Guide · 8 min read

DPDP Act, 2023 and Consent Management: A Practical Guide

India’s Digital Personal Data Protection Act, 2023 puts consent at the centre of how organizations handle personal data. This guide explains the essentials and how to build a consent process that holds up.

What is the DPDP Act?

The Digital Personal Data Protection Act, 2023 (DPDP Act) is India’s law governing the processing of digital personal data. It applies to personal data collected in digital form, or collected offline and later digitised, and to processing outside India where it relates to offering goods or services to people in India.

The Government notified the DPDP Rules in November 2025, with obligations phased in over roughly 12 to 18 months. Organizations should use this window to put processes, notices and systems in place.

Key roles under the DPDP Act

  • Data Principal: the individual the personal data relates to (for a child, the parent or lawful guardian).
  • Data Fiduciary: the organization that decides why and how personal data is processed.
  • Significant Data Fiduciary: a Data Fiduciary notified by the Government, with additional obligations such as a Data Protection Officer and audits.
  • Data Processor: an entity that processes data on behalf of a Data Fiduciary.
  • Consent Manager: a registered entity that lets Data Principals give, manage, review and withdraw consent through an accessible platform.
  • Data Protection Board of India: the body that handles complaints, inquiries and penalties.

What makes consent valid?

Under the DPDP Act, consent must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action, and limited to the personal data necessary for the specified purpose.

Consent must be preceded or accompanied by a notice explaining what personal data is being collected and why, how the person can withdraw consent and exercise their rights, and how to complain to the Data Protection Board.

  • Ask for consent for a specific, clearly stated purpose
  • Collect only the personal data needed for that purpose
  • Make withdrawing consent as easy as giving it
  • Stop processing (and have your processors stop) after withdrawal, unless the law allows otherwise
  • Obtain verifiable parental consent before processing a child’s personal data (under 18)

Rights of Data Principals

  • Right to access a summary of their personal data and the processing activities
  • Right to correction, completion, updating and erasure of personal data
  • Right to grievance redressal by the Data Fiduciary
  • Right to nominate another person to exercise rights in case of death or incapacity

Penalties

The DPDP Act sets out financial penalties that can go up to ₹250 crore for certain failures, such as not taking reasonable security safeguards to prevent a personal data breach. Penalties are imposed by the Data Protection Board after an inquiry, considering the nature, gravity and duration of the breach.

A practical DPDP consent checklist

  • Map every touchpoint where you collect personal data: websites, apps, branches, forms, call centres
  • Record the purpose and the legal basis (consent or a legitimate use) for each
  • Rewrite notices in clear language, with the option to read them in English or Eighth Schedule languages
  • Implement a consent record for each Data Principal and purpose, with timestamps
  • Build a withdrawal path and make sure downstream systems and processors act on it
  • Set up a grievance channel and response process
  • Review retention: erase data when the purpose is served and consent is withdrawn

How a consent management platform helps

Spreadsheets and scattered checkboxes do not scale across channels and systems. A consent management platform such as ConsentLo provides one centralized, configurable place to manage consent, preferences and the consent lifecycle, giving compliance teams structure and visibility.

This guide is general information and not legal advice. Please consult your legal advisers on how the DPDP Act and Rules apply to your organization.

Frequently asked questions

Is the DPDP Act in force?

The DPDP Act was enacted in 2023 and the DPDP Rules were notified in November 2025, with obligations phased in over about 12 to 18 months. Check the latest notified timelines with your legal advisers.

Does the DPDP Act apply to offline data?

It applies to personal data collected digitally, and to data collected offline that is later digitised.

Can a Data Principal withdraw consent?

Yes. Withdrawal must be as easy as giving consent, and the Data Fiduciary must stop processing within a reasonable time unless processing is otherwise permitted by law.

Related