securion.ai
  • Solutions
  • Cyber & Cloud Security
  • Frameworks
  • Resources
  • Contact Us
SolutionsCyber & Cloud SecurityFrameworksResourcesContact Us
Preferences
securion.ai

Advanced AI agents for cybersecurity automation and threat detection.

Resources

  • Resources
  • Contact Us

Legal

  • Privacy Policy
  • Terms of Service

© 2026 Securion.ai. All rights reserved.

Back to Resources
Compliance & Frameworks 8 min read

DPDP Consent Explained: How to Collect Consent the Right Way

Learn the five pillars of valid consent under the DPDP Act, how to design compliant sign-up forms, and the common mistakes that make consent invalid.

DPDP Consent Explained: How to Collect Consent the Right Way
In This Article
  • Overview
  • Watch: consent under the DPDP Act
  • Why Consent is the Cornerstone of the DPDP Act
  • The Five Pillars of Valid Consent
  • The Notice: Your Duty Before You Ask
  • Anatomy of a Compliant Sign-up Form
  • Children's Data: A Higher Bar
  • Common Consent Mistakes to Avoid
  • Withdrawing Consent and Managing Artefacts
  • Recap: your consent checklist
  • How Securion.ai Helps
  • Official Reference

Overview

Under India's Digital Personal Data Protection (DPDP) Act 2023, consent isn't just a checkbox; it's the very foundation of lawful data processing. Get it wrong, and the entire structure of your compliance can crumble. Unlike GDPR, which allows for processing based on 'legitimate interests', the DPDPA is much stricter: you either have valid consent or a recognised 'legitimate use'.

For most businesses, consent will be the primary legal basis for processing personal data. This makes understanding its nuances non-negotiable. This guide builds on our introduction to the DPDPA by diving deep into the practicalities of collecting, managing, and proving valid consent.

We will explore the five pillars of valid consent, the anatomy of a compliant sign-up form, and the common pitfalls that businesses must avoid to stay on the right side of the law.

Watch: consent under the DPDP Act

Prefer to watch? Here's the full breakdown in a few minutes.

Why Consent is the Cornerstone of the DPDP Act

The DPDP Act places the individual, the 'Data Principal', firmly in control of their personal data. The entire framework is built on their permission. Section 6 of the Act states that you can only process personal data after obtaining the free, specific, informed, unconditional, and unambiguous consent of the Data Principal.

The only alternative is to rely on one of the narrowly defined 'Legitimate Uses' listed in Section 7, such as complying with a court order or responding to a medical emergency. For day-to-day business operations like marketing, analytics, or user account management, valid consent is the only path forward.

This high bar means organisations must fundamentally rethink their user journeys and data collection practices. The era of assuming consent or hiding it in lengthy legal documents is over.

The Five Pillars of Valid Consent

For consent to be considered valid under the DPDPA, it must satisfy five key conditions. Think of these as a checklist for every consent request you make.

  1. Free: Consent must be given voluntarily, without any coercion or undue influence. You cannot force a user to consent by threatening to withhold a service they have already paid for or are entitled to.
  2. Specific: The consent must be for a clearly stated purpose. If you collect data for email marketing, you cannot later use it for personalised advertising without seeking separate, specific consent for that new purpose.
  3. Informed: The user must know what they are consenting to. This is where the 'Notice' comes in. Before you ask for consent, you must provide clear, simple-language information about the data being collected and the purpose of its processing.
  4. Unconditional: Consent cannot be a precondition for accessing a service unless it's strictly necessary for that service. For example, you cannot force a user to agree to marketing emails just to be able to use your app's basic functionality.
  5. Unambiguous: Consent must be given through a 'clear affirmative action'. This means the user must take a deliberate step to indicate their agreement, such as ticking a box, clicking a button, or selecting a setting. Silence, pre-ticked boxes, or inactivity do not count as consent.

The five pillars of valid consent under the DPDP Act: free, specific, informed, unconditional, unambiguous

The Notice: Your Duty Before You Ask

Before or at the time of requesting consent, a Data Fiduciary must provide the user with a clear and concise notice. This notice is critical for fulfilling the 'informed' pillar of consent.

Under the Act, the notice must contain:

  • The personal data you intend to collect.
  • The specific purpose for which it will be processed.
  • Clear instructions on how the user can exercise their rights, including the right to withdraw consent.
  • The contact details of a Data Protection Officer or a designated point of person who can answer questions.

Crucially, this notice must be available in English or any of the 22 languages specified in the Eighth Schedule of the Indian Constitution, ensuring accessibility for a diverse population.

Anatomy of a Compliant Sign-up Form

Let's move from theory to practice. What does a DPDP-compliant consent mechanism look like on a website or app?

The Wrong Way (Non-Compliant):

  • A single pre-ticked checkbox that says, "I agree to the Terms of Service and Privacy Policy." This bundles multiple consents and isn't a clear affirmative action because it was pre-selected.
  • Vague language like, "We will use your data to improve our services."
  • Forcing users to consent to marketing communications to create an account.

A non-compliant sign-up: one pre-ticked box bundling terms, privacy and marketing

The Right Way (DPDP-Compliant):

  • Granular Options: Separate, unticked checkboxes for each distinct processing purpose.
    • [ ] I consent to my email address being used to send product updates.
    • [ ] I consent to my usage data being used for personalised recommendations.
  • Clear and Simple Language: The purpose next to each checkbox is easy to understand.
  • Layered Information: A clear link to the full privacy notice is provided for those who want more detail.
  • Unbundled Consent: Consenting to marketing is entirely optional and not required to create an account or use the service.

