Shieldra Compliance · DPDP Compliance

Consent Management Implementation Playbook

A practical guide to building DPDP-compliant consent flows

1. What Counts as Valid Consent

Under the DPDP Act, consent must be , specific, informed, unconditional, and unambiguous, with a clear affirmative action. Pre-ticked boxes, bundled consents, and vague language do not meet this standard.

2. Designing the Consent Notice

Notices should clearly state what personal data is being collected, the purpose of processing, and how individuals can withdraw consent. Notices must be available in English and, where required, in the language of the data principal.

3. The Role of Consent Managers

Consent Managers are registered intermediaries that allow data principals to give, manage, review, and withdraw consent across multiple data fiduciaries through a single interface. Organizations should evaluate whether integrating with a Consent Manager fits their data collection model.

4. Recording and Auditing Consent

Maintain verifiable, timestamped records of consent — including what was disclosed, when consent was given, and any subsequent withdrawal. These records form the backbone of your audit trail in the event of a regulatory inquiry.

5. Handling Withdrawal of Consent

Withdrawal must be as easy as giving consent. Once withdrawn, organizations should stop processing the relevant personal data within a reasonable timeframe and cascade the withdrawal to any processors acting on their behalf.