Consent management under the DPDP Act

Updated 19 Sep 2026 · 6min read · Reviewed by ConsentLo's DPDP audit team

Consent is the main lawful basis for processing personal data under the DPDP Act, and the bar is high. This guide explains what valid consent looks like and how to manage it at scale.

Purpose by purpose

If you process data for order delivery, marketing emails and personalised ads, each is a separate purpose and needs a separate choice. A person may say yes to delivery and no to ads. Any clause in your notice or terms that goes against the Act is invalid to that extent.

Withdrawal as easy as giving

People must be able to withdraw consent as easily as they gave it, for example with one switch in a portal or app. After withdrawal you, and your processors, must stop processing for that purpose within a reasonable time.

Frequently asked questions

Are cookie banners enough for DPDP consent?

Not by themselves. DPDP consent must be purpose-specific, backed by a clear notice, as easy to withdraw as to give, and provable later. Many cookie banners fail on at least one of these.

Can consent be bundled with terms and conditions?

No. Consent must be specific and unconditional. Bundling it into terms of service, or making a service conditional on consent to unnecessary processing, does not meet the standard.

What is the difference between a consent management platform and a Consent Manager?

A consent management platform is software a business uses to run its own consent. A Consent Manager is an entity registered with the Data Protection Board that lets individuals manage consent across many businesses. ConsentLo can connect to registered Consent Managers.

This guide is general information about the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, not legal advice.