Readiness assessment
DPDP Implementation Tool

DPDP Consent Audit Checklist: Controls, Evidence Tests and Remediation

This tool tests whether your consent controls actually operate, not just whether a policy mentions consent. Work through representative checks across notice, collection, evidence, withdrawal, internal systems and Data Processors, see where the gaps sit, then take away the full 42-control audit workbook.

42 core controls Evidence-based testing Status reviewed: 19 Aug 2026

Internal audit and self-assessment aid. Not certification or legal opinion.

What is a DPDP consent audit?

A DPDP consent audit tests not merely whether policies mention consent, but whether valid consent is obtained, required notice is presented, consent can be proved, withdrawal works, affected processing stops, Data Processor actions can be caused where required, retained data are handled correctly, and operational evidence exists for each of these. It examines controls in real systems, not statements on a page.

The method

What this tool tests

The audit follows one chain for every control. It starts from the legal outcome the Act or Rules require, moves to the operational control that delivers it, then asks what evidence exists, tests whether the control works, records a finding, and points to remediation.

The consent audit method A six-stage chain: legal duty, then operational control, then evidence, then test, then finding, then remediation. Legal dutywhat the law requiresOperational controlhow you achieve itEvidencewhat you can showTestdoes it workFindingpass, partial or failRemediationclose the gap

The same chain runs through every control in the workbook.

A legal duty is not the same as an audit control, and neither is the same as an evidence or implementation mechanism. This tool keeps those three distinct: it tests the operational control, references the underlying legal duty, and treats evidence examples as possible artefacts rather than mandated ones.
Distinction that matters

Legal duty vs implementation

The Act generally specifies an outcome. How you reach that outcome is an implementation choice. The left column is the required outcome; the right column lists possible ways to deliver it, none of which the Act mandates by name.

Legal requirement or outcomePossible implementation
Be able to prove notice and consent for sampled Data PrincipalsVersioned notice and consent records, UI screenshots, form captures, consent events, account mapping
Stop affected processing after withdrawalCRM or CDP suppression, an API event, a manual workflow, campaign exclusion
Cause a Data Processor to cease affected processingA contract clause, an instruction record, an integration event, a vendor ticket
Erase where Section 8(7) requiresA deletion workflow, a retention review, a Processor deletion instruction
The Act generally specifies outcomes, not particular software architectures. Where a control below is classified as an implementation control or good practice, treat the mechanism as one reasonable way to meet the duty, not as a statutory requirement in itself.
Regulatory status: reviewed 19 August 2026

Regulatory status and commencement

Most DPDP consent duties are future-readiness obligations, not current requirements. This audit is published in August 2026. Use the timeline to keep current obligations separate from readiness gaps.

DPDP consent-duty commencement timelineRules notified 13 November 2025; this tool reviewed 19 August 2026; Consent Manager registration framework 13 November 2026; most substantive consent duties operational 13 May 2027.13 Nov 2025Rules notified; commencement machinerybeganNOW19 Aug 2026Status of this audit tool (reviewed)13 Nov 2026Consent Manager registration framework13 May 2027Most substantive consent dutiesbecome operational
Current

Existing obligations already apply. For example, relevant RBI Digital Lending Directions bind in-scope regulated lending arrangements today. Commencement-aware reporting is expected now.

13 Nov 2026

Consent Manager registration framework. The framework under Section 6(9) and Rule 4 opens. Most businesses will not need to register as a Consent Manager themselves.

13 May 2027

Substantive consent duties. Most consent, notice, withdrawal, cessation and erasure obligations tested here become operational.

A future-readiness gap is not a current statutory violation. A control that is not yet in place for a duty that commences on 13 May 2027 is a readiness gap to close before then. This tool does not describe such gaps as violations.

Sources: DPDP Act, 2023; DPDP Rules, 2025 (notified 13 November 2025); the commencement notification; and the RBI Digital Lending Directions, 2025. Full links are in the primary sources section below.

Audit architecture

Ten audit areas

The 42 core controls are grouped into nine domains, plus a tenth set of conditional modules that only some organisations need to answer. The counts below come directly from the workbook.

