India’s DPDP Act: what consent managers must get right
The Digital Personal Data Protection Act, 2023 recasts consent as a recorded, purpose-bound choice. Here is how platforms should operationalize it.

India’s Digital Personal Data Protection Act, 2023 (DPDP Act) is one of the most consequential privacy statutes of this decade. It applies to digital personal data processed in India, and in many cases to processing outside India when it is connected with offering goods or services to people in India.
Unlike a purely notice-and-cookie model, DPDP treats consent as a specific, informed, unconditional, and unambiguous indication of the Data Principal’s wishes. That consent must be tied to a stated purpose. A consent manager is not a nice-to-have overlay — it is the system of record for those choices.
Consent that can be proven later
Data Fiduciaries must be able to demonstrate that consent was obtained. That means storing more than a banner checkbox. Capture the policy version, purpose list, language, timestamp, user agent, and the Data Principal identifier that your product actually uses.
DPDP also expects withdrawal to be as easy as giving consent. If users can accept in one tap, they should be able to reverse that decision from a preference center without calling support.
Where a consent manager helps
A dedicated consent manager translates legal purposes into runtime signals: which tags fire, which vendors receive data, and which processing activities remain lawful. It also gives India-facing teams a single place to update notices when purposes change, instead of editing every property by hand.
This is not legal advice. Work with counsel on fiduciary classifications, children’s data, and Significant Data Fiduciary duties. Use the product to make those decisions enforceable once they are written.
Educational overview only — not legal advice. Confirm requirements with counsel for your products and markets.


