Skip to main contentChat with us

DPDP Act 2023 · Section 6 & Rule 4 · Consent Management

DPDP Consent
Management

Consent is the cornerstone of the DPDP Act. Understanding consent requirements and leveraging Consent Managers is essential for lawful data processing.

Section 6 requires consent to be free, specific, informed, unconditional, and unambiguous — and withdrawal must be as easy as giving it.

5Validity attributes
₹2 CrConsent Manager net worth
500+Audits delivered

DPDP Act 2023 · Section 6 + Rule 4, DPDP Rules 2025 · Last reviewed June 2026

Direct Answer

What makes consent valid under the DPDP Act?

Under the DPDP Act 2023, consent is the primary lawful basis for processing personal data, and Section 6 requires it to be free, specific, informed, unconditional, and unambiguous, given through a clear affirmative action. The DPDP Rules 2025 add the Consent Manager — a Board-registered platform under Rule 4 that lets individuals give, manage, review, and withdraw consent in one interoperable place — with the right to withdraw consent as easily as it was given.

Section 6

What Constitutes Valid Consent?

Free

Consent must be given freely without coercion or undue influence

Specific

Consent must be specific to the purpose for which data is processed

Informed

Data Principal must be fully informed about processing activities

Unconditional

Consent cannot be bundled with other services as a condition

Unambiguous

Clear affirmative action indicating agreement is required

At a Glance

Consent Requirements at a Glance

Each attribute of valid consent under Section 6, what it means in practice, and a common way organizations get it wrong.

AttributeWhat it meansCommon failure
FreeGiven without coercion, pressure, or undue influenceDenying a service unless unrelated marketing consent is also given
SpecificTied to each distinct purpose of processingA single blanket tick-box covering many unrelated purposes
InformedPreceded by clear notice of what data, why, and rightsConsent buried in dense terms with no plain-language notice
UnconditionalNot bundled as a condition for an unrelated serviceForcing analytics consent to access core functionality
UnambiguousIndicated by clear affirmative actionPre-ticked boxes or inferring consent from silence

Rule 4

Consent Manager (Rule 4)

A Consent Manager is a registered entity that enables Data Principals to give, manage, review, and withdraw consent through an accessible, transparent, and interoperable platform.

Register with the Data Protection Board of India
Maintain technical capability for interoperability
Provide accessible and transparent consent management
Enable Data Principals to give, manage, review, and withdraw consent
Maintain accurate records of all consents
Act only on instructions of Data Principal
Not have any conflict of interest
Provide consent audit trail when requested

Registration Requirements

Entity Requirements

Company incorporated in India
Net worth of at least ₹2 crore
No criminal convictions for directors

Technical Requirements

Interoperable platform
Secure consent storage
User-friendly interface
Audit trail capability

Operational Requirements

24/7 availability
Grievance redressal mechanism
Data protection measures
Regular compliance audits

Section 6(4)

Withdrawal of Consent

Data Principals have the right to withdraw consent at any time with the same ease as giving consent.

  • Must be as easy as giving consent
  • Takes effect from time of withdrawal
  • Does not affect prior processing

Upon withdrawal, Data Fiduciaries must:

  • Stop processing immediately
  • Erase personal data within specified time
  • Ensure processors also erase data

Frequently Asked Questions

Common questions on valid consent, Consent Managers, withdrawal, and records.

What makes consent valid under the DPDP Act?

Under Section 6 of the DPDP Act 2023, consent must be free, specific, informed, unconditional, and unambiguous, signalled by a clear affirmative action. It must be preceded by a notice describing the personal data collected, the purpose, and how to exercise rights and withdraw consent. Pre-ticked boxes, bundled consent, and inferring consent from silence are not valid.

What is a Consent Manager under the DPDP Act?

A Consent Manager is an entity registered with the Data Protection Board that gives data principals a single, interoperable platform to give, manage, review, and withdraw consent across multiple data fiduciaries. Rule 4 of the DPDP Rules 2025 sets the registration and operating conditions, including a minimum net worth of ₹2 crore, interoperability, and no conflict of interest.

Can a data principal withdraw consent at any time?

Yes. The DPDP Act guarantees the right to withdraw consent at any time, and withdrawal must be as easy as giving it. Withdrawal takes effect from that point and does not invalidate processing already carried out lawfully. On withdrawal, the data fiduciary must stop processing and ensure it and its processors erase the personal data unless retention is legally required.

Do I still need consent if I already comply with GDPR?

Often, yes, and more frequently than under the GDPR. The DPDP Act is consent-centric and does not recognise a legitimate-interest basis, so several activities that rely on legitimate interest under the GDPR will need consent (or a narrow legitimate use) under DPDP. Existing GDPR consent mechanisms are a strong starting point but usually need re-engineering.

How should consent records be maintained?

Data fiduciaries should keep an auditable record of each consent — what was consented to, when, the notice shown, and any withdrawal — so they can demonstrate a valid basis for processing if the Data Protection Board asks. Where a Consent Manager is used, it maintains an interoperable consent audit trail that the data principal can access.

Continue your DPDP research

Written By Expert Auditors

Saundhi Chauhan
Saundhi Chauhan
Lead Auditor
ISO 27001 Lead AuditorISO 27701 Lead Auditor
Surendra Pal Singh
Surendra Pal Singh
Chief Information Security Officer & Data Protection Officer
CISODPOCISAMCSEITILISO 27001 Lead AuditorISO 27701 Lead AuditorISO 42001 Lead Auditor
Last reviewed: June 2026Content verified by certified lead auditors

Get in touch

Book a free consultation or send us your requirements. We respond within 24 hours.

Quick Call

Pick a time slot

Send Requirements

Get a custom quote in 24 hours

We're Online

⚠️ Business inquiries only. Personal email addresses will be rejected.

24hr Response
Free Consultation
No Obligations