
DPDP Granular Consent: Why One Checkbox Is No Longer Enough
One checkbox covering terms, marketing, WhatsApp and partner sharing is unlikely to hold up under the DPDP Act. Here is what Section 6 and Rule 3 require, what purpose-level consent looks like on a real form, and a checklist to finish before 13 May 2027.
Most Indian sign-up forms still ask for consent the same way: one checkbox that covers the terms of service, the privacy policy, marketing emails, WhatsApp updates and "sharing with our partners". Under the Digital Personal Data Protection Act, 2023, that single tick is unlikely to hold up. DPDP granular consent means asking for consent purpose by purpose, so that a person can say yes to one use of their data and no to another.
This guide explains what the Act and the DPDP Rules, 2025 actually require, what granular consent looks like on a real form, the mistakes that quietly invalidate consent, and a checklist you can work through before the main obligations begin on 13 May 2027.
Key takeaways
- Section 6(1) requires consent to be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the data necessary for the specified purpose.
- Consent bundled across several purposes, or covering data you do not need, is invalid to the extent it goes beyond the law (Section 6(2)).
- The notice under Section 5 and Rule 3 must itemise the personal data and the specified purpose for each processing activity.
- Withdrawal must be as easy as giving consent (Section 6(4)), and in any dispute the burden of proving notice and consent sits with you (Section 6(10)).
- Practical rule: one purpose, one clear choice, one record.
What the DPDP Act says about consent
Section 6(1) of the DPDP Act sets five qualities for valid consent: it must be free, specific, informed, unconditional and unambiguous, and it must be signified by a clear affirmative action. It also says consent covers only the personal data that is necessary for the specified purpose.
The Act illustrates this with a telemedicine app that asks for consent to provide telemedicine services and also to access the user's phone contact list. The user agrees to both. Because the contact list is not necessary for telemedicine, the Act treats her consent as limited to the telemedicine purpose only. The extra permission simply does not count.
Section 6(2) goes further: any part of a consent that infringes the Act or the Rules is invalid to that extent. In other words, bundling does not make a broad consent stronger. It makes the excess part worthless, and it leaves you processing data without a valid basis.
The notice has to be itemised too
Granular consent starts with a granular notice. Section 5 requires a Data Fiduciary to give a notice before or at the time of asking for consent, describing the personal data and the purpose of processing, how to withdraw consent and raise grievances, and how to complain to the Data Protection Board.
Rule 3 of the DPDP Rules, 2025 adds detail. The notice must be understandable on its own, in clear and plain language, and must include at minimum an itemised description of the personal data and the specified purpose, along with the goods, services or uses that the processing enables. A single paragraph that says "we use your data to improve our services and for business purposes" does not meet this standard.
If you already hold consents collected before the Act commenced, Section 5(2) requires you to give these Data Principals a notice as soon as reasonably practicable. That is a good moment to re-collect consent at the purpose level.
What DPDP granular consent looks like in practice
Take an online retailer. A typical account sign-up might involve these processing activities:
- Creating the account and delivering orders
- Sending order updates on WhatsApp
- Sending promotional emails and offers
- Personalised product recommendations based on browsing history
- Sharing contact details with a partner for co-branded offers
A granular approach treats each optional purpose as its own choice, with its own short description of the data involved. The person can agree to order updates and decline promotional email. None of the optional boxes is pre-ticked, and declining an optional purpose does not block the core service.
Some processing, such as what is strictly needed to deliver an order the customer asked for, may fall under the legitimate uses in Section 7 rather than consent. Where exactly that line sits for your business is a question to settle with counsel. What should not happen is using the core service as leverage to collect consent for purposes it does not need.
Common mistakes that make consent invalid
- Pre-ticked boxes. A box the person did not tick is not a clear affirmative action.
- "By continuing, you agree". Scrolling or continuing is not an unambiguous signal of consent.
- Bundling with terms of service. Marketing consent hidden inside acceptance of the terms is neither specific nor free.
- Vague purposes. "Business purposes" or "improving your experience" are not specified purposes.
- Conditional access. Refusing service unless someone agrees to unrelated processing runs against the "unconditional" requirement.
- Hard exits. A one-click opt-in paired with an email-only opt-out fails Section 6(4).
Regulators are paying attention to the design of these journeys. On 23 September 2026, IRDAI released a consultation paper proposing that insurers show product and premium information without first asking for personal details, and describing such data walls as a dark pattern, as reported by MediaNama. It is a proposal, not a final rule, but the direction is clear.
Checklist: granular consent before 13 May 2027
- List every processing activity that touches personal data, and the purpose behind each one.
- Mark which purposes rely on consent and which may fall under Section 7 legitimate uses. Get legal sign-off.
- For each consent-based purpose, write a one-line plain-language description and an itemised list of the data it uses.
- Rebuild forms so each optional purpose has its own unticked choice, separate from the terms of service.
- Check that declining any optional purpose does not block the core product.
- Offer a withdrawal route that is as easy as the way consent was given.
- Record each consent with the notice version, the purposes chosen, a timestamp and the identifier of the person, so you can meet the Section 6(10) burden of proof.
- Plan how you will re-notify Data Principals whose consent predates the Act.
For a broader walkthrough of notice and consent, see our DPDPA consent guide and the deeper dive on Rule 3 itemised notices. Once consent is granular, you also have to be able to prove it: see proving consent under Section 6(10). To gauge how far your current setup is from these requirements, try the DPDP compliance calculator.
How Consently supports purpose-level consent
Consently is a DPDP-native consent management platform, legal-reviewed by G. Giri & Partners LLP. It captures granular consent per processing activity and purpose, with templates to help teams draft each purpose clearly. Consent can be verified with an email OTP at the point of collection, and the Data Principal's email identifier is stored hashed in the consent record.
Data Principals can review, update or withdraw consent from a preference centre, and consent renewal helps keep records current. Consently is a platform that Data Fiduciaries use to manage consent. It is not a registered Consent Manager under Section 6(9). If you want to see how purpose-level consent would look on your own forms, book a demo.
Frequently asked questions
Does granular consent mean a separate checkbox for every data field?
No. Granularity is about purposes, not fields. Each purpose gets its own choice, and within that choice you itemise the personal data it uses.
Can I make my service conditional on consent?
Only for personal data that is actually necessary for that service. Under Section 6(1), consent is limited to necessary data, and under Section 6(2) consent that goes beyond the law is invalid to that extent.
When do these notice and consent obligations apply?
The DPDP Rules, 2025 were notified in November 2025 with phased commencement. The core notice and consent provisions, including Rule 3, apply from 13 May 2027. Starting now leaves time to redesign forms and re-collect consent.
Is Consently a Consent Manager under the DPDP Act?
No. Consent Managers are entities registered with the Data Protection Board under Section 6(9) and Rule 4. Consently is a consent management platform that Data Fiduciaries use to collect, record and manage consent.
This article is for general information and is not legal advice. Please consult a qualified lawyer for advice on your specific situation.

