Consent Management Is Not DPDP Compliance: What a Real DPDP Assessment Actually Covers background
Back to Journal
Regulatory Compliance

Consent Management Is Not DPDP Compliance: What a Real DPDP Assessment Actually Covers

Peyush Baranwal
August 17, 2026
18 min read

A consent tool is not DPDP compliance. What a real DPDP assessment covers: data discovery, security safeguards, rights, retention, breach and vendors.

A consent banner goes live, consent records start accumulating, and the DPDP programme gets reported as green. It is the most common failure pattern we see — and the gap it hides is exactly where the largest penalties sit. A genuine DPDP assessment treats consent as one control among many, and starts somewhere else entirely.

The Digital Personal Data Protection Act, 2023 has been operational law since the DPDP Rules, 2025 were notified on 13 November 2025. Compliance is phased across roughly eighteen months, with the full obligation landing on 13 May 2027. The Data Protection Board of India already functions, and Consent Manager registration opens around November 2026.

Penalties are set by the Act's schedule and stack per category. Two figures tell you where the regulator's attention sits: failure to take reasonable security safeguards to prevent a breach attracts up to ₹250 crore, the highest single category in the Act. Failure to notify a breach is penalised separately, up to ₹200 crore. Neither is a consent obligation, and no consent platform reduces either exposure by a rupee.

Key Takeaways
  • 01Consent establishes lawful basis — nothing about security, retention, rights, breach response or governance.
  • 02The real foundation is data discovery and a RoPA. You cannot protect or erase what you have not mapped.
  • 03"Reasonable security safeguards" is an evidentiary claim, not a policy — and it carries the ₹250 crore ceiling.
  • 04Rights, retention and breach response are workflows with clocks, not clauses.
  • 05Appointing a processor does not transfer liability. The Data Fiduciary answers for it.

Give the tooling its due: a competent consent platform does real work that would otherwise be done badly in spreadsheets.

A Data Fiduciary — the entity determining the purpose and means of processing — must present a notice that is itemised rather than bundled, each purpose stated separately in clear language, with the option of English or any language in the Eighth Schedule. Consent must be free, specific, informed, unconditional and unambiguous, given by clear affirmative action. Pre-ticked boxes and consent buried in terms of service do not qualify. A good platform also handles the parts teams routinely get wrong:

  • Withdrawal at comparable ease. If consent took one click to give, it cannot take a support ticket to withdraw.
  • Consent artefacts. A defensible record of what was shown, which version, when, and what the Data Principal — the individual the data is about — agreed to.
  • Consent Manager integration. The Rules contemplate registered Consent Managers through whom individuals manage and withdraw consent. That is an engineering task, not a procurement one.
  • Purpose granularity. Marketing analytics and fraud prevention are different purposes with different bases; collapsing them is a common defect.

There is nuance inside consent too. Certain legitimate uses permit processing without it — an employment relationship, a voluntary disclosure for a stated purpose, compliance with a legal obligation. Mapping which processing rests on consent and which on a legitimate use is itself assessment work, and errors cut both ways: you either collect consent you cannot honour on withdrawal, or you rely on consent for something that should never have depended on it. All of this is necessary. None of it is sufficient.

DPDP is not a consent statute. It is an accountability framework: it grants permission to process personal data on stated conditions, then holds you answerable for everything that happens to that data afterwards — how it is secured, how long it is kept, whether you can find it when someone asks, what happens when it leaks, and who else touches it.

Consent answers one question: may we process this? The Act asks several more, and the penalties attach to those answers.

A consent platform coversA DPDP assessment also covers
Itemised notice and valid consent captureWhere personal data actually lives, across every system and vendor
Consent withdrawal mechanicsWhether withdrawal triggers real deletion downstream
Consent audit recordsTested evidence of reasonable security safeguards
Preference dashboardsRights fulfilment as a workflow with owners and SLAs
Consent versioningBreach detection, and notification to the Board and individuals
Cookie categorisationProcessor contracts, sub-processor control, transfer mapping

Read the right-hand column and a pattern emerges: almost all of it depends on knowing where your data is. Which is why a real assessment does not begin at consent.

1. Data discovery and the Record of Processing Activities

What it is. A systematic inventory of the personal data you hold — what categories, in which systems, under what purpose and basis, shared with whom, retained how long, crossing which borders — documented as a Record of Processing Activities (RoPA) that is maintained, not produced once for an audit.

