Post

Consent Under DPDPA and GDPR: A Comparative Lens for Indian Businesses

Consent Under DPDPA and GDPR: A Comparative Lens for Indian Businesses

The Digital Personal Data Protection Act, 2023 (DPDPA), now fully operational as of July 29, 2026, has fundamentally reshaped India’s data privacy landscape. For businesses operating in India or handling Indian personal data, understanding its nuances, especially regarding consent, is paramount. A comparative look at DPDPA’s Section 6 against the European Union’s General Data Protection Regulation (GDPR) Article 7 offers valuable insights into compliance obligations, particularly concerning granularity, withdrawal mechanisms, and the onus of proof.

Both DPDPA and GDPR champion the principle of specific and informed consent. However, DPDPA introduces a potentially stricter requirement through its emphasis on “itemised consent.” Section 6(2) of the DPDPA mandates that consent must be “itemised” for processing different personal data for different specified purposes. This implies a highly granular approach, where a Data Fiduciary cannot bundle multiple, distinct processing activities under a single, overarching consent request. For instance, consent for marketing communications must be distinct from consent for analytics, even if both relate to the same individual. This builds on Section 6(1)(a), which requires consent for a “specified purpose.”

In contrast, GDPR Article 7(2) requires that if a data subject’s consent is sought in the context of a written declaration which also concerns other matters, the request for consent must be “clearly distinguishable from the other matters.” While GDPR Recitals 32, 42, and 43 also advocate for specific, informed, and unbundled consent, DPDPA’s explicit use of “itemised” might be interpreted as demanding an even finer level of breakdown within a consent request, potentially making the Indian framework marginally stricter in its textual prescription.

Ease of Withdrawal: Empowering the Data Principal

The right to withdraw consent is a cornerstone of both regimes, reflecting a commitment to data principal autonomy. DPDPA Section 6(4) unequivocally grants the Data Principal the right to withdraw consent at any time. Crucially, Section 6(5) stipulates that the withdrawal mechanism must be “as easy as it was to give consent.” This ensures that businesses cannot create artificial barriers or complex processes to deter withdrawal. Furthermore, Section 6(6) explicitly states that a Data Principal shall not be penalised for withdrawing consent.

Similarly, GDPR Article 7(3) provides that the data subject “shall have the right to withdraw his or her consent at any time.” It also mirrors DPDPA by stating that “it shall be as easy to withdraw as to give consent.” Both frameworks align closely on this front, ensuring that the process of revoking consent is straightforward and accessible. DPDPA’s explicit mention of no penalty further reinforces this principle, leaving no room for ambiguity.

Onus of Proof: Demonstrating Compliance

A critical aspect of consent frameworks is determining who bears the responsibility of proving valid consent. Both DPDPA and GDPR place this burden squarely on the entity processing the data. DPDPA Section 6(7) explicitly states that the “Data Fiduciary shall be able to demonstrate that notice has been given and consent has been obtained… in accordance with the provisions of this Act.” This requires robust record-keeping and auditable processes.

Likewise, GDPR Article 7(1) mandates that “where processing is based on consent, the controller shall be able to demonstrate that the data subject has consented to processing of his or her personal data.” In practice, this means maintaining comprehensive consent records, including when and how consent was obtained, the specific purposes it covered, and any subsequent withdrawals. On this crucial point, both the Indian and European frameworks are equally stringent, demanding clear accountability from data handlers.

The Indian Regulatory Ecosystem

Beyond the DPDPA, India’s broader regulatory landscape, particularly in the financial sector, reinforces and complements the DPDPA’s consent principles. The Reserve Bank of India (RBI) has, for instance, long emphasised explicit and revocable consent for sharing financial data, notably through its Account Aggregator framework. These sector-specific regulations often pre-empted DPDPA’s general requirements and now serve to strengthen its application in critical areas. While the IT Rules, 2011, previously touched upon consent for sensitive personal data, the DPDPA now serves as the primary and more comprehensive legal framework for personal data protection across sectors, harmonising previous disparate requirements.

Practical takeaway: For Indian businesses, General Counsels, and Data Protection Officers, the DPDPA’s consent requirements demand a proactive and detailed approach. While aligning with global best practices seen in GDPR, DPDPA’s “itemised consent” in Section 6(2) necessitates a careful review of all consent mechanisms to ensure each distinct processing purpose is clearly delineated and consented to separately. Implement user-friendly interfaces for consent withdrawal, ensuring they are as intuitive as the consent-giving process. Most importantly, establish robust record-keeping systems to demonstrably prove valid consent for every processing activity, as the onus of proof unequivocally rests with the Data Fiduciary.

This post is licensed under CC BY 4.0 by the author.