Short Answer
Yes, you must maintain detailed records showing when consent was taken, for what purpose, and how it can be withdrawn.
Yes, maintaining consent records is essential. You should be able to demonstrate when consent was taken, for what purpose, and how it can be withdrawn.
These records act as proof during audits or disputes, making them a critical part of your compliance framework.
Law Reference
Section 8 – Accountability of Data Fiduciary
Consent records serve as proof during audits and disputes. Without them, businesses cannot demonstrate compliance and face higher penalty risk.
During an audit, a telecom company must show timestamped records proving that each customer consented to marketing communications before being added to campaign lists.
Was this answer helpful?
Our team is here to help you with any questions about DPDP compliance.