What is Consent Management?
Consent management is the practice of collecting, recording, and updating user consent to process personal data.
In India, consent management is now a legal obligation for Indian businesses after the notification of Digital Personal Data Protection (DPDP) Act, 2023 and the DPDP Rules, 2025.
Under the DPDP Act, consent management involves two things: (i) Consent collection i.e. capturing valid consent for all personal data processed, and (ii) Data Principal rights management i.e. allowing customers to manage preference changes, withdraw consent, and request deletion of their data across every system that holds it.
Penalties for non-compliance go up to ₹250 crore, which means consent management is now more important than ever!
What Does "Consent" Mean Under The DPDP Act?
The DPDP Act defines consent in Section 6(1). A DPDP compliant consent must be:
- Free: not coerced or made a condition for services unless the data is genuinely necessary for that service.
- Specific: tied to a defined purpose. The data cannot be used beyond what the customer originally agreed to.
- Informed: preceded by a notice that clearly states what data is being collected and why.
- Unconditional: not bundled with consent for unrelated purposes.
- Unambiguous: expressed through a clear affirmative action. Pre-ticked or default-on checkboxes, "deemed consent" and dark patterns like hiding the opt-out are no longer permitted.
- Withdrawable: the Data Principal must have the right to withdraw consent at any time. If the Data Principal withdraws consent, the processing must stop and the data needs to be deleted from the Data Fiduciary’s systems.
When Is Consent Required - and When Is It Not?
A data fiduciary can only process personal data under two pathways:
- via consent of the Data Principal (as per Section 6 of the DPDP Act).
- under "certain legitimate uses" under Section 7.
Section 7 lists nine grounds where processing is permitted without explicit consent:
Section 7(a) is the most confusing one and businesses sometimes read it to mean that they do not require consent for activities like account opening or KYC.
This is incorrect. Section 7(a) is a very narrow exception - which we explain here.
Section 17 also provides certain exemptions under which data can be processed without consent. Read more about these exemptions here.
Consent Collection: What Should Your Consent Notice Look Like?
The DPDP Act and Rules have various provisions that prescribe what your consent notice must look like. Below is a checklist:
This is what a DPDP-compliant consent notice looks like:

The notice must allow the Data Principal to make granular choices. A notice that lists every purpose separately but only offers an "accept all" or "reject all" button is non-compliant.
Each purpose has to be separately consentable, for example the user must be able to say yes to credit underwriting and no to marketing.
Managing Data Principal Rights: What Obligations Do You Have?
Consent management doesn't end at collection. The DPDP Act gives Data Principals six rights over their data.
Allowing Data Principals to manage these rights is the second pillar of consent management - and Data Fiduciaries are responsible for this.
What Should a Consent Management Platform Actually Do?
To actually operationalise consent management at scale, an organisation needs to handle four functions. These can be built in-house or through a dedicated consent management platform.

