Under the DPDP Act, consent must be , specific, informed, unconditional, and unambiguous, with a clear affirmative action. Pre-ticked boxes, bundled consents, and vague language do not meet this standard.
Notices should clearly state what personal data is being collected, the purpose of processing, and how individuals can withdraw consent. Notices must be available in English and, where required, in the language of the data principal.
Consent Managers are registered intermediaries that allow data principals to give, manage, review, and withdraw consent across multiple data fiduciaries through a single interface. Organizations should evaluate whether integrating with a Consent Manager fits their data collection model.
Maintain verifiable, timestamped records of consent — including what was disclosed, when consent was given, and any subsequent withdrawal. These records form the backbone of your audit trail in the event of a regulatory inquiry.
Withdrawal must be as easy as giving consent. Once withdrawn, organizations should stop processing the relevant personal data within a reasonable timeframe and cascade the withdrawal to any processors acting on their behalf.