Under the DPDP Act 2023, consent must be free, specific, informed and unambiguous, and a Data Principal can withdraw it as easily as it was given. Consent does not last forever: it becomes stale when the purpose changes, when it was collected without a proper notice, or when a Data Principal withdraws it. A DPDP-ready process tracks what each consent covers, flags when it needs to be refreshed, honours withdrawals promptly, and keeps a dated record. Relying on old or blanket consent is one of the most common DPDP gaps.
Consent is not permanent. This checks whether you can tell which consents are still valid, which are stale, and how quickly you honour withdrawals.
A common misconception is that once a Data Principal has said yes, that consent lasts indefinitely and covers whatever the business does next. The DPDP Act 2023 does not work that way. Consent is tied to the specific purpose disclosed in the notice at the time it was collected. If the purpose changes, if the processing expands, or if the original notice was inadequate, the old consent no longer covers the new activity. In effect, consent goes stale, and continuing to rely on it becomes a liability rather than a defence.
Withdrawal makes this dynamic. Because the Act requires withdrawal to be as easy as giving consent, a Data Principal can revoke at any time, and your systems must reflect that promptly across every place the data flows — including your processors. A consent record that cannot tell you which consents are current, which have been withdrawn, and which need refreshing leaves you exposed. Niti Bharat helps companies build consent tracking that treats consent as a living record, not a one-time checkbox.
A working consent lifecycle starts with a structured record: for each Data Principal, what they consented to, for what purpose, against which notice version, and on what date. From there, you add the two things most organisations miss — a genuinely easy withdrawal path, and a trigger that re-seeks consent when the purpose changes. Finally, a periodic review flags consent that has gone stale so it can be refreshed before it is relied upon in error.
This becomes especially important as the DPDP Rules 2025 bed in ahead of full enforcement around May 2027, because consent is the most visible and most litigated part of the framework. Niti Bharat runs privacy governance programmes that stand up this consent renewal process end to end, including propagation of withdrawals to downstream systems, so you can prove valid consent existed at the moment each piece of data was used.
A consent tracking template with purpose, date and notice-version fields, plus a short guide on when consent needs to be refreshed or re-sought.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.