1

Governance & Scope

Know which consent-based purposes are in scope and who owns each consent control.

4 core controls
2

Lawful Basis & Purpose

Confirm each activity has a lawful purpose and a sound processing ground.

5 core controls
3

Notice & Consent Experience

Test that notice and the consent request meet the Act and Rules in the actual flow.

6 core controls
4

Consent Evidence & Proof

Check that notice and consent can be reconstructed and proved for a sample.

5 core controls
5

Withdrawal & Preference Execution

Verify that withdrawal is accessible, comparably easy and acted upon.

6 core controls
6

Systems & Data-flow Propagation

Trace whether a withdrawal actually reaches the systems that perform the purpose.

5 core controls
7

Data Processor Controls

Confirm you can cause Processors to cease or erase where the Act requires.

4 core controls
8

Retention, Erasure & Suppression

Test erasure on withdrawal or purpose-end and any lawful retention basis.

4 core controls
9

Testing, Monitoring & Remediation

Check that controls are tested end to end and failures are remediated.

3 core controls
10

Conditional and high-risk modules

Answered only where the processing, data population, sector or Rule trigger actually applies.

24 conditional controls
Interactive

Quick consent audit

Fifteen representative controls drawn from the workbook, spanning every domain. For each, mark whether the control passes, partially operates, fails, does not apply, or needs review. This is a self-assessment, not a compliance rating.

0 of 15 answered
GOV-01ImplementationGovernance & Scope

Underlying legal duty: A Data Fiduciary must comply with the Act for processing undertaken by it or on its behalf, and must cease applicable processing after consent withdrawal (DPDP Act Sections 6(6), 8(1))

Can sampled consent purposes be traced to relevant internal systems and Data Processors?

BAS-01StatutoryLawful Basis & Purpose

Underlying legal duty: Processing may occur only in accordance with the Act and for a lawful purpose, based on consent or certain legitimate uses (DPDP Act Sections 4(1), 7)

Can the organisation explain the applicable processing ground for each sample?

NTC-01StatutoryNotice & Consent Experience

Underlying legal duty: Notice before or with a consent request (DPDP Act Section 5(1))

Do sampled flows provide notice at the required time?

NTC-02RuleNotice & Consent Experience

Underlying legal duty: Act notice content; Rule 3 details (DPDP Act Section 5(1); DPDP Rules Rule 3)

Do sampled notices contain required Act/Rule content?

NTC-05StatutoryNotice & Consent Experience

Underlying legal duty: Valid consent criteria (DPDP Act Section 6(1))

Do sampled flows satisfy each Section 6(1) element?

EVD-01StatutoryConsent Evidence & Proof

Underlying legal duty: Data Fiduciary proof burden (DPDP Act Section 6(10))

Can sampled records reconstruct compliant notice and consent?

EVD-03ImplementationConsent Evidence & Proof

Underlying legal duty: Ability to prove notice and consent (DPDP Act Section 6(10))

Can organisation identify what wording the sample saw?

WDR-01StatutoryWithdrawal & Preference Execution

Underlying legal duty: Right to withdraw at any time with comparable ease (DPDP Act Section 6(4); Rule 3 for notice route)

Can sample users access a working withdrawal route?

WDR-02StatutoryWithdrawal & Preference Execution

Underlying legal duty: Comparable ease (DPDP Act Section 6(4))

Is withdrawal materially harder than original consent?

WDR-04StatutoryWithdrawal & Preference Execution

Underlying legal duty: Cessation after withdrawal (DPDP Act Section 6(6))

Does a test withdrawal stop the affected internal processing?

SYS-02ImplementationSystems & Data-flow Propagation

Underlying legal duty: Cessation of affected consent-based processing after withdrawal (DPDP Act Section 6(6))

Does a test withdrawal stop relevant communications?

PRC-01StatutoryData Processor Controls

Underlying legal duty: Data Processor engagement by valid contract (DPDP Act Section 8(2))

Are sampled Processors covered by valid agreements?

