Short Answer
Consent under DPDP must be free, specific, informed, unambiguous, and withdrawable. A consent management platform captures, stores, enforces, and audits consent across every customer touchpoint.
Section 6 of the DPDP Act sets a high bar for consent. It must be: freely given (no coercion or pre-checked boxes), specific (one purpose at a time), informed (plain-language notice attached), unambiguous (a clear affirmative action), and as easy to withdraw as it was to give.
Operationally, this means every consent event must be (a) captured with timestamp, purpose, channel, and language; (b) stored in a tamper-evident log; (c) enforced in real time across downstream systems (CRM, marketing, analytics, vendors); and (d) revocable through a self-serve preference centre.
A Consent Management Platform (CMP) like OneConsent unifies these four functions into one system of record, eliminating the spreadsheets and fragmented consents that lead to violations.
Law Reference
Section 6 – Consent
Section 7 – Legitimate Uses
Without a CMP, consent fragments across forms, vendors, and channels, making withdrawal enforcement and audit response practically impossible at scale.
A telecom enrolling 10,000 users daily uses OneConsent to log each opt-in with purpose and channel, then propagates withdrawals to 30+ downstream systems within seconds.
Was this answer helpful?
Our team is here to help you with any questions about DPDP compliance.