Infosek
INFOSEK

Do You Need to Re-Collect Consent From Existing Users?

The honest answer is that it depends on what you can prove, and most companies cannot prove much about consent captured before the Rules existed.

Do You Need to Re-Collect Consent From Existing Users?

The question to ask first

Not “did we get consent” but “can we show what they consented to, and that it met the section 6 standard”. Those are very different questions, and the second is the one that matters.

Section 6(1) requires consent that is free, specific, informed, unconditional and unambiguous, given by clear affirmative action, and limited to the data necessary for the specified purpose. Consent captured as acceptance of a general privacy policy at sign-up rarely satisfies “specific”.

Three honest outcomes

Why a blanket re-consent campaign is a bad first move

It is expensive, it depresses your user base, and it is often unnecessary for a meaningful share of your processing. Do the mapping first: which activities actually depend on consent, and which rest on another footing. Only the first group needs anything.

A re-consent request also has to meet Rule 3 on its own terms. If your fresh notice is as vague as the original, you have annoyed your users and changed nothing.

The worst version of this project is a mass email asking everyone to re-agree to a policy nobody reads. That reproduces the original problem with more steps.

Infosek Team

A workable sequence

Common questions

Do companies need to obtain fresh consent under the DPDP Act?

Where existing consent does not meet the section 6 standard of free, specific, informed, unconditional and unambiguous consent given by clear affirmative action, and limited to the data necessary for the specified purpose, it will not support continued processing on a consent basis. Many pre-DPDP consent records do not meet that standard.

What if we cannot show how consent was obtained?

Then you cannot demonstrate the processing has a valid basis. The practical options are to obtain fresh consent, to establish that the processing rests on a legitimate use under section 7, or to stop the processing.

Working out what your existing consent covers?

Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.

Book Free 30-Min Assessment