PRC-02StatutoryData Processor Controls

Underlying legal duty: Cause Data Processors to cease after withdrawal (DPDP Act Section 6(6))

Can organisation direct and verify cessation for sampled Processor activity?

RET-01StatutoryRetention, Erasure & Suppression

Underlying legal duty: A Data Fiduciary must erase personal data when consent is withdrawn or the specified purpose is no longer served, whichever occurs earlier, unless retention is necessary for compliance with law; it must also cause its Data Processors to erase personal data made available to them (DPDP Act Section 8(7))

For sampled withdrawal or purpose-end cases, does the organisation erase applicable personal data unless it can identify a legally necessary retention basis?

TST-01Good practiceTesting, Monitoring & Remediation

Underlying legal duty: Underlying duties include valid consent, withdrawal cessation and Processor cessation; testing cadence is not prescribed (DPDP Act Sections 6(1), 6(4)–(6), 8(1))

Has organisation tested control operation end-to-end?

Answer what you can. Unanswered controls are shown as still to review.

Your consent control health snapshot

A finding-based diagnostic. It counts where controls may need work; it does not produce a compliance percentage.

Potential statutory-readiness gaps0
Evidence gaps0
Operational-control gaps0
Good-practice improvements0
Controls requiring closer review0

This snapshot is an initial diagnostic, not a legal determination or certification. Most controls tested here relate to duties that become operational on 13 May 2027, so a gap is a readiness gap to close, not a current violation. The full workbook lets you test all 42 controls and record evidence and remediation.

Sample controls

Twelve controls from the audit, in full

A representative set of real controls, spanning all five classifications. Expand any control to see its final classification and underlying legal duty as separate fields, the exact source, commencement, the audit test and possible evidence. Evidence examples are possible artefacts, not artefacts the Act requires by name.

