Consent management under the DPDP Act: a practical checklist
By DPDP Manager Compliance Team · 12 June 2026 · 6 min read
The DPDP Act treats consent as the default lawful basis for processing personal data, with a narrow set of "legitimate uses" as the exception rather than the rule. In practice, that means most product and marketing flows need to be re-examined for how consent is actually captured, not just whether a checkbox exists somewhere.
Start with specificity. A single, broad "I agree to the privacy policy" checkbox rarely holds up as informed consent for multiple distinct purposes — analytics, marketing communication, and third-party sharing are different processing activities and, where practical, deserve to be presented as separable choices.
Consent also needs to be as easy to withdraw as it was to give. If a Data Principal can opt in with one tap inside your app, burying withdrawal behind a support email or a multi-step settings flow is the kind of asymmetry regulators and auditors notice first.
Finally, build a record. Being able to show when, how, and for what purpose consent was captured — and when it was withdrawn — is what turns "we have consent" from a claim into evidence. This is exactly the kind of operational discipline the DCPP and DCDPO tracks are built around.