Consent: Mechanics, Withdrawal, and Deemed Consent
Reading module · approx 14 min
Consent under the DPDP Act is not a passive checkbox or a buried terms-of-service clause. The Act imposes specific requirements on how consent must be sought, what information must accompany it, and how Data Principals must be able to withdraw it.
Requirements for valid consent
Consent under the DPDP Act must be:
- Free: not obtained through coercion, undue influence, or as a condition of a service where processing is not necessary for that service
- Specific: for a clearly stated purpose, not a catch-all consent for undefined future uses
- Informed: accompanied by a consent notice that meets the requirements of the Act
- Unconditional: not bundled with unrelated terms or conditions
- Unambiguous: obtained through a clear affirmative action, not pre-ticked boxes or silence
Consent notices
Before seeking consent, the Data Fiduciary must provide a consent notice specifying: the personal data to be collected; the purpose of processing; the way in which the Data Principal can withdraw consent; and the way the Data Principal can exercise their rights and file grievances. The notice must be available in multiple languages as specified by the DPDP Rules.
The Act also requires that personal data collected before the Act came into force, where consent was the basis for processing, be treated as if consent was given under the DPDP Act if the Data Fiduciary provides the consent notice and the Data Principal has not opted out. This is the "deemed consent" provision for existing data.
Withdrawal of consent
A Data Principal may withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing that occurred before withdrawal. However, the Data Fiduciary must cease processing the personal data after withdrawal, and must facilitate withdrawal as easily as it was given — a principle that has significant implications for UI/UX design of consent flows.
Legitimate uses (deemed consent)
The DPDP Act specifies certain "legitimate uses" for which processing is permitted without explicit consent. These include: processing for the state (government functions, subsidies, licences, and benefits); processing to comply with legal obligations; processing for medical emergencies or disasters; processing for employment purposes; and processing for certain public interest activities.
The legitimate uses are narrower than GDPR's legitimate interests — there is no general balancing test. If processing does not fall within a specified legitimate use and consent is not obtained, the processing is unlawful under the Act.
Module 4 covers cross-border transfer restrictions and data localisation requirements under the DPDP Act.