All articles
Consent

What verifiable consent requires under DPDP

Smoketrees Digital LLP·10 Jun 2026·6 min read

Under the DPDP Act, consent must be free, specific, informed, unconditional, and unambiguous, given through a clear affirmative action. It must be tied to a specific purpose, recorded so you can prove it, and as easy to withdraw as it was to give. Pre-ticked boxes, bundled terms, and silence do not count.

What each word in the standard carries

  • Free means consent cannot be a condition for a service that does not need the data.
  • Specific means one purpose per consent, not a single tick covering everything.
  • Informed means the user saw a plain-language notice first.
  • Unambiguous means a deliberate action, not a default that they failed to uncheck.

What happens after the tick

The harder half is what happens after the tick. You have to store consent in a way that records what was agreed, when, and for which purpose, and you have to version it so that a later change in purpose triggers fresh consent. You have to offer withdrawal that is genuinely as easy as granting, and withdrawal has to stop the processing it covered. A withdrawal button that updates a flag but does not change what your systems do is not compliance.

Consent Managers

The DPDP Rules also introduce Consent Managers, registered platforms that store and manage consent on a user's behalf. Registration is expected to open around November 2026. A Consent Manager is useful infrastructure, but it stores consent. Your product still has to obey it, which means reading consent state and gating processing on it.

"Consent capture, storage, versioning, and enforcement all live in code."

Next step

Find out how compliant your product is.

Ten questions covering consent, data rights, security, and breach readiness. Takes two minutes.

Start the readiness check →

Written by Smoketrees Digital LLP, a product engineering studio based in Bengaluru. We implement DPDP compliance directly into codebases for Indian product companies.