5 min read

DPDP Consent and Notice Rules for D2C Consumer Apps

Understand the DPDP Act 2023 and Rules 2025 consent requirements for e-commerce platforms. Learn how to unbundle notices, manage language requirements, and prepare your compliance team before the deadline.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

Overview

Exactly 221 days remain until the DPDP hard compliance deadline of 13 May 2027. For a Head of Compliance at a large D2C or e-commerce enterprise, updating consumer app consent flows is an immediate priority. The Digital Personal Data Protection Act, 2023, changes how consumer apps collect data from the Data Principal, the individual to whom the personal data relates. Blanket terms and conditions are no longer valid. Data Fiduciaries, the entities determining the purpose and means of processing, must generate regulator-ready evidence packs for every consent transaction. This requires re-engineering app onboarding, checking control owners, and preparing accurate board reporting metrics.

What the DPDP Act says

Section 4 of the DPDP Act, 2023, states that personal data processing requires a lawful purpose. A business must obtain consent under Section 6 or rely on legitimate uses under Section 7. Section 5 mandates that a notice must accompany or precede any consent request. This notice must detail the personal data collected, the purpose of processing, and the mechanisms for rights withdrawal and grievance redressal. Section 6 requires consent to be free, specific, informed, unconditional, and unambiguous with a clear affirmative action. An app collecting data for a specific purpose cannot force users to consent to unrelated processing.

DPDP Act vs Rules, 2025: what changed

The Act provides the statutory framework, while the DPDP Rules, 2025, specify the operational mechanics. The Rules require itemised notices rather than long legal policies. They operationalise the requirement to make notices available in English and the 22 regional languages listed in the Eighth Schedule of the Constitution. For consumer apps, this changes the user interface directly. The Rules also detail verifiable parental consent workflows and outline specific duties for Significant Data Fiduciaries (SDF). The volume of data processed and the risk to consumer rights dictate SDF designation, which brings obligations like appointing an India-based Data Protection Officer and conducting periodic Data Protection Impact Assessments (DPIA).

What every Data Fiduciary must do now

Historically, e-commerce platforms bundled consent. Users agreed to receive marketing emails simply by accepting standard shipping terms. Section 6 outlaws this practice entirely. Compliance teams must now separate shipping data collection from promotional data collection. The enterprise must maintain distinct consent artefacts for each purpose. A competent legal team can draft the initial privacy notice in a spreadsheet. Translating that notice into 22 languages and dynamically tracking user withdrawals across millions of accounts breaks manual processes. Scale requires an automated registry. CMOs often fear that unbundling will destroy their email lists. CTOs worry about the technical debt of building custom consent loggers. A practical compliance strategy bridges this gap by offering a seamless interface that captures consent unambiguously while generating a precise audit trail.

Breach notification specifics

The DPDP Rules, 2025, establish strict incident response timelines that require immediate cross-team coordination. A Data Fiduciary must intimate affected Data Principals without delay upon discovering a personal data breach. Concurrently, the compliance team must submit a detailed report to the Data Protection Board of India within 72 hours. This creates a heavy ongoing operational burden. An enterprise must have predefined workflows linking the security operations center directly to the legal reporting team. Data Fiduciaries often rely on Processors for backend infrastructure, but the primary enterprise remains liable for ensuring vendor breaches are reported up the chain in time to hit the 72-hour window.

Common misconceptions

One widespread myth assumes consent is the only legal basis for processing. This is incorrect. Consent is the primary basis for processing, except where Section 7 legitimate uses apply. Another misconception involves data classification. The DPDP Act, 2023, does not create a separate category for health or financial data. Risk and data volume dictate SDF designation instead of a formal data category. A third error involves legacy user lists. Marketing teams often assume they can retain old data without action. The Act requires sending a new, compliant notice to all existing users if their data processing continues.

Implementation checklist

1. Map all data collection points in the consumer app to build an initial RoPA [In-house feasible].

2. Draft a master itemised privacy notice covering personal data elements and specific processing purposes [In-house feasible].

3. Translate the privacy notice into 22 regional languages to ensure compliance and tier-2 market access [Tooling-assisted].

4. Unbundle app permissions, physically separating functional data like shipping addresses from marketing data [Tooling-assisted].

5. Deploy a consent registry to log the time, IP address, and exact text presented for every user consent [Tooling-assisted].

6. Update vendor contracts to require immediate alerts from Processors in the event of an incident [In-house feasible].

7. Configure breach reporting templates to meet the 72-hour DPBI notification requirement [In-house feasible].

Penalties and enforcement risk

The Data Protection Board of India enforces these requirements. The Act defines proportional penalties for non-compliance based on the severity of the violation. Failure to implement reasonable security safeguards carries a maximum penalty of 250 crore rupees. Breaches involving children and the failure to secure verifiable parental consent carry penalties up to 200 crore rupees. Failing to provide the mandatory Section 5 notice limits the legal validity of the collected consent. This directly exposes the enterprise during a DPBI audit, as the burden of proving that consent was validly obtained rests entirely on the Data Fiduciary.

How ComplyDP helps

Large D2C enterprises cannot rely on heavy banking GRC tools to manage consumer scale. ComplyDP provides a Consent Unbundler that separates shipping data from marketing data natively. The platform auto-translates itemised notices into regional languages and generates regulator-ready audit trails for every transaction. Teams can assess their current readiness and identify specific gaps in their consent workflows by visiting https://www.complydp.com/audit-preview today.

Sources

Frequently asked questions

Does the DPDP Act ban bundled terms and conditions?

Yes. Section 6 requires consent to be specific and limited to the exact purpose of processing. E-commerce platforms can no longer force users to accept marketing emails just to complete a checkout process.

Do we need to translate our privacy notices?

Yes. Under Section 5 of the Act and the DPDP Rules 2025, Data Fiduciaries must give users the option to view the notice in English or any of the 22 languages specified in the Eighth Schedule of the Constitution.

How fast must we report a data breach under the new Rules?

The DPDP Rules 2025 mandate strict incident response timelines. A Data Fiduciary must intimate affected Data Principals without delay and submit a detailed report to the Data Protection Board within 72 hours.

Can we use existing consents collected before the Act?

You can continue processing data based on prior consent, but you must send a fresh, itemised notice to those users. The processing must stop if the user withdraws consent after receiving this new notice.

What is the penalty for failing to obtain valid consent?

The Data Protection Board of India can impose substantial fines for non-compliance. Violations related to consent duties or breaches involving children carry penalty ceilings up to 200 crore rupees.