Compliance 6 min read 9 March 2026

DPDP Consent Requirements: What Valid Consent Actually Looks Like

Section 6 sets five tests for valid consent — free, specific, informed, unconditional, unambiguous. What each means and what fails it in practice.

Consent is the foundation of the DPDP Act 2023. For most commercial data processing, consent is the only valid legal basis — unlike GDPR, there's no broad "legitimate interests" exception. But not all consent is valid under the Act. Here's what the law requires and what common practices fail the test.

Quick Answer: What Makes Consent Valid Under DPDP?

Under Section 6 of the DPDP Act 2023, valid consent must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action — so pre-ticked boxes, bundled consent, and consent buried in terms don't count. Section 6(4) requires that withdrawing consent be as easy as giving it. Getting consent wrong is a violation carrying penalties up to ₹50 Crore.

Five tests, not four

If you are searching for consent that is "free, specific, informed and unambiguous", that is the GDPR formulation. Section 6(1) of the DPDP Act 2023 sets five tests — it adds unconditional — plus a clear affirmative action:

Free · Specific · Informed · Unconditional · Unambiguous — with a clear affirmative action.

For a business porting a GDPR consent flow into India, unconditional is the test most likely to fail, because bundling consent into terms-of-service acceptance is common practice under GDPR-era design and does not survive Section 6(1).

What Valid Consent Requires (Section 6)

Section 6(1) is explicit, and worth reading in the Act's own words:

"The consent given by the Data Principal shall be free, specific, informed, unconditional and unambiguous with a clear affirmative action, and shall signify an agreement to the processing of her personal data for the specified purpose and be limited to such personal data as is necessary for such specified purpose." — Section 6(1), DPDP Act 2023

Note the two limbs most summaries drop: consent must signify agreement for a specified purpose, and it is limited to the data necessary for that purpose. Consent for an over-broad data grab is not cured by a well-designed checkbox. Each test, and what fails it in practice:

Test What it means What fails it
Free Not coerced, and not the price of a service that can reasonably be provided without that particular data "Consent to marketing or we won't deliver your order"
Specific Tied to a particular, named purpose — not blanket permission for all uses One box covering orders, marketing, analytics and third-party sharing
Informed Preceded by a plain-language notice the person can actually understand Legalese, or a notice in a language the customer does not read
Unconditional Not tied to unrelated conditions — the DPDP-specific fifth test, absent from the GDPR's four Consent bundled into terms-of-service acceptance
Unambiguous No room to doubt the person agreed Silence, inaction, or "by continuing you agree"
Clear affirmative action A positive step the person actually takes A pre-ticked box — unticking is not an action

What Does NOT Count as Valid Consent

Pre-Ticked Checkboxes

A checkbox that is already checked by default — "I agree to receive marketing messages" — is not valid consent. Consent must be an active, positive action by the customer. Unchecking a pre-ticked box is not an affirmative action.

Bundled Consent

A single checkbox that covers multiple purposes — "I consent to my data being used for order processing, marketing, analytics, and sharing with third parties" — is not valid consent. Consent must be specific. If you want to process data for three different purposes, you need consent for each purpose separately (or at minimum, clearly separate consent statements).

Consent Buried in Terms & Conditions

A clause in your Terms of Service that says "by using our service you consent to data collection" is not valid consent under the DPDP Act. The consent must be obtained separately, before or at the time of data collection, through a dedicated consent mechanism — not embedded in lengthy terms that no one reads.

Forced Consent

Making consent a condition of a service where it doesn't need to be. If you're a delivery service and you require consent to share the customer's address with advertisers as a condition of delivering their order — that's forced consent and invalid. The consent to use the address for delivery is necessary; the consent to share with advertisers is not, and must be separate and optional.

Implied Consent

"They gave me their number so they obviously agree to be contacted" is not valid consent. Giving you a phone number for a specific purpose (confirming an order) does not constitute consent to add them to your marketing broadcast list.

The Consent Notice

Before obtaining consent, you must provide a consent notice. The notice must be in clear, plain language (not legal jargon) and must explain:

The notice must be available in any of the 22 Eighth Schedule languages if the customer requests it. This is an important and often overlooked requirement — for an Indian SMB with customers across the country, having your consent notice only in English may not meet this standard.

Consent Must Be Withdrawable

Section 6(4): A Data Principal may withdraw consent at any time. And critically — withdrawing consent must be "as easy as the process by which consent was given." If you made it a one-click opt-in, you must offer a one-click opt-out. You cannot require someone to send an email and wait 30 days to withdraw the consent they gave with a single tap.

Records of Consent

You must keep a record of every consent obtained — who gave consent, for what purpose, when, and how. This record becomes essential if:

The record should include: customer identifier, consent timestamp, the version of the consent notice shown, the specific purposes consented to, and the channel (in-person, online, WhatsApp, etc.).

Consent for Children

For anyone under 18, consent must come from a verified parent or legal guardian. Standard consent mechanisms that work for adults are not sufficient. See our Parental Consent Guide for the specific requirements.

Practical Checklist: Is Your Consent Valid?

If you answered "no" to any of these, your current consent collection method likely does not meet DPDP requirements. If you'd rather not build all of this by hand, consent-management software built for the DPDP Act captures and records valid consent across web, WhatsApp and offline automatically.

References & Sources

  1. Ministry of Electronics & IT, Government of India — The Digital Personal Data Protection Act, 2023 (Section 5 notice; Section 6(1) the five consent tests and clear affirmative action; Section 6(4) withdrawal with comparable ease; Section 6(5) consequences of withdrawal; Sections 6(7)–(9) Consent Managers; Section 9 children's consent).
  2. The Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)) — Rule 3 (notice) and Rule 4 (Consent Managers).
  3. India Code — Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), official consolidated text.

This article is general information about the DPDP Act 2023 and DPDP Rules 2025, not legal advice. Section and rule references are cited from the official text; verify against the current notified version for your specific situation.

ConsentDPDPSection 6Data Collection

Check Your DPDP Compliance

Free 2-minute checker — get your specific obligations and penalty exposure.

Related Articles

← All Blog Posts