Back to Technical Publications
TAMPER-EVIDENT SPECIFICATION
++++
STATUTORY COMPLIANCE#DPDP Act#Itemised Notice#Section 6#Audit Dossier

DPDP Act 2023 Consent Notice Architecture: Verifiable Itemisation Under Section 6

A deep dive into building itemised, multilingual, and withdrawable consent notices that satisfy Data Protection Board audit mandates with cryptographic certainty.

AR
AUTHORAmjad Rathod
PUBLISHEDOctober 8, 2026
READING TIME6 min read
SOVEREIGNTYAWS AP-SOUTH-1
DPDP Act 2023 Consent Notice Architecture: Verifiable Itemisation Under Section 6
+
EXECUTIVE SUMMARY & STATUTORY HIGHLIGHT

A deep dive into building itemised, multilingual, and withdrawable consent notices that satisfy Data Protection Board audit mandates with cryptographic certainty.

Under Section 6(1) of the Digital Personal Data Protection (DPDP) Act 2023, consent must be free, specific, informed, unconditional, and unambiguous with a clear affirmative action. Bundled terms of service or ambiguous opt-out checkmarks are statutory violations subject to penalties reaching up to ₹250 Crore under Schedule 1.

For enterprise Data Fiduciaries, achieving provable compliance requires moving beyond static client-side modals toward an append-only state machine.

// Canonical Consent State Model
interface DPDPNoticePayload {
  fiduciaryId: string;
  principalIdentifierHash: string; // SHA-256 salted pseudonym
  purposes: {
    purposeId: string;
    description22Schedule: Record<LanguageCode, string>;
    retentionDays: number;
    mandatory: boolean;
    granted: boolean;
  }[];
  timestampUtc: string;
  hmacSignature: string;
}

The 4 Pillars of Section 6 Compliance

1. Granular Purpose Itemisation

Notice must present each processing purpose as an independent decision. Principals cannot be forced to accept analytics or advertising trackers to access core platform functionality.

2. Mandatory Multilingual Delivery

Notices must be renderable in English and all 22 Eighth Schedule Indian languages (Hindi, Bengali, Marathi, Telugu, Tamil, Gujarati, Urdu, Kannada, Odia, Malayalam, Punjabi, Assamese, etc.) upon user selection or browser locale detection.

3. Asymmetric Withdrawal Friction is Prohibited

Under Section 6(4), the ease of withdrawing consent must equal the ease of giving it. A single-click rights portal or preference drawer is mandatory.

4. Non-Repudiation Through Signed Receipts

When an inquiry is filed by the Data Protection Board of India (DPBI), the fiduciary bears the legal burden of proof. Client cookies or application database boolean columns (has_consented = true) are inadmissible without immutable audit trails.


Verifiable Receipts: How ConsentPlix Solves Burden of Proof

Every user action captured by ConsentPlix’s sub-12KB autonomous SDK creates an HMAC-SHA256 signed event anchored into a sovereign Merkle tree hosted in AWS Mumbai (ap-south-1).

“A fiduciary that cannot provide cryptographic inclusion proofs during an audit is treated as non-compliant from the date of alleged violation.”

With verifiable receipts, legal counsel can export a self-contained cryptographic package verifying the exact terms, language, and timestamp presented to the principal.

DISCUSS WITH YOUR COMPLIANCE TEAMShare this architectural specification with your legal counsel and engineering leads.
++
AR
TECHNICAL AUTHOR & FOUNDER· VERIFIED CONTRIBUTOR

Amjad Rathod

Co-Founder & Chief Architect

Lead architect of the ConsentPlix sovereign cryptographic ledger and autonomous sub-12KB client SDK. Specialises in statutory DPDP Section 6 state machines and high-throughput privacy engineering.

RELATED BRIEFINGS & RECENT POSTSView All Publications→
FURTHER READING

Continue exploring sovereign compliance engineering.

ENTERPRISE READINESS

Ready to deploy provable consent infrastructure?

Deploy in minutes with our sub-12KB SDK or schedule a customized technical consultation with our privacy engineering team.