Next due
11 OCTGSTR-1 · Outward supplies · Sep 2026tomorrow 15 OCTPF & ESI · Contributions · Sep 2026in 5 days 20 OCTGSTR-3B · Summary return · Sep 2026in 10 days 21 OCTTax Audit Report · Form 3CA/3CB · AY 2026-27 · extended from 30 Sepin 11 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 20 days 7 NOVTDS / TCS deposit · Deducted in Oct 2026in 28 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 42 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 50 days
All due dates

Section 6(10) of the Digital Personal Data Protection Act, 2023: The burden of proving notice and consent

Where consent is the basis of processing and a question arises in a proceeding, the Data Fiduciary is obliged to prove that a notice was given to the Data Principal and that...

Published
Updated
Reading time
7 min
Views
8
Questions
6 answered
  • Expert Reviewed
  • Medium Complexity
Topic
Data Protection
Published
September 30, 2026
Last updated
Oct 9, 2026
Reading time
7 min
0:00
Last updated: October 2026Verified against: Government sources

Section 6(10) is a short sub-section with large practical weight. When consent is the basis of processing and a question about it arises in a proceeding, the Data Fiduciary must prove that notice was given and that consent was given in accordance with the Act and the rules. The safest assumption is that a consent you cannot evidence is a consent you cannot rely on. Our legal dispute resolution team can help you test whether your records would hold up before a complaint arrives.

Section 6(10) at a glance

ElementWhat the text says
When it appliesWhere consent is the basis of processing and a question arises in this regard in a proceeding
Who bears the burdenThe Data Fiduciary
What must be proved(1) a notice was given to the Data Principal; (2) consent was given by the Data Principal to the Data Fiduciary
Standard"In accordance with the provisions of this Act and the rules made thereunder"
ForumA "proceeding", which is any action taken by the Board (section 2(w))

What is being proved

There are two separate facts, and each must meet the statutory standard.

  1. Notice was given. Under section 5(1), the notice must accompany or precede the request for consent, cover the data and purpose, explain the routes to exercise rights under section 6(4) and section 13 and to complain to the Board, and be available in English or an Eighth Schedule language (section 5(3)). The form and manner are prescribed. For legacy consent, the section 5(2) notice is the relevant one.
  2. Consent was given in accordance with the Act and the rules. That means it was given without pressure, was specific, informed, unconditional and unambiguous, came through a clear affirmative action, and was limited to data necessary for the specified purpose (section 6(1)); it was presented in plain language with a contact person (section 6(3)); and, if a Consent Manager was used, the Consent Manager's role fits section 6(7) to (9).

The Act says the Data Fiduciary must prove "that a notice was given by her to the Data Principal". Read in context, "her" refers to the Data Fiduciary, since the Act uses "she" for any individual or person under section 2(y).

Why it matters: the burden sits with the fiduciary

In a typical dispute, the Data Principal says she never agreed. Section 6(10) means the Data Fiduciary cannot answer by saying "prove that you did not". It must produce evidence of the notice and of the consent. If it cannot, the Board may find that the processing lacked a valid ground under section 4(1)(a). Where the breach is significant, section 33 allows a monetary penalty, and entry 7 of the Schedule sets up to fifty crore rupees for a breach of a provision with no specific entry, which is a ceiling and not a fixed amount.

The Act does not say what kind of record is enough. It does not name a form or a technical standard. The safe approach is to keep records from which each element of the sub-section can be shown.

What records to keep

The Act does not list records, so this is a practical guide rather than a statutory checklist. A Data Fiduciary that relies on consent should be able to show, for each consent:

RecordWhy
The version of the notice shown, with dateProves notice content and that it accompanied or preceded the request
The language option offered and selectedShows section 5(3) and 6(3) compliance
The exact consent text and the purpose(s)Shows the specified purpose and that consent was specific
The affirmative action taken, with timestamp and a way to link it to the individualShows a clear affirmative action and who gave it
Withdrawal requests and what was doneShows compliance with section 6(4) to (6)
Processor instructions to stopShows the duty in section 6(6) to cause processors to cease

Records should be retained only as long as needed and be protected, because they contain personal data themselves and fall under section 8(5) and section 8(7). Do not keep the records of a consent beyond what the Act permits without a ground.

Where the burden arises

The trigger is a question "in a proceeding", and a proceeding is an action taken by the Board. So the burden arises in matters such as an inquiry on a complaint under section 27(1)(b) or on an intimation of personal data breach under section 27(1)(a). In the course of an inquiry under section 28, the Board may inspect data, books and documents under section 28(7)(c), so the records should be retrievable. Civil courts are barred from entertaining matters the Board is empowered to deal with under section 39, so the Board is the practical forum.

What section 6(10) does not say

  • It does not apply to processing under section 7 (certain legitimate uses). It is about processing where consent is the basis.
  • It does not prescribe any particular technology or format for records.
  • It does not say how long records must be kept. The Rules may address that; check the DPDP Rules, 2025 (notified November 2025), because different provisions commence on different dates.

Practical examples

Example 1: missing notice version. A fintech app collected consent through a screen that has been redesigned three times. A user complains. The company cannot show which notice the user saw. It fails the first limb of section 6(10).

Example 2: clean record. An insurer stores the notice version, language, consent text, tick action, timestamp and user ID for each policy. On a complaint, it produces the record and shows the processing was on a valid consent.

Example 3: paper form. A clinic takes signed consent forms for digital records. It keeps the form version and the signed copy. The form is evidence of notice and consent for the digitised processing.

Common mistakes

  • Relying on a generic "terms accepted" log with no link to notice or purpose.
  • Overwriting old notice texts, so the version shown cannot be proved.
  • Keeping no record of withdrawals.
  • Keeping consent records in a system that is itself poorly protected.

Need help with consent records and dispute readiness?

If you rely on consent, it is worth testing whether your records would stand up in a Board inquiry. Our legal dispute resolution team can help you review the evidence trail and prepare for a complaint or inquiry.

Key takeaways

  • The Data Fiduciary must prove that notice was given and consent was given in accordance with the Act and the rules.
  • The burden arises in a proceeding, meaning any action taken by the Board.
  • Keep dated records of notice version, language, purpose, action and withdrawal.
  • The burden applies where consent is the basis, not to section 7 uses.
  • Records themselves are personal data and need safeguards.

Read next

Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.

Quick recapKey facts & short answers

Key Facts About Section 6

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

Who has to prove consent?

Under section 6(10), the Data Fiduciary.

What must be proved?

That a notice was given to the Data Principal and that consent was given in accordance with the Act and the rules.

Consent is meaningful only if the person understood what they were agreeing to.

— TaxClue Data Protection Desk

Section 6: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

Under section 6(10), the Data Fiduciary.

That a notice was given to the Data Principal and that consent was given in accordance with the Act and the rules.

Where consent is the basis of processing and a question arises in a proceeding, which under section 2(w) means any action taken by the Board.

No. It does not list records or formats. Keep records that can show each element of notice and consent.

Section 6(10) is framed for processing where consent is the basis, so it does not by its terms apply to section 7 uses.

The processing may be found to lack a valid ground under section 4(1)(a), and a significant breach can attract a monetary penalty under section 33 and the Schedule.