Readiness assessment
DPDP Act 2023 · Consent

DPDP Consent Management: The Complete 2026–2027 Implementation Guide for Indian Businesses

What valid consent requires, what is effective when, what your organisation must build, and exactly where to go next.

Direct answer

DPDP consent management is how a Data Fiduciary that relies on consent meets India’s Digital Personal Data Protection Act: define a specified purpose, give the required notice, obtain valid affirmative consent, let people withdraw as easily as they agreed, stop consent-based processing (and make its processors stop) within a reasonable time of withdrawal, and keep evidence able to prove all of it. DPDP consent management is an operating model, not a checkbox, cookie banner or CRM field.

Now · since 13 Nov 2025
Rules notified
The Act and final DPDP Rules 2025 are notified. 2026 is a build-and-test window, not a completed obligation.
Deadline · 13 May 2027
Core consent duties
Sections 5 and 6 and Rule 3 (notice, valid consent, withdrawal) are scheduled to become operative.

Pick a path and jump straight to the sections that matter for your problem.

On this page
The model

What DPDP consent management actually requires

When a Data Fiduciary relies on consent, it must be able to collect, use, change, withdraw, stop and prove consent-based processing. That is not a single feature. It is a connected operating model across purpose, notice, capture, identity, enforcement, withdrawal, processors and evidence.

Under the DPDP Act, a Data Fiduciary decides the purpose and means of processing; a Data Principal is the individual the data is about. Relying on consent means you can later demonstrate that the person received the required notice and gave valid consent for a specified purpose. Most organisations discover the hard part is not capturing consent, it is stopping and proving it downstream.

1 · Purposedefine specified purpose 2 · Noticebefore / with the request 3 · Consent captureclear affirmative action 4 · Identityresolve to the person 5 · Enforcementpurpose & policy limits 6 · Withdrawalas easy as giving 7 · Propagationprocessors must stop 8 · Evidenceprove it later
The consent operating model: eight connected stages, from defining a purpose to proving the outcome.
What your organisation should do in 2026
  • Map processing purposes and every consent-dependent data flow.
  • Find legacy data with missing or uncertain consent evidence.
  • Design withdrawal and processor-propagation workflows before they are mandatory.
  • Review CRM, marketing, analytics, cloud and AI vendor data paths.
Practice

The Act does not name a “consent ledger,” CMP, cookie banner or dashboard. It creates a proof burden when you rely on consent. A controlled consent record is one implementation approach that supports that burden; it is a recommendation, not a statutory product.

Status

What is at stake: the Act sets maximum penalties of up to ₹250 crore for a failure of reasonable security safeguards and up to ₹200 crore for breaches of children’s-data obligations, imposed by the Data Protection Board after inquiry. Provable consent and its evidence trail are part of how a Data Fiduciary limits that exposure.

Understand

Consent vs certain legitimate uses

Consent is not the only lawful route. Section 7 “certain legitimate uses” can cover processing such as a voluntarily provided purpose, legal obligations, or specified employment uses. Asking for consent where a legitimate use genuinely applies, or calling optional marketing a “legitimate use,” both create risk.

Is the processing necessary for aSection 7 legitimate use? Yes No Document the Section 7ground and its limits Is valid consent required?if yes, run the consent path Define purpose → give notice → obtain affirmative consent→ retain evidence → enable withdrawal → enforce downstream
Pick the basis before you design the journey. Consent is one route, not the default.
Practice

Maintain a processing-purpose register: each purpose gets one primary legal basis, data categories, system owners, recipient categories, a retention rule and a withdrawal/rights impact.

Consent vs Certain Legitimate Uses Under DPDP: when each basis applies and how to document it.
Read the guide →
Understand

Notice vs consent (and why a privacy policy is not enough)

A DPDP notice explains the proposed processing; consent is the Data Principal’s affirmative agreement to it. Section 5 requires notice before or with a consent request. A privacy policy supports transparency but is not automatically the Section 5 notice or a valid consent record.

ItemMain functionExpressly required?Typical format
DPDP noticeExplain the data and specified purpose before/with the requestYes, under Section 5Just-in-time product/form/account notice
Privacy policyBroad transparency documentNot named as the Section 5 notice formatWebsite / app policy
Consent requestAsk for affirmative agreementYes, where relying on consentCheckbox, toggle, button, signed/verbal record
Consent recordPreserve proof of notice and actionProof burden under Section 6(10)Ledger, event log, auditable record
Risk

A lone privacy-policy link beside a checkbox is weak if the person cannot tell what data is collected, why, whether a purpose is optional, how to withdraw, and what action counts as agreement. Design the notice and affirmative event around the actual context.

