Readiness assessment

DPDP Guide · Consent

Notice vs Consent Under the DPDP Act: What Is the Difference?

A DPDP notice and DPDP consent are two separate obligations that people constantly merge. Getting the distinction right is the foundation of a compliant consent flow.

In short

A DPDP notice and DPDP consent are two different things. The notice, under Section 5, is the information a Data Fiduciary must give before or when it asks for consent: what personal data it wants, for what specified purpose, and how the individual can withdraw consent or complain. The consent, under Section 6, is the individual's free, specific, informed and unambiguous agreement to that purpose. You cannot obtain valid consent without first giving a compliant notice, but a notice on its own is not consent.

The core difference in one line

The notice is something you give. The consent is something they give. The notice informs; the consent agrees. One is an act by the Data Fiduciary, the other is an act by the Data Principal, and the law treats them as distinct steps that happen in a specific order.

DimensionDPDP NoticeDPDP Consent
What it isInformation you present to the individualThe individual's agreement to the purpose
Statutory basisSection 5 (and Rule 3 of the DPDP Rules 2025)Section 6
Who actsThe Data FiduciaryThe Data Principal
TimingBefore or at the moment consent is requestedAfter, or together with, the notice
FormA clear, itemised, standalone statementA clear affirmative action (tick, toggle, tap)
Proof neededThat the notice was shown, and its contentsThat agreement was freely and specifically given

What a DPDP notice must contain

Section 5 requires that the notice accompany or precede every consent request. Rule 3 of the DPDP Rules 2025 adds that it must be clear, understandable, and capable of standing on its own, so an individual can read it independently of any other document. In practice a compliant notice sets out:

  • An itemised description of the personal data being collected, not a vague catch-all.
  • The specified purpose, meaning the exact goods, services or processing the data will be used for.
  • How to withdraw consent, which must be as easy as giving it.
  • How to exercise rights and how to make a complaint to the Data Protection Board of India.
  • A contact point for the Data Protection Officer or a person who can answer questions.

The notice must be available in English or any language listed in the Eighth Schedule to the Constitution, at the individual's option.

Practice

A privacy policy is not a Section 5 notice. A policy is a broad, background document; the notice is a specific, just-in-time statement tied to the exact purpose you are asking to process for. You can link to your policy from the notice, but the notice itself has to carry the itemised data and purpose.

The correct sequence

A compliant flow runs in a fixed order, and each step produces something you may later need to prove.

  • Show the notice with the itemised data and specified purpose.
  • Request consent through a clear affirmative action tied to that purpose.
  • Record both, the notice that was shown and the consent that was given, with enough detail to reconstruct them later.
  • Honour withdrawal whenever it is requested, and stop the processing that relied on that consent.
The law

Notice sits in Section 5; consent sits in Section 6; and Section 6(10) places the burden of proving valid consent on the Data Fiduciary. Most of these obligations take effect on 13 May 2027, so the time to design the sequence is now.

Common mistakes

  • Treating the privacy policy as the notice. The policy is not itemised or purpose-specific enough to satisfy Section 5.
  • Bundling consent. Asking for one agreement that covers many unrelated purposes fails the "specific" test.
  • Collecting first, informing later. The notice has to come before or with the request, not after the data is already taken.
  • No withdrawal path. If withdrawing consent is harder than giving it, the consent is not valid.
Risk

If you cannot show the notice that was displayed and the consent that was captured, you have not met the Section 6(10) burden of proof, regardless of what your database says a user "agreed" to.

Notice vs consent: frequently asked questions

Is a privacy policy the same as a DPDP notice?

No. A privacy policy is a broad transparency document. A DPDP notice under Section 5 is a specific, itemised, just-in-time statement of the exact personal data and purpose tied to a consent request. You can link to the policy from the notice, but the policy does not replace it.

Does giving a notice always require getting consent?

Not always. Consent is one lawful basis. Section 7 lists certain legitimate uses where processing is allowed without consent, though transparency obligations can still apply. When you rely on consent, however, a compliant notice must come first.

What language must a DPDP notice be in?

The notice must be available in English or any language listed in the Eighth Schedule to the Constitution of India, at the individual's option.

Can I combine the notice and the consent request on one screen?

Yes. They can appear together, and often should, as long as the notice content is clear and itemised and the consent is a distinct affirmative action. Combining them on screen is fine; merging them so the individual cannot tell what they are agreeing to is not.

What happens if I collect consent without a notice?

The consent is unlikely to be valid, because consent must be informed and the notice is what informs it. In any proceeding, Section 6(10) puts the burden of proving valid consent on the Data Fiduciary, and without a notice that burden is very hard to meet.

Sources

  • Digital Personal Data Protection Act, 2023, Sections 5 and 6 (including 6(10)).
  • Digital Personal Data Protection Rules, 2025, Rule 3 (notice to Data Principals).
  • Constitution of India, Eighth Schedule (languages).

General information about the DPDP Act and Rules, not legal advice, and not affiliated with any government body.