Readiness assessment
DPDP guide

DPDP Consent Form: Sample Format, Requirements & Template

There is no official government consent form under the DPDP Act. This guide shows what a valid consent request must contain, gives you a copy-ready sample, and helps you decide whether consent is even the right basis before you build anything.

DPDP Act 2023DPDP Rules 2025Updated Aug 2026
On this page
  1. Do you need consent?
  2. What makes consent valid
  3. What a consent form contains
  4. Sample consent form
  5. Bad vs better examples
  6. Consent vs notice vs policy
  7. Consent evidence to keep
  8. Withdrawing consent
  9. Children's consent
  10. FAQs

There is no official DPDP consent form. The Digital Personal Data Protection Act, 2023 and the final Digital Personal Data Protection Rules, 2025 do not prescribe one universal government format or an official downloadable template. They set requirements: for the notice you give, for what makes consent valid, for withdrawal, and for the rights and grievance routes you must offer. You can meet those requirements through an online form, an app screen, a preference centre, a paper form, or another suitable mechanism. Before any of that, this guide helps you check something most templates skip: whether consent is even the right basis for what you are doing.

Timing note. Substantive Section 5 notice duties, most of the Section 6 consent requirements, and Rule 3 commence on 13 May 2027. This guide is published in August 2026, so treat it as readiness work. The requirements below are what you should be designing toward now, not provisions that are already operative today.
Key takeaways
  • There is no official or government DPDP consent form. The Act and the final Rules set requirements, not a prescribed template.
  • Decide the processing route before you build the form. Under Section 4, processing can rest on consent or on a certain legitimate use under Section 7. Not everything needs a checkbox.
  • To be valid under Section 6, consent must be free, specific, informed, unconditional, unambiguous, and given through a clear affirmative action, limited to the data necessary for the purpose.
  • A compliant consent request itemises the personal data, states a specific purpose in plain language, and links to withdrawal, the rights and grievance route, and the notice.
  • Keep consent records to meet the Section 6(10) burden of proof. There is no universal seven-year rule for ordinary Data Fiduciaries; the seven-year minimum applies to registered Consent Managers under the First Schedule.
  • Withdrawal must be as easy as giving consent, and a child's data needs verifiable parental or lawful-guardian consent, not a simple checkbox.

Do you need consent under the DPDP Act?

Start here, not with the form. Under Section 4, personal data may be processed where the Data Principal has given consent, or for a certain legitimate use under Section 7 where that applies. Consent is one route, not the only one. Adding a consent checkbox to processing that does not need consent can create obligations you did not have to take on, and it can undermine the consent you genuinely rely on elsewhere.

Personal data to be processed Which route applies? Consent Sections 4 and 6, build the form Certain legitimate use Section 7, no consent checkbox
Decide the lawful route first. Not every activity needs a consent form.

Use the table below as a starting point for the direction of travel, then apply the facts of your own processing.

Processing situationStarting pointPractical direction
Optional email newsletterUsually consent-ledUse a separate affirmative opt-in
Promotional SMS or WhatsAppOften consent-led, and subject to other applicable lawsKeep it separate from core service
Optional sharing with partnersUsually consent-ledState the purpose and separate the choice
Data voluntarily supplied for a specific requested serviceExamine Section 7(a)Do not add a checkbox automatically
Account or order fulfilmentExamine the facts and Section 7(a)Separate service processing from marketing
Employee processingExamine Section 7(i) and the factsDo not assume an employee consent form solves everything
A child's personal dataSpecial requirements applyVerifiable parental or lawful-guardian consent
Non-essential behavioural advertising or trackingAssess carefullyDetermine the DPDP route and other applicable laws
This is a starting point, not a legal classification of every processing activity. Section 7 depends on the facts, the specified purpose, the manner in which the personal data was provided, and other applicable laws. See consent versus certain legitimate uses for the distinction. Do not read the table as a ruling that any activity automatically qualifies.

If consent is the right route for a given activity, the rest of this guide is for you. If it is not, forcing a checkbox onto it is the wrong design.

What makes consent valid under the DPDP Act?

Section 6 sets the standard. Consent must be free, specific, informed, unconditional, unambiguous, given through a clear affirmative action, and limited to the personal data necessary for the specified purpose. The request itself must be in clear and plain language, and the Data Principal should be able to access it in English or in a language listed in the Eighth Schedule to the Constitution. For the full standard, see the guide to valid consent under Section 6.

Where implementations tend to fail. The following patterns can be difficult to reconcile with the requirements above: pre-selected choices, passive "by continuing, you consent" language, vague or open-ended purposes, making an unrelated core service conditional on marketing permission, and bundling several unrelated purposes into one choice.

