5 mins

DPDP Act 2023 Section 6 Consent: Free, Specific, Informed, Unconditional and Unambiguous

Understand the exact requirements for Section 6 consent under the DPDP Act 2023. Learn how founders implement specific, unconditional consent flows to pass investor due diligence.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

Under Section 6(1) of the Digital Personal Data Protection Act, 2023, valid consent requires precise elements. The consent given by the Data Principal is free, specific, informed, unconditional and unambiguous. It requires a clear affirmative action. The user signifies an agreement to the processing of her personal data for a specified purpose. The Act limits this agreement strictly to such personal data as is necessary for that specified purpose. Data fiduciaries cannot assume permission. They cannot bundle terms of service to extract broad data access.

Section 6 operates alongside Section 4 and Section 5. Under Section 4, a person processes personal data only in accordance with the Act for a lawful purpose. The Act defines a lawful purpose as any purpose not expressly forbidden by law. The lawful basis is either consent or legitimate uses. When relying on consent, Section 5 introduces mandatory notice requirements. Every request made to a Data Principal under Section 6 requires an accompanying notice. The Data Fiduciary informs the individual about the personal data collected and the proposed processing purpose. This notice explains how the user exercises rights under Section 6(4) and Section 13. It also details the complaint mechanism to the Data Protection Board of India. The DPDP Rules, 2025 specify itemised notice formats to eliminate hidden data clauses.

The Act provides a distinct illustration regarding a telemedicine app. X, an individual, downloads Y, a telemedicine application. Y requests the consent of X for processing her personal data to make telemedicine services available. Y also asks for access to her mobile phone contact list. X signifies her consent to both requests. Because a phone contact list is not necessary for telemedicine services, her consent is limited to the telemedicine processing. The secondary data request is void. Companies cannot condition core services on unrelated data access. Bundling unnecessary data grabs violates the unconditional requirement.

Section 5 includes an additional illustration regarding video identification. X opens a bank account using the mobile app of Y, a bank. To complete Know-Your-Customer requirements under law, X opts for a live, video-based customer identification process. The bank provides notice regarding this specific processing before execution. This proves the customer knows the exact nature of the data collection. The affirmative action of opting into the video process satisfies the unambiguous requirement. The notice maps directly to the specific banking function.

Engineering teams translate these five statutory criteria into product features. Free choice gives the user the ability to refuse without suffering detriment. Specific consent links data fields to exact product functions. General analytical purposes fail the specificity test. An informed user reads the Section 5 notice in plain language. The Act requires this notice to be available in English and the 22 regional languages specified in the Eighth Schedule. An unconditional request prevents locking product features behind unrelated data grabs. An unambiguous action requires a physical or digital step. The user clicks a button or slides a toggle. Passive scrolling provides no legal basis for processing.

Enterprise software buyers evaluate these consent mechanisms during procurement. Sales cycles stall when applications rely on broad data collection. A B2B product faces security questionnaires about data isolation. Founders track consent logs to pass investor due diligence. The system logs affirmative consent from every user. A verifiable audit trail prevents deal delays. Investors know non-compliant data collection creates legal liabilities. Failing to show verifiable consent logs delays funding rounds. It drains startup runway while teams scramble to rebuild their onboarding flows.

Section 6(4) grants the Data Principal the right to withdraw consent at any time. The ease of withdrawal matches the ease of granting consent. When a user revokes permission, the Data Fiduciary ceases processing within a reasonable time. The fiduciary directs its Data Processors to stop processing as well. This operational cascade requires precisely mapped data flows. A withdrawal signal triggers automated deletion scripts across all storage environments. Manual deletion introduces systemic errors. Building these internal tracking pipelines takes significant engineering hours.

Teams preparing for audits execute the following technical steps immediately.

1. Remove passive acceptance banners and pre-ticked checkboxes from registration forms.

2. Map every requested data point to a specific product function to prove necessity.

3. Rewrite privacy notices to present itemised data processing details.

4. Deploy backend systems that record the exact timestamp, the notice version presented, and the specific affirmative action taken.

Startups often assume original consent covers future product features. This misconception creates severe compliance debt. If a company pivots or launches an artificial intelligence tool trained on user data, fresh consent is required. The initial agreement applies only to the specified purpose communicated at the time of collection. Processing data for a new purpose violates Section 6. Another error involves assuming consent applies to every interaction. Consent is the primary basis for processing, except where Section 7 legitimate uses apply. Legitimate uses cover specific scenarios like compliance with court orders or medical emergencies.

Processing the data of minors introduces stricter operational mechanics. The DPDP Rules, 2025 mandate verifiable parental consent. A simple age-gate checkbox fails this standard entirely. Educational technology platforms and gaming applications require token systems or identity tracking to confirm parental authority. Product teams redesign onboarding flows to verify age while keeping the process free and informed. These structural changes affect user conversion rates. Companies balance frictionless onboarding against strict compliance mandates.

Tracking user choices requires specialized platform capabilities. A compliant system maps consent logs to the individual identity of the data principal. It stores the exact notice text presented at the time of the affirmative action. Manual spreadsheets fail investor scrutiny. They lack immutable audit trails. Basic tables cannot trigger automated data deletion workflows across third-party tools. Dedicated tooling automates evidence collection and vendor oversight. Getting your consent flows audit-ready requires technical precision. Check your current exposure and map your forms to Section 6 requirements at freescan.complydp.com.

Sources

Frequently asked questions

What does Section 6 of the DPDP Act say about consent?

Section 6(1) states that consent given by the Data Principal is free, specific, informed, unconditional and unambiguous. It requires a clear affirmative action. The Act limits data collection only to what is necessary for the specified purpose. Fiduciaries cannot bundle unrelated data requests into a single mandatory agreement.

Can we use pre-ticked boxes for user consent under the DPDP Act?

No. The Act specifies that consent requires a clear affirmative action. Pre-ticked boxes, passive scrolling, or assuming consent through continued use of a website do not meet the unambiguous standard.

What happens if a user refuses to give consent for non-essential data?

The unconditional requirement prohibits fiduciaries from denying access to a core service. If a telemedicine app asks for optional access to phone contacts, the user declines it and still uses the medical consultation features.

How do the DPDP Rules 2025 affect consent collection?

The Rules specify operational mechanics for presenting itemised notices and logging consent. They also detail how fiduciaries implement verifiable parental consent mechanics for minors. This requires structural changes to user onboarding flows.

Why do investors check DPDP consent flows during due diligence?

Investors know that non-compliant data collection creates legal liabilities and blocks enterprise sales. Failing to show verifiable consent logs delays funding rounds. It extends the time to compliance and drains startup runway.