Decision aid

Is this consent valid?

Section 4 allows processing on one of two grounds: the Data Principal's consent, or one of the legitimate uses in Section 7. If consent is the ground, Section 6 sets the tests it must meet and Section 5 the notice that must go with it. Answer from the facts of one specific request for consent.

Step 1

Which ground do you rely on for this processing?

All steps in this tool
  1. Which ground do you rely on for this processing?

    Rests on: Section 4 — Grounds for processing personal data

  2. Was the request for consent accompanied or preceded by a notice telling the Data Principal (i) the personal data and the purpose of processing, (ii) how she may exercise her rights under Section 6(4) and Section 13, and (iii) how she may complain to the Board?

    Rests on: Section 5 — Notice, Section 6 — Consent, Section 13 — Right of grievance redressal

  3. Consent not required — a legitimate use applies. Consent is not required where one of the legitimate uses in Section 7 applies.

    Section 4(1)(b) permits processing for a lawful purpose for certain legitimate uses, and Section 2(d) says those are the uses set out in Section 7. Section 7 lists them: the specified purpose for which the Data Principal voluntarily provided her personal data and in respect of which she has not indicated that she does not consent (clause (a)); certain processing by the State and its instrumentalities (clauses (b), (c) and (d)); compliance with a judgment, decree or order (clause (e)); a medical emergency (clause (f)); epidemics and other threats to public health (clause (g)); disasters and breakdown of public order (clause (h)); and employment-related purposes (clause (i)). The processing must fit the words of the clause you rely on. Under clause (a), once the Data Principal indicates that she no longer wants the processing, it must stop — see Illustration (II) to Section 7.

    Rests on: Section 4 — Grounds for processing personal data, Section 7 — Certain legitimate uses, Section 2 — Definitions

  4. Was the consent given freely?

    Rests on: Section 6 — Consent

  5. Not valid: fails the notice requirement. Not valid: no notice accompanied or preceded the request for consent.

    Section 5(1) says every request for consent under Section 6 shall be accompanied or preceded by a notice informing the Data Principal of the personal data and the purpose for which it is proposed to be processed, the manner in which she may exercise her rights under Section 6(4) and Section 13, and the manner in which she may make a complaint to the Board. Section 6(1) also requires consent to be informed. Section 6(10) puts the burden on the Data Fiduciary to prove, in any proceeding, that notice was given and consent obtained in accordance with the Act. Rule 3, which applies from 13 May 2027, sets out what the notice must contain: it must be understandable on its own, give an itemised description of the personal data and the specified purposes, and give the link and other means for withdrawing consent, exercising rights and complaining to the Board.

    Rests on: Section 5 — Notice, Section 6 — Consent, Section 13 — Right of grievance redressal, Rule 3 — Notice given by Data Fiduciary to Data Principal

  6. Was the consent specific — did it signify agreement to processing for the specified purpose, that is, the purpose stated in the notice?

    Rests on: Section 6 — Consent, Section 2 — Definitions

  7. Not valid: fails the test of free consent. Not valid: the consent was not free.

    Section 6(1) requires that the consent given by the Data Principal be free. Consent that was not freely given does not meet the first word of the test and cannot found processing under Section 4(1)(a). The Act does not define the word; read it in its ordinary sense alongside the other requirements of Section 6(1), in particular that consent be unconditional.

    Rests on: Section 6 — Consent, Section 4 — Grounds for processing personal data

  8. Was the consent informed?

    Rests on: Section 6 — Consent, Section 5 — Notice

  9. Not valid: fails the test of specific consent. Not valid: the consent was not specific to the specified purpose.

    Section 6(1) requires consent to be specific and to signify an agreement to the processing of her personal data for the specified purpose. Section 2(za) defines the specified purpose as the purpose mentioned in the notice given by the Data Fiduciary to the Data Principal under Section 5. A general or open-ended consent, or one that does not match the purpose in the notice, does not meet this test.

