There is no official DPDP consent form. The Digital Personal Data Protection Act, 2023 and the final Digital Personal Data Protection Rules, 2025 do not prescribe one universal government format or an official downloadable template. They set requirements: for the notice you give, for what makes consent valid, for withdrawal, and for the rights and grievance routes you must offer. You can meet those requirements through an online form, an app screen, a preference centre, a paper form, or another suitable mechanism. Before any of that, this guide helps you check something most templates skip: whether consent is even the right basis for what you are doing.
- There is no official or government DPDP consent form. The Act and the final Rules set requirements, not a prescribed template.
- Decide the processing route before you build the form. Under Section 4, processing can rest on consent or on a certain legitimate use under Section 7. Not everything needs a checkbox.
- To be valid under Section 6, consent must be free, specific, informed, unconditional, unambiguous, and given through a clear affirmative action, limited to the data necessary for the purpose.
- A compliant consent request itemises the personal data, states a specific purpose in plain language, and links to withdrawal, the rights and grievance route, and the notice.
- Keep consent records to meet the Section 6(10) burden of proof. There is no universal seven-year rule for ordinary Data Fiduciaries; the seven-year minimum applies to registered Consent Managers under the First Schedule.
- Withdrawal must be as easy as giving consent, and a child's data needs verifiable parental or lawful-guardian consent, not a simple checkbox.
Do you need consent under the DPDP Act?
Start here, not with the form. Under Section 4, personal data may be processed where the Data Principal has given consent, or for a certain legitimate use under Section 7 where that applies. Consent is one route, not the only one. Adding a consent checkbox to processing that does not need consent can create obligations you did not have to take on, and it can undermine the consent you genuinely rely on elsewhere.
Use the table below as a starting point for the direction of travel, then apply the facts of your own processing.
| Processing situation | Starting point | Practical direction |
|---|---|---|
| Optional email newsletter | Usually consent-led | Use a separate affirmative opt-in |
| Promotional SMS or WhatsApp | Often consent-led, and subject to other applicable laws | Keep it separate from core service |
| Optional sharing with partners | Usually consent-led | State the purpose and separate the choice |
| Data voluntarily supplied for a specific requested service | Examine Section 7(a) | Do not add a checkbox automatically |
| Account or order fulfilment | Examine the facts and Section 7(a) | Separate service processing from marketing |
| Employee processing | Examine Section 7(i) and the facts | Do not assume an employee consent form solves everything |
| A child's personal data | Special requirements apply | Verifiable parental or lawful-guardian consent |
| Non-essential behavioural advertising or tracking | Assess carefully | Determine the DPDP route and other applicable laws |
If consent is the right route for a given activity, the rest of this guide is for you. If it is not, forcing a checkbox onto it is the wrong design.
What makes consent valid under the DPDP Act?
Section 6 sets the standard. Consent must be free, specific, informed, unconditional, unambiguous, given through a clear affirmative action, and limited to the personal data necessary for the specified purpose. The request itself must be in clear and plain language, and the Data Principal should be able to access it in English or in a language listed in the Eighth Schedule to the Constitution. For the full standard, see the guide to valid consent under Section 6.
Where implementations tend to fail. The following patterns can be difficult to reconcile with the requirements above: pre-selected choices, passive "by continuing, you consent" language, vague or open-ended purposes, making an unrelated core service conditional on marketing permission, and bundling several unrelated purposes into one choice.
A note on wording, because precision matters. The Act does not expressly refer to pre-ticked boxes. A pre-selected choice may nonetheless be difficult to reconcile with the requirement for a clear affirmative action, which is a different and more defensible statement. Apply that same discipline whenever you describe what the law requires: separate what the statute says from what is a sound implementation conclusion.
What should a DPDP consent form contain?
At its core, a compliant consent request is built from a small set of components. These are the building blocks.