A note on wording, because precision matters. The Act does not expressly refer to pre-ticked boxes. A pre-selected choice may nonetheless be difficult to reconcile with the requirement for a clear affirmative action, which is a different and more defensible statement. Apply that same discipline whenever you describe what the law requires: separate what the statute says from what is a sound implementation conclusion.

What should a DPDP consent form contain?

At its core, a compliant consent request is built from a small set of components. These are the building blocks.

Itemised dataExactly what personal data is collected
Specific purposeA single, clearly stated purpose
Affirmative choiceAn unticked, deliberate opt-in
Plain languageClear wording, no legalese
Withdrawal routeAs easy to withdraw as to give
Rights & grievanceWhere to exercise rights or complain

The table below separates what the law or Rules point to from what is an evidence control you keep for your own protection. Do not read the evidence-control rows as mandatory statutory form fields.

ElementStatusExample
Itemised personal dataRule 3 requirement once operativeEmail address
Specific purposeAct and Rule 3Send weekly DPDP compliance updates
Goods, service or use connected with the purposeRule 3Newsletter and resource alerts
Clear affirmative choiceSection 6An unticked opt-in
Clear and plain languageSection 6Plain wording, no legalese
Withdrawal routeSections 5 and 6, and Rule 3Link to withdraw at any time
Rights and grievance routeSections 5 and 13, and Rule 3Link to exercise rights or complain
Board complaint informationSection 5 and Rule 3How to complain to the Board
Language accessAct requirementEnglish or an Eighth Schedule language
TimestampEvidence controlDate and time captured
Notice versionEvidence controlWhich notice version was shown
Capture channelEvidence controlWeb form, app, or paper

The final group, from timestamp downward, is not a set of fields the Act tells you to display. It is the record you keep so that you can discharge the Section 6(10) burden of proof, discussed further below.

Sample DPDP consent form

You do not need to download anything to use the example below. It is written for a simple, defensible use case, an optional newsletter, so the structure is easy to adapt.

Example: optional DPDP compliance newsletter

Personal data: Name and email address

Purpose: To send DPDP compliance updates, practical guides and resources by email.

Optional: You do not need to subscribe to use [relevant core site, resource or service, where applicable].

☐ Yes, send me DPDP compliance updates and resources by email.

You can withdraw this consent at any time through [preference-centre or withdrawal link].

Exercise your rights or raise a grievance: [rights and grievance link].

Read the notice for this consent request: [notice link].

Two points on the checkbox. It must appear visually unticked. And an unticked checkbox is not itself something the statute expressly prescribes; it is a strong implementation mechanism for evidencing a clear affirmative action, which is what the Act does require.

Bad vs better DPDP consent examples

These are implementation conclusions that apply the Section 6 standards. The Act does not enumerate every poor interface pattern; it sets the standard, and these examples show designs that are easier or harder to reconcile with it.

Risky patternBetter implementationWhy
☑ I accept the Privacy Policy and agree to receive updates from us and our partners☐ Send me the weekly DPDP compliance newsletter by emailSeparates a distinct marketing purpose and removes the pre-selected choice
I agree to the use of my data for marketing, analytics and business purposes☐ Use my email address to send the DPDP compliance newsletterReplaces a vague, open-ended purpose with a specific one
By continuing to use this website, you consent...☐ Yes, send me product updates by emailReplaces passive language with a clear affirmative action
Agree to all to continueCore service explained separately; optional marketing kept as a separate choiceRemoves conditionality and bundling
One choice for first-party marketing and partner sharingSeparate the organisation's own marketing from a distinct sharing purposeSupports specificity and a free choice per purpose

DPDP consent form vs notice vs privacy policy

These are often confused, and treating one as another is a common source of risk.

DocumentWhat it isWhat it is not
Consent form or requestThe mechanism that captures an affirmative choice, where consent is the applicable routeNot, on its own, the information the person needs to be informed
DPDP noticeThe information that accompanies or precedes the request and provides the required detailNot the choice itself
Privacy policyA broader organisational transparency documentNot automatically consent to any specific processing
Terms and conditionsCommercial and service termsNot, by acceptance, valid consent for unrelated processing

The practical takeaway: a consent request should be paired with a proper DPDP notice, and neither a privacy policy nor accepting terms and conditions substitutes for the affirmative choice. For what the notice itself must contain, see the guide to the DPDP privacy notice under Section 5.

What consent evidence should you keep?