Status

Rule 3 (effective 13 May 2027) will require the notice to be independently understandable, in clear and plain language, itemising the data, purpose, withdrawal route, rights and a link to the Data Protection Board.

Practice

DPDP consent aligns with the GDPR on free, specific, informed and unambiguous consent and easy withdrawal, but do not port a GDPR programme wholesale: there is no cookie-banner mandate, no standalone right to explanation, and notices must be available in English and the Eighth Schedule languages.

Notice vs Consent Under DPDP: Rule 3 notice content and journey design.
Read the guide →
Operationalise

Legacy data and existing customers

You do not need to erase pre-DPDP customer data on 13 May 2027. Under Section 5(2), consent obtained before commencement can support continued processing until withdrawal, but as soon as reasonably practicable you must give notice of the data, purpose, withdrawal route, rights and how to complain to the Board. This is one of the largest practical problems for Indian businesses.

Inventory &identify person Find originalpurpose + basis Assess evidence& current purpose Classify eachrecord Update systems+ preserve evidence retain / re-notice / re-consent / restrict / delete
Do not treat all historical contacts as equally usable. Classify, then act on each category.
Risk

Purchased or scraped lead lists are high risk: a seller’s assurance is not proof that you have valid consent for your intended purpose. Old marketing leads with no purpose-specific consent should be quarantined, re-permissioned or suppressed.

Legacy Consent Under DPDP: CRM Data, Purchased Leads and Existing Customers
Detailed guide Coming soon
Operationalise

Consent evidence and records

Section 6(10) puts the proof burden on the Data Fiduciary: where a question arises in a proceeding, you must be able to show notice was given and valid consent obtained. That makes consent evidence an operational control, not a UX afterthought. The Act does not fix a record format, but a controlled record helps you answer the questions that matter.

Who & what
Data Principal & account identifier, consent status, personal-data categories, exact purpose.
How & when
Timestamp, channel, notice version, consent wording, affirmative-action method.
Where it went
Source system, processor/recipient flags, change history, evidence reference.
Risk

“Marketing opt-in = yes” in a CRM is rarely enough. It usually cannot show which purpose, which channel, which notice version, whether a separate third-party choice existed, or whether a later withdrawal reached email, SMS, WhatsApp, ad audiences and external processors.

Practice

Treat consent records as integrity-sensitive evidence: access controls, tamper-evident logging where proportionate, change histories and backup/recovery, especially for financial, lending, health, insurance and children’s services.

How to Prove Consent Under DPDP: Evidence, Receipts and Audit Trails
Read the guide →
Operationalise

Consent withdrawal

A Data Principal may withdraw consent at any time, and withdrawal must be as easy as giving it. After withdrawal the Data Fiduciary must stop consent-based processing within a reasonable time and cause its processors to stop, unless another law authorises or requires continued processing. This is where many otherwise-good programmes fail: they capture consent in one place but cannot stop it everywhere.

1Receive request 2Resolve identity 3Find purposes 4Update consent status 5Stop internal processing 6Instruct processors 7Retention review 8Suppress future contact 9Record completion evidence + send closure response
Withdrawal is not an unsubscribe link. It is an end-to-end workflow that must reach processors and leave evidence.
Practice

Support granular withdrawal. Someone may stop marketing while keeping the service. Do not read a marketing withdrawal as a delete-everything request, and do not use active account status as an excuse to continue unrelated marketing or profiling.

DPDP Consent Withdrawal: The End-to-End Operational Playbook
Read the guide Live

See where your consent programme stands

Run the free readiness assessment to score notice, consent, evidence, withdrawal and processor controls, and get a prioritised gap list.

Operationalise

Withdrawal, erasure and retention are not the same

Withdrawal stops consent-based processing. Erasure deletes stored data. Retention keeps limited data where a law or specified purpose still requires it. Do not promise total deletion when tax, fraud, security, claims or regulatory duties require records to remain, and do not keep data for unrelated reuse just because you are allowed to retain some of it.

