New

DPDP Rules 2025 compliance checklist is live —

Read now
← All articles Consent

Consent under the DPDP Act: building receipts that stand up

VaultDef Team25 Aug 20261 min read

Under the DPDP Act, consent must be free, specific, informed, unconditional and unambiguous, given for a defined purpose. That last phrase does most of the work — and it is where most consent implementations quietly fail.

The tick box is not the point

Recording that a user clicked "I agree" tells you nothing useful six months later. What a regulator, an auditor, or the data principal themselves will ask is: agree to what, when, and on what terms?

A defensible consent receipt captures:

  • Who consented, verified to a real identity.
  • What purpose the consent covers, in the exact wording shown at the time.
  • When it was given, and from where.
  • Which notice version was on screen.
  • How it can be withdrawn, and whether it since has been.

Purpose is a first-class object

Treating purpose as a string you paste into a banner is how consents rot. Treat each purpose as an object with a lifecycle: created, shown, consented, withdrawn, expired. Then a withdrawal is not an email to an inbox — it is a state change with downstream effects you can prove you honoured.

Withdrawal is the test

Anyone can capture consent. The system that can show it stopped processing within the window after a withdrawal — and produce the record on demand — is the one that survives scrutiny.

The difference between a consent programme and a consent liability is whether every one of these is retrievable in seconds, not reconstructed in a panic.