GOV-04 Commencement-aware audit reportingDoes reporting label future-readiness gaps accurately? Good practice
Source: DPDP Act commencement notification dated 13 November 2025Current obligation
Final classification
Good practice
Underlying legal duty
None prescribing an audit-report format; commencement dates determine enforceability
Audit test
Does reporting label future-readiness gaps accurately?
Commencement
Current
Evidence examples
Audit methodology, report templates, finding labels
Why a gap matters
This reflects an existing obligation. None prescribing an audit-report format; commencement dates determine enforceability. A gap here can matter now for in-scope entities.
Remediation direction
Add mandatory commencement-status field to findings
BAS-01 Lawful purpose and processing groundCan the organisation explain the applicable processing ground for each sample? Statutory
Source: DPDP Act Sections 4(1), 7Effective 13 May 2027
Final classification
Statutory
Underlying legal duty
Processing may occur only in accordance with the Act and for a lawful purpose, based on consent or certain legitimate uses
Audit test
Can the organisation explain the applicable processing ground for each sample?
Commencement
13 May 2027
Evidence examples
Processing assessment, legal analysis, notice, product documentation
Why a gap matters
This is a future-readiness control. From 13 May 2027, the underlying duty applies: Processing may occur only in accordance with the Act and for a lawful purpose, based on consent or certain legitimate uses. A gap now is a readiness gap to close before commencement, not a current violation.
Remediation direction
Complete processing-ground assessment
NTC-02 Notice contentDo sampled notices contain required Act/Rule content? Rule
Source: DPDP Act Section 5(1); DPDP Rules Rule 3Effective 13 May 2027
Final classification
Rule
Underlying legal duty
Act notice content; Rule 3 details
Audit test
Do sampled notices contain required Act/Rule content?
Commencement
13 May 2027
Evidence examples
Notice versions, screenshots, translations
Why a gap matters
This is a future-readiness control. From 13 May 2027, the underlying duty applies: Act notice content; Rule 3 details. A gap now is a readiness gap to close before commencement, not a current violation.
Remediation direction
Update notices to Rule 3 content
NTC-05 Valid consent outcomeDo sampled flows satisfy each Section 6(1) element? Statutory
Source: DPDP Act Section 6(1)Effective 13 May 2027
Final classification
Statutory
Underlying legal duty
Valid consent criteria
Audit test
Do sampled flows satisfy each Section 6(1) element?
Commencement
13 May 2027
Evidence examples
Screenshots, UX walkthroughs, forms, scripts, purpose data map
Why a gap matters
This is a future-readiness control. From 13 May 2027, the underlying duty applies: Valid consent criteria. A gap now is a readiness gap to close before commencement, not a current violation.
Remediation direction
Redesign consent journey
EVD-01 Ability to prove notice and consentCan sampled records reconstruct compliant notice and consent? Statutory
Source: DPDP Act Section 6(10)Effective 13 May 2027
Final classification
Statutory
Underlying legal duty
Data Fiduciary proof burden
Audit test
Can sampled records reconstruct compliant notice and consent?
Commencement
13 May 2027
Evidence examples
Notice content, UI capture, form, call record, consent event, account identifier
Why a gap matters
This is a future-readiness control. From 13 May 2027, the underlying duty applies: Data Fiduciary proof burden. A gap now is a readiness gap to close before commencement, not a current violation.
Remediation direction
Build retrievable consent-evidence process
WDR-01 Withdrawal routeCan sample users access a working withdrawal route? Statutory
Source: DPDP Act Section 6(4); Rule 3 for notice routeEffective 13 May 2027
Final classification
Statutory
Underlying legal duty
Right to withdraw at any time with comparable ease
Audit test
Can sample users access a working withdrawal route?
Commencement
13 May 2027
Evidence examples
Preference centre, unsubscribe link, app flow, scripts, test records
Why a gap matters
This is a future-readiness control. From 13 May 2027, the underlying duty applies: Right to withdraw at any time with comparable ease. A gap now is a readiness gap to close before commencement, not a current violation.
Remediation direction
Implement accessible withdrawal channel
WDR-04 Cessation of internal processingDoes a test withdrawal stop the affected internal processing? Statutory
Source: DPDP Act Section 6(6)Effective 13 May 2027
Final classification
Statutory
Underlying legal duty
Cessation after withdrawal
Audit test
Does a test withdrawal stop the affected internal processing?
Commencement
13 May 2027
Evidence examples
Test record, campaign suppression, system configuration, access logs
Why a gap matters
This is a future-readiness control. From 13 May 2027, the underlying duty applies: Cessation after withdrawal. A gap now is a readiness gap to close before commencement, not a current violation.
Remediation direction
Integrate consent state with affected processing
SYS-02 Communications suppression operationDoes a test withdrawal stop relevant communications? Implementation
Source: DPDP Act Section 6(6)Effective 13 May 2027
Final classification
Implementation control