A compliant sign-up: separate, unticked toggles for each purpose, with marketing optional

Children's Data: A Higher Bar

Consent for a child (anyone under 18) works differently. Before processing a child's personal data, a Data Fiduciary must obtain verifiable consent from a parent or lawful guardian — not the child. On top of that, the Act prohibits two things outright: tracking or behavioural monitoring of children, and targeted advertising directed at them. If your service is likely to be used by under-18s, age-assurance and parental-consent flows are not optional — build them in from the start.

Common Consent Mistakes to Avoid

Most consent failures come down to the same handful of errors. Use this as a quick pre-launch check:

  • ❌ Pre-ticked boxes or "consent by default" — silence and inactivity are not consent.
  • ❌ Bundling — one checkbox covering terms + privacy + marketing all at once.
  • ❌ Vague purposes — "to improve our services" tells the user nothing specific.
  • ❌ Forced consent — making optional marketing a condition of using the core service.
  • ❌ Hard-to-withdraw — easy to opt in, buried or impossible to opt out.
  • ❌ No record — being unable to prove what was consented to and when.
  • ❌ English-only notice where your users need a regional language.

Withdrawing Consent and Managing Artefacts

The right to withdraw consent is as important as the right to give it. The DPDPA mandates that withdrawing consent must be as easy as giving it. If a user can consent with a single click, they should be able to withdraw it just as simply, perhaps through a user account dashboard.

When consent is withdrawn, you must stop processing their data for that purpose. You must also ensure that any data processors you work with (like a third-party email service) also cease processing the data.

Furthermore, you must be able to prove you obtained valid consent. This is what auditors will ask for. You need to maintain a log, often called a 'consent artefact', which records:

  • Who consented (user ID).
  • When they consented (timestamp).
  • What they consented to (the specific purpose and the version of the notice they saw).
  • How they consented (e.g., 'web form checkbox').

This verifiable record is your evidence of compliance.

Recap: your consent checklist

Getting consent right under the DPDP Act comes down to five moves. Use this as your implementation checklist:

  1. Give notice first — tell people what you collect and why, before you ask.
  2. Get valid consent — free, specific, informed, unconditional, and unambiguous.
  3. No pre-ticks, no bundling — consent needs a clear, separate, affirmative action.
  4. Make it easy to withdraw — as simple to switch off as it was to switch on.
  5. Keep proof — store the consent artefact (who, what, when, and how).

Your DPDP consent checklist: give notice first, get valid consent, no pre-ticks or bundling, easy to withdraw, keep proof

How Securion.ai Helps

Achieving and maintaining compliance with the DPDP Act involves implementing robust technical and organisational controls. While the Act is about legal principles, proving compliance is an operational challenge. It requires a systematic way to manage, evidence, and audit your data protection practices.

At Securion.ai, our platform is designed to automate the collection of evidence for controls like those required under Rule 6 of the DPDPA. By turning compliance frameworks into agentic workflows, we help you prove that you have the right processes in place for consent management, data retention, and user rights requests, making you audit-ready, continuously.

Navigating the complexities of the DPDPA can be challenging. If you need help understanding your obligations and implementing the right controls, talk to us.

Frequently Asked Questions

1. What about consent collected before the DPDP Act came into force?

You must provide a notice to these users as soon as reasonably practicable, informing them of the data you hold and its purpose, and giving them an easy way to withdraw consent. If they do not withdraw, you can continue processing, but the burden is on you to prove the original consent was valid.

2. Can I use a single checkbox for my Terms of Service and Privacy Policy?

No. This is known as 'bundling' and is not compliant. Consent for processing personal data must be separate from agreeing to general terms and conditions. Each distinct data processing purpose requires its own specific, un-ticked checkbox.

3. What is a Consent Manager? Do I need one?

A Consent Manager is a licensed entity registered with the Data Protection Board that can act as a single point of contact for users to manage their consent across multiple platforms. While you can use one, a Data Fiduciary is perfectly entitled to manage its own consent collection directly, provided it meets all the Act's requirements.

4. What happens if a user withdraws consent? Do I have to delete all their data?

Not necessarily. You must stop processing their data for the purpose for which consent was withdrawn. However, you may be required to retain some of their data to comply with other legal obligations (e.g., financial transaction records for tax purposes).

Official Reference

This guide is a practical explainer. For the authoritative text, read the official government documents:

  • The Digital Personal Data Protection Act, 2023 (PDF) — consent (Section 6), legitimate uses (Section 7), and notice requirements.
  • The DPDP Rules, 2025 (PDF) — the operative rules, including the Consent Manager framework.

For the full picture, start with our pillar guide: DPDPA Explained.

Why Securion?

  • AI-driven threat detection across cloud and SaaS
  • Continuous compliance for SOC 2, ISO 27001, and more
  • Hundreds of security agents — no extra headcount
  • Live audit trail your auditors can self-serve
Try Securion Free
Article Info
Author
Saravanakumar Malaichami, Founder, Securion.ai
Published
14 September 2026
Read time
8 min read
Tags
dpdp actdata privacyconsent managementindiacompliancedata protection
securion.ai
  • Solutions
  • Cyber & Cloud Security
  • Frameworks
  • Resources
  • Contact Us
Login
SolutionsCyber & Cloud SecurityFrameworksResourcesContact Us
Preferences
Login