Home Courses DPDP Act 2023 Compliance Module 3
Module 3 of 6 — DPDP Act 2023 Compliance

Consent: Mechanics, Withdrawal, and Deemed Consent

Reading module · approx 14 min

Consent under the DPDP Act is not a passive checkbox or a buried terms-of-service clause. The Act imposes specific requirements on how consent must be sought, what information must accompany it, and how Data Principals must be able to withdraw it.

Requirements for valid consent

Consent under the DPDP Act must be:

Consent notices

Before seeking consent, the Data Fiduciary must provide a consent notice specifying: the personal data to be collected; the purpose of processing; the way in which the Data Principal can withdraw consent; and the way the Data Principal can exercise their rights and file grievances. The notice must be available in multiple languages as specified by the DPDP Rules.

The Act also requires that personal data collected before the Act came into force, where consent was the basis for processing, be treated as if consent was given under the DPDP Act if the Data Fiduciary provides the consent notice and the Data Principal has not opted out. This is the "deemed consent" provision for existing data.

Withdrawal of consent

A Data Principal may withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing that occurred before withdrawal. However, the Data Fiduciary must cease processing the personal data after withdrawal, and must facilitate withdrawal as easily as it was given — a principle that has significant implications for UI/UX design of consent flows.

Children's consent For Data Principals who are children (under 18, or a lower age if specified by government notification), consent must be obtained from a verifiable parent or guardian. Data Fiduciaries must implement age verification and parental consent mechanisms before processing children's data. The Act also prohibits tracking or behavioural monitoring of children and targeted advertising directed at children — a provision with significant implications for edtech, gaming, and consumer apps.

Legitimate uses (deemed consent)

The DPDP Act specifies certain "legitimate uses" for which processing is permitted without explicit consent. These include: processing for the state (government functions, subsidies, licences, and benefits); processing to comply with legal obligations; processing for medical emergencies or disasters; processing for employment purposes; and processing for certain public interest activities.

The legitimate uses are narrower than GDPR's legitimate interests — there is no general balancing test. If processing does not fall within a specified legitimate use and consent is not obtained, the processing is unlawful under the Act.

Module 4 covers cross-border transfer restrictions and data localisation requirements under the DPDP Act.