U 110, First Floor, Shakarpur, Delhi 110092, Indiacssunnygupta@gmail.comMon - Sat: 10:00 AM - 7:00 PM
Follow Us:
Data Protection & Privacy

Consent and Withdrawal Under DPDP: Practical Points for Businesses

Consent wording should be clear, linked to purpose and easy to act on when a user asks to withdraw.

Sunny G And Co. Editorial Team 23 June 2026 4 min read
Last updated 23 Jun 2026

Consent under DPDP is not a decorative checkbox. It should connect the person, the data, the purpose and the action being taken. If a user gives data for one purpose and the business quietly uses it for another, the risk starts there.

This article is written for websites, apps, HR teams, consultants, agencies, schools, clinics and businesses that collect digital personal data. Check the latest MeitY and PIB notifications before finalising legal wording, because DPDP implementation details can change through rules and notifications.

Consent should be clear, informed and linked to a purpose where consent is the basis for processing. The person should know what they are agreeing to. The business should also keep a record of how consent was taken and what happens if consent is withdrawn.

Purpose identified
        ↓
Notice shown in simple language
        ↓
User gives clear consent
        ↓
Business records consent
        ↓
Data used only for stated purpose
        ↓
User asks to withdraw / correct / delete
        ↓
Team records request and acts as per law and records policy
  • What data is being collected?
  • Why is it being collected?
  • Will it be used for calls, service delivery, billing, marketing, account creation or support?
  • Will it be shared with vendors, consultants, payment gateways, CRM tools or authorities?
  • How can the person withdraw consent or raise a request?
  • What happens after withdrawal, especially when records must be retained for law, tax, contract or dispute reasons?
SituationConsent / notice issueBetter practice
Website consultation formUser gives phone/email for service enquirySay that the data will be used for callback and service guidance
Newsletter signupUser gives email for updatesKeep newsletter consent separate from service enquiry where possible
Job applicationCandidate shares CV, phone, email and documentsUse candidate data notice and restrict access to HR/recruitment team
Student admission enquiryStudent or guardian shares contact and education detailsExplain counselling, admission follow-up and record retention purpose
Customer KYCPAN, identity or address document is collectedCollect at the right stage and restrict access

Withdrawal is not only a legal line in the policy. Your team needs a working process.

  1. Receive request: user sends email, form request or written message.
  2. Identify record: match user with CRM, app, HR, billing or service record.
  3. Check reason and scope: is the user withdrawing marketing consent, service communication, account processing or something else?
  4. Check retention duties: some records may need to be kept for legal, tax, contract or dispute reasons.
  5. Act and record: update the system, restrict future use where required and keep a request log.
  6. Confirm response: send a short confirmation if appropriate.
  • Using one checkbox for privacy policy, terms, marketing and unrelated permissions.
  • Collecting documents before the business actually needs them.
  • Using vague wording like "for business purposes" without saying what the business will do.
  • Keeping no record of when and how consent was taken.
  • Not training the team on what to do when someone withdraws consent.
  • Continuing marketing messages after opt-out because the CRM and WhatsApp list were not updated.

What to record internally

  • date and time of consent, where available;
  • form, page, app screen or document through which consent was taken;
  • exact consent wording or version used;
  • purpose selected by the user;
  • withdrawal or correction requests;
  • action taken and date of action;
  • reason if some data cannot be deleted immediately due to legal or service record requirements.

Question and answer

Can consent be taken through a website checkbox?
Yes, a checkbox can be used where appropriate, but the wording should be clear and linked to purpose. Do not hide unrelated permissions inside one long sentence.
Can consent be withdrawn by email?
A business can provide an email route or another clear method. The important part is that the team knows how to identify the record and act on the request.
Does withdrawal mean every record must be deleted immediately?
Not always. Some records may need to be retained for legal, tax, contractual, service or dispute reasons. The action depends on the facts and current law.
Should marketing consent be separate?
Usually yes, because service communication and promotional communication are different uses. Keep the wording clear so the user is not misled.
  • List every form where consent is taken.
  • Check whether purpose is clear.
  • Separate service, marketing and account-related permissions where needed.
  • Keep version history of consent wording.
  • Prepare withdrawal handling steps.
  • Update CRM, WhatsApp, email and marketing lists after withdrawal.
  • Review the latest DPDP Rules before final implementation.

If your team cannot process withdrawal without confusion, the consent system is not ready yet. Fix the process before adding more checkboxes.

Related Blogs

Continue reading practical guides on this topic.

LET'S GET STARTED

Need help with registration or compliance?

Talk to an experienced company secretary about your next step.