Under the DPDP Act, consent must be free, specific, informed, unconditional and unambiguous, given for a defined purpose. That last phrase does most of the work — and it is where most consent implementations quietly fail.
The tick box is not the point
Recording that a user clicked "I agree" tells you nothing useful six months later. What a regulator, an auditor, or the data principal themselves will ask is: agree to what, when, and on what terms?
A defensible consent receipt captures:
- Who consented, verified to a real identity.
- What purpose the consent covers, in the exact wording shown at the time.
- When it was given, and from where.
- Which notice version was on screen.
- How it can be withdrawn, and whether it since has been.
Purpose is a first-class object
Treating purpose as a string you paste into a banner is how consents rot. Treat each purpose as an object with a lifecycle: created, shown, consented, withdrawn, expired. Then a withdrawal is not an email to an inbox — it is a state change with downstream effects you can prove you honoured.
Withdrawal is the test
Anyone can capture consent. The system that can show it stopped processing within the window after a withdrawal — and produce the record on demand — is the one that survives scrutiny.
The difference between a consent programme and a consent liability is whether every one of these is retrievable in seconds, not reconstructed in a panic.