ConceptMain questionTypical outcome
Consent withdrawalCan we continue consent-based processing?Stop the affected processing within a reasonable time
CessationWhich systems and processors must stop?Disable marketing, profiling or sharing for that purpose
ErasureMust stored data be deleted?Delete unless retention is necessary for a purpose or law
Retention restrictionCan data stay but be blocked from ordinary use?Keep only necessary records with restricted access
SuppressionHow do we prevent future marketing?Keep a minimal “do not contact” record where justified
Law

Section 8(7) requires erasure when consent is withdrawn or the purpose is no longer served, whichever is earlier, unless retention is needed to comply with law, and requires you to cause processors to erase data made available to them. Section 12 gives the Data Principal a right to seek erasure, subject to the same retention limits.

Consent Withdrawal vs Erasure Under DPDP: What Must Stop, What May Remain
Detailed guide Coming soon
Build & govern

The consent operating model in systems

DPDP does not prescribe an architecture, but a Data Fiduciary relying on consent should build systems that can prove what was agreed, enforce purpose limits, handle withdrawal, and push stop-processing instructions to processors. The pattern below is an implementation reference, not a statutory design.

Purpose register Notice service & consent experience Consent event, identity & record Purpose & policy enforcement Apps, CRM, analytics, marketing,support systems Processors + withdrawal,retention & audit evidence
Centralised, federated or hybrid: connect legal requirements to a consent system of record, enforcement and processor propagation.
Practice

Identity resolution is the hidden dependency. A consent status only works if it maps to the right person across email, mobile, customer ID, device and cookie identifiers. Weak matching can suppress, delete or disclose the wrong person’s data. Then make consent a system input: an API blocks a marketing export when consent is withdrawn, a CDP drops the person from ad audiences.

DPDP Consent Architecture: Records, Identity, APIs and Policy Enforcement
Detailed guide Coming soon
Operationalise

Processors and consent propagation

A Data Fiduciary stays accountable for consent-dependent processing done by its processors. Withdrawal is incomplete if internal systems stop but vendors, SaaS tools, ad platforms or outsourced teams keep using the data. Changing one CRM field is not enough.

Withdrawalstop-processing signal Email / SMS / WhatsApp CRM & marketing automation CDP & ad audiences Analytics & data warehouse Support tool, cloud, AI / LLM vendor Each returns evidence:suppression log, API response, deletion cert.
One withdrawal must fan out to every processor of that data, and each should return proof it acted.
Practice

Keep a purpose-to-processor map and use a vendor test: “If we send a withdrawal for Data Principal 12345, which datasets, caches, tickets, backups, tables, profiles and subprocessors are affected, and what evidence will you return?” If a vendor cannot answer, you likely cannot meet your Section 6 and 8 duties through them.

Consent Propagation to Data Processors: Vendor Controls, Workflows and Evidence
Detailed guide Coming soon
Apply

Children, marketing and the highest-risk signals

Some processing carries sharply higher penalties and scrutiny. Before processing a child’s data (anyone under 18), you must obtain verifiable parental consent and must not track, behaviourally monitor or run targeted advertising at children, except under a narrow Fourth Schedule exemption. Marketing carries a different trap: do not import GDPR cookie-banner assumptions.

Verifiable parental consent before processing; no tracking, behavioural monitoring or targeted ads at children. Rule 10 (effective 13 May 2027) allows specified identity/age verification but does not mandate DigiLocker. The Fourth Schedule exemptions disapply only s9(1) and s9(3), never the s9(2) well-being duty.
Marketing, cookies & tracking
DPDP has no cookie chapter and no “accept all / reject all” rule. But where a cookie, device or ad ID is personal data and you rely on consent for marketing, tracking or profiling, the Section 5 and 6 requirements still apply. Keep suppression data separate from marketing profiles.
Rule 10 Parental Consent and Marketing, Cookies, CRM and Tracking Under DPDP
Detailed guides Coming soon
Apply

Sector snapshots

The consent framework is uniform, but the operational tension changes by sector. These are summaries, not complete sectoral advice; each links to a deeper vertical guide as we publish more guides.

