requests. | Write the request plainly, offer the required language options, and name a real contact route for rights. |
| 6(4) | The Data Principal may withdraw consent at any time, with the ease of doing so comparable to the ease with which consent was given. | Provide a withdrawal route that is as easy to reach and use as the original opt-in. |
| 6(5) | The Data Principal bears the consequences of withdrawal, and withdrawal does not affect the legality of processing carried out before it. | Withdrawal is prospective. Processing done while consent was valid stays lawful; you may explain what the person loses. |
| 6(6) | On withdrawal, the Data Fiduciary shall within a reasonable time cease, and cause its Data Processors to cease, processing, unless required or authorised by law. | Propagate withdrawal to your own systems and to processors. Keep only what another legal basis requires. |
| 6(7) | The Data Principal may give, manage, review or withdraw consent through a Consent Manager. | A Consent Manager is an optional channel the individual may use; it is not something you impose. |
| 6(8) | The Consent Manager is accountable to the Data Principal and acts on her behalf, in the manner and subject to obligations as prescribed. | The Consent Manager's accountability runs to the individual, not to you as Data Fiduciary. |
| 6(9) | Every Consent Manager must be registered with the Board, subject to technical, operational, financial and other conditions as prescribed (Rule 4 and the First Schedule of the DPDP Rules 2025). | Only a Board-registered entity is a statutory Consent Manager. Registration opens 13 November 2026. |
| 6(10) | Where consent is the basis of processing and a question arises in a proceeding, the Data Fiduciary must prove that a notice was given and that valid consent was obtained in accordance with the Act and the Rules. | Keep evidence of both the notice and the consent. The burden of proof sits with you. |
Do you need Section 6 consent?
An orientation tool, not a complete lawful-basis determination. Each basis must be tested against its own statutory provision.
Section 5 notice, then valid consent, then evidence and a withdrawal route.
Test the exact Section 7 legitimate use on its own terms.
Section 5 vs Section 6 vs Section 7
Three adjacent provisions that people often blur. Notice, consent, and the alternative to consent.
| Provision | Core question | What it governs | Read next |
|---|---|---|---|
| Section 5 | What must the person be told? | The notice that must accompany or precede a consent request. | Section 5 |
| Section 6 | What makes consent valid and controllable? | The conditions for valid consent, its withdrawal, and proof. | This page |
| Section 7 | When may processing occur without consent? | Certain legitimate uses that do not rely on Section 6 consent. | Section 7 |
What valid consent requires
Section 6(1) sets a seven-part test. Each factor must hold; a single failure can invalidate the consent.
The full UI examples, a good-versus-bad walkthrough and the detailed test live in the deep guide. See the complete Valid Consent under Section 6 guide →
A consent journey under Section 6
Practice This is an implementation model showing how the provisions fit together, not statutory wording.
Can you prove consent?
Section 6(10) puts the burden on the Data Fiduciary: if consent is questioned in a proceeding, you must show that a notice was given and that valid consent was obtained. In practice this means keeping a reconstructable record of each consent event.
Practice Suggested evidence design. The Act creates the proof burden but does not prescribe this exact schema.
What happens when consent is withdrawn
Under Sections 6(4) to 6(6), a Data Principal can withdraw at any time with ease comparable to giving consent. Withdrawal is prospective, and on withdrawal you must stop processing and cause your processors to stop within a reasonable time, unless another law authorises retention.
Consent given by a website toggle, but withdrawal only through an email to support, a wait and a manual ticket.
A visible preference control, or a digital route as easy to reach as the original opt-in.
Law The Act requires ease comparable to giving consent. It does not prescribe a single click; that is one way to operationalise the standard, not the wording of the Act.
Withdrawal request → identify the affected purpose → stop consent-based processing internally → cause processors to stop → check for any independent legal basis or retention duty → preserve evidence. See the full Consent withdrawal guide →
Consent Manager under Sections 6(7) to 6(9)
A Consent Manager lets a Data Principal give, manage, review or withdraw consent through a single, interoperable point [6(7)]. It is accountable to the individual [6(8)] and must be registered with the Board [6(9)], under Rule 4 and the First Schedule of the DPDP Rules 2025. Using one is not mandatory for every Data Fiduciary.
| What it is | Role | Status |
|---|---|---|
| Statutory Consent Manager | Board-registered intermediary acting for the Data Principal. | Defined in Section 6(7) to (9); registration from 13 Nov 2026. |
| CMP / consent software | A tool a Data Fiduciary uses to capture and store consent. | Useful, but not a statutory Consent Manager. |
| CRM preference field | An internal record of a marketing preference. | Not consent evidence on its own, and not a Consent Manager. |
Common Section 6 mistakes
- Vague or open-ended purposes. Consent tied to broad language rather than a specified purpose.