    Rests on: Section 6 — Consent, Section 2 — Definitions, Section 5 — Notice

  10. Was the consent unconditional?

    Rests on: Section 6 — Consent

  11. Not valid: fails the test of informed consent. Not valid: the consent was not informed.

    Section 6(1) requires consent to be informed. The Act ties this to the notice: Section 5(1) requires the request for consent to be accompanied or preceded by a notice informing the Data Principal of the personal data, the purpose, her rights and how to complain, and Section 6(3) requires the request itself to be in clear and plain language. A consent given without that information is not informed.

    Rests on: Section 6 — Consent, Section 5 — Notice

  12. Was the consent unambiguous and signified by a clear affirmative action of the Data Principal?

    Rests on: Section 6 — Consent

  13. Not valid: fails the test of unconditional consent. Not valid: the consent was conditional.

    Section 6(1) requires consent to be unconditional. The Act does not elaborate the word; read it with the requirement in the same sub-section that consent be limited to the personal data necessary for the specified purpose, and with Section 6(2), under which any part of a consent that infringes the Act, the rules or any other law is invalid to the extent of the infringement.

    Rests on: Section 6 — Consent

  14. Is the consent limited to the personal data that is necessary for the specified purpose?

    Rests on: Section 6 — Consent

  15. Not valid: fails the test of a clear affirmative action. Not valid: no clear affirmative action, or an ambiguous one.

    Section 6(1) requires consent to be unambiguous, with a clear affirmative action, signifying an agreement to the processing. Where the Data Principal has taken no clear affirmative action, or the action taken is ambiguous as to what it agrees to, the test is not met.

    Rests on: Section 6 — Consent

  16. Was the request for consent presented in clear and plain language, with the option to read it in English or any language in the Eighth Schedule to the Constitution, and with the contact details of a Data Protection Officer or another person authorised to answer the Data Principal?

    Rests on: Section 6 — Consent

  17. Not valid for the excess: fails the necessity limit. Not valid for the excess: the consent covers personal data the purpose does not need.

    Section 6(1) requires consent to be limited to such personal data as is necessary for the specified purpose. The Illustration to Section 6(1) shows the effect: a telemedicine app that obtains consent both to provide its service and to access the user's phone contact list has valid consent only for the service, because the contact list is not necessary for it. Consent for personal data beyond what the purpose needs does not carry, even if the Data Principal agreed to it. The consent for the necessary data is judged on the remaining tests.

    Rests on: Section 6 — Consent

  18. Does any part of the consent ask the Data Principal to agree to something that infringes the Act, the rules or any other law in force — for example, to waive a right the Act gives her?

    Rests on: Section 6 — Consent

  19. Not valid: fails the requirements for the request in Section 6(3). Not valid: the request did not meet Section 6(3).

    Section 6(3) requires every request for consent under the Act or the rules to be presented to the Data Principal in clear and plain language, giving her the option to access it in English or any language specified in the Eighth Schedule to the Constitution, and providing the contact details of a Data Protection Officer, where applicable, or of any other person authorised by the Data Fiduciary to respond to communications about her rights. Section 5(3) applies the same language option to the notice.

    Rests on: Section 6 — Consent, Section 5 — Notice

  20. Can the Data Principal withdraw her consent at any time, with the ease of doing so comparable to the ease with which she gave it?

    Rests on: Section 6 — Consent

  21. Not valid to that extent: fails Section 6(2). Not valid to that extent: part of the consent infringes the Act or another law.

    Section 6(2) says any part of a consent that constitutes an infringement of the provisions of the Act, the rules or any other law in force is invalid to the extent of that infringement. The Illustration to Section 6(2) gives the example of an insurance customer who consents both to processing for issuing her policy and to waiving her right to complain to the Data Protection Board of India: the waiver part of the consent is invalid. The remainder of the consent is judged on the other tests in Section 6.

