Next due
11 OCTGSTR-1 · Outward supplies · Sep 2026tomorrow 15 OCTPF & ESI · Contributions · Sep 2026in 5 days 20 OCTGSTR-3B · Summary return · Sep 2026in 10 days 21 OCTTax Audit Report · Form 3CA/3CB · AY 2026-27 · extended from 30 Sepin 11 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 20 days 7 NOVTDS / TCS deposit · Deducted in Oct 2026in 28 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 42 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 50 days
All due dates

Section 6 of the Digital Personal Data Protection Act, 2023: What valid consent requires

Consent under section 6(1) must be given without pressure, specific, informed, unconditional and unambiguous, with a clear affirmative action, for the specified purpose, and...

Published
Updated
Reading time
7 min
Views
11
Questions
6 answered
  • Expert Reviewed
  • Medium Complexity
Topic
Data Protection
Published
September 30, 2026
Last updated
Oct 9, 2026
Reading time
7 min
0:00
Last updated: October 2026Verified against: Government sources

Section 6(1) to (3) set the standard for consent. It must be given without pressure, specific, informed, unconditional and unambiguous, expressed by a clear affirmative action, tied to a specified purpose and limited to the personal data necessary for it. Section 6(2) strikes down any part of a consent that breaches the law, and section 6(3) deals with how the request is presented. If your forms need a check against this standard, a legal consultation can cover it.

Sub-sections (1) to (3) at a glance

Sub-sectionRule
6(1)Consent must be given without pressure (the first limb of the wording), specific, informed, unconditional and unambiguous with a clear affirmative action; signifies agreement to processing for the specified purpose; limited to personal data necessary for that purpose
6(2)Any part of consent that infringes the Act, the rules or any other law in force is invalid to the extent of the infringement
6(3)Every consent request in clear and plain language; option to access in English or an Eighth Schedule language; contact details of a Data Protection Officer, where applicable, or of another person authorised to respond

The elements of section 6(1)

The first limb of the statutory wording is that consent must be given without pressure. The Act does not define this limb further, so the ordinary sense applies: a Data Principal should not be forced, misled or pressed into agreeing. The other limbs are:

ElementPractical reading
SpecificTied to the specified purpose in the notice, not a blanket "for all purposes"
InformedGiven after a notice under section 5 has told her the data and purpose
UnconditionalNot made a condition of something unrelated. The Illustration shows this: the telemedicine app cannot bundle contact-list access with the health service
UnambiguousNo doubt about what she agreed to
Clear affirmative actionShe must do something positive, such as tick a box or tap a button. Silence, pre-ticked boxes and inactivity are not affirmative action on the ordinary meaning of the words

The Act does not spell out that pre-ticked boxes are invalid, and this article does not claim that it does. The requirement of a "clear affirmative action" points that way, and the conservative course is to avoid them.

Limited to what is necessary

Consent must be "limited to such personal data as is necessary for such specified purpose". The Illustration makes this concrete: X downloads a telemedicine app, and Y asks for consent to process personal data for telemedicine services and also for access to the phone contact list. X agrees to both. Because the contact list is not necessary for telemedicine services, her consent is limited to processing for the telemedicine services.

So a Data Fiduciary cannot obtain wide consent and rely on it. Even if the Data Principal ticks everything, the consent extends only to what is necessary for the purpose. Collecting beyond that is processing without a ground under section 4.

Invalid parts of consent: section 6(2)

Section 6(2) works part by part. The consent is not wholly void because one part is bad; the offending part is invalid "to the extent of such infringement". The Illustration involves X buying an insurance policy on Y's app. She consents to (i) processing for issuing the policy and (ii) waiving her right to file a complaint to the Data Protection Board. Part (ii) is invalid.

The same logic covers consent terms that conflict with any other law in force. Drafters should therefore avoid waivers of rights under the Act inside consent screens, since they will not survive and may show a pattern of breach.

Presentation of the request: section 6(3)

Every request for consent under the Act or rules must be presented:

  • in clear and plain language;
  • with the option to access it in English or any Eighth Schedule language; and
  • with contact details of a Data Protection Officer, where applicable, or of any other person authorised by the Data Fiduciary to respond to communications from the Data Principal about her rights.

A Data Protection Officer exists only for a Significant Data Fiduciary (section 10(2)(a)). Other Data Fiduciaries must name another authorised person, and section 8(9) also requires publication of business contact information. The form of the consent request is also affected by the rules, which are not dealt with in this article. The DPDP Rules, 2025 (notified November 2025) prescribe the detail, and different provisions commence on different dates; check the Rules.

How it fits with the rest of section 6

Sections 6(4) to (6) give the right to withdraw and set the consequences, and these are in the article on withdrawal of consent. Section 6(7) to (9) allow consent to be given through a Consent Manager, covered in the Consent Manager article. Section 6(10) puts the burden of proof on the Data Fiduciary, in the article on burden of proving notice and consent. For the consequences of breach, see section 33 and the Schedule.

Practical examples

Example 1: bundled sign-up. A shopping app asks a user to consent to order processing, marketing and sharing with partners in a single tick. The consent for marketing and sharing is not specific to the purpose of fulfilling the order. Separate requests with separate actions are safer.

Example 2: waiver clause. A loan app's consent form includes "I waive any right to approach the Board". Under section 6(2), that part is invalid to the extent of the infringement.

Example 3: contact-list access. A ride-booking app asks for access to the user's contacts although its purpose needs only her location. Consent for contacts would not be limited to what is necessary for the specified purpose.

Common mistakes

  • One tick for many purposes.
  • Making consent for marketing a condition of a service.
  • Pre-ticked boxes, or treating inaction as consent.
  • Omitting a contact person in the consent request.

Need help with consent screens and forms?

If your sign-up flows, forms or apps bundle several purposes in one consent, it is worth fixing them before a complaint arrives. Our legal consultation service can review your screens against section 6(1) to (3) and suggest wording changes.

Key takeaways

  • Consent must be given without pressure, specific, informed, unconditional, unambiguous and expressed by a clear affirmative action.
  • It is limited to personal data necessary for the specified purpose.
  • Parts of consent that infringe the Act, the rules or any other law are invalid to that extent.
  • The request must be in plain language, with an English or Eighth Schedule language option and a contact person.
  • Waivers of the right to complain to the Board are invalid.

Read next

Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.

Quick recapKey facts & short answers

Key Facts About Section 6

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

What must consent be under the Act?

Section 6(1) says it must be given without pressure, specific, informed, unconditional and unambiguous with a clear affirmative action.

Can a company take consent for data it does not need?

The consent is limited to personal data necessary for the specified purpose. The Illustration on the telemedicine app shows an unnecessary contact-list request falling outside it.

What is not written down will be remembered differently by everyone involved.

— TaxClue Compliance Desk

Section 6: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

Section 6(1) says it must be given without pressure, specific, informed, unconditional and unambiguous with a clear affirmative action.

The consent is limited to personal data necessary for the specified purpose. The Illustration on the telemedicine app shows an unnecessary contact-list request falling outside it.

No. Section 6(2) makes it invalid to the extent of the infringement, as the insurance Illustration shows.

Section 6(3) requires the option to access it in English or any language in the Eighth Schedule to the Constitution.

A Data Protection Officer, where applicable, or another person authorised by the Data Fiduciary to respond to communications about the exercise of rights.

The Act does not address them by name. It requires a clear affirmative action, so pre-ticked boxes are a risk.