Writing a DPDP Consent Notice (With Examples in Plain English)
How to write a DPDP-compliant consent notice: what it must include, plain-English examples, and common mistakes that make a notice invalid.
A valid DPDP consent notice tells a person, in plain language, exactly what data you are collecting, why, and how they can say no or withdraw later - and it must stand on its own, not be buried in a terms-and-conditions page.
Key facts at a glance
- Consent must be clear, affirmative and specific - pre-ticked boxes or silence do not qualify.
- A notice must be presented separately and prominently, not bundled into general T&Cs.
- Withdrawal of consent must be as easy as giving it.
- Full DPDP notice and consent obligations become enforceable on 13 May 2027.
- Consent should cover one specific purpose at a time - broad, catch-all consent is not compliant in spirit.
- Notices should be understandable, which in practice favours plain language over legal jargon.
- Penalties for non-compliance with security and consent obligations can reach up to Rs 250 crore per instance.
The Core Elements of a Valid Notice
A DPDP-compliant consent notice needs to answer four questions clearly:
- What data is being collected (e.g. name, phone number, location, payment details).
- Why it is being collected (the specific purpose - not a vague "to improve services").
- How the person can access, correct, or withdraw consent for their data.
- Who to contact with questions or complaints (typically your Data Protection Officer or a designated contact).
Example: Weak Notice (Avoid This)
"By using this app you agree to our Privacy Policy and Terms of Service, which may be updated from time to time. We may collect and use your information for business purposes."
This fails on almost every count: it is vague about what data and why, it is bundled with general terms, and "business purposes" is not a specific purpose.
Example: Compliant-Style Notice
"We collect your name, phone number and delivery address to process and deliver your order. We do not use this information for anything else without asking you again. You can view, correct or delete this information anytime from Account Settings, or by contacting privacy@yourcompany.in."
This version names the specific data, states one specific purpose, and tells the person exactly how to exercise their rights.
Consent Notice Checklist
| Requirement | Weak practice | Better practice |
|---|---|---|
| Clarity | Legal jargon, long paragraphs | Short plain-language sentences |
| Specificity | "For business purposes" | Named purpose, e.g. "to process your order" |
| Separateness | Buried in Terms & Conditions | Standalone notice or clearly separated section |
| Affirmative action | Pre-ticked checkbox | Unticked checkbox or explicit "I agree" action |
| Withdrawal | No visible option | Clear "withdraw consent" or account-settings option |
| Language | English only | Available in languages users are likely to understand |
Consent for Multiple Purposes
If you collect data for more than one purpose - say, order processing and marketing emails - DPDP practice favours separating these into distinct consent asks rather than one combined checkbox. A person should be able to agree to order processing while declining marketing emails.
This matters operationally too: if someone withdraws consent for marketing but not for order fulfilment, your systems need to be able to act on that distinction rather than treating consent as one on/off switch.
Consent Managers
The DPDP Rules 2025 introduce a Consent Manager framework (Rule 4), which becomes operational on 13 November 2026. Consent Managers are intended to act as a registered intermediary through which individuals can view and manage consents given across different data fiduciaries. Businesses do not need to build this themselves, but should be aware that consent records may eventually need to interoperate with this framework.
Common Mistakes to Avoid
- Treating a privacy policy and a consent notice as the same document - they serve different purposes.
- Asking for consent to "all future uses" of data instead of the specific purpose at hand.
- Making withdrawal harder than giving consent (e.g. requiring a phone call to opt out but a single click to opt in).
- Failing to update the notice when a new data use is introduced.
- Assuming consent obtained before DPDP enforcement automatically satisfies the Act's requirements going forward.
Getting your consent notices right now, well before the 13 May 2027 enforcement date, avoids a scramble later and reduces the chance of a data-principal complaint reaching the Data Protection Board.
If you are not sure whether your current notices and consent flows would hold up, ComplianceCheck's DPDP assessment gives you a clear picture in a few minutes.
Sources
- Ministry of Electronics and Information Technology, DPDP Act and Rules - meity.gov.in
- Data Protection Board of India
This guide is general information, not legal advice. Requirements vary by state, sector and headcount - confirm specifics with a compliance professional or the relevant authority.
Frequently Asked Questions
- What must a DPDP consent notice include?
- It must clearly state what personal data is collected, the specific purpose of processing, and how the individual can exercise their rights and withdraw consent, in clear and plain language rather than legal jargon.
- Can a consent notice be bundled with general terms and conditions?
- No. Under the DPDP framework, the notice and request for consent should be presented clearly and separately, not buried inside a long terms-of-service document.
- Does consent have to be in English only?
- No, the notice should be available in a way the data principal can understand, which in practice means offering it in multiple Indian languages where feasible, consistent with the DPDP Act's intent.
- Can a user withdraw consent after giving it?
- Yes, withdrawal of consent must be as easy as giving it, and once withdrawn the data fiduciary must stop processing that data for the withdrawn purpose within a reasonable time, subject to any other legal basis for retention.
- Is pre-ticked consent valid under DPDP?
- No, consent must be a clear affirmative action - pre-ticked boxes, silence, or inactivity do not count as valid consent.
- Do I need separate consent for each purpose of data collection?
- Yes, purpose limitation is a core DPDP principle, so consent obtained for one specific purpose cannot be stretched to justify a different, unrelated use of the same data.
- What happens if my consent notice is found non-compliant?
- Full substantive DPDP obligations, including notice and consent requirements, become enforceable on 13 May 2027, after which non-compliant notices can expose a data fiduciary to penalties and Data Protection Board scrutiny.
Check your status
DPDP Gap Assessment
A 45-question gap assessment for the Digital Personal Data Protection (DPDP) Act 2023, scoring data-protection maturity across 6 phases.