    Rests on: Section 6 — Consent

  22. Was the consent given, or is it managed, through a Consent Manager?

    Rests on: Section 6 — Consent

  23. Not valid: fails the right to withdraw. Not valid: the Data Principal cannot withdraw as easily as she consented.

    Section 6(4) gives the Data Principal the right to withdraw consent at any time, with the ease of doing so being comparable to the ease with which it was given. A consent mechanism that offers no route to withdraw, or one markedly harder than the route to consent, does not respect that right. Section 6(4) is framed as a right rather than as one of the words in Section 6(1), and the Act does not say in terms that such a consent is void; but Section 4(1) permits processing only in accordance with the Act, and Section 6(10) requires the Data Fiduciary to prove that consent was obtained in accordance with the Act and the rules. On withdrawal, Section 6(6) requires the Data Fiduciary, within a reasonable time, to cease processing and to cause its Data Processors to cease, unless processing without consent is required or authorised by law; Section 6(5) preserves the legality of processing done before withdrawal. Rule 3, which applies from 13 May 2027, requires the notice itself to give the link and other means by which consent can be withdrawn.

    Rests on: Section 6 — Consent, Section 4 — Grounds for processing personal data, Rule 3 — Notice given by Data Fiduciary to Data Principal

  24. Is that Consent Manager registered with the Data Protection Board of India?

    Rests on: Section 6 — Consent, Section 2 — Definitions, Rule 4 — Registration and obligations of Consent Manager

  25. Valid on these facts. Valid on these facts.

    On these facts the consent meets each requirement of Section 6(1) — free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, signifying agreement to processing for the specified purpose and limited to the personal data necessary for it — the request met Section 6(3), a notice under Section 5(1) accompanied or preceded it, no part of it infringes the Act or another law (Section 6(2)), and the Data Principal can withdraw it as easily as she gave it (Section 6(4)). Two things remain with the Data Fiduciary: under Section 6(10) it must be able to prove, in any proceeding, that notice was given and consent obtained in accordance with the Act and the rules; and processing must stay within the specified purpose, since Section 4(1) permits processing only in accordance with the Act and for a lawful purpose.

    Rests on: Section 6 — Consent, Section 5 — Notice, Section 4 — Grounds for processing personal data

  26. Valid on these facts. Valid on these facts, given through a registered Consent Manager.

    Section 6(7) lets the Data Principal give, manage, review or withdraw her consent to the Data Fiduciary through a Consent Manager. Section 2(g) defines a Consent Manager as a person registered with the Board who acts as a single point of contact for the Data Principal through an accessible, transparent and interoperable platform; Section 6(9) requires registration with the Board on prescribed conditions, and Section 6(8) makes the Consent Manager accountable to the Data Principal. Rule 4, which applies from 13 November 2026, sets the registration procedure and points to the First Schedule for the conditions of registration (Part A) and the Consent Manager's obligations (Part B). The consent itself stands on the Section 6(1) tests you have just applied; Section 6(10) leaves the Data Fiduciary to prove notice and consent in any proceeding.

    Rests on: Section 6 — Consent, Section 2 — Definitions, Rule 4 — Registration and obligations of Consent Manager, First Schedule — First Schedule (see rule 4)

  27. Cannot rely on the Consent Manager route: the intermediary is not registered. The Consent Manager route is not available: the intermediary is not registered with the Board.

    Section 2(g) defines a Consent Manager as a person registered with the Board, and Section 6(9) requires every Consent Manager to be registered with the Board in the prescribed manner and on the prescribed conditions. An intermediary that is not registered is not a Consent Manager within the meaning of the Act, so Section 6(7) does not describe what happened. The Act does not say in terms that consent routed through an unregistered intermediary is void; whether the consent stands depends on whether the Data Principal's own act meets the tests in Section 6(1), with notice under Section 5, which you have applied above. The registration procedure is in Rule 4, which applies from 13 November 2026.

    Rests on: Section 6 — Consent, Section 2 — Definitions, Section 5 — Notice, Rule 4 — Registration and obligations of Consent Manager