Your sign-up screen has one checkbox. It is already ticked, and the sentence beside it covers the terms, the privacy policy, marketing emails and sharing data with partners. That single box now fails the law in four separate ways.
Consent under the DPDP Act must be free, specific, informed, unconditional and unambiguous, given separately for each purpose, and as easy to withdraw as it was to give — and from 13 November 2026 registered Consent Managers give users one place to do all of it.
The bottom line
What valid consent looks like: an unticked box or an equivalent affirmative action, one per purpose, after a plain-language notice.
What is banned: pre-ticked boxes, hidden reject buttons, bundling unrelated purposes into one agreement.
The date: 13 November 2026, when Consent Managers go live. Your consent capture has to be able to talk to them.
Why consent carries so much weight here
GDPR gives a business six lawful bases for processing data. The DPDP Act runs almost entirely on one, which is whether the person agreed. That concentration is what makes a loosely drafted "I agree" checkbox a liability rather than a formality: there is no fallback basis to argue in the alternative.
What counts as valid consent
The Act sets the bar at five things at once. Consent must be:
- free — not coerced, and not the price of unrelated access;
- specific — tied to a defined purpose;
- informed — preceded by a clear notice;
- unconditional — not bundled with unrelated terms; and
- unambiguous — given by a clear affirmative action, such as ticking an empty box or tapping "I agree".
Silence is not consent. Inactivity is not consent. A pre-checked box is not consent. And the burden of proving valid consent sits on you as the Data Fiduciary, which in practice means logging it with a timestamp. An assertion that a user agreed, with no record behind it, is worth nothing.
The notice has to come first
Consent is only informed if a proper notice preceded it. Before the person agrees, show an itemised, plain-language notice covering what data you collect, the specific purpose, how to exercise rights and how to complain. Consent obtained without that notice is not valid consent, however clean the checkbox looks.
One consent per purpose
This is where most sign-up flows break. A single blanket "I agree" covering account creation, marketing emails, analytics and data sharing with partners does not work. Each distinct purpose needs its own consent that the user can give or refuse on its own.
Someone who wants the product but not the marketing has to be able to say exactly that, and still get the product.
Withdrawal has to be as easy as agreeing
If users opted in with one tap, they must be able to opt out with one tap. Not by emailing support, not by working through five menus, not by filling in a form. Once consent is withdrawn you stop the relevant processing going forward, though processing already carried out before withdrawal stays lawful.
The practical answer is a single visible "manage your data" control in the product. It satisfies the rule, and it is easier to build once than to retrofit under a grievance.
What a Consent Manager is
This is the genuinely new piece of machinery. A Consent Manager is a registered intermediary — a dashboard where an individual can see every consent they have given across different services and give, review or withdraw them from one place. It owes its duty to the user, not to any business plugged into it.
Only India-incorporated entities meeting the eligibility criteria, which include a minimum net worth and demonstrated technical capacity, can register as Consent Managers with the Data Protection Board. That requirement keeps foreign consent-management platforms from operating as registered managers here, whatever they do elsewhere.
The November 2026 deadline
The framework becomes operational on 13 November 2026, twelve months after the Rules were notified. It is the most concrete intermediate deadline before full compliance lands in May 2027.
For a consumer-facing platform the implication is technical: consent capture and management have to be compatible with Consent Manager APIs and the interoperability standards around them. Bolting that on afterwards means rebuilding the flow a second time, so it belongs in the 2026 design rather than after it.
When you do not need consent
The Act recognises a short list of "legitimate uses" where consent is not required. The one most businesses rely on is standard employment processing — recruitment, onboarding, payroll, benefits — which needs no separate consent.
The carve-out is narrower than it first reads. Use employee data for something unrelated to employment and you are back to needing consent for that use. Data a person has voluntarily made public also sits outside the consent requirement.
A worked example
A fintech app's old sign-up screen carries one pre-ticked box: "I agree to the Terms, Privacy Policy, marketing communications, and data sharing with partners." It is pre-ticked, bundled, conditional and offers no granular choice, so it fails four ways at once.
The rebuilt flow:
- The itemised notice appears before anything is asked.
- Consent for account creation is a single unticked, affirmative checkbox.
- Marketing emails get their own optional, unticked checkbox.
- Partner data-sharing gets a third, refusable without losing the core service.
- A "Manage consent" link in settings withdraws any of them in one tap.
- Every consent is timestamped and logged.
It is the same screen. The difference is that this version can be explained to the Board.
Common mistakes
- Pre-ticked or bundled consent. Each purpose needs its own affirmative opt-in.
- No consent log. If you cannot prove consent was validly given, you did not obtain it as far as the Board is concerned.
- Burying withdrawal several screens deep. It has to match the effort of the opt-in.
- Treating Consent Managers as a 2027 problem. The API integration is due in November 2026.
- Stretching "legitimate use" past the employment relationship it was written for.
Frequently asked questions
What makes consent valid under the DPDP Act? It must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, for each purpose separately.
When do Consent Managers go live? The framework becomes operational on 13 November 2026.
Can I use one consent for all my data processing? No. Consent is purpose-specific, and users must be able to agree to some purposes while refusing others.
How easy must it be to withdraw consent? As easy as it was to give. A one-tap opt-in requires a one-tap withdrawal.
Do I always need consent? No. Certain legitimate uses, including standard employment processing, do not require separate consent, but the exceptions are narrow.
Does withdrawing consent make past processing unlawful? No. Processing done before withdrawal remains lawful. You have to stop the relevant processing from that point on.