1. Consent collection:
Consent needs to be obtained at every point where personal data is collected. In India, this could be through:
- Web and mobile app forms
- WhatsApp Business flows
- IVR and call-centre journeys
- In-branch and feet-on-street sign-ups
- Agent-assisted onboarding
- Email and SMS opt-ins
In every case, a valid notice needs to be provided to the user in their preferred language. The consent must have the user's affirmative action.
2. Consent storage:
A timestamped, tamper-proof record of every consent event needs to be stored. Under Section 6(10), the burden of proof in a dispute sits with the Data Fiduciary i.e. they have to prove valid consent was obtained. The consent record should capture:
- Who gave consent
- For which specific purposes
- When (timestamp)
- Through which channel
- In which language
- Against which version of the notice
- Through which affirmative action artefact (signed document, captured tap, voice confirmation)
In addition, the Data Fiduciary also needs to have a unified consent repository and ROPA records i.e. single source of truth for every user's current consent state. The repository needs to be addressable across user identifiers, including phone number, email, customer ID, PAN, and Aadhaar virtual ID, so that a withdrawal raised via WhatsApp updates the same record as the consent originally collected on the app.
3. Preference management:
The Data Principal should be able to exercise their Data Principal Rights i.e. review what they have, change specific preferences, and withdraw consent. They must have access rights (Section 11), correction and erasure (Section 12), grievance redressal (Section 13), and nomination (Section 14), within the timelines specified in the Rules. Rule 14 requires erasure responses within 90 days.
This can be operationalised through a self-service interface where the Data Principal can see what they have consented to, exercise rights to access, correct, or erase under Sections 11–12, raise grievances under Section 13, and toggle individual consents without affecting others.
For this, an authentication mechanism is required to ensure that only the actual customer can access and modify her preferences (an OTP-based check is typically sufficient), and a preference centre where the customer can manage their preferences.
4. Downstream withdrawal, updation and retention signalling:
When a user grants, modifies, or withdraws consent, the change has to be made across every system that holds or uses that data:
- Marketing automation tools
- CRM
- Data warehouses
- Third-party processors
Systems that need to retain the data also need to be notified - for example, an LMS that uses the customer's email to service an active loan, or an audit-only store held for regulatory retention has to be protected from accidental deletion.
This is the hardest part of consent management. To be able to operationalise these to ensure DPDP compliance, you need a consent management platform built for the DPDP context.
This is what Consentin is built to do - it ensures DPDP compliance through consent infrastructure designed for the Indian regulatory context by integrating with the systems large enterprises already run.
Consent Management Under Non-DPDP frameworks
India already has sector-specific consent frameworks that existed before the DPDP Act and continue to exist alongside it.
BFSI. The Account Aggregator (AA) framework, run under the RBI, enables consent-based financial data sharing between banks, lenders, and wealth managers. DPDP compliance for financial institutions has to account for both AA obligations and the broader DPDP consent requirements, particularly around marketing data, third-party data sharing, and customer onboarding. [Link to What DPDP means for lenders →]
Healthcare. The Ayushman Bharat Digital Mission (ABDM) operates its own consent layer for health record sharing. Healthcare providers need to manage consent across both ABDM and DPDP frameworks simultaneously.
Telecom and commercial communications. TRAI's Distributed Consent Architecture (DCA) governs consent for commercial messages and calls. Any business that runs outbound calling, SMS, or RCS marketing is subject to both TRAI and DPDP obligations.
In each of these sectors, the regulator has been ahead of the general market on consent infrastructure. DPDP is now raising the floor for every business that processes personal data, not just those in regulated industries.
FAQ
Q. What is consent management under the DPDP Act?
Ans - Consent management under the DPDP Act is the system a Data Fiduciary uses to collect compliant consent, maintain an auditable record, facilitate withdrawal, propagate changes across data infrastructure, and meet obligations on notice, purpose limitation, and Data Principal rights.
Q. Who needs a consent management platform in India?
Ans - Any business that processes personal data of Indian residents needs a consent management system. Large enterprises with multiple customer touchpoints and data processors are particularly exposed without one.
Q. What is the difference between consent management and a cookie banner?
Ans - A cookie banner is one narrow mechanism for collecting web-based tracking consent. Consent management is the full system across every channel, every purpose, every touchpoint. It includes storage, audit, withdrawal, and downstream propagation that a banner alone cannot handle. [Why you still need a cookie banner under DPDP →]
Q. When do the DPDP consent requirements kick in?
Ans - The DPDP Act and DPDP Rules, 2025 are in force from 14 November 2025. However, the implementation is phased. The Consent Manager registration framework will be from November 2026. Companies will need to ensure full operational compliance with the DPDP Act by 13 May 2027.
Q. What happens if a user withdraws consent?
Ans - The Data Fiduciary must stop processing the user's data for the purpose the user withdrew consent for, within a reasonable time. If there is no other lawful basis to retain the data, the data must be erased. The obligation extends to Data Processors and third-party vendors that hold the personal data.
Q. Is a Consent Manager mandatory under the DPDP Act?
Ans - No. A Consent Manager is an optional intermediary that helps manage consent on behalf of users at scale. A Data Fiduciary may meet the consent requirement under Section 6 through an empanelled Consent Manager or through its own platform. [Is it mandatory to use a NeGD-empanelled Consent Manager? →]
.png)
.png)
.png)

.avif)

.png)