Walk into any mid-size Indian enterprise today and ask about consent compliance. Most will show you a consent banner. Some will show you a cookie pop-up. Very few will show you what happens six months after a Data Principal clicks "I agree."
That gap — between consent collected and consent managed — is where most DPDPA compliance programmes quietly fall apart.
What Consent Collection Looks Like
Consent collection is the front-door activity: presenting a notice, recording a tick, generating a timestamp. It is necessary. It is not sufficient.
Most CMP implementations stop here. They can tell you that consent was captured at 14:32 on a given date. They cannot tell you whether that consent is still valid, whether processing has stopped after it was withdrawn, or whether the Data Principal's data was deleted after the consent expired.
The DPDPA does not stop at collection either.
What the DPDPA Actually Requires
Section 6(1): Consent must be free, specific, informed, unconditional, and unambiguous — with a separate, clear option to refuse.
Section 6(4): A Data Principal may withdraw consent at any time. Withdrawal must be as easy as giving consent was. And withdrawal must actually stop processing — not just log the request.
Section 8(7): Data Fiduciaries must erase personal data once the purpose for which consent was given has been fulfilled, or once consent is withdrawn — whichever comes first.
Section 7: Even where Legitimate Interest applies, the Data Principal must be able to opt out. That opt-out must propagate downstream.
These are lifecycle obligations, not collection obligations. They require ongoing system behaviour, not a one-time database write.
The Consent Lifecycle: What It Actually Covers
A complete consent management programme has five phases, not one:
1. Collection Notice + affirmative action. Purpose-specific, per-recipient, with separate opt-in for each processing activity. This is where most organisations currently operate.
2. Validation and versioning Tracking which version of a notice was shown when consent was given. If your notice changes — a new purpose added, a description revised — existing consent may need to be refreshed. The platform must detect this and trigger re-consent campaigns automatically.
3. Expiry management Consent periods have configurable duration. When consent expires, data processing for that purpose must stop. This requires proactive notification to the Data Principal before expiry and automated workflows for data deletion or archiving.
4. Withdrawal enforcement This is the hardest phase to implement correctly. Withdrawal is not a log entry — it is a system control. When a Data Principal withdraws, the signal must propagate downstream: to connected systems, to third-party processors, to marketing platforms, to analytics tools. Every system that was processing data under that consent must stop. The platform must be able to prove this happened.
5. Deletion validation Section 8(7) requires erasure once the purpose is fulfilled or consent is withdrawn. Deletion validation workflows ensure this is tracked and auditable across all systems — not just the primary database.
One-Time vs. Recurring Consent
Not all consent is the same. A consent for a single transaction has a natural end point. A consent for ongoing marketing or personalisation is recurring and requires active management.
| Consent Type | Example | Lifecycle Requirement |
|---|---|---|
| One-time / transactional | Order fulfilment, identity verification | Expires when purpose is fulfilled; deletion validation required |
| Recurring | Marketing, personalisation, loyalty analytics | Active refresh management; withdrawal must stop all downstream processing |
| Legitimate Interest | Fraud detection, statutory obligations | Data Principal must be able to opt out; opt-out must propagate |
The Question to Ask Your Current CMP Vendor
"If a Data Principal withdraws consent for marketing communications today, can you show me — six months from now — that processing stopped across every connected system and vendor, and that their data was deleted when required? And can you produce that evidence in a format the Data Protection Board of India can review?"
If the answer is hesitant, you have a collection tool, not a management platform.
See the full consent lifecycle in action — book a truConsent walkthrough