Guide5 min readMarketing Technology · Technology & Intelligence

DPDP Act consent in practice: a field guide for marketing teams

India’s Digital Personal Data Protection Act asks for consent that is free, specific, informed, unconditional and unambiguous. What that means for sign-up forms, email lists and ad audiences, the records to keep, and the timeline to May 2027.

Xterra Edze studioEditorial

Published Reviewed

A door standing open from a dark room into a sunlit corridor.
Consent is a door someone chooses to open, and can close again as easily.Photo: Greg Rosenke on Unsplash

India’s Digital Personal Data Protection Act, 2023 was enacted on 11 August 2023, and the Digital Personal Data Protection Rules, 2025 that put it into operation were published in the Official Gazette on 13 November 2025.1 2 3 For marketing teams, consent is where the law meets daily work: every sign-up form, newsletter list, lead-generation campaign and ad audience built from first-party data.

Section 6 of the Act sets the test. Consent must be free, specific, informed, unconditional and unambiguous, given with a clear affirmative action, and limited to the personal data necessary for the purpose stated.1 Each of those words retires a familiar pattern.

  • Free and unconditional: do not make the newsletter the price of a downloadable guide unless the newsletter is the point. Bundled consent is the pattern to retire first.
  • Specific: one purpose, one choice. Product updates, event invitations and partner offers are separate purposes.
  • Informed: the notice comes first, in clear and plain language, with an itemised description of the data and what it is for.2
  • Unambiguous, by a clear affirmative action: an empty box the person ticks, or a button that says exactly what it does. Silence and pre-ticked boxes are not consent.

The notice

Rule 3 asks for a notice that can be understood on its own, without reading anything else first. At minimum it gives an itemised description of the personal data, the specified purpose with a description of the goods, services or uses it enables, and a link through which the person can withdraw consent, exercise their rights and complain to the Data Protection Board.2 The Act also requires that the notice can be read in English or in any language listed in the Eighth Schedule to the Constitution.1

Where consent is the basis for processing, the person may withdraw it at any time, and doing so must be comparable in ease to giving it. Once they do, the business must stop processing within a reasonable time and make its processors stop too.1 For email that means a one-click unsubscribe; for a preference centre, the same number of steps to switch something off as it took to switch it on.

Be able to prove it

If consent is ever questioned, the burden is on the business: the Act says the Data Fiduciary must prove that a notice was given and that consent was given in line with the law.1 Design the record into the form itself, not into a spreadsheet afterwards.

json
{
  "subject": "sha256:7f3c9e…",
  "purpose": "newsletter.monthly",
  "notice_version": "2026-09-01",
  "notice_language": "en",
  "action": "checkbox+submit",
  "given_at": "2026-09-14T10:42:07+05:30",
  "source": "/blog/dpdp-consent-for-marketers",
  "withdrawn_at": null
}
One record per purpose: what was agreed, under which notice, how and when. A withdrawal closes the record; it is never deleted.

Children and targeted advertising

Under the Act a child is anyone under eighteen. Processing a child’s personal data needs the verifiable consent of a parent, and a Data Fiduciary must not track or behaviourally monitor children or direct targeted advertising at them.1 2 Audience tools that infer age, and lookalike audiences built from mixed lists, deserve a careful review before May 2027.

Vendors, retention and breaches

  • Your processors (email platforms, CDPs, ad partners) act on your behalf under contract. You remain responsible for what they do with the data.
  • Erase personal data once its purpose is served or consent is withdrawn, unless a law requires you to keep it, and have your processors erase it too.
  • Keep the personal data, traffic data and logs of processing for at least one year, as Rule 8 requires, then erase them unless another law needs them longer.2
  • If there is a breach, tell each affected person without delay, and give the Board the detailed report Rule 7 lists within seventy-two hours.2
  • Publish the business contact of someone who can answer questions about how you process personal data.2

The penalties

Failing to take reasonable security safeguards
₹250 cr
Failing to report a breach, or breaching the obligations for children
₹200 cr
Breaching any other provision of the Act or the Rules
₹50 cr

The maximum penalties in the Schedule to the Act (“up to”). One crore is ten million rupees.

The timeline

The Rules arrive in phases, counted from their publication on 13 November 2025. Rules 1 and 2, and rules 17 to 21 on the Data Protection Board, applied that day. Rule 4, on Consent Managers, applies one year later, in November 2026. Rules 3 and 5 to 16, which cover notices, security safeguards, breach intimation, retention and children’s data among others, apply with rules 22 and 23 eighteen months after publication, in May 2027.2 The months in between are the time to redesign forms and records, not a reason to wait.

  1. List every place you collect personal data: forms, chat, events, imports, ad platforms.
  2. Split each form’s purposes into separate choices, and remove every pre-ticked box.
  3. Write one plain-language notice per purpose, and offer it in the languages your audience reads.
  4. Add a one-click way to withdraw wherever consent is given.
  5. Store a consent record per purpose, with the notice version.
  6. Check that no campaign aimed at children uses tracking or targeted advertising.
  7. Review processor contracts, retention periods and the breach runbook.

We design consent and preference systems as part of Customer Relationship Strategy, and review data handling end to end in Cybersecurity & AI Trust.

Dates. What this guide tracks.

The changes this article covers, in order, each with the source that sets the date. See every date in the standards ledger

  1. The Digital Personal Data Protection Act, 2023 is enacted

    Consent must be free, specific, informed, unconditional and unambiguous.

    Source 1Ministry of Electronics and Information Technology, Government of India

  2. The DPDP Rules, 2025 are published in the Official Gazette

    The rules on the Data Protection Board apply the same day.

    Source 2Ministry of Electronics and Information Technology, Government of India

  3. Upcoming

    The Consent Manager rule applies

    Rule 4, one year after the Rules were published.

    Source 2Ministry of Electronics and Information Technology, Government of India

  4. Upcoming

    Most obligations under the DPDP Rules apply

    Notices, security safeguards, breach intimation, retention and children’s data, eighteen months after publication.

    Source 2Ministry of Electronics and Information Technology, Government of India

Sources. Where the facts come from.

Numbered as they are cited in the text. Each link opens the original.

Review log

When this guide was checked against its sources, and what changed. Newest first.

  1. Corrected the date the Rules were published to 13 November 2025, the date of the Gazette notification (G.S.R. 846(E)); it had said 14 November, the date the government’s summary gives. The phased dates now follow rule 1 word for word.

  2. First published. Checked the consent test, the notice, withdrawal, children’s data and the penalties against the Act, the Rules and the government’s summary.

Let’s build what happens next.

Tell us what you’re building. We’ll answer straight.

Book a discovery call

Three ways to start

  1. 01About 2 minutes

    A quick question

    You get A reply from a lead, not a sales queue

  2. 02About 8 minutesMost useful

    A project brief

    You get Options and a first scope after one call

  3. 03About 15 minutes

    A formal RFQ or RFP

    You get Receipt confirmed and a named bid lead

Every engagement starts with a written scope and a quote agreed before work begins. How each package is priced