Digital & E-Commerce Legal Support7 min readUpdated July 2026

Consent Notices Under DPDP Rules 2025: The Exact Requirements, With Examples

Somewhere in your app or website, right now, sits a sentence shaped like this: “By continuing, you agree to our Terms of Service and Privacy Policy.” For a decade, that sentence was Indian data compliance in its entirety. Under the DPDP Act, 2023 and the DPDP Rules, 2025, that sentence is close to worthless, and the companies that understand why will spend the runway to May 2027 rebuilding a layer of product most teams have never consciously designed: the consent notice.

Tirth Inamdar, founder of Inamdar Legal

Tirth Inamdar

Founder · Inamdar Legal

Founder-reviewed legal guidanceSurat · India · Global clients

Somewhere in your app or website, right now, sits a sentence shaped like this: “By continuing, you agree to our Terms of Service and Privacy Policy.” For a decade, that sentence was Indian data compliance in its entirety. Under the DPDP Act, 2023 and the DPDP Rules, 2025, that sentence is close to worthless, and the companies that understand why will spend the runway to May 2027 rebuilding a layer of product most teams have never consciously designed: the consent notice. This article does one job thoroughly: it sets out exactly what a valid consent notice must contain under the Rules, shows worked before and after examples, and covers the machinery around the notice, withdrawal, consent records, and the arriving Consent Managers, that turns a compliant sentence into a compliant system.

Quick Answer

  • 01The DPDP Rules turn consent from a checkbox into a designed product surface: self contained plain language notices at each collection point, itemising data against purposes, unbundled affirmative actions, withdrawal as easy as consent and wired to real pipelines, all recorded because the burden of proof is yours, with Consent Managers arriving to interoperate from late 2026. Rebuild the flows during the runway to May 2027 and the “by continuing you agree” sentence can retire with the era it belonged to.

Worked example one: the login flow

Before, the classic: “Sign up with your mobile number. By continuing you agree to our Privacy Policy.” One checkbox, every purpose bundled, notice by hyperlink. After, DPDPA shaped. At the collection moment, a short notice: “To create your account, we collect your mobile number and name. Mobile number: used for login by OTP and for order and payment messages. Name: used on your invoices and deliveries. We do not use these for marketing unless you separately agree below. Withdraw anytime in Settings, Privacy, or write to grievance@yourapp.in. Full details: Privacy Notice.” Below it, a separate, unticked toggle: “Send me offers and recommendations by SMS and email,” its own purpose, its own consent. Two design decisions carry the compliance: the notice is readable in one breath and itemises data against purposes, and marketing is unbundled, so the account works whether or not the toggle is touched, which is what unconditional means.

Worked example two: the delivery app’s location ask

Before: the operating system permission dialog alone, “Allow YourApp to access this device’s location?”, treated as consent. It is not; it is a technical permission with no purpose notice behind it. After: a pre permission screen in the app’s own voice: “We use your live location only while an order is active, to show delivery progress and help the rider find you. We do not collect location in the background or use it for advertising. You can refuse and type your address instead.” Then the OS dialog. The pattern generalises: the OS asks about the sensor; the DPDPA notice explains the purpose, the limits, and the alternative, and the refusal path keeps the service usable wherever the data is not strictly necessary.

The machinery behind the sentence

Consent records. Since the fiduciary must prove consent, log the notice version, language, timestamp, and the affirmative action for every consent, and keep the mapping between notice versions and processing purposes as notices evolve. When a user complains to the Board in 2028, your defence is this log. Withdrawal that works. Build a privacy dashboard where each granted consent appears as a switch, and wire the switches to the actual pipelines, the marketing system, the analytics SDKs, the processors, because withdrawal that updates a database flag while the emails continue is a documented violation, not a compliance feature. Grievances route to the published contact with the response clock our grievance officer article describes. Consent Managers. From November 2026, the Rules’ Consent Manager provisions come alive: registered platforms through which users can give, review, and withdraw consent across fiduciaries, interoperable by design. Most companies will not become Consent Managers, but consent architectures built now should assume an external platform may someday present, and revoke, consent on a user’s behalf, one more reason consent records need clean structure rather than screenshots. Legitimate uses. Honesty requires the boundary note: not all processing runs on consent. Section 7 permits defined legitimate uses, notably where the individual voluntarily provides data for a purpose and does not object, employment related processing, medical emergencies, and state functions. These are narrower than the GDPR’s legitimate interests, they are enumerated, not open ended, and choosing between the consent gate and a legitimate use gate for each processing activity is exactly the legal judgment that should not be improvised.

When to obtain a review

A review is especially useful when…

  • The DPDP Rules turn consent from a checkbox into a designed product surface: self contained plain language notices at each collection point, itemising data against purposes, unbundled affirmative actions, withdrawal as easy as consent and wired to real pipelines, all recorded because the burden of proof is yours, with Consent Managers arriving to interoperate from late 2026. Rebuild the flows during the runway to May 2027 and the “by continuing you agree” sentence can retire with the era it belonged to.

Legal information notice

This article is for general information only and is not legal advice. Consent architecture depends on your specific processing, so take professional advice before acting.

Questions, answered clearly

Common questions

What must a DPDPA consent notice contain?+

A self contained, plain language text itemising the personal data collected, the specific purposes and the goods or services they enable, how to exercise rights and withdraw consent, contact and grievance details, and the way to complain to the Data Protection Board, per Rule 3 of the 2025 Rules.

Is a checkbox linking to the privacy policy valid consent?+

Almost certainly not for multiple purposes: it fails specificity, the notice’s independence requirement, and often the unconditional test when the tick gates unrelated services. Purpose level notices with separate affirmative actions are the compliant pattern.

Do consent notices need to be in regional languages?+

The Rules push availability toward English and the Eighth Schedule languages; serving notices in the user’s language is both the safe reading and good design.

Does everything need consent under the DPDPA?+

No. Section 7’s legitimate uses cover enumerated situations, voluntary provision, employment, emergencies, state functions, but they are narrower than GDPR’s legitimate interests, and classification per activity deserves legal review.

When do these requirements bite?+

The core obligations become enforceable on 13 May 2027, with Consent Manager provisions arriving from November 2026, the runway our DPDPA compliance checklist maps deadline by deadline.

How do we prove consent later?+

Consent records: notice version and language, timestamp, and the affirmative action, retained and queryable. The burden of proof sits on the fiduciary, so the log is the compliance.

A practical next step

Need Help with Consent Notices Under DPDP Rules 2025: The Exact Requirements, With Examples?

Contact Tirth Inamdar at Inamdar Legal for customized assistance on your specific requirements.