Consent is the engine of the entire DPDP Act. Unlike GDPR, which gives businesses six lawful bases to process data, India's law runs almost entirely on one: did the person actually agree? That makes consent the thing you most need to get right β and the area where a whole new layer, the Consent Manager, switches on in November 2026. If your "I agree" checkbox was designed loosely in a pre-DPDP world, it's now a liability.
Here's how valid consent works under the DPDP Act, what the Consent Manager framework changes, and the deadline you can't push to 2027.
Quick answer: Under the DPDP Act, consent must be free, specific, informed, unambiguous, and given by a clear affirmative action, for each distinct purpose. Manipulative designs β pre-ticked boxes, hidden reject buttons, bundled consent β are banned, and withdrawing consent must be as easy as giving it. From 13 November 2026, registered Consent Managers go live: India-incorporated intermediaries that let users give, review, and withdraw consent across services. Build your consent architecture to integrate with them now.
What counts as valid consent?
The Act sets a high bar. Consent must be:
- Free β not coerced or a condition for unrelated access;
- Specific β tied to a defined purpose;
- Informed β preceded by a clear notice;
- Unconditional β not bundled with unrelated terms; and
- Unambiguous β given by a clear affirmative action, like ticking an empty box or tapping "I agree."
Silence, inactivity, or a pre-checked box is not consent. The burden is on you, the Data Fiduciary, to prove you obtained valid consent β which means you need to log it.
The notice that must come before consent
Consent is only "informed" if a proper notice came first. Before the person agrees, show them an itemised, plain-language notice: what data you're collecting, the specific purpose, how to exercise their rights, and how to complain. (The privacy-policy guide covers exactly what this notice must contain.) Consent without a preceding notice isn't valid consent.
Consent for each purpose, not in a bundle
This is where most sign-up flows break. You cannot collect one blanket "I agree" that covers account creation, marketing emails, analytics, and data sharing with partners all at once. Each distinct purpose needs its own consent the user can give or refuse independently. If someone wants the product but not the marketing, your flow must let them say exactly that.
Withdrawal must be as easy as giving
A defining rule: withdrawing consent must be as simple as granting it. If users opted in with one tap, they must be able to opt out with one tap β not by emailing support, navigating five menus, or filling a form. When consent is withdrawn, you must stop the relevant processing going forward (though processing already done before withdrawal remains lawful).
π‘ Build a single, visible "manage your data / withdraw consent" control into the product. It's both a legal requirement and a trust signal.
What is a Consent Manager?
This is the genuinely new piece. A Consent Manager is a registered intermediary β think of it as a dashboard where an individual can see every consent they've given across different services and give, review, or withdraw them from one place. It acts as a fiduciary to the user, not to any one business.
Only India-incorporated entities meeting eligibility criteria (including a minimum net worth and proven technical capacity) can register as Consent Managers with the Data Protection Board. That requirement effectively keeps foreign consent-management platforms from operating as registered managers in India.
The November 2026 deadline
The Consent Manager framework becomes operational on 13 November 2026 β twelve months after the Rules were notified, and the most concrete intermediate deadline before full compliance in May 2027. For consumer-facing platforms, the practical implication is that your consent capture and management systems need to be compatible with Consent Manager APIs and interoperability standards. Architecting that retroactively is painful, so design for it during your 2026 build.
Legitimate uses: when you don't need consent
Consent isn't required for everything. The Act recognises a short list of "legitimate uses" β most usefully for businesses, standard employment processing (recruitment, onboarding, payroll, and benefits) doesn't need separate consent. The carve-out is narrow, though: the moment you use employee data for something unrelated to employment, you're back to needing consent. Data a person has voluntarily made public also falls outside the consent requirement.
Worked example: fixing a sign-up flow
A fintech app's old sign-up screen has a single pre-ticked box: "I agree to the Terms, Privacy Policy, marketing communications, and data sharing with partners." That fails on four counts β pre-ticked, bundled, unconditional, and no granular choice.
The fixed flow:
- An itemised notice appears first.
- Account creation consent is a single unticked, affirmative checkbox.
- Marketing emails are a separate, optional, unticked checkbox.
- Partner data-sharing is its own optional checkbox, refusable without losing the core service.
- A "Manage consent" link in settings lets the user withdraw any of these in one tap.
- Every consent is timestamped and logged.
Same screen, redesigned β and now defensible if the Board ever asks how consent was obtained.
Common mistakes
- Pre-ticked or bundled consent. Each purpose needs its own affirmative opt-in.
- No consent log. You must be able to prove consent was validly given.
- Hard-to-find withdrawal. It must be as easy as the opt-in.
- Ignoring Consent Managers. Build for the November 2026 API integration now.
- Over-relying on "legitimate use." The employment carve-out is narrow.
Checklist
- Replace blanket consent with purpose-by-purpose opt-ins.
- Remove every pre-ticked box and dark pattern.
- Show an itemised notice before consent is requested.
- Build a one-tap consent-withdrawal control.
- Log and timestamp every consent.
- Make consent capture compatible with Consent Manager APIs by November 2026.
Frequently asked questions
What makes consent valid under the DPDP Act? It must be free, specific, informed, unconditional, and unambiguous, given by a clear affirmative action, for each purpose.
When do Consent Managers go live? The Consent Manager framework becomes operational on 13 November 2026.
Can I use one consent for all my data processing? No. Consent must be specific to each purpose; users must be able to agree to some purposes and refuse others.
How easy must it be to withdraw consent? As easy as it was to give. One-tap opt-in requires one-tap withdrawal.
Do I always need consent? No. Certain "legitimate uses," including standard employment processing, don't require separate consent, but the exceptions are narrow.
This article is for legal awareness and education only and is not legal advice. The framework is being implemented in phases; confirm the current rules and consult a qualified professional before redesigning your consent flows.