Underlying legal duty
Cessation of affected consent-based processing after withdrawal
Audit test
Does a test withdrawal stop relevant communications?
Commencement
13 May 2027
Evidence examples
Test campaigns, suppression logs, configuration screenshots
Why a gap matters
This is a future-readiness control. From 13 May 2027, the underlying duty applies: Cessation of affected consent-based processing after withdrawal. A gap now is a readiness gap to close before commencement, not a current violation.
Remediation direction
Integrate purpose withdrawal with channel suppression
PRC-02 Processor cessation capabilityCan organisation direct and verify cessation for sampled Processor activity? Statutory
Source: DPDP Act Section 6(6)Effective 13 May 2027
Final classification
Statutory
Underlying legal duty
Cause Data Processors to cease after withdrawal
Audit test
Can organisation direct and verify cessation for sampled Processor activity?
Commencement
13 May 2027
Evidence examples
Contract clause, instruction record, test case, vendor response
Why a gap matters
This is a future-readiness control. From 13 May 2027, the underlying duty applies: Cause Data Processors to cease after withdrawal. A gap now is a readiness gap to close before commencement, not a current violation.
Remediation direction
Add cessation support and test workflow
RET-01 Erasure on withdrawal or purpose completionFor sampled withdrawal or purpose-end cases, does the organisation erase applicable personal data unless it can identify a legally necessary retention basis? Statutory
Source: DPDP Act Section 8(7)Effective 13 May 2027
Final classification
Statutory
Underlying legal duty
A Data Fiduciary must erase personal data when consent is withdrawn or the specified purpose is no longer served, whichever occurs earlier, unless retention is necessary for compliance with law; it must also cause its Data Processors to erase personal data made available to them
Audit test
For sampled withdrawal or purpose-end cases, does the organisation erase applicable personal data unless it can identify a legally necessary retention basis?
Commencement
13 May 2027
Evidence examples
Withdrawal record; purpose-end assessment; deletion record; Processor deletion instruction; legal-retention assessment
Why a gap matters
This is a future-readiness control. From 13 May 2027, the underlying duty applies: A Data Fiduciary must erase personal data when consent is withdrawn or the specified purpose is no longer served, whichever occurs earlier, unless retention is necessary for compliance with law; it must also cause its Data Processors to erase personal data made available to them. A gap now is a readiness gap to close before commencement, not a current violation.
Remediation direction
Implement Section 8(7) trigger handling and legally justified retention review
LND-01 Need-based DLA collection and explicit consentRE ensures DLA/LSP data collection is need-based and has prior explicit borrower consent with audit trail Regulatory
Source: RBI Digital Lending Directions, 2025, para 13Current obligation
Final classification
Regulatory interaction
Underlying legal duty
Audit test
RE ensures DLA/LSP data collection is need-based and has prior explicit borrower consent with audit trail
Commencement
Current
Evidence examples
App flow, consent logs
Why a gap matters
This reflects an existing obligation. None. A gap here can matter now for in-scope entities.
Remediation direction
See workbook
RET-R8-01 Third Schedule inactivity trigger and 48-hour advance-erasure noticeHas the organisation determined Third Schedule applicability, tracked the relevant period, and issued the required 48-hour advance-erasure notice before the Rule 8(1) period ends? Rule
Source: DPDP Rules Rule 8(1)–(2); Third ScheduleEffective 13 May 2027
Final classification
Rule
Underlying legal duty
Rule 8(1) requires listed Data Fiduciaries to erase personal data after the corresponding Third Schedule period where the Data Principal neither approaches the Fiduciary for the specified purpose nor exercises rights in relation to that processing, unless retention is necessary for compliance with law. Rule 8(2) requires notice at least 48 hours before completion of that erasure period
Audit test
Has the organisation determined Third Schedule applicability, tracked the relevant period, and issued the required 48-hour advance-erasure notice before the Rule 8(1) period ends?
Commencement
13 May 2027
Evidence examples
Third Schedule applicability assessment; activity/rights records; inactivity timer; notice template; notice-delivery timestamp; erasure-job configuration; legal-retention assessment
Why a gap matters
This is a future-readiness control. From 13 May 2027, the underlying duty applies: Rule 8(1) requires listed Data Fiduciaries to erase personal data after the corresponding Third Schedule period where the Data Principal neither approaches the Fiduciary for the specified purpose nor exercises rights in relation to that processing, unless retention is necessary for compliance with law. Rule 8(2) requires notice at least 48 hours before completion of that erasure period. A gap now is a readiness gap to close before commencement, not a current violation.
Remediation direction
Map Third Schedule scope; configure inactivity/right-exercise tracking and 48-hour notice workflow
Statutory

