Triad ICS
Menu

Insights/Regulatory Newsroom

DPDP Consent Management: Building a Granular Framework That Actually Works

Published

Reading time2 minutes

FromTriad ICS Research

Consent under the DPDP Act is specific, withdrawable and provable. Here is how to build for it.

Under the DPDP Act 2023, consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the personal data necessary for the stated purpose. A single “I agree to the terms” checkbox does not meet that bar. Here is how to design a consent system that does.

Start from purposes, not screens

Build a register of every purpose for which you process personal data: account creation, order delivery, credit assessment, marketing, analytics. Each purpose has an owner, the data it needs and its lawful basis. Remember that Section 7 lists certain legitimate uses that do not need consent; do not ask for consent you do not need, and do not rely on consent where another basis applies.

Ask per purpose

Present separate choices for separate purposes. Delivering an order and sending promotional offers are different purposes, so a customer should be able to accept one without the other. Pre-ticked boxes and bundled consent undermine the “unconditional” requirement.

Each consent record should store which version of the privacy notice the person saw, what they agreed to, when, and through which channel. Without this, you cannot prove consent was informed.

Make withdrawal as easy as giving

If consent was given in one tap in your app, withdrawal should also take one or two taps. When consent is withdrawn, processing for that purpose must stop within a reasonable time, and so must processing by your Data Processors.

Propagate changes everywhere

Consent state must reach every system that uses the data: CRM, marketing tools, analytics, vendors. Many organisations get the interface right but leave old data flowing to a marketing platform for months.

The DPDP Rules 2025 provide for Consent Managers registered with the Data Protection Board, with registration provisions taking effect from November 2026. If your sector adopts them, your system will need to accept and honour consent coming through a registered Consent Manager.

A minimal architecture

  • Purpose register: the single source of truth for purposes and data categories.
  • Consent ledger: an append-only record of grants and withdrawals, tied to notice versions.
  • Enforcement points: APIs and data pipelines that check consent before processing.
  • Audit trail: reports that let you answer a Data Principal or the Board quickly.

Built this way, consent becomes a product feature customers can see and trust, not a legal page nobody reads.

This article is general information, not legal advice. Compliance services do not guarantee certification; certification bodies issue certificates.

Turn Insight into Action