Under the DPDP Act 2023, consent must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action, and limited to what is necessary for the stated purpose. To prove it, a data fiduciary needs a consent record that shows what the person consented to, when, against which notice version, and how they can withdraw it just as easily. This checker scores your consent records against those DPDP-defensible criteria — dated, specific, unbundled and withdrawable — and shows where the record would fail if challenged.
Would your consent records survive scrutiny? Score them against the DPDP tests — dated, specific, unbundled and withdrawable — in under three minutes.
The DPDP Act 2023 sets a high bar for consent: it must be free, specific, informed, unconditional and unambiguous, expressed through a clear affirmative action, and confined to the personal data necessary for the stated purpose. A tick buried in terms of service, a pre-ticked box, or a single blanket consent covering many unrelated purposes all fall short. Just as importantly, the burden is on the fiduciary to prove valid consent was obtained — which means the record matters as much as the consent itself.
A defensible consent record therefore captures four things: what was consented to, when, against which version of the notice, and how withdrawal is offered. If any of those is missing, you can still process data, but you cannot prove you did so lawfully — and inability to prove valid consent is functionally the same as not having it when the Data Protection Board asks.
Two failure modes account for most non-compliant consent in India: bundling and one-way doors. Bundling forces a person to accept marketing or data-sharing purposes to use the core service, which strips the consent of being free and specific. A one-way door lets people opt in with one click but makes withdrawal slow or hidden, which breaches the requirement that withdrawal be as easy as giving consent.
Niti Bharat rebuilds consent capture and record-keeping for Indian mid-market companies as part of its fixed-price DPDP engagements — separating purposes, removing pre-ticked boxes, wiring a one-step withdrawal, and logging every event so the record is genuinely defensible. It is one of the highest-leverage fixes to complete before the expected May 2027 enforcement date.
A consent-record audit template scoring each capture point against the DPDP tests, plus a purpose-splitting worksheet and a withdrawal-flow checklist.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.