Section 6 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Section 6(4) to (6) give the Data Principal a right to withdraw consent at any time, and the Act says how easy it must be. The consequences of withdrawal fall on her, but past processing stays lawful, and the Data Fiduciary must, within a reasonable time, stop processing and make its Data Processors stop. To design a withdrawal route that holds up, a legal consultation can help.
Where consent is the basis of processing, the Data Principal may withdraw it at any time, and the ease of withdrawing must be comparable to the ease of giving consent (section 6(4)). Consequences of withdrawal are borne by the Data Principal, and withdrawal does not affect the legality of earlier processing (section 6(5)). The Data Fiduciary must within a reasonable time cease, and cause its Data Processors to cease, processing, unless the law requires or authorises it without consent (section 6(6)).
Sub-sections (4) to (6) at a glance
| Sub-section | Rule |
|---|---|
| 6(4) | Right to withdraw consent at any time; ease of withdrawal comparable to ease of giving consent. Applies where consent is the basis of processing |
| 6(5) | Consequences of withdrawal borne by the Data Principal; processing before withdrawal remains lawful |
| 6(6) | Data Fiduciary must within a reasonable time cease and cause Data Processors to cease processing, unless required or authorised by the Act, the rules or any other law in force in India |
The right to withdraw: section 6(4)
The right applies "where consent given by the Data Principal is the basis of processing". It therefore does not apply to processing under section 7's certain legitimate uses, where consent is not the basis. The right can be used "at any time", so there is no lock-in period and no window.
The second part is often missed: "with the ease of doing so being comparable to the ease with which such consent was given". This is a design standard. If consent was given with a single tap in an app, withdrawal should not need a letter, a call to a helpline or a multi-step process. The Act gives no further test, so compare the steps, time and effort for each. The notice under section 5(1)(ii) must already tell the Data Principal how to exercise this right, so the route needs to exist and be described.
Who bears the consequences: section 6(5)
Section 6(5) has two limbs.
- The consequences of withdrawal are borne by the Data Principal. If she withdraws consent for a service that needs that data, she may lose the service.
- Withdrawal does not affect the legality of processing before it. Processing carried out on the strength of consent earlier stays lawful.
The Illustration gives a clean example. X uses an online shopping app of Y and consents to processing for fulfilling her supply order; she places an order and pays. If X withdraws consent, Y may stop enabling X to use the app or website for placing orders, but may not stop the processing for the supply of goods already ordered and paid for.
So "consequences borne by the Data Principal" is not a licence to penalise her beyond what is necessary. The Illustration shows the business may stop offering the facility that depends on the consent, but it cannot walk away from an obligation already undertaken.
The duty to stop: section 6(6)
When a Data Principal withdraws consent under section 6(5), the Data Fiduciary must:
- within a reasonable time, cease processing the personal data of that Data Principal; and
- cause its Data Processors to cease processing as well,
unless processing without her consent is required or authorised under the Act, the rules or any other law for the time being in force in India.
The text says "reasonable time", not a number of days. What is reasonable depends on the systems involved, for example how many processors hold copies. Keep a log of the request, the date received and the date on which processing stopped at the fiduciary and each processor.
The exception is narrow. It applies when the law requires or authorises the processing. A business cannot just say "we need it for our records"; it has to point to a provision that requires or allows the processing without consent. In practice that may be a legal retention duty, or a section 7 use where it truly applies to that data.
The Illustration: X, a telecom provider, contracts with Y, a Data Processor, to email bills. Z, a customer who had consented to emailed bills, downloads X's app and opts to receive bills only there. X must itself cease, and cause Y to cease, processing Z's data for emailing bills.
Erasure is a separate duty
Stopping processing is not the same as erasing the data. Section 8(7)(a) requires erasure upon withdrawal of consent, or as soon as it is reasonable to assume that the specified purpose is no longer being served, whichever is earlier, unless retention is necessary for compliance with law; and section 8(7)(b) requires the Data Fiduciary to cause its Data Processor to erase data made available to it. See the article on erasure and retention under section 8(7). Read the two sections together when designing a withdrawal workflow.
Withdrawal and legacy consent
For consent given before commencement, section 5(2)(b) lets the Data Fiduciary continue processing "until and unless the Data Principal withdraws her consent". The same section 6(4) to (6) mechanics apply from the point of withdrawal. See section 5(2).
Practical examples
Example 1: app with a newsletter. A user withdraws consent to marketing e-mails. The company must stop the marketing processing within a reasonable time and tell its e-mail service provider, a Data Processor, to stop too. It may keep serving her other orders if those rest on a different purpose.
Example 2: paid-up order. A customer withdraws consent after paying for goods not yet delivered. The business may stop her from placing new orders but must go on processing the data needed to deliver what she paid for.
Example 3: withdrawal made hard. A service lets users sign up in one tap but requires a written request by post to withdraw. That is hard to reconcile with the requirement that the ease of withdrawal be comparable to the ease of giving consent.
Common mistakes
- Making withdrawal harder than giving consent.
- Forgetting to instruct Data Processors to stop.
- Treating withdrawal as invalidating earlier processing. Section 6(5) says it does not.
- Stopping processing but keeping the data. Section 8(7) separately requires erasure, subject to legal retention.
Need help with withdrawal workflows?
If your consent screens offer no clear way to withdraw, or your vendors do not know how to act on a stop instruction, a short review can fix the gaps. Reach out through our legal consultation service and we will go through the steps with you.
Key takeaways
- Withdrawal is possible at any time where consent is the basis of processing.
- The ease of withdrawal must be comparable to the ease of giving consent.
- Earlier processing stays lawful; the Data Principal bears the consequences of withdrawal.
- The Data Fiduciary must stop within a reasonable time and cause Data Processors to stop.
- Erasure is a separate duty under section 8(7).
Read next
- Section 6 of the DPDP Act, 2023: what valid consent requires
- Section 6 of the DPDP Act, 2023: Consent Manager
- Section 8 of the DPDP Act, 2023: erasure and retention of personal data
- Rights of the Data Principal under sections 11 to 14
Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.