- Bundling unnecessary data. Asking for more than the stated purpose needs.
- Pre-selected or passive consent. Pre-ticked boxes or inferred agreement instead of a clear affirmative action.
- Hiding optional processing in terms. Folding unrelated processing into a single accept.
- Hard withdrawal. An opt-out route far harder to reach than the opt-in.
- No reconstructable evidence. Being unable to show what was consented to, and when.
- Withdrawal that stops at your border. Ceasing internally but leaving processors running.
- Treating CMP software as a statutory Consent Manager. Two different things.
What Section 6 means for your business
One concrete checkpoint per function.
Confirm which processing rests on consent and which on a tested Section 7 basis.
Unbundled, purpose-specific requests with a clear affirmative action and no pre-ticked boxes.
Separate marketing consent from service terms; keep the opt-out as easy as the opt-in.
Log consent events and wire withdrawal to stop processing across systems.
Ensure processors can receive and act on withdrawal signals.
Retain notice and consent evidence so consent can be proved on request.
What are you trying to do?
Section 6 is the statutory anchor. These guides go deeper on each task.
Not sure your consent flow meets Section 6?
The readiness check maps where consent, notice, withdrawal and evidence stand against the DPDP requirements, and where the gaps are.
Frequently asked questions about Section 6
What makes consent valid under Section 6?
Consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action. It must be tied to a specified purpose and limited to the personal data necessary for that purpose, and it must follow a Section 5 notice. A pre-ticked box or consent buried in terms does not qualify.
Does every business need consent to process personal data?
No. Consent under Section 6 is one lawful basis. Some processing may instead rely on a Section 7 certain legitimate use, which is tested on its own terms. Where you rely on consent, Section 6 applies in full; where you rely on Section 7, you must satisfy that provision.
Can several purposes be bundled into one consent?
No. Consent must be specific and unconditional. Bundling unrelated purposes into a single accept, or making an unrelated benefit conditional on consent, undermines validity. Ask for consent per purpose and collect only the data each purpose needs.
How easy must consent withdrawal be?
Section 6(4) requires the ease of withdrawal to be comparable to the ease with which consent was given. The Act does not mandate a specific mechanism such as one click; a route as easy to reach and use as the original opt-in is the standard.
What happens after consent is withdrawn?
Withdrawal is prospective, so processing done beforehand stays lawful [6(5)]. Going forward, the Data Fiduciary must within a reasonable time stop processing and cause its Data Processors to stop [6(6)], unless another law requires or authorises continued processing.
Who has to prove that consent was valid?
The Data Fiduciary. Under Section 6(10), if consent is questioned in a proceeding, you must prove that a notice was given and that valid consent was obtained in accordance with the Act and the Rules. Keeping evidence of both is essential.
What consent records should a Data Fiduciary keep?
The Act sets the proof burden but does not prescribe a schema. In practice, retain enough to reconstruct each consent event: the identity, purpose, notice version, consent wording, the affirmative action, a timestamp, the channel, the current state, and any withdrawal.
Does a Data Fiduciary have to appoint a Consent Manager?
No. A Consent Manager is an optional channel a Data Principal may use to manage consent [6(7)]. It is a Board-registered intermediary [6(9)], not the same as consent software or a CRM field. Most Data Fiduciaries are not required to use one.
What is the difference between a Section 5 notice and Section 6 consent?
Section 5 governs what the person must be told before or when consent is sought. Section 6 governs what makes the resulting consent valid, how it can be withdrawn, and who must prove it. A valid consent under Section 6 assumes a proper Section 5 notice.
When does Section 6 take effect?
Section 6 is notified but not yet in force. The core consent obligations are scheduled to come into force on 13 May 2027, and Consent Manager registration on 13 November 2026, under the phased commencement of the DPDP Rules 2025. Dates should be confirmed against the current official notification.
Primary sources
This page is legal information about Section 6 of the DPDP Act, 2023, not legal advice. Statutory provisions and commencement dates should be confirmed against the current official Government of India sources before you rely on them. Reviewed 7 September 2026.