Fintech & lending →
Consent must coexist with RBI KYC, AML, fraud and retention duties. RBI’s Digital Lending Directions 2025 require need-based collection, explicit borrower consent, auditable trails and restrict app access to contacts, media and call logs. Keep cross-selling separate from core loan processing.
Insurance & health →
Separate policy servicing, claims, underwriting, fraud, wellness and cross-selling. Medical or clinical-trial consent is not automatically DPDP consent. A health-data flow must not imply reuse of claims or medical data for unrelated marketing or product work.
SaaS & enterprise →
Role confusion is the risk: the customer is often the Data Fiduciary for user data while you are the Processor, and separately a Fiduciary for billing, marketing and telemetry. Build purpose-specific role maps, not one blanket notice.
AI & foundation models
Map personal data across training, fine-tuning, prompts, RAG, telemetry and human review. “Improve our AI” is not an unlimited purpose; assess whether the original notice, consent or other ground supports each distinct reuse.
EdTech & child-facing →
Assess whether students are children, whether Fourth Schedule conditions apply, whether ad-tech or behavioural analytics run, and whether “safety” features stay genuinely limited to safety and education.
High-volume consumer →
Many channels, processors and identifiers multiply withdrawal and evidence complexity. This is where spreadsheets break and identity resolution becomes the deciding constraint.
RBI Digital Lending and DPDP Consent and AI Training and Consent Under DPDP are the first sector guides.
Detailed guides Coming soon
Build & govern

Governance and ownership

Consent management is cross-functional. Legal defines the framework, but product captures consent, engineering enforces it, security protects the evidence, marketing uses preferences, procurement governs vendors and support receives withdrawals. The Act prescribes no RACI; this is a recommended ownership model.

FunctionPrimary responsibility
Board / executiveRisk oversight, resourcing, escalation
DPO / privacyLegal interpretation, policy, notices, rights governance
LegalContracts, disputes, retention, sectoral-law analysis
ProductConsent journeys, purpose presentation, user controls
EngineeringSystem of record, APIs, events, withdrawal propagation
Security (CISO)Access control, log integrity, monitoring, breach readiness
Marketing / CRMPreference use, suppression, campaign governance
ProcurementProcessor diligence, contract controls, deletion support
SupportIntake, identity verification, grievance escalation
Internal auditControl testing, end-to-end withdrawal and retention validation
Build & govern

Build, buy or integrate?

The Act does not require you to buy consent software. A spreadsheet may suffice for a small organisation with few purposes, low volume and few processors, if it still preserves access controls, change history and evidence. It becomes risky once you have multiple channels, large marketing stacks, ad audiences, many processors, children’s data or AI reuse.

Multiple systems, channels and processors? No Yes Controlled records +workflow + testing Need real-time enforcement / APIs / scale? Yes Engineering capacity to own it? No Evaluate a vendor,keep accountability Yes Build internal consent service
Do not buy technology before purpose mapping, system inventory and processor mapping. A platform cannot fix unclear purposes.
Assess & act

The 2026–27 implementation roadmap

The most effective approach is to build the operating model before core consent provisions commence on 13 May 2027. Start with data and purpose discovery, then move through decisions, design, build, testing and governance. This is product, data, security and vendor work, not only legal preparation.

1 Discoverinventory 2 Decidelegal basis 3 Designnotices & flows 4 Buildintegrate 5 Testprove it works 6 Governkeep accurate
PeriodPriority action
Q3–Q4 2026Purpose and data-flow discovery; legacy-data triage; monitor Consent Manager registration (opens 13 Nov 2026)
Q1 2027Notice and consent redesign; processor contract updates; architecture decisions
Q2 2027System integrations; withdrawal propagation; test programmes; staff training
Before 13 May 2027Final readiness assessment; remediate critical gaps; executive sign-off
Assess & act

Could you pass a consent test today?

A DPDP consent audit tests whether you can demonstrate valid notice and consent, enforce purpose limits, complete withdrawals across processors, and explain any retained data. You do not need a formal annual audit for every organisation, but auditability is how you meet the Section 6 proof burden.

Eight controls to self-test
  • Every consent-dependent purpose has a clear description, owner and data-category map.
  • You can show the exact notice version used for each channel and period.
  • Affirmative action is distinguishable from inactivity or forced acceptance.
  • You can produce consent records for sampled Data Principals.
  • A sample withdrawal can be completed end-to-end across systems.
  • Processors received and completed cessation / deletion instructions.
  • Retained data categories are tied to a documented purpose or legal duty.
  • Legacy records with missing purpose or consent evidence are identified.

