DPDPA Section 6 Decoded: What Makes Consent Valid in India?
Section 6 is the heart of the DPDPA. Every consent your business collects must meet its four-part test or it is legally worthless.

The Section Most Businesses Are Already Violating
Before we get into what Section 6 requires, it's worth pausing on something uncomfortable.
If your current consent mechanism is a checkbox at account registration that says "I agree to the terms and conditions and privacy policy" — you are almost certainly not compliant with Section 6. If your marketing opt-in is pre-ticked, or bundled into the service sign-up flow, or phrased as "by continuing, you consent to receive communications" — not compliant. If you collect data for one purpose and use it for three others under a single broad consent — not compliant.
This isn't a peripheral issue. Section 6 of the DPDPA 2023 defines what makes consent legally valid in India. Everything else in your compliance programme — your audit trails, your DSAR processes, your vendor contracts — depends on the consent you're collecting actually holding up. If it doesn't, you don't have a compliance programme. You have a liability dressed as one.

The Four-Part Test Every Consent Must Pass
Section 6 sets four conditions. A consent that fails any one of them is invalid. Not weakly compliant. Not a grey area. Invalid.
Free. Consent given under coercion, undue influence, or as a condition of accessing a service is not free. This has a specific practical implication: you cannot make a customer's access to your core product conditional on consenting to non-essential processing like marketing analytics, personalisation algorithms, or third-party data sharing. The service and the optional consent must be separable. Many organisations currently do exactly the opposite — the "accept all" button is on the path to checkout, and there is no meaningful way to say no without losing access to the service.
Specific. Consent must be obtained for a defined, particular purpose. "We may use your data to improve our services" fails this test. So does "marketing purposes." The purpose must be named clearly enough that a customer knows exactly what they're agreeing to. This requirement also means you need separate consent for each distinct purpose — you cannot bundle marketing emails, SMS campaigns, profiling for personalisation, and partner data sharing into a single consent item.
Informed. The Data Principal must have received and understood a Notice before giving consent. Not after. Not simultaneously buried in fine print. The Notice comes first, then the consent action follows. This matters operationally because it means the Notice version shown at the time of consent must be recorded — because if your Notice later changes, you'll need to know which customers consented under which version.
Unambiguous. Consent must be a clear affirmative action. A tap, a click, a signature, a spoken confirmation on a recorded call. Silence doesn't count. Continued use of a service doesn't count. A pre-ticked box that the customer failed to untick doesn't count. The customer must do something to indicate consent — and that something must be documented.
Section 5 and the Notice That Must Come First
Section 6 doesn't operate alone. It sits on top of Section 5, which governs the Notice that must precede any consent collection.
That Notice must contain five things: a description of the personal data being collected, the specific purpose of processing, how the Data Principal can withdraw consent, how they can file a complaint with the Data Protection Board, and the contact details of the Data Fiduciary.
Here's the part organisations often miss: the consent you collect is only as valid as the Notice that preceded it. A consent collected without a compliant Notice is itself invalid — even if the four Section 6 conditions were otherwise met. If your current Notice is a wall of legal boilerplate that doesn't clearly identify processing purposes, the consent collected under it is on shaky ground.
The DPDP Rules 2025 add another layer: the Notice must be available in the language the Data Principal understands. For national consumer brands reaching customers across India's linguistic regions, this means multilingual Notice delivery isn't a nice-to-have. It's part of what makes consent valid. If you haven't reviewed what the Rules require operationally, our breakdown of the 10 key obligations under the DPDP Rules 2025 is a useful starting point.

OneConsent Item Per Purpose — No Exceptions
The per-purpose requirement is where the operational complexity of Section 6 really lands.
Think through a typical D2C brand's data processing purposes: transactional communications (order confirmations, shipping updates), promotional email campaigns, SMS marketing, push notifications, behavioural analytics, personalised product recommendations, loyalty programme profiling, and data sharing with third-party advertising platforms. That's eight purposes. Each one needs its own consent item. Each one must be independently revokable. A customer should be able to receive transactional emails while opting out of every other purpose — and your systems must be able to enforce that combination in real time.
This is exactly why understanding the full consent lifecycle under DPDPA matters — grant is just one stage. Managing per-purpose status across millions of customers in real time is the infrastructure challenge most organisations haven't yet confronted.
Most consent UIs today present one or two broad categories. Rebuilding that architecture to support per-purpose granularity is real work, but it's not optional. The Board will not accept "we had a general marketing consent" as a defence when a customer complains they received communications they didn't specifically agree to.
What Section 6 Explicitly Prohibits
The Act doesn't just define what consent must be — it names practices that are prohibited.
Conditioning service access on consent for non-essential processing is prohibited.
Collecting consent through deceptive design patterns — dark patterns — is prohibited.
Bundling consent for unrelated purposes is prohibited.
Using pressure or manipulation to obtain consent is prohibited.
Dark patterns deserve specific attention because they're widespread. Making the "accept" button large, green, and prominent while the "decline" option is small, grey, and buried in a settings menu is a dark pattern. Framing consent refusal with alarming language about service degradation is a dark pattern. The Data Protection Board will scrutinise consent interface design — this is one of the most visually auditable parts of your compliance posture.
Section 7 Is Not a Workaround
Some legal teams, when faced with the work of rebuilding consent infrastructure, reach for Section 7 — the Act's "legitimate use" grounds that allow processing without consent for specific purposes like state functions, employment, medical emergencies, and certain public interest activities.
For commercial data processing by private businesses, Section 7 is not an escape route from Section 6. It is a narrow carve-out for genuinely non-commercial scenarios. Using it to justify marketing analytics, customer profiling, or third-party data sharing because building proper consent is inconvenient is legally incorrect and will not survive Board scrutiny.

The Legacy Data Problem Nobody Wants to Think About
Here's a difficult reality for any organisation that has been collecting customer data for more than a few years: that historical data was almost certainly collected under consent mechanisms that don't meet Section 6's standard.
The DPDPA provides a path forward through a one-time Notice to existing customers — informing them of the data held, the purposes it's used for, and their rights under the Act. But continued processing of legacy data for new purposes, without fresh Section 6-compliant consent, is not permitted. If your next marketing campaign is targeting customers whose data was collected before DPDPA and who haven't been given this Notice, you're operating on non-compliant ground.
The one-time Notice programme is urgent work — and we cover exactly how to structure and execute it in the next post on handling past consents before DPDPA enforcement begins.
Section 6 sets a high bar. But it's a bar that can be cleared with the right architecture — per-purpose consent design, compliant Notice delivery, affirmative grant mechanisms, and the infrastructure to manage and enforce it all at scale.
OneConsent by Easyrewardz builds consent-first customer data collection into every brand touchpoint — from loyalty enrolment to digital engagement — so the consent your organisation collects is valid from the moment it's granted.