6 min read
DPDP Act 2023 Section 6 Consent: Free, Specific, Informed, Unconditional and Unambiguous
A detailed breakdown of DPDP Act 2023 Section 6 consent requirements for startup founders, covering how to implement free, specific, informed, unconditional, and unambiguous consent to pass enterprise due diligence.
Last updated:
Section 6 of the Digital Personal Data Protection Act, 2023 sets the legal standard for user agreement. The consent given by a Data Principal shall be free, specific, informed, unconditional and unambiguous with a clear affirmative action. A business cannot rely on pre-ticked boxes. Bundled service agreements fail this test. Forced opt-ins violate the law. The agreement is strictly limited to the personal data necessary for the specified purpose. If an app collects data outside this strict boundary, the consent is legally invalid for the excess data.
The Act provides a direct illustration of unconditional limits. An individual downloads a telemedicine app. The application requests consent to process personal data for making telemedicine services available. The app also requests access to the user contact list. The individual signifies consent to both requests. Phone contact lists are not necessary for making available telemedicine services. The legal text dictates that consent is limited only to the processing of personal data for the telemedicine services. The excess consent for the contact list is void.
Each of the five statutory words carries a specific operational burden. Free indicates the Data Principal faces no detriment if they refuse unrelated data processing. Specific compels the Data Fiduciary to state exactly what data it collects for which exact purpose. Informed requires a detailed notice preceding the user action. Unconditional bans tying service delivery to unnecessary data harvesting. Unambiguous demands a clear affirmative action. A user closing a cookie banner or continuing to browse a website does not constitute an affirmative action.
Section 6 consent relies entirely on Section 5 notice. Every request made to a Data Principal for consent shall be accompanied or preceded by a notice. The Data Fiduciary gives this notice to inform the user about the personal data and the proposed purpose. The DPDP Rules 2025 mandate an itemised format. The notice explains the data category. It states the exact processing purpose. The document details the manner in which the user exercises their withdrawal right. The system provides the grievance redressal mechanism. A business cannot capture valid consent if the user never sees this precise information.
Startups face exactly 244 days until the compliance deadline of 13 May 2027. Enterprise buyers audit vendor consent flows during security reviews. A mature security posture requires auditable proof of legal data processing. Procurement teams look for the itemised notice presented just before the clear affirmative action occurs. Archiving the specific version of the privacy notice forms the foundation of this record. Failing to log the exact notice text leaves a software vendor unable to prove the consent was genuinely informed. This documentation gap routinely blocks B2B deals.
Section 6 gives the Data Principal the right to withdraw consent at any time. The process for withdrawal is subject to strict ease-of-use standards. The Act states that withdrawing consent shall be as easy as giving it. A startup cannot let users opt in with one click while requiring an email to customer support to opt out. Once a user withdraws consent, the Data Fiduciary ceases processing their personal data within a reasonable time. The Fiduciary causes its Data Processors to cease processing that data as well. Manual withdrawal processes drain engineering resources quickly.
The DPDP Act introduces a new technical framework for managing these requests. Section 6 allows a Data Principal to give, manage, review, or withdraw consent through a Consent Manager. A Consent Manager is a platform registered with the Data Protection Board. These entities operate as accountable intermediaries on behalf of the user. Software vendors need technical infrastructure capable of receiving and executing automated signals from these registered managers. Building an architecture that ignores external withdrawal signals puts a company out of compliance.
Many founders treat consent as the sole legal basis for data collection. This approach creates heavy friction. Section 4 permits processing for lawful purposes based on consent or for certain legitimate uses. Section 7 defines these legitimate uses. Examples include responding to a medical emergency or fulfilling a state legal obligation. Identifying data flows that qualify as legitimate uses reduces the volume of explicit opt-ins a product requires. You skip the affirmative action screen entirely when a recognized exception applies.
Processing data of users under eighteen requires different mechanics. The DPDP Rules 2025 outline specific steps for verifiable parental consent. A standard adult consent flow violates the Act if the user is a minor. The business identifies the parent or lawful guardian. It obtains verifiable consent before processing the minor personal data. A rigid consent architecture that fails to handle age gating exposes the startup to immediate regulatory risk. Development teams build parallel intake flows to verify parental identity before logging the affirmative action.
Evaluating your consent implementation requires three steps. 1. Audit all user intake forms to eliminate pre-checked boxes and bundled terms. 2. Map downstream data flows to ensure a withdrawal request triggers automated erasure alerts to all connected Data Processors. 3. Update the core database schema to tag every user record with its current consent status. A missing tag forces developers to manually hunt for records across multiple tables when a withdrawal occurs. Manual tracking consumes hours better spent on core product development.
Proving compliance requires software built directly around the Act and Rules. A credible solution records the exact version of the notice. It logs the timestamp of the affirmative action. The system tracks the specific purposes the user approved. This evidence trail answers auditor questions instantly. It clears security reviews for enterprise software deals. Companies evaluating their compliance infrastructure need tools that manage itemised notices and capture granular consent without manual intervention. See how your current data collection flows measure up at freescan.complydp.com.
Sources
Frequently asked questions
Does DPDP Section 6 require a checkbox for consent?
Section 6 requires a clear affirmative action from the Data Principal. Pre-ticked boxes or passive agreement through continued website use fail the standard for unambiguous consent.
What does unconditional consent mean under the DPDP Act?
A business cannot force a user to agree to unrelated data processing as a condition of using a service. The company only requests consent for personal data strictly necessary to provide the specific feature.
Can we bundle consent into our Terms of Service?
The Act requires specific and informed agreement. Hiding data processing terms inside a lengthy Terms of Service document violates the requirement for a separate, itemised notice.
What happens if a user withdraws consent under Section 6?
The Data Fiduciary ceases processing the personal data within a reasonable time after withdrawal. The statutory text dictates that the process for withdrawing consent remains as easy as giving it.
Do we need consent for every single data processing activity?
Section 4 permits processing based on consent or for certain legitimate uses. If the processing falls under a legitimate use defined in Section 7, explicit consent is unnecessary.
ComplyDP