Section 6 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Section 6(10) is a short sub-section with large practical weight. When consent is the basis of processing and a question about it arises in a proceeding, the Data Fiduciary must prove that notice was given and that consent was given in accordance with the Act and the rules. The safest assumption is that a consent you cannot evidence is a consent you cannot rely on. Our legal dispute resolution team can help you test whether your records would hold up before a complaint arrives.
Where consent is the basis of processing and a question arises in a proceeding, the Data Fiduciary is obliged to prove that a notice was given to the Data Principal and that consent was given in accordance with the Act and the rules. The burden does not fall on the Data Principal. A "proceeding" means any action taken by the Board (section 2(w)). A gap in evidence can leave the processing without a valid ground under section 4.
Section 6(10) at a glance
| Element | What the text says |
|---|---|
| When it applies | Where consent is the basis of processing and a question arises in this regard in a proceeding |
| Who bears the burden | The Data Fiduciary |
| What must be proved | (1) a notice was given to the Data Principal; (2) consent was given by the Data Principal to the Data Fiduciary |
| Standard | "In accordance with the provisions of this Act and the rules made thereunder" |
| Forum | A "proceeding", which is any action taken by the Board (section 2(w)) |
What is being proved
There are two separate facts, and each must meet the statutory standard.
- Notice was given. Under section 5(1), the notice must accompany or precede the request for consent, cover the data and purpose, explain the routes to exercise rights under section 6(4) and section 13 and to complain to the Board, and be available in English or an Eighth Schedule language (section 5(3)). The form and manner are prescribed. For legacy consent, the section 5(2) notice is the relevant one.
- Consent was given in accordance with the Act and the rules. That means it was given without pressure, was specific, informed, unconditional and unambiguous, came through a clear affirmative action, and was limited to data necessary for the specified purpose (section 6(1)); it was presented in plain language with a contact person (section 6(3)); and, if a Consent Manager was used, the Consent Manager's role fits section 6(7) to (9).
The Act says the Data Fiduciary must prove "that a notice was given by her to the Data Principal". Read in context, "her" refers to the Data Fiduciary, since the Act uses "she" for any individual or person under section 2(y).
Why it matters: the burden sits with the fiduciary
In a typical dispute, the Data Principal says she never agreed. Section 6(10) means the Data Fiduciary cannot answer by saying "prove that you did not". It must produce evidence of the notice and of the consent. If it cannot, the Board may find that the processing lacked a valid ground under section 4(1)(a). Where the breach is significant, section 33 allows a monetary penalty, and entry 7 of the Schedule sets up to fifty crore rupees for a breach of a provision with no specific entry, which is a ceiling and not a fixed amount.
The Act does not say what kind of record is enough. It does not name a form or a technical standard. The safe approach is to keep records from which each element of the sub-section can be shown.
What records to keep
The Act does not list records, so this is a practical guide rather than a statutory checklist. A Data Fiduciary that relies on consent should be able to show, for each consent:
| Record | Why |
|---|---|
| The version of the notice shown, with date | Proves notice content and that it accompanied or preceded the request |
| The language option offered and selected | Shows section 5(3) and 6(3) compliance |
| The exact consent text and the purpose(s) | Shows the specified purpose and that consent was specific |
| The affirmative action taken, with timestamp and a way to link it to the individual | Shows a clear affirmative action and who gave it |
| Withdrawal requests and what was done | Shows compliance with section 6(4) to (6) |
| Processor instructions to stop | Shows the duty in section 6(6) to cause processors to cease |
Records should be retained only as long as needed and be protected, because they contain personal data themselves and fall under section 8(5) and section 8(7). Do not keep the records of a consent beyond what the Act permits without a ground.
Where the burden arises
The trigger is a question "in a proceeding", and a proceeding is an action taken by the Board. So the burden arises in matters such as an inquiry on a complaint under section 27(1)(b) or on an intimation of personal data breach under section 27(1)(a). In the course of an inquiry under section 28, the Board may inspect data, books and documents under section 28(7)(c), so the records should be retrievable. Civil courts are barred from entertaining matters the Board is empowered to deal with under section 39, so the Board is the practical forum.
What section 6(10) does not say
- It does not apply to processing under section 7 (certain legitimate uses). It is about processing where consent is the basis.
- It does not prescribe any particular technology or format for records.
- It does not say how long records must be kept. The Rules may address that; check the DPDP Rules, 2025 (notified November 2025), because different provisions commence on different dates.
Practical examples
Example 1: missing notice version. A fintech app collected consent through a screen that has been redesigned three times. A user complains. The company cannot show which notice the user saw. It fails the first limb of section 6(10).
Example 2: clean record. An insurer stores the notice version, language, consent text, tick action, timestamp and user ID for each policy. On a complaint, it produces the record and shows the processing was on a valid consent.
Example 3: paper form. A clinic takes signed consent forms for digital records. It keeps the form version and the signed copy. The form is evidence of notice and consent for the digitised processing.
Common mistakes
- Relying on a generic "terms accepted" log with no link to notice or purpose.
- Overwriting old notice texts, so the version shown cannot be proved.
- Keeping no record of withdrawals.
- Keeping consent records in a system that is itself poorly protected.
Need help with consent records and dispute readiness?
If you rely on consent, it is worth testing whether your records would stand up in a Board inquiry. Our legal dispute resolution team can help you review the evidence trail and prepare for a complaint or inquiry.
Key takeaways
- The Data Fiduciary must prove that notice was given and consent was given in accordance with the Act and the rules.
- The burden arises in a proceeding, meaning any action taken by the Board.
- Keep dated records of notice version, language, purpose, action and withdrawal.
- The burden applies where consent is the basis, not to section 7 uses.
- Records themselves are personal data and need safeguards.
Read next
- Section 6 of the DPDP Act, 2023: what valid consent requires
- Section 5 of the DPDP Act, 2023: notice to Data Principal
- Section 28 of the DPDP Act, 2023: inquiry procedure of the Board
- DPDP compliance checklist for businesses
Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.