The table below separates what the law or Rules point to from what is an evidence control you keep for your own protection. Do not read the evidence-control rows as mandatory statutory form fields.
| Element | Status | Example |
|---|---|---|
| Itemised personal data | Rule 3 requirement once operative | Email address |
| Specific purpose | Act and Rule 3 | Send weekly DPDP compliance updates |
| Goods, service or use connected with the purpose | Rule 3 | Newsletter and resource alerts |
| Clear affirmative choice | Section 6 | An unticked opt-in |
| Clear and plain language | Section 6 | Plain wording, no legalese |
| Withdrawal route | Sections 5 and 6, and Rule 3 | Link to withdraw at any time |
| Rights and grievance route | Sections 5 and 13, and Rule 3 | Link to exercise rights or complain |
| Board complaint information | Section 5 and Rule 3 | How to complain to the Board |
| Language access | Act requirement | English or an Eighth Schedule language |
| Timestamp | Evidence control | Date and time captured |
| Notice version | Evidence control | Which notice version was shown |
| Capture channel | Evidence control | Web form, app, or paper |
The final group, from timestamp downward, is not a set of fields the Act tells you to display. It is the record you keep so that you can discharge the Section 6(10) burden of proof, discussed further below.
Sample DPDP consent form
You do not need to download anything to use the example below. It is written for a simple, defensible use case, an optional newsletter, so the structure is easy to adapt.
Personal data: Name and email address
Purpose: To send DPDP compliance updates, practical guides and resources by email.
Optional: You do not need to subscribe to use [relevant core site, resource or service, where applicable].
☐ Yes, send me DPDP compliance updates and resources by email.You can withdraw this consent at any time through [preference-centre or withdrawal link].
Exercise your rights or raise a grievance: [rights and grievance link].
Read the notice for this consent request: [notice link].
Two points on the checkbox. It must appear visually unticked. And an unticked checkbox is not itself something the statute expressly prescribes; it is a strong implementation mechanism for evidencing a clear affirmative action, which is what the Act does require.
Bad vs better DPDP consent examples
These are implementation conclusions that apply the Section 6 standards. The Act does not enumerate every poor interface pattern; it sets the standard, and these examples show designs that are easier or harder to reconcile with it.
| Risky pattern | Better implementation | Why |
|---|---|---|
| ☑ I accept the Privacy Policy and agree to receive updates from us and our partners | ☐ Send me the weekly DPDP compliance newsletter by email | Separates a distinct marketing purpose and removes the pre-selected choice |
| I agree to the use of my data for marketing, analytics and business purposes | ☐ Use my email address to send the DPDP compliance newsletter | Replaces a vague, open-ended purpose with a specific one |
| By continuing to use this website, you consent... | ☐ Yes, send me product updates by email | Replaces passive language with a clear affirmative action |
| Agree to all to continue | Core service explained separately; optional marketing kept as a separate choice | Removes conditionality and bundling |
| One choice for first-party marketing and partner sharing | Separate the organisation's own marketing from a distinct sharing purpose | Supports specificity and a free choice per purpose |
DPDP consent form vs notice vs privacy policy
These are often confused, and treating one as another is a common source of risk.
| Document | What it is | What it is not |
|---|---|---|
| Consent form or request | The mechanism that captures an affirmative choice, where consent is the applicable route | Not, on its own, the information the person needs to be informed |
| DPDP notice | The information that accompanies or precedes the request and provides the required detail | Not the choice itself |
| Privacy policy | A broader organisational transparency document | Not automatically consent to any specific processing |
| Terms and conditions | Commercial and service terms | Not, by acceptance, valid consent for unrelated processing |
The practical takeaway: a consent request should be paired with a proper DPDP notice, and neither a privacy policy nor accepting terms and conditions substitutes for the affirmative choice. For what the notice itself must contain, see the guide to the DPDP privacy notice under Section 5.
What consent evidence should you keep?