Your path from here:

1
Read the roadmap
Use the 2026–27 phases above to sequence the work.
2
Run the checklist
Self-test the eight controls for a first-pass read.
3
Take the assessment
Score notice, consent, evidence, withdrawal and processors.
4
Get your gaps
Receive prioritised gaps and recommended next actions.

Use the DPDP Consent Readiness Assessment

Turn this checklist into a scored result with a prioritised gap list for your organisation.

DPDP Consent Audit Checklist: the full evidence, withdrawal and vendor control test.
Open the tool →
FAQ

Frequently asked questions

What is valid consent under the DPDP Act?

Consent that is free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, limited to the personal data necessary for a specified purpose and confined to that purpose (Section 6).

Does every company need consent for every type of processing?

No. Consent is one basis. Section 7 “certain legitimate uses” can cover some processing, such as a voluntarily provided purpose, legal obligations or specified employment uses. Map each purpose to one primary basis.

Is a privacy policy enough for DPDP consent?

Usually not. A privacy policy supports transparency but is not automatically the Section 5 notice or a valid consent record. Design a context-specific notice and a clear affirmative consent event.

Does the DPDP Act require a cookie banner?

No. There is no cookie-specific rule or mandated “accept all / reject all” control. But where an online identifier is personal data and you rely on consent, the Section 5 and 6 requirements apply.

Can a Data Principal withdraw consent?

Yes, at any time, and withdrawal must be as easy as giving consent. You must stop consent-based processing within a reasonable time and cause processors to stop, subject to other authorised or required processing.

Does consent withdrawal require deletion of all data?

Not necessarily. Withdrawal, cessation and erasure are distinct. Data may be retained where necessary for a specified purpose or to comply with law, but it should not be reused for unrelated purposes such as marketing.

How should a company prove consent?

The Act requires you to prove notice was given and valid consent obtained when a question arises in a proceeding. A controlled record of identifier, purpose, timestamp, notice version, affirmative action and withdrawal history is a practical way to support that proof.

Must Data Processors stop processing after withdrawal?

Yes, where processing depends on withdrawn consent. Section 6 requires the Data Fiduciary to cause its processors to cease within a reasonable time, unless another legal basis authorises or requires it.

Is a DPDP Consent Manager mandatory for every company?

No. A Consent Manager is a distinct Board-registered role for enabling Data Principals to manage consent through an interoperable platform. You do not become or use one merely because you process personal data.

Do employers need employee consent under DPDP?

Not always. Section 7 includes certain employment-related legitimate uses, such as preventing loss or liability, protecting confidentiality and providing employee benefits. Still map each purpose rather than treating employment as a blanket exemption.

Does DPDP create a right to explanation for AI or automated decisions?

No. There is no standalone GDPR-style right to explanation of automated decisions. Section 11 provides a right to access information about personal data and processing activities in specified circumstances.

Browse by topic

Explore consent management

The specialist guides below go deeper on each part of this guide. They publish in priority order; the readiness assessment is live now.

Understand
Operationalise
  • Legacy Consent Under DPDP Soon
  • How to Prove Consent Under DPDP Soon
  • DPDP Consent Withdrawal Playbook Soon
  • Withdrawal vs Erasure Soon
  • Consent Propagation to Processors Soon
Build & govern
Apply
  • Rule 10 Parental Consent & Children’s Data Soon
  • Marketing, Cookies & Tracking Under DPDP Soon
  • RBI Digital Lending & DPDP Consent Soon
  • Health Data Consent Under DPDP Soon
  • AI Training & Consent Under DPDP Soon
Assess & act
Written by
DPDPActIndia editorial team
Last regulatory review
August 2026, against the DPDP Act 2023 and the notified DPDP Rules 2025
Editorial methodology
This guide separates Act requirements and Rules requirements (express obligations), future obligations (notified provisions not yet commenced) and implementation recommendations (practical controls, not statutory mandates).
Report an error
Tell us about an inaccuracy and we will review it against primary sources.
References

Primary sources and regulatory references

  • Digital Personal Data Protection Act, 2023 — Ministry of Electronics and Information Technology (MeitY)
  • Digital Personal Data Protection Rules, 2025 — Gazette notification
  • DPDP Act phased commencement notification, 13 November 2025
  • Reserve Bank of India (Digital Lending) Directions, 2025

This guide is general information about the DPDP framework, not legal advice. Confirm application to your organisation with a qualified Indian privacy-law adviser.