Consent records & proof · DPDP S. 6(4), 6(10) · Rules 6 and 8(3)

Consent records that prove what each person agreed to.

If a question comes up, you must prove that you gave notice and got consent. Promiz keeps every grant, change and withdrawal as a linked entry that nobody can edit or delete.

0
edits or deletes: every change is a new linked entry
1
click to verify the whole chain
2
receipt formats: PDF and machine-readable
Consent record · C-58213✓ Chain verified Given · 14 Jun 2027, 10:42Notice "Account opening" v3 · हिन्दी · OTP verified · snapshot saved Marketing withdrawn · 2 Sep 2027From privacy portal · linked to entry 1 Marketing re-granted · 9 Jan 2028Linked to entry 2 · retention task cancelled Download receipt (PDF) Machine-readable View screen shown
Figure 1. One consent record with three linked entries. Sample data.
What the law asks

What proof does the DPDP Act expect?

The Act puts the burden of proof on you. In any proceeding, you must show that you gave the notice and that the person gave consent.

RequirementSourceWhat it meansHow Promiz helps
Prove notice and consent S. 6(10) If consent is questioned, the Data Fiduciary must prove notice was given and consent was given. Each record holds the notice version, language, fingerprinted text and a snapshot of the screen.
Withdrawal as easy as consent S. 6(4) A person can withdraw at any time, as easily as they gave consent. Portal withdrawal in one step. Staff can also withdraw on request, with a reason.
Record the effect of withdrawal S. 6(6) After withdrawal you must stop processing within a reasonable time. Each withdrawal opens a stop-processing task. See Obligations & retention.
Logs and monitoring Rule 6 Keep logs and monitoring to detect and investigate unauthorised access. Tamper-evident audit trail for every admin action. Masked IDs with logged reveals.
Keep processing logs for one year Rule 8(3) Keep personal data, traffic data and processing logs for at least one year, for the listed purposes. Records are never deleted by edits. Set retention and legal holds to match your policy.

Sources: Digital Personal Data Protection Act, 2023, section 6; DPDP Rules, 2025, Rules 6 and 8(3). Confirm how Rule 8(3) applies to your logs with your legal team.

In Promiz

How does Promiz build the proof?

Proof starts at the moment of consent, not when someone asks for it.

How Promiz builds consent proof At consentCaptureNotice version,language, choicesAt consentFingerprintBinding text andscreen snapshotOn changeLinkNew entry chainedto the last oneOn requestVerifyWalk the chain,flag any breakOn requestExportPDF receipt ormachine-readable
Figure 2. From the moment of consent to the proof you hand over.
  1. Step 1 Consent is captured

    Promiz stores the notice, version, language, each purpose's status, legal basis and data involved.

  2. Step 2 The screen is saved

    A picture of the exact screen the person saw is stored with the record.

  3. Step 3 Changes are chained

    A change or withdrawal adds a new entry linked to the one before it.

  4. Step 4 Anyone can verify

    One click walks the chain and confirms nothing was altered.

  5. Step 5 You export the proof

    Download the notice PDF and a consent receipt in PDF or machine-readable form.

Capabilities

What is in a Promiz consent record?

Exact notice and version

Older records always show the version the person agreed to, even after you edit the notice.

Snapshot of the screen

A picture of what the person saw at the moment of consent.

Per-purpose status

Each purpose shows given, refused or withdrawn, with its legal basis and data categories.

Chained history

Grants, changes, withdrawals and re-grants in order, each linked to the last.

One-click integrity check

Promiz walks the chain and confirms it has not been tampered with.

Search and filter

Find records by application, date or reference.

Receipts

Notice PDF, plus a consent receipt in PDF or machine-readable form, for you and for the customer in the portal.

Privacy by design

Email addresses are encrypted. IP addresses and phone numbers are stored only as one-way codes.

Compare

Why is a database row not enough?

Task Email, spreadsheets and a basic banner Promiz
Show which wording the person saw Row says "consent = yes" Notice version, fingerprint and screen snapshot
Show the record was not changed Anyone with access can edit it Chained entries and a one-click check
Show the full history Last value only Every grant, change and withdrawal in order
Give the person a copy Manual email Receipt in the portal, PDF or machine-readable
Protect identifiers IPs and phones in plain text Encrypted email; one-way codes for IP and phone
FAQ

Consent records & proof: frequent questions

Not answered here? Ask us in a demo.

Who must prove consent under the DPDP Act?

The Data Fiduciary. Under section 6(10), if consent is questioned in a proceeding, you must prove that you gave notice and that the person gave consent.

Can anyone edit or delete a Promiz consent record?

No. A change is always a new entry linked to the previous one. The integrity check shows any break in the chain.

What does a Promiz consent receipt contain?

The notice and version, the language, the status of each purpose, the legal basis and the data involved. You can download it as a PDF or in machine-readable form.

Does Promiz store IP addresses?

Only as one-way codes, never in plain text. Email addresses are encrypted at rest.

Can staff withdraw consent for a customer?

Yes. An Admin can withdraw consent on a customer's behalf when they ask, and must record a reason.

See a record verified in front of you.

In 30 minutes we collect a consent, withdraw it and verify the chain with you.

Book a 30-minute demo We reply within 1 business day.

This page explains the law in plain words. It is not legal advice. Your legal team decides how the Act applies to you. Last reviewed 21 September 2026.