What does valid consent look like under the DPDP Act?

Under India's Digital Personal Data Protection Act (DPDP Act), valid consent is a clear, affirmative act by the Data Principal, signifying agreement to process their personal data for a specified purpose. It must be free, specific, informed, unconditional, and unambiguous. Data Principals retain the right to withdraw consent at any time, and such withdrawal must be as easy as giving it.

For Data Fiduciaries, obtaining valid consent necessitates transparent communication regarding the types of data collected, the specific purposes of processing, and the Data Principal's rights. This requires presenting information in clear, plain language, avoiding technical jargon, and offering granular options for different processing activities rather than relying on bundled consent. Pre-ticked boxes or implied consent mechanisms are generally insufficient. Fiduciaries must also maintain verifiable records of consent, including when and how it was obtained, to demonstrate compliance.

Failure to secure valid consent carries significant compliance risks, including potential penalties and reputational damage. Data Fiduciaries must implement robust consent management frameworks that allow Data Principals to easily review, modify, or withdraw their consent. Any material change to the processing purpose or the data collected requires re-obtaining fresh consent. Practitioners often err by assuming existing consent covers new processing activities or by making withdrawal processes overly complex, which undermines the "as easy as giving it" principle.

Sources

  • The Digital Personal Data Protection Act, 2023, Section 6(1)
  • The Digital Personal Data Protection Act, 2023, Section 6(4)

Related