Section 6(10) is the reason record-keeping matters. If a consent-based processing is challenged in proceedings, the Data Fiduciary carries the burden of proving that the required notice was given and that valid consent was obtained. You cannot prove that from memory. You prove it from records.

FieldPurpose
Data Principal or account identifierTies the record to a person
PurposeShows what the consent was for
Personal data describedShows what was covered
Notice versionShows what information was presented
Consent stateGiven or withdrawn
Date and timeEvidences when the choice was made
ChannelWeb, app, or paper
Withdrawal eventEvidences a later withdrawal
Correction to a common myth. Do not assume that ordinary Data Fiduciaries must retain consent records for seven years. There is no universal statutory seven-year consent-record period for every business. The specific seven-year minimum retention requirement applies to registered Consent Managers under the First Schedule to the final Rules. For an ordinary Data Fiduciary, the obligation is the ability to discharge the Section 6(10) burden of proof, which is a reason to keep sound records, not a licence to invent a fixed statutory period.

Withdrawing consent

A Data Principal can withdraw consent. Withdrawal should be as easy to do as it was to give consent. Where consent is withdrawn, consent-based processing should stop within a reasonable time, and any Data Processors acting on your instructions may also need to stop the relevant processing. Withdrawal does not retrospectively invalidate processing that was already carried out lawfully while the consent was in force.

Two things to design for: a withdrawal route that is genuinely as simple as the opt-in, and a way to propagate the withdrawal to downstream systems and processors. For the mechanics and edge cases, see consent withdrawal.

What about children's consent?

Children's personal data is treated differently. Where the relevant provisions apply, processing a child's data requires a verifiable parental or lawful-guardian consent process. A normal adult consent checkbox is not enough, and a single "Are you the parent? Yes or No" question does not, by itself, necessarily satisfy the verification requirement. The verification standard is the point, and it needs a real mechanism behind it. For how to approach that, see children's data under the DPDP Act.

DPDP consent form FAQs

Is there an official DPDP consent form?

No. Neither the Act nor the final Rules prescribe one universal government format or an official downloadable template. They set requirements you implement in your own mechanism.

Does DPDP require written or signed consent?

Written or signed consent is not universally mandated. What matters is that the consent meets the Section 6 standard and that you can evidence it.

Can consent be collected electronically?

Yes, provided the applicable requirements are satisfied, including a clear affirmative action, a specific purpose, and a proper notice.

Is a checkbox valid consent?

Potentially. A checkbox is an implementation mechanism, not the statutory definition of consent. It is valid when the surrounding design meets the Section 6 requirements.

Are pre-ticked boxes valid under DPDP?

The Act does not expressly name pre-ticked boxes. A pre-selected choice is, however, difficult to reconcile with the requirement for a clear affirmative action.

Can several purposes be bundled into one consent?

Bundling unrelated purposes creates risk against the requirements for specificity, freedom, unconditionality and clarity. Separating purposes is the more defensible design.

Does accepting a privacy policy count as consent?

Not automatically. A privacy policy is a transparency document, not an affirmative choice for a specific processing purpose.

Can consent be withdrawn?

Yes. Withdrawal should be as easy as giving consent, and consent-based processing should then stop within a reasonable time.

How long should DPDP consent records be retained?

There is no universal statutory period for ordinary Data Fiduciaries. Keep records sufficient to discharge the Section 6(10) burden of proof. The seven-year minimum applies to registered Consent Managers under the First Schedule, not to businesses generally.

Does marketing require separate consent?

The statute does not literally say separate marketing consent. Separating optional marketing from core-service processing is a defensible design because it supports a free, specific and unconditional choice.

Does every business activity require consent under the DPDP Act?

No. Under Section 4, processing may rest on consent or on a certain legitimate use under Section 7 where it applies. Start with the route decision above rather than assuming consent for everything.

Not sure whether you should be asking for consent at all?

The hardest part is usually not the form, it is deciding the right DPDP route for each processing activity. A short readiness check maps where you stand, so you are not adding checkboxes you do not need.

Download the editable consent form template

The consent and withdrawal template is part of the DPDP Compliance Toolkit, with field guidance, purpose-level consent examples, withdrawal wording and consent-record fields. It is a starting point you adapt to your own data and product journey, not an official or legally approved form, and not sufficient by itself for DPDP compliance.

This guide is general information about the DPDP Act, 2023 and the DPDP Rules, 2025. It is not legal advice and does not create a client relationship. DPDPActIndia is an independent resource and is not affiliated with the Government of India or the Data Protection Board. Confirm your specific obligations with a qualified adviser before you rely on any consent design.