One-Time Notice for Past Consents Under DPDPA: What You Must Do Before Enforcement
You have years of customer data collected before the DPDPA existed. The Act has a specific provision for exactly this situation — and it requires immediate action.

Think about what's sitting in your CRM right now. Email addresses collected at checkout five years ago. Mobile numbers gathered through a loyalty form in 2019. Purchase histories built through a decade of transactions. Every one of those records was collected under some version of terms and conditions that looked nothing like DPDPA compliance.
Most businesses in India are in exactly this position, and many assume the DPDPA only governs data collected after the Act came into force. That assumption is wrong. The Act specifically addresses legacy data and what it requires isn't optional.
What the DPDPA Actually Says About Past Data
The Act provides that Data Fiduciaries who have already collected personal data and are currently processing it based on consent given before the Act's commencement must issue a one-time Notice to those Data Principals. This notice must describe what data is held, the purpose for which it was originally collected, and most importantly, the Data Principal's rights under the new law, including the right to withdraw consent.
Processing can continue after the notice. But only if the Data Principal does not exercise their right to opt out.
This is a crucial distinction. The Act isn't saying your old data is automatically invalid. It's saying your customers now have rights over that data that they didn't have before and they need to know it.

Why the Window Is Closing Faster Than You Think
The Data Protection Board of India is operational. DPDP Rules 2025 have been finalised. The gap between commencement and active enforcement is not infinite, and organisations that haven't issued this one-time notice are already in a technical compliance gap, whether or not any investigation has been filed against them yet.
The logic is straightforward: once enforcement begins, continued processing of legacy data without a compliant notice is a violation. Not a future risk. A current one.
There's also a secondary concern that doesn't get enough attention. Competitors who act now will be able to document clean consent posture. Businesses that wait will face the dual pressure of issuing notices under a compliance deadline while also managing withdrawal volumes they haven't planned for.
What the One-Time Notice Must Actually Contain
This is where a lot of organisations go wrong. The instinct is to delegate this to legal, get a boilerplate drafted, and push it out through a bulk email tool. That's not going to work.
The notice must clearly identify:
Who is sending it- The Data Fiduciary's full name and contact details, not just a sender email address.
What data is held and for what purpose- Specific enough that the customer understands what they're being asked about. "We hold your name, mobile number, and purchase history for marketing and service delivery purposes" is more compliant than "your personal data may be used for various purposes."
How to withdraw consent- This mechanism needs to be genuinely accessible. A link that leads to a buried settings page is going to be scrutinised by the Data Protection Board. The withdrawal path must be clear, functional, and require no more steps than the original consent did.
How to request correction or erasure- The right to erasure under DPDPA extends to legacy data too. If a customer wants their historical data deleted, the mechanism to request that must be communicated.
Contact details of the Grievance Officer- A named individual, not a generic inbox.
The entire notice must be in plain language. This is explicitly required by the Act. Dense legal phrasing that most customers won't read doesn't satisfy the spirit or the letter of the requirement.
The Operational Challenge Nobody Is Talking About
Sending a legally compliant one-time notice to ten million customers is not a task for your legal team alone. It requires coordinated technical infrastructure.
First, your database of existing customers needs to be clean and current. Contact information that was accurate three years ago may not be deliverable today. A notice that bounces or goes to a defunct number doesn't count.
Second, you need a consent management system capable of recording responses. Silence is one state where the customer received the notice and didn't opt out, so processing can continue. Active withdrawal is another where the processing must stop immediately. Re-grant is a third where a customer who initially withdrew later decides to opt back in. Your systems need to handle all three and timestamp each event.
Third, every customer response must trigger a real-time enforcement update. If a customer withdraws consent at 2pm on a Tuesday, a marketing campaign that fires at 2:01 pm to that customer is a violation. This isn't hypothetical. At scale, the probability of this happening without real-time enforcement is close to certainty.
Finally, you need an audit trail that proves every customer was notified. Not just that the notice was sent. That it was sent to this specific customer, at this time, through this channel, with this notice version. The Data Protection Board may ask for this.

The Dark Pattern Trap
Some organisations will be tempted to optimise the notice for minimal withdrawals rather than genuine compliance. Burying the opt-out using language that makes withdrawal sound consequential in ways that aren't accurate or sending it through a channel like an old email address where delivery is unlikely.
This approach doesn't just create ethical problems. Under the DPDP Rules, dark patterns in consent interfaces are explicitly prohibited. The Board will look at the design of the notice, not just whether it was sent. A notice engineered to be ignored is not a compliant notice.
There's also a strategic argument against this approach. Customers who withdraw consent for purposes they don't value aren't your best customers anyway. A clean consent refresh that produces a smaller but genuinely opted-in database is worth more commercially and legally than a bloated list that includes millions of customers who were never meaningfully engaged.
When Consent Is Withdrawn- What Happens Next
If a Data Principal withdraws consent for processing their historical data, the obligation is clear: cease that processing immediately. Not at the next campaign cycle. Not when the batch job runs overnight. Immediately.
If there's no other legal basis for retaining that data then it becomes a regulatory requirement, a contractual obligation, a legitimate use ground under DPDPA section 7 deletion is required. Your systems need to be technically capable of executing this across every database, data warehouse, marketing platform, and third-party processor where that customer's data lives.
This is genuinely hard. Most organisations have data scattered across systems that weren't built to talk to each other. But it's the legal requirement.
Connecting This to Your Broader DPDPA Compliance Programme
The one-time notice for legacy data isn't a standalone task, it feeds directly into your ongoing consent management infrastructure. The same system that records withdrawal responses to your legacy notice will need to handle new consent events, withdrawal requests, and DSAR Responses going forward.
If your BFSI organisation is managing legacy KYC and banking customer data from years of account openings, the specific regulatory intersections are more complex. DPDPA compliance for banks and NBFCs adds layers around what can be retained under RBI obligations versus what requires fresh consent.
And if you haven't yet read what makes consent valid under DPDPA Section 6, that foundational context matters for how you structure the notice itself. The four conditions of valid consent (free, specific, informed, unambiguous) apply to the notice design.
This Is Not a Box to Tick
The one-time notice requirement is easy to frame as bureaucratic housekeeping. Issue a notice, record responses, move on. But that framing misses what's actually happening here.
This is the moment when you formally acknowledge your customers rights over data they may have never known you held. Done well, it's a trust-building exercise. Done poorly or not at all. It's your first compliance violation.
The organisations that execute this thoughtfully, with proper infrastructure, genuine plain-language notices, and real-time enforcement of withdrawals, will emerge from it with a cleaner, more engaged, more legally defensible customer database.
The organisations that send a vague bulk email and hope for the best will be fielding Data Protection Board inquiries before the year is out.
OneConsent handles mass consent notice delivery, tracks individual responses in real time, and maintains the complete audit trail your legal team needs for legacy data compliance before enforcement begins.
Frequently Asked Questions
Have more questions?
Search our full DPDP knowledge base for more answers.