Buyer Questions • 5 minutes
What does valid consent look like under DPDP?
A precise breakdown of valid consent under the DPDP Act 2023, focusing on unbundling marketing data from shipping data, notice translation requirements, the legality of prior processing, and building regulator-ready evidence packs for enterprise compliance teams.
Last updated:
What Does Valid Consent Look Like Under DPDP
Under Section 6(1) of the Digital Personal Data Protection Act, 2023, valid consent must be free, specific, informed, unconditional, and unambiguous. It explicitly requires a clear affirmative action within your product interface, signifying a direct agreement to the processing of personal data for a specified purpose. Consent is the primary basis for processing, except where Section 7 legitimate uses apply. For D2C and e-commerce enterprises, this means fundamentally changing how you collect data during customer registration and checkout flows. You can no longer rely on passive agreements.
A direct consequence of this strict legal definition is the absolute end of bundled consent. If a customer agrees to your terms of service to complete a purchase, you cannot use that same action to opt them into promotional emails. You must separate the shipping data needed to fulfil the order from the marketing data used for future campaigns. Users must actively provide a clear affirmative action for each specific processing purpose. This means separating checkboxes and providing distinct opt-in mechanisms for every distinct processing activity.
The Core Elements of Section 5 Notice and Section 6 Consent
Valid consent under Section 6 cannot exist without a compliant notice under Section 5. Every request made to a Data Principal for consent must be accompanied or preceded by a detailed privacy notice. Section 5(1) mandates that this notice must explicitly detail four things: the personal data collected, the precise purpose for which it is proposed to be processed, the manner in which the Data Principal may exercise their rights to withdraw consent and seek grievance redressal under Section 13, and the exact manner in which they may make a complaint to the Data Protection Board.
The DPDP Rules further expand the operational and technical requirements of this notice. The rules dictate that privacy notices must be made available in English and all 22 languages specified in the Eighth Schedule of the Constitution. If your e-commerce platform targets Tier-2 or Tier-3 customers, your application must dynamically present these translated notices at the point of data collection, allowing the Data Principal to comprehend exactly what they are agreeing to in their preferred local language.
Unconditional and specific consent also strictly limits data collection to what is necessary for the stated purpose. The DPDP Act provides a clear illustration to emphasize this limitation: if an individual downloads a telemedicine app, and the app requests consent for both providing telemedicine services and accessing the user's mobile phone contact list, the user may signify consent to both. However, because a phone contact list is not necessary for providing telemedicine services, the valid consent is legally limited only to the processing of personal data strictly required for the telemedicine services. Collecting extra data points just in case you might need them later violates the specific and unconditional requirements of Section 6.
Managing Consent Withdrawal and Prior Processing
Section 6(4) introduces a major user experience challenge by mandating that the ease of withdrawing consent must be comparable to the ease with which such consent was given. If a customer opted into marketing emails via a single click during checkout, requiring them to draft an email, send a physical letter, or call a customer service line to unsubscribe is a direct violation. The withdrawal mechanism must be frictionless and embedded directly in their user profile or the communication itself.
Crucially, Section 6(5) clarifies the legal standing of data processed before a user changes their mind. The consequences of the withdrawal shall be borne by the Data Principal, and such withdrawal shall not affect the legality of processing of the personal data based on consent before its withdrawal. The Act illustrates this with an online shopping scenario: If a Data Principal consents to an e-commerce platform processing her data to fulfill a supply order and makes a payment, but later withdraws consent before delivery, the platform's processing of data up to the point of withdrawal remains entirely legal. However, the platform must halt further processing once consent is withdrawn, and the consequences (such as the order not being shipped) are borne by the Data Principal.
What This Means for Enterprise Compliance Teams
As a Head of Compliance or Data Protection Officer, you must produce a definitive evidence pack showing exactly what notice the user saw, the language it was presented in, and what specific button they clicked. Your control owners cannot rely on a blanket privacy policy link buried in the website footer. You must maintain regulator-ready consent artefacts for every Data Principal interacting with your storefront. These artefacts must log the timestamp, the specific version of the privacy notice presented, and the distinct affirmative action taken.
