India's new Parliament building in New Delhi, photographed by the Ministry of Parliamentary Affairs in May 2023
DPDP implementationConsent withdrawn. What happens to the next request?
India's Parliament building, New Delhi. Photograph: 27 May 2023.Image: Ministry of Parliamentary Affairs / PIBGODL-IndiaImage fitted for layout; headline added by Securelay. Editorial context, not endorsement.
Primary source DPDP Act, 2023: Section 6 on consent and withdrawalPrimary source MeitY: phased commencement notification, 13 November 2025

Start with the legal distinction

Section 6(4) of India's DPDP Act addresses withdrawal where consent is the basis of processing, with ease comparable to giving consent. Section 6(6) addresses stopping that processing, including by processors, within a reasonable time, subject to processing required or authorised by applicable law. Withdrawal does not make previously lawful consent-based processing unlawful. These are provisions to map into your readiness work; commencement is phased.

Choose one purpose and follow its dependencies

Our practical checklist starts with one purpose, such as optional promotional messages. Record the permission state, the notice version, the time of change and the systems relying on it. Check the application, scheduled jobs, event queues and relevant processors. Do not assume an account-level flag describes every purpose or that every use relies on consent.

Run a synthetic withdrawal exercise

Use a test identity with permission for the selected purpose. Confirm the permitted operation, withdraw that permission and attempt the next operation. Also test a job queued before withdrawal, a retry and an unavailable consent service. Agree how current permission is checked and how failures are handled. Document actual outcomes rather than relying on the preference screen.

Separate stopping a use from deleting every record

Stopping a purpose and erasing information are connected but different tasks. A team must identify any continuing lawful processing and retention requirements. Keep processor responses and exceptions attributable to an owner. Do not promise instant deletion from every backup, export and external service merely because the user clicked a button.

What the implementation conversation should cover

Securelay supports consent workflows and configured consent checks on integrated routes. The integration must connect the right subject and purpose to the decision and preserve a useful record without sensitive payloads. A consent-management feature does not mean Securelay is a Board-registered Consent Manager. Start with one purpose, its dependent systems and a testable acceptance checklist.

Put the control on the data path.Discuss an architecture review