Required outcome expressly stated in the DPDP Act.

Rule

Required outcome expressly prescribed by the DPDP Rules, 2025.

Regulatory

A requirement from another applicable Indian regulatory framework, for in-scope entities only.

Implementation

A practical method for achieving, proving or testing a legal outcome. The mechanism is not itself a DPDP mandate.

Good practice

A resilience, governance or auditability practice beyond express legal text.

Evidence

What evidence should an auditor inspect?

Different controls call for different evidence. The map below groups the kinds of artefacts an auditor might sample.

Notice evidence

Notice versions, UI screenshots, copy variations and translations that show what a Data Principal was told.

Consent evidence

Forms, consent screens, call records, consent events and account identifiers that show the affirmative action taken.

Withdrawal evidence

Preference changes, request records, unsubscribe events and system activity showing a withdrawal was received and acted on.

System evidence

Configuration, campaign and suppression logs, and data-flow tests showing the withdrawal reached the right systems.

Processor evidence

Contracts, cessation and deletion instructions, and vendor completion responses.

Retention evidence

A legal-retention assessment, deletion records and purpose-end reviews.

These are examples of possible audit evidence, not universally prescribed DPDP artefacts. The Act generally requires an outcome; the artefact that proves it is an implementation choice unless a source expressly requires that exact record.
Conditional

Conditional and high-risk modules

Not every organisation should answer every control. The workbook enables these modules only where the relevant trigger applies. The final conditional controls, and their exact wording, live in the workbook.

Children and guardian data

Answer only where you process the personal data of children or of persons with lawful guardians.

Not every organisation handles children. Where it applies:

  • Verifiable parental or guardian consent is required.
  • Detrimental processing of children is prohibited.
  • Tracking, behavioural monitoring and targeted advertising directed at children are restricted, unless a narrow Rule 12 or Fourth Schedule exemption applies.

The Act does not prescribe a particular age-gate or verification technology.

Marketing, CRM and ad-tech

Answer where marketing, personalisation, audience or partner-marketing processing relies on consent.

Not every marketing activity is consent-based. Where consent is the basis:

  • Withdrawal must stop the affected communications, and audience or retargeting processing, within a reasonable time.
  • Partner-marketing use must be provable.
  • Suppression data used to prevent re-contact should be purpose-restricted.

The Act does not prescribe a marketing taxonomy or specific tooling.

AI and ML personal-data processing

Answer where AI or ML uses of personal data rely on consent.

Not every AI system relies on consent, and there is no special DPDP lawful basis for AI. Where consent is relied upon:

  • Withdrawal stops future consent-based processing within a reasonable time.
  • It does not, by default, require retraining or deletion of model weights.
  • Vendors acting as Data Processors must be capable of ceasing applicable processing.

RBI-regulated digital lending

Answer only for arrangements within the scope of the RBI Digital Lending Directions.

These are current regulatory-interaction controls, not DPDP duties, and they apply only to in-scope regulated entities, digital lending apps and lending service providers. They cover:

  • Need-based collection with explicit consent.
  • Restrictions on access to device files, contacts and call logs.
  • One-time onboarding permissions.
  • Borrower retention and deletion controls.
  • Lending service provider storage limitation.
  • India-based storage with an overseas bring-back requirement.

RBI requirements apply only to in-scope entities, not to every company.

Rule 8 retention situations

Answer only where a Third Schedule class and purpose, or a Seventh Schedule purpose, actually applies.

Rule 8 does not create a universal one-year or three-year retention rule.

  • The Third Schedule inactivity trigger applies only where the entity class and the corresponding processing purpose fall within that schedule.
  • The 48-hour advance-erasure notice applies on the same basis.
Human legal review required. The Seventh Schedule one-year retention control requires human legal review to determine whether Rule 8(3) applies to your processing. This tool preserves that review status; do not treat it as a settled requirement without review.
The operational asset

Download the DPDP consent audit workbook

The public page helps you understand the method and run an initial audit. The workbook is where the real work happens: the full 42-control instrument plus conditional modules, logs and a remediation tracker in one spreadsheet.

  • 42 core controls with classification, legal duty, source, commencement and evidence
  • Conditional modules for children, marketing, AI/ML, RBI lending and Rule 8 retention
  • An audit scope sheet to define what is being tested
  • An evidence register for the artefacts you rely on
  • A withdrawal test log for sampled or live workflow testing
  • A Data Processor test log for cessation and erasure testing
  • A findings and remediation tracker
  • An executive summary that counts findings and deliberately avoids a compliance score

Consent Audit Workbook (2026)

The complete audit instrument. Editable spreadsheet, no sign-up required.