You have exactly 288 days until the 13 May 2027 deadline to retrofit your checkout flows and backend architectures. Your Chief Marketing Officer will likely resist unbundling shipping data from marketing data out of fear that email lists will shrink and conversion rates will drop. However, relying on non-compliant bundled consent creates massive DPBI exposure and exposes the enterprise to financial penalties of up to 250 crore rupees from the Data Protection Board.
Solving this complex data orchestration problem requires specific tooling. Heavy, legacy banking GRC tools fail in this high-velocity environment because they lack agile integrations with modern e-commerce storefronts and marketing automation platforms. A credible enterprise solution must generate granular consent logs, auto-translate itemised notices into all regional languages, and seamlessly sync withdrawal requests across your entire marketing stack in real-time without burdening your internal engineering teams with custom development.
Related Questions
Does a user deleting their account count as withdrawing consent?
Not necessarily, as deletion and withdrawal are distinct rights under the DPDP Act. Section 6(4) requires a specific mechanism for withdrawing consent that directly matches the ease of providing it. This means you need a dedicated privacy preference center or an intuitive toggle within the account settings, separate from the ultimate account deletion process, allowing users to pause specific processing without destroying their entire profile.
Can we still pre-tick marketing checkboxes during checkout?
No. Section 6(1) explicitly requires unambiguous consent with a clear affirmative action. Pre-ticked boxes, pre-toggled switches, or assuming consent through continued use of the website or silence do not meet the threshold of a clear affirmative action. The user must actively initiate the action themselves.
How do we handle consent for existing customer databases?
You must serve a fresh, itemised notice to your existing customers detailing the personal data currently processed and the precise purpose of processing. You may continue processing their data until they explicitly withdraw consent, provided you give them a clear mechanism to do so as defined by the DPDP Rules, 2025.
What happens to data processed before a customer withdraws consent?
Under Section 6(5), the withdrawal of consent does not affect the legality of any processing of personal data that occurred based on consent before its withdrawal. Your historical processing remains legally sound, but you must immediately cease processing for future actions, and any consequences of the withdrawal are borne by the Data Principal.
What to Do Next
1. Audit your current checkout and registration flows to identify any bundled consent practices where terms of service, shipping requirements, and marketing opt-ins are combined into a single click.
2. Map all personal data fields collected on your website against their specific purpose to ensure compliance with the data minimisation principles detailed in Section 6, removing any unnecessary data collection requests.
3. Evaluate if your current technology stack can capture verifiable consent artefacts, manage immediate withdrawal requests, and serve itemised notices in 22 languages without requiring extensive custom software development.
To understand the exact technical gap between your current checkout flow and DPDP compliance, run an assessment at freescan.complydp.com before the 288-day compliance deadline hits.
Sources
Frequently asked questions
Does a user deleting their account count as withdrawing consent?
Not necessarily. Deletion and withdrawal are distinct rights under the DPDP Act. Section 6(4) requires a specific mechanism for withdrawing consent that matches the ease of providing it, meaning you need a dedicated toggle separate from account deletion allowing users to stop processing without erasing their profile.
Can we still pre-tick marketing checkboxes during checkout?
No. Section 6(1) requires unambiguous consent with a clear affirmative action. Pre-ticked boxes or implying consent through continued use of a website fail the affirmative action test under the DPDP Act. Users must actively click to opt-in.
How do we handle consent for our existing e-commerce customer database?
You must send a fresh, itemised notice to your existing customers detailing the data processed and the exact purpose. You can continue processing until they withdraw consent, provided the withdrawal mechanism complies with the DPDP Rules, 2025.
What is the penalty for violating the consent requirements under DPDP?
Failing to obtain valid consent or failing to provide an equal mechanism for withdrawal creates severe DPBI exposure. The Data Protection Board can impose financial penalties up to 250 crore rupees for non-compliance with Section 6 obligations.
ComplyDP