Implementation

    Do we need to maintain records of user consent, and how detailed should these records be?

    Short Answer

    Yes, you must maintain detailed records showing when consent was taken, for what purpose, and how it can be withdrawn.

    Answer

    Yes, maintaining consent records is essential. You should be able to demonstrate when consent was taken, for what purpose, and how it can be withdrawn.

    These records act as proof during audits or disputes, making them a critical part of your compliance framework.

    Law Reference

    Section 8 – Accountability of Data Fiduciary

    Business Impact

    Consent records serve as proof during audits and disputes. Without them, businesses cannot demonstrate compliance and face higher penalty risk.

    Real-World Example

    During an audit, a telecom company must show timestamped records proving that each customer consented to marketing communications before being added to campaign lists.

    Was this answer helpful?

    Still have questions?

    Our team is here to help you with any questions about DPDP compliance.