
India’s Digital Personal Data Protection Act, 2023 (DPDP Act) makes one idea central: if you process someone’s personal data, you generally need their consent to do it. With the DPDP Rules, 2025 now notified and a phased runway to enforcement underway, “getting consent right” has moved from a principle to an operational requirement and for most organisations, the way they collect consent today doesn’t meet the new bar.
Here’s what the law actually asks for, and what it means for how you build.
Consent is now the default basis for processing
Under the DPDP Act, consent is the primary lawful basis for processing personal data, unless a specific “legitimate use” applies (such as certain State functions, medical emergencies, or employment-related purposes). Where consent is the basis, it has to clear a specific standard. Consent must be:
- Free: not coerced or made a condition of unrelated services.
- Specific: tied to a defined purpose, not a catch-all.
- Informed: the person knows what they’re agreeing to.
- Unconditional and unambiguous: given through a clear affirmative action.
- Limited: covering only the personal data necessary for the stated purpose.
The practical casualties of this standard are familiar patterns: pre-ticked boxes, bundled “accept everything” consents, and vague purposes like “to improve our services.” Those don’t survive the DPDP test.
Consent doesn’t stand alone notice comes with it
Every request for consent must be accompanied by, or preceded by, a notice. That notice has to tell the individual, in plain language, at least: the personal data being collected, the purpose of processing, how they can exercise their rights, how they can withdraw consent, and how they can complain to the Data Protection Board of India.
Two details catch people out. First, the notice must be available in English and in the languages set out in the Eighth Schedule of the Constitution so a single English-only banner may not be enough. Second, notice obligations reach back to personal data you already hold: collecting consent once, years ago, doesn’t discharge the duty going forward.
Withdrawal must be as easy as giving
This is the requirement that reshapes system design. Individuals can withdraw consent at any time, and withdrawing must be as easy as giving it was. When consent is withdrawn, you must stop processing that data and ensure any processors acting on your behalf stop too within a reasonable time, unless another legal basis applies.
That means consent can’t be a one-time checkbox captured at sign-up and forgotten. It has to be a living record: a state you store, can act on, and can propagate downstream when it changes. If your architecture treats consent as a moment rather than an ongoing relationship, this is where it will break.
The Consent Manager: a new regulated intermediary
The DPDP framework introduces a distinctive new role: the Consent Manager. This is a registered, neutral intermediary that gives individuals a single, accessible, transparent, and interoperable platform through which they can give, manage, review, and withdraw consent across multiple businesses at once. Think of it as a consent broker, conceptually similar to the Account Aggregator model already used in Indian finance.
Consent Managers register with the Data Protection Board and must meet conditions set out in the Rules, including a minimum net worth threshold and a set of ongoing obligations, with the Board able to suspend or cancel a registration for non-adherence. The Consent Manager framework is scheduled to come into force roughly a year after the Rules were notified, so it’s a runway to prepare for rather than an immediate switch. For most businesses, the near-term action isn’t to become a Consent Manager, but to design consent capture so it can interoperate with one.
Children and guardians need special handling
Processing the personal data of a child (anyone under 18) requires verifiable parental consent, and comparable verifiable consent applies for persons with disabilities who have a lawful guardian. Tracking, behavioural monitoring, and targeted advertising directed at children are restricted. If any part of your user base may include minors, age assurance and parental-consent flows are not optional extras.
Consent is not the whole Act
It’s worth being clear about scope. Lawful consent is necessary, but it isn’t sufficient. The DPDP framework also requires organisations to protect personal data with reasonable security safeguards and to report personal data breaches. A perfectly documented consent record offers no protection if the data behind it is exposed, or if a breach goes undetected and unreported. Consent governs whether you may hold the data; safeguards and breach response govern what happens to it once you do.
A practical readiness checklist
- Inventory. Map what personal data you hold, why, and on what basis; you can’t fix consent you can’t see.
- Rebuild consent flows. Make them purpose-specific, affirmative, unbundled, and paired with a plain-language notice in the required languages.
- Engineer for withdrawal. Build a mechanism to capture withdrawal, honour it, and propagate it to your processors.
- Design for Consent Managers. Structure consent capture to be interoperable ahead of the framework taking effect.
- Handle children properly. Put verifiable parental consent in place wherever minors may be involved.
- Don’t stop at consent. Stand up the security safeguards and breach-detection capability the Act also demands.
The timeline gives you room; use it
The Act’s obligations are arriving in phases rather than overnight, which is a gift most compliance regimes don’t offer: time to do this deliberately. The organisations that struggle will be the ones that treat consent as a banner to bolt on at the deadline. The ones that do well will treat it as an architecture decision made now, while there’s runway.
| Consent management is largely a governance and legal workstream, but two of the DPDP framework’s obligations sit squarely in security operations: protecting personal data with reasonable safeguards, and detecting and reporting breaches on time. That’s where ForshSec helps set up the logging, monitoring, and detection that keep consented data protected and make timely breach reporting possible. If those obligations are on your roadmap, let’s talk. |




