Can you prove your users said yes? Consent under India's DPDP Act

The DPDP Act requires provable consent, not just a checkbox. Six requirements, six common gaps, and how Promiz records consent with tamper-evident proof.

By Promiz · Published · 4 min read · Based on the DPDP Act, 2023 and DPDP Rules, 2025 · Not legal advice

Most Indian websites collect consent with a checkbox and a line in the database. Under the Digital Personal Data Protection (DPDP) Act, 2023, that is not enough. When a customer complains or the Data Protection Board asks, you have to show what the person was told, what they agreed to, and when.

The DPDP Rules were notified in November 2025, and most obligations apply from mid-2027. That leaves a short window to fix consent before it becomes a legal risk. Penalties under the Act go up to ₹250 crore per breach.

We built Promiz to close that gap. It is a consent management platform made for the DPDP Act, not adapted from a European GDPR tool.

What the DPDP Act asks of you

If your website or app collects personal data from people in India, the Act expects six things.

  • A clear notice (Section 5). Tell people what data you collect, why, and how they can complain, in English or any of the 22 scheduled Indian languages they choose.
  • Valid consent (Section 6). Consent must be free, specific, informed and unambiguous, given for each purpose. Pre-ticked boxes do not count.
  • Easy withdrawal. Withdrawing consent must be as easy as giving it.
  • Children's data (Section 9). For users under 18, you need verifiable consent from a parent or guardian.
  • User rights (Sections 11 to 14). People can ask to see, correct or erase their data, raise a grievance, and nominate someone to act for them.
  • Proof. You must be able to show all of this happened, long after the click.

Ask any compliance team how consent works on their website today, and the same gaps come up.

  • No proof of what was shown. The database says "consented: true", but nobody can show the notice text or screen the person saw.
  • One checkbox for everything. Marketing, analytics and service are bundled into one "I agree", which fails the specific-purpose test.
  • English only. Notices are not available in the languages customers actually read.
  • Withdrawal buried in an email address. Saying no takes far more effort than saying yes.
  • Records that can be edited. If an admin can quietly change a consent row, the record is weak evidence.
  • Children treated like adults. A "Yes, I am 18" checkbox is not verifiable parental consent.

How Promiz covers each requirement

Promiz handles the whole consent lifecycle, from the first banner to the day a user asks you to delete their data.

  • Clear notice: Versioned notices in Indian languages, translated through the government's Bhashini service. Each one lists purposes, data collected, retention and the grievance contact.
  • Valid consent: Separate choices for each purpose. Non-essential purposes can never start switched on; the server rejects them.
  • Easy withdrawal: A preference centre where users change or withdraw consent in one click, any time.
  • Children's data: Server-side age checks, verification through DigiLocker, and verified guardian consent linked to the child's record.
  • User rights: A self-service portal for access, correction, erasure, grievance and nomination requests, each tracked against a 30-day deadline.
  • Proof: Every consent is stored with a fingerprint of the exact notice and screen the user saw, in a tamper-evident, append-only record. Any later change is detectable.

Consent does not last forever either. Promiz tracks expiry and asks users to renew before consent lapses.

Getting started takes one line of code

You do not need to rebuild your website to use Promiz.

  1. Set up your notice. Add your purposes and the data you collect in the Promiz console, and pick your languages.
  2. Design your banner. Choose the layout and colours, and preview the banner and preference centre before going live.
  3. Add one script tag. Paste the Promiz snippet into your site. The consent banner appears and every choice is recorded from that moment.

From then on, your compliance team works from one dashboard: consent records, rights requests, grievances and deadlines, all in one place.

The DPDP deadline is closer than it looks. Consent you collect today, with proof, is consent you will not have to collect again.

Want to see Promiz on your own website? Visit www.promiz.in to book a demo, and we will set up a working banner with you.

Promiz supports your DPDP compliance programme. It is not legal advice. Your legal team decides purposes, lawful bases and retention periods.

Bring one purpose. Leave with the proof.

A 30-minute session on your own use case.

  1. 5 min Find your DPDP gaps for that purpose
  2. 20 min Build the notice, collect consent, withdraw it, and close the task
  3. 5 min Download the receipt and verify the chain

Book your demo

Enter your website. We scan its cookies before the call and show you the results.

Reply within 1 business day