Section 6 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Section 6(1) to (3) set the standard for consent. It must be given without pressure, specific, informed, unconditional and unambiguous, expressed by a clear affirmative action, tied to a specified purpose and limited to the personal data necessary for it. Section 6(2) strikes down any part of a consent that breaches the law, and section 6(3) deals with how the request is presented. If your forms need a check against this standard, a legal consultation can cover it.
Consent under section 6(1) must be given without pressure, specific, informed, unconditional and unambiguous, with a clear affirmative action, for the specified purpose, and limited to the personal data necessary for it. Any part of consent that infringes the Act, the rules or any other law is invalid to that extent (section 6(2)). The request must be in clear and plain language, available in English or an Eighth Schedule language, with contact details of a Data Protection Officer or another authorised person (section 6(3)).
Sub-sections (1) to (3) at a glance
| Sub-section | Rule |
|---|---|
| 6(1) | Consent must be given without pressure (the first limb of the wording), specific, informed, unconditional and unambiguous with a clear affirmative action; signifies agreement to processing for the specified purpose; limited to personal data necessary for that purpose |
| 6(2) | Any part of consent that infringes the Act, the rules or any other law in force is invalid to the extent of the infringement |
| 6(3) | Every consent request in clear and plain language; option to access in English or an Eighth Schedule language; contact details of a Data Protection Officer, where applicable, or of another person authorised to respond |
The elements of section 6(1)
The first limb of the statutory wording is that consent must be given without pressure. The Act does not define this limb further, so the ordinary sense applies: a Data Principal should not be forced, misled or pressed into agreeing. The other limbs are:
| Element | Practical reading |
|---|---|
| Specific | Tied to the specified purpose in the notice, not a blanket "for all purposes" |
| Informed | Given after a notice under section 5 has told her the data and purpose |
| Unconditional | Not made a condition of something unrelated. The Illustration shows this: the telemedicine app cannot bundle contact-list access with the health service |
| Unambiguous | No doubt about what she agreed to |
| Clear affirmative action | She must do something positive, such as tick a box or tap a button. Silence, pre-ticked boxes and inactivity are not affirmative action on the ordinary meaning of the words |
The Act does not spell out that pre-ticked boxes are invalid, and this article does not claim that it does. The requirement of a "clear affirmative action" points that way, and the conservative course is to avoid them.
Limited to what is necessary
Consent must be "limited to such personal data as is necessary for such specified purpose". The Illustration makes this concrete: X downloads a telemedicine app, and Y asks for consent to process personal data for telemedicine services and also for access to the phone contact list. X agrees to both. Because the contact list is not necessary for telemedicine services, her consent is limited to processing for the telemedicine services.
So a Data Fiduciary cannot obtain wide consent and rely on it. Even if the Data Principal ticks everything, the consent extends only to what is necessary for the purpose. Collecting beyond that is processing without a ground under section 4.
Invalid parts of consent: section 6(2)
Section 6(2) works part by part. The consent is not wholly void because one part is bad; the offending part is invalid "to the extent of such infringement". The Illustration involves X buying an insurance policy on Y's app. She consents to (i) processing for issuing the policy and (ii) waiving her right to file a complaint to the Data Protection Board. Part (ii) is invalid.
The same logic covers consent terms that conflict with any other law in force. Drafters should therefore avoid waivers of rights under the Act inside consent screens, since they will not survive and may show a pattern of breach.
Presentation of the request: section 6(3)
Every request for consent under the Act or rules must be presented:
- in clear and plain language;
- with the option to access it in English or any Eighth Schedule language; and
- with contact details of a Data Protection Officer, where applicable, or of any other person authorised by the Data Fiduciary to respond to communications from the Data Principal about her rights.
A Data Protection Officer exists only for a Significant Data Fiduciary (section 10(2)(a)). Other Data Fiduciaries must name another authorised person, and section 8(9) also requires publication of business contact information. The form of the consent request is also affected by the rules, which are not dealt with in this article. The DPDP Rules, 2025 (notified November 2025) prescribe the detail, and different provisions commence on different dates; check the Rules.
How it fits with the rest of section 6
Sections 6(4) to (6) give the right to withdraw and set the consequences, and these are in the article on withdrawal of consent. Section 6(7) to (9) allow consent to be given through a Consent Manager, covered in the Consent Manager article. Section 6(10) puts the burden of proof on the Data Fiduciary, in the article on burden of proving notice and consent. For the consequences of breach, see section 33 and the Schedule.
Practical examples
Example 1: bundled sign-up. A shopping app asks a user to consent to order processing, marketing and sharing with partners in a single tick. The consent for marketing and sharing is not specific to the purpose of fulfilling the order. Separate requests with separate actions are safer.
Example 2: waiver clause. A loan app's consent form includes "I waive any right to approach the Board". Under section 6(2), that part is invalid to the extent of the infringement.
Example 3: contact-list access. A ride-booking app asks for access to the user's contacts although its purpose needs only her location. Consent for contacts would not be limited to what is necessary for the specified purpose.
Common mistakes
- One tick for many purposes.
- Making consent for marketing a condition of a service.
- Pre-ticked boxes, or treating inaction as consent.
- Omitting a contact person in the consent request.
Need help with consent screens and forms?
If your sign-up flows, forms or apps bundle several purposes in one consent, it is worth fixing them before a complaint arrives. Our legal consultation service can review your screens against section 6(1) to (3) and suggest wording changes.
Key takeaways
- Consent must be given without pressure, specific, informed, unconditional, unambiguous and expressed by a clear affirmative action.
- It is limited to personal data necessary for the specified purpose.
- Parts of consent that infringe the Act, the rules or any other law are invalid to that extent.
- The request must be in plain language, with an English or Eighth Schedule language option and a contact person.
- Waivers of the right to complain to the Board are invalid.
Read next
- Consent under the DPDP Act: specific and informed
- Section 6 of the DPDP Act, 2023: withdrawal of consent
- Section 5 of the DPDP Act, 2023: notice to Data Principal
- Section 6 of the DPDP Act, 2023: Consent Manager
Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.
