Consent Withdrawal Under DPDP: A Product Requirement
The rule is one clause long and it reshapes how consent has to be stored. If withdrawal cannot propagate, your consent record was never a record, only a flag.
The requirement
Rule 3(c)(i) requires the notice to give the communication link and a description of other means by which the Data Principal may withdraw her consent, with the ease of doing so being comparable to that with which such consent was given.
Comparable ease is the operative phrase. One tap in, one tap out.
What has to happen downstream
A withdrawal is not a UI event. When it arrives:
- Processing that depended on that consent stops, including in systems the data was copied into.
- Processing that rests on another basis continues, so the two have to be distinguishable.
- Downstream copies matter. Data exported to a warehouse, a CRM or an analytics tool is still your responsibility as Data Fiduciary.
- Data Processors acting on your behalf need to receive the signal, which is part of why Rule 6(1)(f) requires contractual provisions with them.
The common failure
A settings toggle that flips a flag, while nightly jobs continue reading the underlying table because they were written before consent existed as a concept. Nothing in the interface is wrong. The processing simply never stopped.
If nobody can name every system that reads a given data set, the honest answer is that withdrawal does not currently work, regardless of what the settings page shows.
Infosek Team
What to build
- Consent as a record with a purpose, a timestamp, a state and a version of the notice shown.
- A withdrawal event that propagates rather than a field that changes.
- A map from purpose to the systems that process for it, so a withdrawal has a defined blast radius.
- A withdrawal route reachable in the same number of steps as the original consent.
Common questions
How easy must it be to withdraw consent under DPDP?
Rule 3(c)(i) requires the notice to describe the means by which the Data Principal may withdraw her consent, with the ease of doing so being comparable to that with which the consent was given.
What happens when a Data Principal withdraws consent?
Processing that depended on that consent must stop. Processing resting on another basis, such as a legitimate use under section 7 or a legal obligation, is unaffected, which is why mapping each activity to its basis matters before a withdrawal arrives.
Can your product actually honour a withdrawal?
Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.
Book Free 30-Min Assessment