Under the DPDP Act, doing the right thing is not enough — you must be able to prove it. Section 6 puts the burden of proving valid notice and consent on the business, and the Data Protection Board can require you to produce evidence of your compliance efforts. EasyDP writes that evidence automatically: timestamped consent records, request trails, breach timelines and notice versions, in one exportable log.
DPDP Act 2023, Sections 6 & 8 · DPDP Rules 2025, Rule 6 (logs) · Updated July 2026
| No. | Obligation | What the Act says | Citation |
|---|---|---|---|
| 01 | The burden of proof is yours | In any proceeding about consent, the Data Fiduciary must prove that a notice was given and valid consent obtained. The customer proves nothing. | Act · S.6 |
| 02 | Security safeguards include logging | Rule 6’s minimum reasonable safeguards include maintaining logs and monitoring for unauthorised access — with logs retained for one year. | Rules · R.6 |
| 03 | The Board can ask for evidence | When a complaint is filed, the Board inquires into what you did and when. Notice versions, consent records, request handling and breach timelines are the record it examines. | Act · S.8, S.27–28 |
Every record stores who consented, to which itemised purposes, at what time, in which language, against which archived notice version — the exact elements the burden of proof demands.
Data principal requests, grievances, withdrawals and their resolutions are logged with received/resolved timestamps against your published timelines.
Discovery, customer notifications, Board intimations and the 72-hour filing are logged as they happen — the timeline that decides whether Rule 7 was met.
The full log exports in a structured format an advisor can verify — turning a Board inquiry or client audit from an archaeology project into a download.
At minimum: consent records (who, what purposes, when, which language, which notice version), the history of your notice versions, data principal requests and how you resolved them, breach incidents and notification timelines, staff training records, and processor agreements. Section 6 makes consent yours to prove, and Rule 6 requires security logs retained for one year.