Compliance 7 min read 25 July 2026

DPDP Consent Records: What You Must Retain, and For How Long

Section 6 of the DPDP Act puts the burden of proving consent on the business. Here's exactly what a defensible consent record contains, what else to retain, and how long to keep each record type.

Under Section 6 of the DPDP Act 2023, if a customer ever disputes their consent, it is you — the Data Fiduciary — who must prove a valid notice was given and valid consent existed. The customer proves nothing. This article is the practical spec for the records that discharge that burden.

The Consent Record: Six Required Elements

A consent record that will survive scrutiny captures:

ElementWhy it's required
Who — the Data Principal's identifierConsent is individual; an aggregate "97% accepted" proves nothing about this customer
What — the itemised data and specified purposesConsent is purpose-specific (Section 6(1)); Rule 3 requires the notice to itemise both
When — a timestampEstablishes consent preceded processing, and sequences any later withdrawal
How — the affirmative action takenSection 6 requires a clear affirmative action — record what the customer actually did
Which notice — the archived notice version shownYou must prove what the customer was told, not what your notice says today
Which language — the language servedEvidence the notice was accessible per Section 5(3), making consent genuinely informed

And the mirror image: every withdrawal needs the same treatment, plus evidence that processing stopped. Withdrawal must be as easy as consent (Section 6(4)) — your records should show it was honoured.

What Else the Board Can Ask For

Consent records are the core, but an inquiry will look wider: your privacy notice version history, data principal requests received and resolved against your published timelines (Rule 14), breach incidents and notification timelines (Rule 7), staff training records, and processor agreements (Section 8(2)). Step 14 of our interactive DPDP compliance checklist covers the full documentation set.

How Long to Keep Each Record

  • Consent records: as long as the consent is relied on — and as evidence afterwards. The burden of proof has no expiry date.
  • Security and access logs: minimum one year, as part of Rule 6's reasonable security safeguards.
  • The personal data itself: only as long as the purpose is served or another law requires (Section 8(7)) — retention of the evidence about processing is different from retention of the data.

Spreadsheet or System?

A disciplined spreadsheet can technically hold these elements for a very small customer base. What it can't do is capture them automatically at the moment of consent across web, WhatsApp and offline — which is where records silently go missing. That capture-at-source problem is what audit-log software with timestamped consent records solves.

References & Sources

  1. Ministry of Electronics & IT — The Digital Personal Data Protection Act, 2023 (Sections 5(3), 6, 8(2), 8(7), 27–28).
  2. The Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)) — Rule 3 (notice), Rule 6 (security safeguards and logs), Rule 7 (breach intimation), Rule 14 (rights of Data Principals).

General information, not legal advice. Verify obligations against the notified text for your specific business.

DPDPConsent RecordsAuditComplianceRetention

Check Your DPDP Compliance

Free 2-minute checker — get your specific obligations and penalty exposure.