42 core controlsReviewed 19 Aug 2026.xlsx
Download the workbook (.xlsx)
Optional: are you currently implementing DPDP consent controls? Tell us and we can point you to the right next step.

The workbook is an internal audit and self-assessment aid. It is not certification, a compliance score or legal advice.

Owners

Who should use this?

Consent controls rarely sit with one team. Different controls have different operational owners; the audit is most useful when these functions run it together.

DPO / privacy lead
Owns the audit and the consent operating model
Legal / privacy team
Confirms lawful grounds and reviews conditional modules
Internal audit
Runs the sampling and tracks findings to closure
CISO / GRC
Owns security, monitoring and evidence retention controls
Product
Owns notice timing, the consent request and withdrawal journeys
Engineering
Owns propagation, suppression and system-level cessation
Marketing operations
Owns consent-based campaigns, suppression and audience use
Procurement / vendor management
Owns Processor contracts, cessation and erasure
Primary sources

Primary sources

Legal authority for the controls comes from official sources only. These are the sources the workbook relies on.

  • DPDP Act, 2023
    The primary statute. Sections 5 to 12 govern notice, consent, withdrawal, obligations and rights.
  • DPDP Rules, 2025
    Notified 13 November 2025. Rule 3 (notice), Rule 4 (Consent Managers) and Rule 8 (retention) are referenced here.
  • Commencement notification
    Sets which provisions are in force and the 13 May 2027 date for most substantive duties.
  • RBI Digital Lending Directions, 2025
    The basis for the digital-lending conditional module. Applies only to in-scope regulated arrangements.
FAQ

Common questions

Is a DPDP consent audit legally mandatory?

The DPDP Act does not prescribe a consent audit in this format. It sets outcomes an organisation must be able to meet and, for a Significant Data Fiduciary, requires an independent data auditor under Section 10. A consent audit is a practical way to test whether your consent controls meet those outcomes and can be evidenced.

What evidence should a company keep for consent?

The Act requires a Data Fiduciary to be able to prove that notice was given and consent obtained (Section 6(10)). It does not prescribe a specific record format. Organisations typically retain notice versions, consent screens or forms, a consent event, and an account identifier that together let them reconstruct what a Data Principal saw and agreed to. The workbook lists these as examples, not mandated artefacts.

Does the DPDP Act require consent-management software?

No. The Act specifies outcomes such as valid consent, withdrawal that is comparably easy, cessation of affected processing and provable notice and consent. How you deliver those outcomes is an implementation choice. A registered Consent Manager under Section 6(9) is a specific statutory role, distinct from a consent-management platform; most businesses will not need to register as a Consent Manager themselves.

Does withdrawal always mean deletion?

No. Withdrawal requires the affected consent-based processing to cease within a reasonable time (Section 6(6)). Separately, Section 8(7) requires erasure when consent is withdrawn or the purpose is no longer served, unless retention is necessary for compliance with law. Withdrawal and an erasure request are distinct mechanisms, and some data may be retained where a specific legal necessity applies.

What is the difference between a consent audit and a readiness assessment?

A readiness assessment gives a high-level view of how prepared you are. A consent audit tests specific controls against evidence: it samples records, asks whether a control actually operates in real systems and with Data Processors, and produces findings and remediation. This tool is the audit-level instrument.

Are all 42 controls statutory requirements?

No. The 42 core controls are a mix of statutory outcomes, rule-based outcomes, implementation controls and good practice. The conditional modules add regulatory-interaction controls. Every control shows a final classification and a separate underlying legal duty, so you can see which are express legal requirements and which are practical methods for meeting them.

When do DPDP consent obligations take effect?

The Rules were notified on 13 November 2025. The Consent Manager registration framework opens on 13 November 2026. Most substantive consent, notice, withdrawal, cessation and erasure duties become operational on 13 May 2027. Some overlapping obligations, such as relevant RBI Digital Lending Directions, already apply to in-scope entities today.

Test your consent controls, not just your policy

Run the quick audit for an initial snapshot, then take the full 42-control workbook to test evidence, withdrawal and Processor cessation across your real systems.