DPDP Act 2023 Consent Notice Architecture: Verifiable Itemisation Under Section 6
A deep dive into building itemised, multilingual, and withdrawable consent notices that satisfy Data Protection Board audit mandates with cryptographic certainty.
A deep dive into building itemised, multilingual, and withdrawable consent notices that satisfy Data Protection Board audit mandates with cryptographic certainty.
Statutory Mandate: The Death of Bundled Consent
Under Section 6(1) of the Digital Personal Data Protection (DPDP) Act 2023, consent must be free, specific, informed, unconditional, and unambiguous with a clear affirmative action. Bundled terms of service or ambiguous opt-out checkmarks are statutory violations subject to penalties reaching up to ₹250 Crore under Schedule 1.
For enterprise Data Fiduciaries, achieving provable compliance requires moving beyond static client-side modals toward an append-only state machine.
// Canonical Consent State Model
interface DPDPNoticePayload {
fiduciaryId: string;
principalIdentifierHash: string; // SHA-256 salted pseudonym
purposes: {
purposeId: string;
description22Schedule: Record<LanguageCode, string>;
retentionDays: number;
mandatory: boolean;
granted: boolean;
}[];
timestampUtc: string;
hmacSignature: string;
}
The 4 Pillars of Section 6 Compliance
1. Granular Purpose Itemisation
Notice must present each processing purpose as an independent decision. Principals cannot be forced to accept analytics or advertising trackers to access core platform functionality.
2. Mandatory Multilingual Delivery
Notices must be renderable in English and all 22 Eighth Schedule Indian languages (Hindi, Bengali, Marathi, Telugu, Tamil, Gujarati, Urdu, Kannada, Odia, Malayalam, Punjabi, Assamese, etc.) upon user selection or browser locale detection.
3. Asymmetric Withdrawal Friction is Prohibited
Under Section 6(4), the ease of withdrawing consent must equal the ease of giving it. A single-click rights portal or preference drawer is mandatory.
4. Non-Repudiation Through Signed Receipts
When an inquiry is filed by the Data Protection Board of India (DPBI), the fiduciary bears the legal burden of proof. Client cookies or application database boolean columns (has_consented = true) are inadmissible without immutable audit trails.
Verifiable Receipts: How ConsentPlix Solves Burden of Proof
Every user action captured by ConsentPlix’s sub-12KB autonomous SDK creates an HMAC-SHA256 signed event anchored into a sovereign Merkle tree hosted in AWS Mumbai (ap-south-1).
“A fiduciary that cannot provide cryptographic inclusion proofs during an audit is treated as non-compliant from the date of alleged violation.”
With verifiable receipts, legal counsel can export a self-contained cryptographic package verifying the exact terms, language, and timestamp presented to the principal.
Amjad Rathod
Co-Founder & Chief ArchitectLead architect of the ConsentPlix sovereign cryptographic ledger and autonomous sub-12KB client SDK. Specialises in statutory DPDP Section 6 state machines and high-throughput privacy engineering.
Continue exploring sovereign compliance engineering.
Ready to deploy provable consent infrastructure?
Deploy in minutes with our sub-12KB SDK or schedule a customized technical consultation with our privacy engineering team.