top of page

Withdrawn but Not Gone: How the DPDP Act’s Consent Framework Fails the Data Principal

by Aman Kumar Jha


Introduction

The Digital Personal Data Protection Act, 2023 (the “DPDP Act”) regards consent as the principal method of lawful processing of an individual’s data. Section 6(4) of the DPDP Act provides every Data Principal with the right to remove their consent at any time; Section 6(6) of the DPDP Act creates an obligation on the Data Fiduciary to stop processing and make sure their vendors stop processing as well. This appears to be a robust legal framework of protection; however, in practice, the erasure of data under Section 8(7) does not apply to data that has been shared beyond the immediate circle of parties involved. Furthermore, through the operation of Section 7(a), organizations can easily and without notice or repercussions re-classify their legal basis for processing data, allowing them to continue processing without the need to respect an individual’s right to withdraw consent, and also the DPDP Rules 2025 set no firm deadline for acting on a withdrawal. These gaps make the right formally sound but operationally fragile.


When Withdrawal Stops at the First Door

According to Section 6(6), the Data Fiduciary must cease processing and direct the Data Processors to cease processing in a reasonable time after the withdrawal of consent. Under Section 8(7), the Data Fiduciary must delete the data and instruct its processors to delete any copies of the data that were shared with them. Unfortunately, these obligations only flow one step down the processing chain and do not apply to third-party marketing affiliates, analytics firms or credit bureaus, who may have received the same data prior to the withdrawal of consent.

This is a meaningful gap. The General Data Protection Regulation’s Article 17 read with Recital 66 requires controllers to take reasonable steps to notify third parties of an erasure request. India’s Act contains no such downstream obligation. An individual who withdraws consent achieves a clean break with the original organisation but has no legal assurance over data already distributed further down the chain.


The Loophole That Makes Withdrawal Optional

The DPDP Act allows for processing of data in only two categories in accordance with its Section 4: i) with the consent as outlined in Section 6; or ii) one of the nine forms of “legitimate means of processing”, as outlined in Section 7. Unlike the balancing tests contained in the GDPR, there is no balancing of the organizations interest versus the individual’s interest in accordance with the provisions outlined in Section 7. More specifically, Section 7(a) provides for the processing of data that an individual has “voluntarily provided at the time of such provision” in order to be used for the stated purpose, unless the individual has subsequently indicated a non-consent to the continued processing of the information.

This creates a readily available workaround. After a withdrawal under Section 6(4), an organisation can argue that the data was originally provided voluntarily, and shift the processing ground to Section 7(a) without informing the individual. The withdrawal is not refused; it is made legally irrelevant. Unlike the Personal Data Protection Bill, 2019, which included a balancing test as a protected step before using legitimate interests, the DPDP Act removed that protection and instead allows for an exit under Section 7 (a).

The Rules Arrive, But the Gap Remains

Though the DPDP Rules 2025, published on November 13, 2025, require an easily-accessible withdrawal link pursuant to Rule 3 and a record of when consent was given or revoked, many aspects of the DPDP Rules indicate a good faith effort at compliance, however, many critical features that would enable consumers to enforce their rights are absent. These include, but are not limited to, timelines for processing revocations and notifications to the consumer regarding the completion of their revocation. Thus, there is presently a complaint driven and reactive process of processing consumer rights enforcement.


Way Forward

The Data Protection Board, can address these deficiencies without additional legislation:

  1. Extend erasure downstream. The Board should provide clarification that Section 8(7) applies to all recipients identified in consent logs and not just to immediate processors as defined therein.

  2. Narrow Section 7(a) by guidance. The Board should confirm that Section 7(a) cannot cover data once Section 6(4) withdrawal is lodged, unless a distinct purpose was separately identified at collection.

  3. Fix a response deadline. The Board should create an auditable record by requiring that acknowledgements of withdrawal requests be responded to within the same 7-day timeframe that applies to other rights requests as that of Rule 14.


If these modifications are made, they would create a practical right that can be exercised by individuals.


 
 
 

Comments


Address

2nd & 4th Floor, Maharashtra National Law University Mumbai, MTNL Building, Technology Street, Powai, Mumbai. 

Our Socials

  • LinkedIn
  • Instagram

Contact

Convenor
Revant Sinha -  91 78270 76105

Associate Convenors
Om Dambhare - 91 93072 24566

Ritesh Karale - 91 93593 07137

bottom of page