Consent is the foundation of the DPDP Act 2023. For most commercial data processing, consent is the only valid legal basis — unlike GDPR, there's no broad "legitimate interests" exception. But not all consent is valid under the Act. Here's what the law requires and what common practices fail the test.
Quick Answer: What Makes Consent Valid Under DPDP?
Under Section 6 of the DPDP Act 2023, valid consent must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action — so pre-ticked boxes, bundled consent, and consent buried in terms don't count. Section 6(4) requires that withdrawing consent be as easy as giving it. Getting consent wrong is a violation carrying penalties up to ₹50 Crore.
If you are searching for consent that is "free, specific, informed and unambiguous", that is the GDPR formulation. Section 6(1) of the DPDP Act 2023 sets five tests — it adds unconditional — plus a clear affirmative action:
Free · Specific · Informed · Unconditional · Unambiguous — with a clear affirmative action.
For a business porting a GDPR consent flow into India, unconditional is the test most likely to fail, because bundling consent into terms-of-service acceptance is common practice under GDPR-era design and does not survive Section 6(1).
What Valid Consent Requires (Section 6)
Section 6(1) is explicit, and worth reading in the Act's own words:
"The consent given by the Data Principal shall be free, specific, informed, unconditional and unambiguous with a clear affirmative action, and shall signify an agreement to the processing of her personal data for the specified purpose and be limited to such personal data as is necessary for such specified purpose." — Section 6(1), DPDP Act 2023
Note the two limbs most summaries drop: consent must signify agreement for a specified purpose, and it is limited to the data necessary for that purpose. Consent for an over-broad data grab is not cured by a well-designed checkbox. Each test, and what fails it in practice:
| Test | What it means | What fails it |
|---|---|---|
| Free | Not coerced, and not the price of a service that can reasonably be provided without that particular data | "Consent to marketing or we won't deliver your order" |
| Specific | Tied to a particular, named purpose — not blanket permission for all uses | One box covering orders, marketing, analytics and third-party sharing |
| Informed | Preceded by a plain-language notice the person can actually understand | Legalese, or a notice in a language the customer does not read |
| Unconditional | Not tied to unrelated conditions — the DPDP-specific fifth test, absent from the GDPR's four | Consent bundled into terms-of-service acceptance |
| Unambiguous | No room to doubt the person agreed | Silence, inaction, or "by continuing you agree" |
| Clear affirmative action | A positive step the person actually takes | A pre-ticked box — unticking is not an action |
What Does NOT Count as Valid Consent
Pre-Ticked Checkboxes
A checkbox that is already checked by default — "I agree to receive marketing messages" — is not valid consent. Consent must be an active, positive action by the customer. Unchecking a pre-ticked box is not an affirmative action.
Bundled Consent
A single checkbox that covers multiple purposes — "I consent to my data being used for order processing, marketing, analytics, and sharing with third parties" — is not valid consent. Consent must be specific. If you want to process data for three different purposes, you need consent for each purpose separately (or at minimum, clearly separate consent statements).
Consent Buried in Terms & Conditions
A clause in your Terms of Service that says "by using our service you consent to data collection" is not valid consent under the DPDP Act. The consent must be obtained separately, before or at the time of data collection, through a dedicated consent mechanism — not embedded in lengthy terms that no one reads.
Forced Consent
Making consent a condition of a service where it doesn't need to be. If you're a delivery service and you require consent to share the customer's address with advertisers as a condition of delivering their order — that's forced consent and invalid. The consent to use the address for delivery is necessary; the consent to share with advertisers is not, and must be separate and optional.
Implied Consent
"They gave me their number so they obviously agree to be contacted" is not valid consent. Giving you a phone number for a specific purpose (confirming an order) does not constitute consent to add them to your marketing broadcast list.
The Consent Notice
Before obtaining consent, you must provide a consent notice. The notice must be in clear, plain language (not legal jargon) and must explain:
- What personal data will be collected
- The specific purpose for which it will be processed
- Any third parties with whom it will be shared
- How the Data Principal can withdraw consent
- How they can access, correct, or request deletion of their data
The notice must be available in any of the 22 Eighth Schedule languages if the customer requests it. This is an important and often overlooked requirement — for an Indian SMB with customers across the country, having your consent notice only in English may not meet this standard.
Consent Must Be Withdrawable
Section 6(4): A Data Principal may withdraw consent at any time. And critically — withdrawing consent must be "as easy as the process by which consent was given." If you made it a one-click opt-in, you must offer a one-click opt-out. You cannot require someone to send an email and wait 30 days to withdraw the consent they gave with a single tap.
Records of Consent
You must keep a record of every consent obtained — who gave consent, for what purpose, when, and how. This record becomes essential if:
- A customer claims they never consented to something
- The Data Protection Board investigates your consent practices
- You need to demonstrate compliance during an audit (part of your wider business responsibilities)
The record should include: customer identifier, consent timestamp, the version of the consent notice shown, the specific purposes consented to, and the channel (in-person, online, WhatsApp, etc.).
Consent for Children
For anyone under 18, consent must come from a verified parent or legal guardian. Standard consent mechanisms that work for adults are not sufficient. See our Parental Consent Guide for the specific requirements.
Practical Checklist: Is Your Consent Valid?
- ☐ Is the checkbox or confirmation step unchecked by default?
- ☐ Is consent obtained before or at the time of data collection?
- ☐ Does the consent notice clearly explain what data and for what purpose?
- ☐ Is marketing consent separate from order-processing consent?
- ☐ Is there an equally easy way to withdraw consent?
- ☐ Is the consent record stored with timestamp and purpose?
- ☐ Is the consent notice available in Indian languages on request?
If you answered "no" to any of these, your current consent collection method likely does not meet DPDP requirements. If you'd rather not build all of this by hand, consent-management software built for the DPDP Act captures and records valid consent across web, WhatsApp and offline automatically.
References & Sources
- Ministry of Electronics & IT, Government of India — The Digital Personal Data Protection Act, 2023 (Section 5 notice; Section 6(1) the five consent tests and clear affirmative action; Section 6(4) withdrawal with comparable ease; Section 6(5) consequences of withdrawal; Sections 6(7)–(9) Consent Managers; Section 9 children's consent).
- The Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)) — Rule 3 (notice) and Rule 4 (Consent Managers).
- India Code — Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), official consolidated text.
This article is general information about the DPDP Act 2023 and DPDP Rules 2025, not legal advice. Section and rule references are cited from the official text; verify against the current notified version for your specific situation.