DPDP consent, explained: what actually counts as valid
A plain-language look at what "valid consent" means when your app asks a user for their data.
Valid consent under the DPDP Act must be free, specific, informed, unconditional, and unambiguous, given through a clear affirmative action. A pre-ticked checkbox or a wall-of-text policy people scroll past does not qualify; you need a plain-language notice shown before you collect the data.
Yes, this applies to you
If your app asks for a phone number at signup, asks for location to show nearby options, or stores someone's email address, the Digital Personal Data Protection Act, 2023 already applies to you. It does not matter if you have 200 users or 2 million. Anyone who decides why and how personal data gets processed counts as a "data fiduciary" under the Act, and a five-person startup fits that definition just as much as a large company does.
What makes consent actually valid
The Act is specific about this: consent has to be free, specific, informed, unconditional, and unambiguous, given through a clear affirmative action. A pre-ticked checkbox does not qualify. Neither does a wall-of-text privacy policy that people scroll past to hit "Continue." What you need instead is a notice, in plain language, telling the user what data you are collecting, why, and what happens to it, shown before you collect it, not buried in a terms page they never open.
If you are collecting data for one purpose, say verifying someone's identity, and later want to use it for another purpose, say marketing, that needs fresh consent. Bundling everything into one broad "I agree" at signup, and hoping it quietly covers whatever you do with the data later, is exactly the pattern the Act is designed to stop.
Withdrawing consent, and who to reach
Consent is not a one-way door. Startups that support withdrawing consent as easily as they support giving it tend to have far fewer headaches later. Users, called "data principals" under the Act, also have the right to know what personal data of theirs is being processed, to correct anything inaccurate or outdated, and to have it erased once it is no longer needed for the purpose it was originally collected for.
Every data fiduciary has to designate a grievance officer, whose contact details are published somewhere users can actually find them, typically the privacy policy or app settings. This is the person a user reaches when they want to know what data is held on them, want it corrected, or want it deleted, and it is meant to be the fallback when a data-related complaint does not get resolved another way.
Quick glossary
- Data fiduciary
- Anyone who decides why and how personal data is processed, regardless of company size.
- Data principal
- The Act's term for the person whose personal data is being collected and used.
- Valid consent
- Consent that is free, specific, informed, unconditional, and unambiguous, given through a clear affirmative action, not a pre-ticked box or a buried policy.
- Grievance officer
- The person a data fiduciary must appoint and publish contact details for, so users can raise data requests and complaints.
- Right to erasure
- A user's right to have their data deleted once it is no longer needed for the purpose it was collected for.
For the full legal detail: DPDP Act Compliance: What Every Indian Startup Handling User Data Must Do.
Get this reviewed for your case. General guides don't know your consent flow, your data, or your users. Vaksy can connect you with a verified advocate on the platform who can review your specific setup, in your own language. Talk to a Vaksy advocate →
Questions people ask
What are the requirements for consent under the DPDP Act?
Consent has to be free, specific, informed, unconditional, and unambiguous, given through a clear affirmative action. A pre-ticked checkbox or a wall-of-text privacy policy people scroll past does not qualify; you need a plain-language notice shown before you collect the data.
Can consent be withdrawn under DPDPA?
Yes. Consent is not a one-way door under the Act. Startups that make withdrawing consent as easy as giving it tend to have far fewer problems later, and users can also ask for their data to be corrected or erased.