6 mins

Itemised Notices and Consent Managers: Evidentiary Burdens for Fiduciaries Under DPDP Rules 2025

Section 5 of the DPDP Act 2023 requires specific itemised notices before consent collection. Large data fiduciaries bear the burden of proof under Section 6(10) to demonstrate compliance, requiring immutable audit trails and integration readiness for registered Consent Managers before the government-notified effective dates.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

Executive Summary

Enterprise compliance leaders face a precise evidentiary burden under the Digital Personal Data Protection Act, 2023. When a Data Principal challenges a processing activity, Section 6(10) places the burden of proof squarely on the Data Fiduciary to demonstrate valid notice and consent. The Rules, 2025 mandate itemised notices that link collected data categories to specific processing purposes. Government-notified effective dates dictate the operational timeline for these requirements. Large organizations need to operationalize these notice rules across all digital touchpoints. The introduction of registered Consent Managers adds a new layer of API-driven consent orchestration that enterprise GRC frameworks have to support.

Statutory Framework

Section 4 of the Act establishes that personal data processing requires a lawful purpose. Consent is the primary basis for processing, except where Section 7 legitimate uses apply. Section 5(1) outlines the mechanics of the consent request. Every request made under Section 6 needs to be accompanied or preceded by a notice given to the Data Principal. The text sets specific requirements for this artifact.

The notice informs the individual of the personal data proposed for processing and the exact purpose. It also details how the Data Principal exercises withdrawal and grievance rights under Section 6(4) and Section 13. Section 6(10) drives the enforcement mechanism. The Data Fiduciary bears the legal obligation to prove that a compliant notice preceded the consent.

Rules 2025 Operational Layer

The Rules, 2025 expand the Section 5 notice into a strict itemised format. Fiduciaries cannot rely on monolithic privacy policies or buried terms of service to satisfy the consent notice requirement. The presentation needs a granular breakdown of data elements matched directly to their processing purposes. A financial application collecting identity documents and location data maps the identity document to regulatory KYC compliance. That same application maps the location data to fraud prevention. Mixing distinct operations into a single paragraph fails the itemization test.

Section 6 introduces the Consent Manager as a new entity in the digital ecosystem. Under Section 6(8), Consent Managers are accountable to the Data Principal and act on their behalf to manage consent choices. Section 6(9) requires these managers to register with the Data Protection Board subject to prescribed technical conditions. Compliance teams build or procure architecture capable of receiving consent state changes pushed by these external managers. A user might revoke marketing consent via a third-party application. The fiduciary then processes that signal and halts downstream processing within statutory timelines.

Enforcement and DPBI

The Data Protection Board of India evaluates consent artifacts primarily during dispute resolution. If a Data Principal claims unauthorized processing, the Board will demand the specific Section 5 notice presented at the time of collection. Missing audit trails or vague notices fail this test. Organizations face penalties up to 250 crore rupees for failing to implement reasonable security safeguards, but process failures around notice directly compromise the legal basis for processing.

Invalidated consent corrupts the data supply chain for the enterprise. Without a proven lawful purpose, downstream uses like analytics or vendor sharing become immediate compliance liabilities. The cost of a failed control extends beyond a regulatory fine. Companies face the forced deletion of data sets collected without verifiable itemised consent.

Comparative Context

Multinational compliance teams often try to reuse European notice frameworks. European models allow broad legitimate interest justifications that minimize granular consent prompts. Under the DPDP Act, legitimate uses are tightly scoped to specific scenarios like medical emergencies or employment administration. Most enterprise processing requires explicit consent based on the itemised notice.

The Indian mechanism relies on a direct link between the notice presented and the user action recorded in the audit trail. Global platforms treating the DPDP Act merely as a localization exercise will fail the Section 6(10) burden of proof. The requirement expects transactional records of consent. Proof that a general policy was published on a website is insufficient.

Decision Matrix

Direct customer onboarding on a mobile application requires specific documentation. The control owner presents the itemised Section 5 notice before or alongside data collection. A time-stamped consent log stores a hash or reference to the exact notice version presented.

Consent withdrawal initiated via a registered Consent Manager triggers immediate action. The Data Protection Officer halts processing of the requested personal data across all internal systems. Teams generate an automated API receipt log alongside a downstream system deletion record.

A Data Protection Board of India audit request tests the enterprise records. The General Counsel proves notice delivery and consent capture under Section 6(10). The organization produces a regulator-ready evidence pack extracting the specific user journey and consent state.

Vendor Evaluation Criteria

Enterprise buyers require specific capabilities for itemised notices when evaluating compliance software. Providers need to version-control the notice text presented at the time of user interaction. If a marketing team updates the notice on Tuesday, the system tracks which version a user saw on Monday. Assess integration readiness for registered Consent Managers under Section 6(9).

A credible vendor explains how their platform exports immutable audit logs satisfying the Section 6(10) burden of proof. The system requires a mechanism to map user choices directly to the data processing inventory. This mapping triggers downstream data stops when users withdraw consent. Discard solutions offering static policy hosting without transactional consent logging or verifiable evidence extraction.

Implementation Roadmap

30 Days. Map all digital collection points across web and mobile assets. Draft itemised notices linking specific data fields to their exact processing purposes based on the enterprise data processing inventory.

60 Days. Deploy consent capture architecture that records the precise version of the notice presented alongside the user identifier. Connect these collection points to a centralized consent ledger.

90 Days. Establish API endpoints or structured workflows to process consent withdrawals initiated through external Consent Managers. Run simulation audits to validate the extraction of evidence packs for legal review.

Further Reading

ComplyDP outlines related operational requirements in guides covering verifiable parental consent mechanisms and breach intimation workflows required under the Rules, 2025. Evaluating a DPIA process against the Data Protection Board expected standards is the next operational step after securing consent logs.

Enterprise compliance requires regulator-ready audit trails instead of basic policy banners. Large fiduciaries use ComplyDP to generate the exact evidence packs the Board expects under Section 6(10). Map technical exposure with an evaluation at freescan.complydp.com.

Sources

Frequently asked questions

How does the DPDP Act treat consent notices compared to standard privacy policies?

Section 5 of the DPDP Act requires an itemised notice preceding or accompanying a consent request. It links specific personal data categories to precise processing purposes. Broad privacy policies do not meet this transactional requirement.

What is the burden of proof for Data Fiduciaries under Section 6?

Section 6(10) requires the fiduciary to prove notice was given and valid consent was obtained. Large enterprises need immutable audit trails matching the user to the exact version of the notice presented at the time of collection.

How do Consent Managers affect enterprise compliance operations?

Consent Managers act on behalf of Data Principals to manage consent choices under Section 6(8). Fiduciaries need technical systems to receive and process consent state changes originating from these external registered platforms.

When is the deadline to implement itemised notices across digital properties?

The implementation timeline depends on the government-notified effective dates for the DPDP Act. Fiduciaries must update all digital touchpoints and notice frameworks before these dates to maintain a lawful basis for processing.

Can we process data without an itemised notice if the user benefits from the service?

Consent is the primary basis for processing, except where Section 7 legitimate uses apply. General business operations and product improvements require valid consent via an itemised notice regardless of perceived user benefit.