Next due
11 OCTGSTR-1 · Outward supplies · Sep 2026tomorrow 15 OCTPF & ESI · Contributions · Sep 2026in 5 days 20 OCTGSTR-3B · Summary return · Sep 2026in 10 days 21 OCTTax Audit Report · Form 3CA/3CB · AY 2026-27 · extended from 30 Sepin 11 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 20 days 7 NOVTDS / TCS deposit · Deducted in Oct 2026in 28 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 42 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 50 days
All due dates

Section 6 of the Digital Personal Data Protection Act, 2023: Withdrawal of consent

Where consent is the basis of processing, the Data Principal may withdraw it at any time, and the ease of withdrawing must be comparable to the ease of giving consent (section...

Published
Updated
Reading time
7 min
Views
9
Questions
6 answered
  • Expert Reviewed
  • Medium Complexity
Topic
Data Protection
Published
September 30, 2026
Last updated
Oct 9, 2026
Reading time
7 min
0:00
Last updated: October 2026Verified against: Government sources

Section 6(4) to (6) give the Data Principal a right to withdraw consent at any time, and the Act says how easy it must be. The consequences of withdrawal fall on her, but past processing stays lawful, and the Data Fiduciary must, within a reasonable time, stop processing and make its Data Processors stop. To design a withdrawal route that holds up, a legal consultation can help.

Sub-sections (4) to (6) at a glance

Sub-sectionRule
6(4)Right to withdraw consent at any time; ease of withdrawal comparable to ease of giving consent. Applies where consent is the basis of processing
6(5)Consequences of withdrawal borne by the Data Principal; processing before withdrawal remains lawful
6(6)Data Fiduciary must within a reasonable time cease and cause Data Processors to cease processing, unless required or authorised by the Act, the rules or any other law in force in India

The right to withdraw: section 6(4)

The right applies "where consent given by the Data Principal is the basis of processing". It therefore does not apply to processing under section 7's certain legitimate uses, where consent is not the basis. The right can be used "at any time", so there is no lock-in period and no window.

The second part is often missed: "with the ease of doing so being comparable to the ease with which such consent was given". This is a design standard. If consent was given with a single tap in an app, withdrawal should not need a letter, a call to a helpline or a multi-step process. The Act gives no further test, so compare the steps, time and effort for each. The notice under section 5(1)(ii) must already tell the Data Principal how to exercise this right, so the route needs to exist and be described.

Who bears the consequences: section 6(5)

Section 6(5) has two limbs.

  1. The consequences of withdrawal are borne by the Data Principal. If she withdraws consent for a service that needs that data, she may lose the service.
  2. Withdrawal does not affect the legality of processing before it. Processing carried out on the strength of consent earlier stays lawful.

The Illustration gives a clean example. X uses an online shopping app of Y and consents to processing for fulfilling her supply order; she places an order and pays. If X withdraws consent, Y may stop enabling X to use the app or website for placing orders, but may not stop the processing for the supply of goods already ordered and paid for.

So "consequences borne by the Data Principal" is not a licence to penalise her beyond what is necessary. The Illustration shows the business may stop offering the facility that depends on the consent, but it cannot walk away from an obligation already undertaken.

The duty to stop: section 6(6)

When a Data Principal withdraws consent under section 6(5), the Data Fiduciary must:

  • within a reasonable time, cease processing the personal data of that Data Principal; and
  • cause its Data Processors to cease processing as well,

unless processing without her consent is required or authorised under the Act, the rules or any other law for the time being in force in India.

The text says "reasonable time", not a number of days. What is reasonable depends on the systems involved, for example how many processors hold copies. Keep a log of the request, the date received and the date on which processing stopped at the fiduciary and each processor.

The exception is narrow. It applies when the law requires or authorises the processing. A business cannot just say "we need it for our records"; it has to point to a provision that requires or allows the processing without consent. In practice that may be a legal retention duty, or a section 7 use where it truly applies to that data.

The Illustration: X, a telecom provider, contracts with Y, a Data Processor, to email bills. Z, a customer who had consented to emailed bills, downloads X's app and opts to receive bills only there. X must itself cease, and cause Y to cease, processing Z's data for emailing bills.

Erasure is a separate duty

Stopping processing is not the same as erasing the data. Section 8(7)(a) requires erasure upon withdrawal of consent, or as soon as it is reasonable to assume that the specified purpose is no longer being served, whichever is earlier, unless retention is necessary for compliance with law; and section 8(7)(b) requires the Data Fiduciary to cause its Data Processor to erase data made available to it. See the article on erasure and retention under section 8(7). Read the two sections together when designing a withdrawal workflow.

Withdrawal and legacy consent

For consent given before commencement, section 5(2)(b) lets the Data Fiduciary continue processing "until and unless the Data Principal withdraws her consent". The same section 6(4) to (6) mechanics apply from the point of withdrawal. See section 5(2).

Practical examples

Example 1: app with a newsletter. A user withdraws consent to marketing e-mails. The company must stop the marketing processing within a reasonable time and tell its e-mail service provider, a Data Processor, to stop too. It may keep serving her other orders if those rest on a different purpose.

Example 2: paid-up order. A customer withdraws consent after paying for goods not yet delivered. The business may stop her from placing new orders but must go on processing the data needed to deliver what she paid for.

Example 3: withdrawal made hard. A service lets users sign up in one tap but requires a written request by post to withdraw. That is hard to reconcile with the requirement that the ease of withdrawal be comparable to the ease of giving consent.

Common mistakes

  • Making withdrawal harder than giving consent.
  • Forgetting to instruct Data Processors to stop.
  • Treating withdrawal as invalidating earlier processing. Section 6(5) says it does not.
  • Stopping processing but keeping the data. Section 8(7) separately requires erasure, subject to legal retention.

Need help with withdrawal workflows?

If your consent screens offer no clear way to withdraw, or your vendors do not know how to act on a stop instruction, a short review can fix the gaps. Reach out through our legal consultation service and we will go through the steps with you.

Key takeaways

  • Withdrawal is possible at any time where consent is the basis of processing.
  • The ease of withdrawal must be comparable to the ease of giving consent.
  • Earlier processing stays lawful; the Data Principal bears the consequences of withdrawal.
  • The Data Fiduciary must stop within a reasonable time and cause Data Processors to stop.
  • Erasure is a separate duty under section 8(7).

Read next

Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.

Quick recapKey facts & short answers

Key Facts About Section 6

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

Can consent be withdrawn at any time?

Yes. Section 6(4) says the Data Principal has the right to withdraw consent at any time.

How easy must withdrawal be?

The ease of withdrawal must be comparable to the ease with which consent was given (section 6(4)).

What is not written down will be remembered differently by everyone involved.

— TaxClue Compliance Desk

Section 6: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

Yes. Section 6(4) says the Data Principal has the right to withdraw consent at any time.

The ease of withdrawal must be comparable to the ease with which consent was given (section 6(4)).

No. Section 6(5) says withdrawal does not affect the legality of processing based on consent before its withdrawal.

Within a reasonable time, cease processing and cause its Data Processors to cease (section 6(6)), unless law requires or authorises it without consent.

Section 6(5) says the Data Principal, for example by losing a service that depends on the data.

Section 8(7)(a) requires erasure upon withdrawal, unless retention is necessary for compliance with law.