Infosek
INFOSEK

Consent Withdrawal Under DPDP: A Product Requirement

The rule is one clause long and it reshapes how consent has to be stored. If withdrawal cannot propagate, your consent record was never a record, only a flag.

Consent Withdrawal Under DPDP: A Product Requirement

The requirement

Rule 3(c)(i) requires the notice to give the communication link and a description of other means by which the Data Principal may withdraw her consent, with the ease of doing so being comparable to that with which such consent was given.

Comparable ease is the operative phrase. One tap in, one tap out.

What has to happen downstream

A withdrawal is not a UI event. When it arrives:

The common failure

A settings toggle that flips a flag, while nightly jobs continue reading the underlying table because they were written before consent existed as a concept. Nothing in the interface is wrong. The processing simply never stopped.

If nobody can name every system that reads a given data set, the honest answer is that withdrawal does not currently work, regardless of what the settings page shows.

Infosek Team

What to build

Common questions

How easy must it be to withdraw consent under DPDP?

Rule 3(c)(i) requires the notice to describe the means by which the Data Principal may withdraw her consent, with the ease of doing so being comparable to that with which the consent was given.

What happens when a Data Principal withdraws consent?

Processing that depended on that consent must stop. Processing resting on another basis, such as a legitimate use under section 7 or a legal obligation, is unaffected, which is why mapping each activity to its basis matters before a withdrawal arrives.

Can your product actually honour a withdrawal?

Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.

Book Free 30-Min Assessment