Section 6(10) is the reason record-keeping matters. If a consent-based processing is challenged in proceedings, the Data Fiduciary carries the burden of proving that the required notice was given and that valid consent was obtained. You cannot prove that from memory. You prove it from records.
| Field | Purpose |
|---|---|
| Data Principal or account identifier | Ties the record to a person |
| Purpose | Shows what the consent was for |
| Personal data described | Shows what was covered |
| Notice version | Shows what information was presented |
| Consent state | Given or withdrawn |
| Date and time | Evidences when the choice was made |
| Channel | Web, app, or paper |
| Withdrawal event | Evidences a later withdrawal |
Withdrawing consent
A Data Principal can withdraw consent. Withdrawal should be as easy to do as it was to give consent. Where consent is withdrawn, consent-based processing should stop within a reasonable time, and any Data Processors acting on your instructions may also need to stop the relevant processing. Withdrawal does not retrospectively invalidate processing that was already carried out lawfully while the consent was in force.
Two things to design for: a withdrawal route that is genuinely as simple as the opt-in, and a way to propagate the withdrawal to downstream systems and processors. For the mechanics and edge cases, see consent withdrawal.
What about children's consent?
Children's personal data is treated differently. Where the relevant provisions apply, processing a child's data requires a verifiable parental or lawful-guardian consent process. A normal adult consent checkbox is not enough, and a single "Are you the parent? Yes or No" question does not, by itself, necessarily satisfy the verification requirement. The verification standard is the point, and it needs a real mechanism behind it. For how to approach that, see children's data under the DPDP Act.
DPDP consent form FAQs
Is there an official DPDP consent form?
No. Neither the Act nor the final Rules prescribe one universal government format or an official downloadable template. They set requirements you implement in your own mechanism.
Does DPDP require written or signed consent?
Written or signed consent is not universally mandated. What matters is that the consent meets the Section 6 standard and that you can evidence it.
Can consent be collected electronically?
Yes, provided the applicable requirements are satisfied, including a clear affirmative action, a specific purpose, and a proper notice.
Is a checkbox valid consent?
Potentially. A checkbox is an implementation mechanism, not the statutory definition of consent. It is valid when the surrounding design meets the Section 6 requirements.
Are pre-ticked boxes valid under DPDP?
The Act does not expressly name pre-ticked boxes. A pre-selected choice is, however, difficult to reconcile with the requirement for a clear affirmative action.
Can several purposes be bundled into one consent?
Bundling unrelated purposes creates risk against the requirements for specificity, freedom, unconditionality and clarity. Separating purposes is the more defensible design.
Does accepting a privacy policy count as consent?
Not automatically. A privacy policy is a transparency document, not an affirmative choice for a specific processing purpose.
Can consent be withdrawn?
Yes. Withdrawal should be as easy as giving consent, and consent-based processing should then stop within a reasonable time.
How long should DPDP consent records be retained?
There is no universal statutory period for ordinary Data Fiduciaries. Keep records sufficient to discharge the Section 6(10) burden of proof. The seven-year minimum applies to registered Consent Managers under the First Schedule, not to businesses generally.
Does marketing require separate consent?
The statute does not literally say separate marketing consent. Separating optional marketing from core-service processing is a defensible design because it supports a free, specific and unconditional choice.
Does every business activity require consent under the DPDP Act?
No. Under Section 4, processing may rest on consent or on a certain legitimate use under Section 7 where it applies. Start with the route decision above rather than assuming consent for everything.
Not sure whether you should be asking for consent at all?
The hardest part is usually not the form, it is deciding the right DPDP route for each processing activity. A short readiness check maps where you stand, so you are not adding checkboxes you do not need.
Download the editable consent form template
The consent and withdrawal template is part of the DPDP Compliance Toolkit, with field guidance, purpose-level consent examples, withdrawal wording and consent-record fields. It is a starting point you adapt to your own data and product journey, not an official or legally approved form, and not sufficient by itself for DPDP compliance.
This guide is general information about the DPDP Act, 2023 and the DPDP Rules, 2025. It is not legal advice and does not create a client relationship. DPDPActIndia is an independent resource and is not affiliated with the Government of India or the Data Protection Board. Confirm your specific obligations with a qualified adviser before you rely on any consent design.