Compliance

Understanding Valid Consent and Withdrawal under India's DPDP Act

Section 6 of the Digital Personal Data Protection Act requires consent to be free, specific, informed and unambiguous, and forces businesses to make withdrawal as easy as giving consent, otherwise processing becomes unlawful and may lead to costly penalties and data‑deletion obligations.

Check your DPDP readiness — free More on the blog

Understanding Valid Consent and Withdrawal under India's DPDP Act

The DPDP Act defines consent as a clear, affirmative act that authorises the processing of personal data for a single, stated purpose. It cannot be implied, bundled or obtained through pre‑ticked boxes. The consent must be given without pressure, with full knowledge of what is being allowed, and it must be specific to that purpose alone.

Key Features of Valid Consent

A valid consent must satisfy five criteria: it must be free, meaning the data subject can refuse without adverse consequences; it must be specific to a particular purpose; it must be informed, relying on the notice required under section 5; it must be unconditional, without hidden conditions; and it must be unambiguous, demonstrated by an active step such as ticking a box. If any of these elements are missing, the consent is invalid. An invalid consent renders the entire data‑processing activity unlawful, exposing the data fiduciary to enforcement action, fines, and the requirement to delete the unlawfully processed data.

  • Free – no coercion or undue influence
  • Specific – tied to one purpose only
  • Informed – based on a clear notice
  • Unconditional – no hidden strings
  • Unambiguous – clear affirmative action

Separate Consent for Each Purpose

Businesses often try to simplify user experience by asking for a single "accept all" tick. Under section 6 this is prohibited because each purpose needs its own distinct consent. A data subject may agree to marketing communications but refuse data sharing with third parties, and the fiduciary must respect each choice independently. When consent is withdrawn for one purpose, processing for that purpose must stop immediately and the data must be erased unless another law mandates retention. The withdrawal does not affect processing that was lawful before the withdrawal, nor does it cancel consent for other purposes that remain valid.

Making Withdrawal Easy

The Act obliges the data fiduciary to provide a withdrawal mechanism that is at least as simple as the original consent method. If consent was given by ticking a checkbox, the same level of ease—such as a single click in a settings page—must be offered for withdrawal. Requiring a written request or navigating through multiple menus would breach the requirement. Failure to honour a withdrawal request can lead to continued unlawful processing, which the Act treats as a fresh breach. The fiduciary must then halt the activity, delete the data, and may face monetary penalties for each instance of non‑compliance. Practical steps for businesses include auditing consent flows, separating consent prompts for each purpose, removing pre‑selected options, and building a one‑click withdrawal button that mirrors the original consent interface. Regular testing ensures the mechanism remains functional and compliant.

Common questions

What makes consent valid under the DPDP Act?

Consent is valid only if it is free, specific to a single purpose, informed by a proper notice, unconditional and shown by a clear affirmative act such as ticking a box. Any default or pre‑ticked option, silence or bundled request does not meet the legal standard.

Can a single consent cover multiple data‑processing purposes?

No. Section 6 requires separate consent for each purpose. A data subject may consent to some uses and refuse others, and the fiduciary must process data only for the purposes that have distinct, valid consent.

How must a business allow users to withdraw consent?

The withdrawal option must be at least as easy as the original consent method. If consent was given by a single click, withdrawal should be possible with a similarly simple click, not through lengthy forms or hidden settings.

What happens to data after consent is withdrawn?

The fiduciary must stop processing the data for that purpose and erase it, unless another law obliges retention. Past lawful processing remains valid, but any further use after withdrawal is unlawful.

Related reading

  • Late payments to MSME suppliers trigger tax disallowance — If a business does not settle dues to a registered micro or small enterprise within the statutory 45‑day (or 15‑day without contract) window, the amount is added back to taxable profit at year‑end, removing the deduction and increasing income‑tax liability.
  • Understanding the Writing Requirement for Arbitration Agreements — Section 7 of the Arbitration and Conciliation Act mandates that arbitration agreements be in writing, and a mere venue clause does not satisfy the requirement, costing businesses delays and extra litigation if ignored
  • Cost of Ignoring Internal Committee Rules Under POSH Act — Failing to set up an Internal Committee or file the required annual report can attract a fine of up to fifty thousand rupees and, on repeat, double the penalty plus possible licence cancellation, threatening a small business’s ability to operate.

Written by Swaraj Layek

Founder & CEO at VidhiSar. I have watched four companies pay for the same mistake, and it was never the mistake anyone expected. VidhiSar is software, not a law firm: every answer names the section it relies on so you can check it, and anything turning on your specific facts is worth putting to a professional. More about who builds this