Consent is the foundation the DPDP Act builds on, but most pre-Act consent flows fall well short of the new standard. Bundled checkboxes, vague purpose statements, and consent that's easy to give but hard to withdraw are now compliance liabilities.
Consent must be , specific, informed, unconditional, and unambiguous, with a clear affirmative action from the individual. Pre-ticked boxes and consent bundled with unrelated terms of service do not meet this bar.
A compliant notice clearly states what data is being collected, why, and how someone can withdraw consent later — written in plain language rather than dense legal text. Notices should be available in the language the data principal can reasonably understand.
Consent Managers are registered intermediaries that let individuals manage consent across multiple organizations from a single interface. As Phase 2 of the Act takes effect, integrating with a Consent Manager becomes central to verifiable, auditable consent.
Withdrawal must be at least as simple as the original consent action. Once withdrawn, processing of that data should stop within a reasonable window, and the withdrawal should cascade to any processors acting on the organization's behalf.