Start with the activity
DPDP distinguishes consent from certain legitimate uses. Identify the relevant ground activity by activity; do not make every business process depend on a generic consent form.
Review the complete choice
Where consent is relied upon, look at the explanation, the choices offered, the record and how a changed choice reaches every relevant team. A saved form alone does not show downstream action.
Decide whether a Consent Manager is relevant
Review whether your organisation plans to use a registered Consent Manager or to seek registration itself. These are different decisions; neither follows simply from handling customer or employee information. Our readiness work records the relevant activities, existing arrangements and questions for advice. The registration provisions have a separate commencement phase.
MeitY: Digital Personal Data Protection Act, 2023 · MeitY: Digital Personal Data Protection Rules, 2025 · Gazette: DPDP Act commencement notification, 13 November 2025
Try a small practical review
Choose one activity, such as optional product updates. Trace a refusal and a later withdrawal using fictional test data; list every manual and system handover that needs an owner.
Common questions
Do we need to buy something first?
First establish the process, responsibilities and evidence. That makes any later technical decision clearer.
Should consent for service contact also permit marketing?
Treat the purposes separately. Explain the requested service contact clearly and provide a distinct optional choice for unrelated marketing.
Discuss the work you need
Agree the service, deliverables, responsibilities and fees before committing to an engagement.
Related reading
References
- MeitY: Digital Personal Data Protection Act, 2023
- MeitY: Digital Personal Data Protection Rules, 2025
- Gazette: DPDP Act commencement notification, 13 November 2025
This page explains topics to scope and discuss. It does not establish applicability, certify compliance or confirm a paid engagement.
← Decision guides