Compliance 7 min read 21 July 2026

DPDP Consent Records: What You Must Retain, and For How Long

Section 6 of the DPDP Act puts the burden of proving consent on you. What a defensible consent record contains and how long to keep each record type.

Under Section 6 of the DPDP Act 2023, if a customer ever disputes their consent, it is you — the Data Fiduciary — who must prove a valid notice was given and valid consent existed. The customer proves nothing. This article is the practical spec for the records that discharge that burden.

The Consent Record: Six Required Elements

A consent record that will survive scrutiny captures:

ElementWhy it's required
Who — the Data Principal's identifierConsent is individual; an aggregate "97% accepted" proves nothing about this customer
What — the itemised data and specified purposesConsent is purpose-specific (Section 6(1)); Rule 3 requires the notice to itemise both
When — a timestampEstablishes consent preceded processing, and sequences any later withdrawal
How — the affirmative action takenSection 6 requires a clear affirmative action — record what the customer actually did
Which notice — the archived notice version shownYou must prove what the customer was told, not what your notice says today
Which language — the language servedEvidence the notice was accessible per Section 5(3), making consent genuinely informed

And the mirror image: every withdrawal needs the same treatment, plus evidence that processing stopped. Withdrawal must be as easy as consent (Section 6(4)) — your records should show it was honoured.

What Else the Board Can Ask For

Consent records are the core, but an inquiry will look wider: your privacy notice version history, data principal requests received and resolved against your published timelines (Rule 14), breach incidents and notification timelines (Rule 7), staff training records, and processor agreements (Section 8(2)). Step 14 of our interactive DPDP compliance checklist covers the full documentation set.

How Long to Keep Each Record

Spreadsheet or System?

A disciplined spreadsheet can technically hold these elements for a very small customer base. What it can't do is capture them automatically at the moment of consent across web, WhatsApp and offline — which is where records silently go missing. That capture-at-source problem is what audit-log software with timestamped consent records solves.

Keeping these records by hand works while the numbers are small. Beyond that, DPDP compliance software records each consent as it happens, with the notice version and the time it was given.

References & Sources

  1. Ministry of Electronics & IT — The Digital Personal Data Protection Act, 2023 (Sections 5(3), 6, 8(2), 8(7), 27–28).
  2. The Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)) — Rule 3 (notice), Rule 6 (security safeguards and logs), Rule 7 (breach intimation), Rule 14 (rights of Data Principals).

General information, not legal advice. Verify obligations against the notified text for your specific business.

DPDPConsent RecordsAuditComplianceRetention

Check Your DPDP Compliance

Free 2-minute checker — get your specific obligations and penalty exposure.

Related Articles

← All Blog Posts