DPDPA & Privacy 7 min read

DPDPA consent: why a checkbox is not a consent strategy.

Valid consent is not created simply by adding a checkbox to a form. It starts with clarity about purpose, the personal data actually required, the choice being offered and what happens when that choice changes.

Read featured insight

Many organisations begin a consent discussion by asking whether their website, application or form has a checkbox. That question starts too late. A stronger approach begins with understanding why personal data is needed, what information is genuinely necessary and what the individual is actually being asked to agree to.

01

Start before the checkbox.

A checkbox is only an interface element. It does not by itself explain the processing that sits behind it.

Before designing a consent screen, an organisation should understand the business activity that requires the personal data.

What service is being provided? Why does the organisation need the information? Which personal data is actually necessary? What processing will occur after the individual makes a choice?

Better starting question

Do not begin with “Where should we add consent?” Begin with “Why are we processing this personal data?”

This distinction matters because the DPDP framework does not make consent the only possible basis for every processing activity.

The organisation should first understand the processing and its purpose, and then determine how the applicable requirements should be addressed.

02

Valid consent requires more than a click.

The DPDP Act describes consent using several important characteristics.

Consent is expected to be free, specific, informed, unconditional and unambiguous, and to involve clear affirmative action.

It also needs to relate to personal data necessary for the specified purpose.

01 Free

The person should have a meaningful opportunity to make the decision.

02 Specific

Consent should relate to an identifiable purpose rather than a vague future use.

03 Informed

The person should understand what they are agreeing to.

04 Unconditional

The request should not depend upon inappropriate conditions.

05 Unambiguous

There should be clarity about the individual's intention.

06 Affirmative

Consent should result from a clear affirmative action.

Design implication

A technically clickable checkbox can still represent a weak consent process when the purpose is vague, unnecessary information is bundled into the request or the individual cannot understand the consequence of the decision.

03

Define the purpose before deciding what data to collect.

Good consent design begins with the business purpose, not with the form fields.

Once the purpose is understood, the organisation can ask a much more useful question:

What personal data is actually necessary to achieve this purpose?

Business need Specified purpose Necessary data Clear notice Choice

This approach can also expose personal information being collected simply because an existing form or application contains the field.

Data that does not support the specified purpose deserves to be challenged before it becomes another item the organisation has to protect, govern, retain and eventually remove.

Weak approach “I agree to the terms and allow use of my data.”

The purpose is unclear, the personal data involved is not apparent and unrelated processing may be bundled into one decision.

Better approach Explain what information is required and what specific service or use it enables.

The individual can understand the relationship between the data, the purpose and the choice being requested.

04

Design the notice before designing the consent control.

Consent cannot be genuinely informed if the explanation surrounding it is difficult to understand.

The final DPDP Rules set out a more operational approach to notices.

When the relevant provisions apply, the notice is expected to be independently understandable and written in clear and plain language.

It should provide an itemised description of the personal data involved and explain the specified purpose for which that information is processed.

What data? Why? What service / use? What choice? What rights?
Practical test

Can the customer understand why you need their information without first reading an entire privacy policy?

The notice framework also provides for a means through which the individual can withdraw consent, exercise applicable rights and make a complaint to the Board.

That means the consent experience needs to connect with the organisation's wider privacy operating model.

05

Make withdrawal as practical as giving consent.

A common weakness appears after consent has already been captured.

Giving consent may take one click, while withdrawing it requires finding a hidden setting, sending an email or contacting customer support.

The DPDP Act provides that the ease of withdrawing consent should be comparable to the ease with which consent was given.

The more difficult challenge is what happens behind that withdrawal action.

Example withdrawal workflow
01 Withdrawal requested
02 Identify relevant consent
03 Identify affected processing
04 Update consent status
05 Stop applicable processing
06 Retain evidence

Where applicable under the Act, withdrawal requires the Data Fiduciary to stop the relevant processing within a reasonable time and cause its Data Processors to do the same, unless continued processing is otherwise required or authorised by law.

This means withdrawal cannot be treated simply as a front-end website function.

CRM systems, marketing platforms, applications, integrations and processors may all need to recognise the changed consent state.

Operational reality

A withdrawal button only changes the interface. A working withdrawal process changes the processing behind it.

06

Consent needs evidence, not just configuration.

An organisation should be able to reconstruct the consent journey rather than merely identify a database field containing “Yes”.

The DPDP framework places importance on being able to demonstrate that the required notice and valid consent were provided.

A useful consent record therefore needs context.

01
Notice
What information was presented when the individual made the decision?
02
Purpose
Which specified purpose did the consent relate to?
03
Action
What affirmative action did the individual perform?
04
Time
When was the decision recorded, modified or withdrawn?
05
Status
What is the current consent status and which processing activities depend on it?

This is where consent management becomes a data and systems-design problem rather than simply a website-design problem.

07

Understand what a Consent Manager actually is.

The DPDP framework also introduces the concept of a Consent Manager.

This is a specific role under the legislation, rather than simply another name for an organisation's internal consent form, CRM preference field or marketing preference centre.

Consent Manager

A distinct role within the DPDP framework.

A Consent Manager enables a Data Principal to give, manage, review or withdraw consent through an accessible, transparent and interoperable platform.

The final Rules establish registration and operating requirements for Consent Managers, including requirements around records, security, governance and accountability.

For most organisations, however, the immediate readiness priority is more fundamental:

Make sure your own purpose, notice, consent, withdrawal and evidence processes actually work.

Good consent design starts with clarity, not compliance language.

The strongest consent experience is usually not the one with the longest privacy statement or the most sophisticated checkbox.

It is the one where the organisation has already decided why it needs the data, limited the request to what is necessary and explained the purpose in a way the individual can understand.

The organisation must then be capable of respecting what happens after that choice.

That includes recording the decision, managing downstream processing and responding appropriately if the individual later withdraws consent.

Define the purpose. Limit the data. Explain the choice. Record the decision. Respect the withdrawal.

A checkbox can capture an action.

A consent strategy manages the complete lifecycle behind that action.

DPDPA Readiness

Is your consent process ready beyond the checkbox?

Understand how personal data is collected, how notice and consent are managed, and where practical controls may be needed across your processes and technology.

This article is intended for general informational purposes only and does not constitute legal advice. The DPDP framework has phased commencement provisions, and organisations should assess the requirements applicable to their circumstances and obtain appropriate professional advice where required.