Under Section 6 of the DPDP Act 2023, if a customer ever disputes their consent, it is you — the Data Fiduciary — who must prove a valid notice was given and valid consent existed. The customer proves nothing. This article is the practical spec for the records that discharge that burden.
The Consent Record: Six Required Elements
A consent record that will survive scrutiny captures:
| Element | Why it's required |
|---|---|
| Who — the Data Principal's identifier | Consent is individual; an aggregate "97% accepted" proves nothing about this customer |
| What — the itemised data and specified purposes | Consent is purpose-specific (Section 6(1)); Rule 3 requires the notice to itemise both |
| When — a timestamp | Establishes consent preceded processing, and sequences any later withdrawal |
| How — the affirmative action taken | Section 6 requires a clear affirmative action — record what the customer actually did |
| Which notice — the archived notice version shown | You must prove what the customer was told, not what your notice says today |
| Which language — the language served | Evidence the notice was accessible per Section 5(3), making consent genuinely informed |
And the mirror image: every withdrawal needs the same treatment, plus evidence that processing stopped. Withdrawal must be as easy as consent (Section 6(4)) — your records should show it was honoured.
What Else the Board Can Ask For
Consent records are the core, but an inquiry will look wider: your privacy notice version history, data principal requests received and resolved against your published timelines (Rule 14), breach incidents and notification timelines (Rule 7), staff training records, and processor agreements (Section 8(2)). Step 14 of our interactive DPDP compliance checklist covers the full documentation set.
How Long to Keep Each Record
- Consent records: as long as the consent is relied on — and as evidence afterwards. The burden of proof has no expiry date.
- Security and access logs: minimum one year, as part of Rule 6's reasonable security safeguards.
- The personal data itself: only as long as the purpose is served or another law requires (Section 8(7)) — retention of the evidence about processing is different from retention of the data.
Spreadsheet or System?
A disciplined spreadsheet can technically hold these elements for a very small customer base. What it can't do is capture them automatically at the moment of consent across web, WhatsApp and offline — which is where records silently go missing. That capture-at-source problem is what audit-log software with timestamped consent records solves.
References & Sources
- Ministry of Electronics & IT — The Digital Personal Data Protection Act, 2023 (Sections 5(3), 6, 8(2), 8(7), 27–28).
- The Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)) — Rule 3 (notice), Rule 6 (security safeguards and logs), Rule 7 (breach intimation), Rule 14 (rights of Data Principals).
General information, not legal advice. Verify obligations against the notified text for your specific business.