Implementing Consent Management Under DPDP
Step 1: Define Data Types & Purposes
- What data do you collect?
- Why are you collecting it?
- Is the data sensitive?
- How long will you retain it?
Step 2: Create Consent Forms
Required elements:
- Plain-language explanation of data collection
- Explicit purpose of each data type
- Retention duration
- How users can withdraw consent
- Right to access, correct, delete data
- Contact info for grievances
NOT acceptable:
Step 3: Consent Capture
Web Forms:
- Clear, visible consent checkboxes
- One checkbox per purpose
- Mandatory for essential data
Cookie Banners:
- Display BEFORE setting non-essential cookies
- Granular selection (analytics, marketing, functional)
- "Reject All" as prominent as "Accept All" dpdp penalties explained
Email Signup:
- Single opt-in with confirmation
- Consent form in signup
- No pre-filled consent dpdp vs gdpr
Step 4: Preference Centers
- Allow users to change consent anytime
- Download copy of consent given
- Withdraw specific consent (e.g., marketing only)
- See what data is collected
Step 5: Audit Trail
- Record timestamp of each consent
- Store exact consent form version
- Log IP address
- Maintain for 3 years minimum
Disclaimer: General informational article. Consult legal counsel. DPDP Compliance Hub
Start Now: Start your free DPDP compliance assessment