Why it matters. Almost every other obligation depends on it. You cannot secure data you have not located, erase it on withdrawal, answer an access request completely, or scope a breach honestly. Starting at consent is building the roof before the foundation.

How to approach it. Combine interviews with technical discovery across databases, object storage, warehouses, SaaS and log stores. Interviews alone reliably miss the analytics copy, the reconciliation CSV, the old backup and the tool procured on a card. Expect to find personal data nobody declared — that finding is the value.

2. Reasonable security safeguards — the ₹250 crore obligation

What it is. A Data Fiduciary must protect personal data in its possession or control by taking reasonable security safeguards to prevent a breach. The Rules describe, illustratively: encryption, obfuscation, masking or tokenisation; access controls; logging and monitoring able to detect unauthorised access; backups enabling recovery; and log retention for a defined period. Examples of a standard of care, not an exhaustive checklist.

Why it matters. Highest-penalty category in the Act, and the one most often answered with a document. The obligation is evidentiary. After an incident, "we had a policy requiring encryption" is not the claim you need. The claim you need is "these systems were encrypted, these paths restricted, this monitoring firing — and here is the testing that shows it." A policy asserts intent; only testing produces evidence.

The distinction that decides this category. "Reasonable" gets judged after the fact against what a competent organisation of your size and sector should have done — on evidence: configuration state, test results, log completeness, remediation timelines. A tested trail puts you in a materially different position from a stated intention, even where the written policies are identical.

How to approach it. Scope testing at the systems your RoPA flags as holding personal data, not at whatever was tested last year: application and API penetration testing where personal data is collected and served, cloud configuration review of the storage and database services holding it, identity and access review of who can reach it, database security assessment where it rests, and verification that monitoring would actually detect unauthorised access rather than collect logs nobody queries. This is the one pillar a GRC exercise alone cannot satisfy — the evidence is generated by testing.

3. Data Principal rights, operationalised

What it is. Individuals hold rights to access a summary of their data and processing, to correction and completion, to erasure, to grievance redressal, and to nominate someone to exercise their rights on death or incapacity. Each must be served within a defined period.

Why it matters. A right is not a clause in a privacy notice; it is a workflow with an owner, a queue, a clock and an audit trail. Nomination gets missed entirely, because no legacy system was built with it in mind.

How to approach it. Run each right as a live drill. Submit a test access request and time it. Attempt a real erasure, then verify in the warehouse, backups, CRM and vendor platforms whether the record is actually gone. Most organisations find erasure removes the primary record and leaves four copies — exactly the finding you want before a Data Principal produces it for you.

4. Retention and erasure

What it is. Personal data must be erased once the purpose it was collected for is served, or when consent is withdrawn — whichever comes first — unless law requires retention. The Rules set default retention periods for certain classes of entity and require advance notice to the individual before erasure in specified circumstances.

Why it matters. The hardest obligation to implement honestly, because every data platform built in the last fifteen years defaults to keeping everything. "Purpose served" is a business determination that must be encoded into a schedule and enforced by machinery rather than intention. It is also where DPDP pulls against sectoral rules — banking, insurance and securities regulation impose their own minimums.

How to approach it. Build a purpose-based schedule per data category, reconcile it explicitly against RBI and SEBI obligations — a documented mapping of which obligation governs which field, not an average of the two — then automate deletion with logged execution. Manual annual purges rarely happen twice.

5. Breach detection and notification

What it is. On becoming aware of a personal data breach, a Data Fiduciary must notify the Data Protection Board and each affected Data Principal without delay, then file a detailed report to the Board within 72 hours covering the nature and scope of the breach, its likely consequences, mitigation undertaken, and the intimations given.

Why it matters. The clock starts at awareness, and this is penalised separately from the breach — up to ₹200 crore. Scoping is the step that fails: an organisation that cannot say which personal data sat in the compromised system ends up notifying on assumption. Indian organisations also carry CERT-In's separate six-hour expectation for specified incidents, covered in CERT-In's six-hour reporting rules — parallel obligations with different clocks, not alternatives.

How to approach it. Wire the RoPA into the incident response plan so identifying a compromised system immediately tells you which data categories and populations are implicated. Pre-draft notification templates, then rehearse: a tabletop that ends with a drafted Board report is worth more than the plan it exercises. Incident response readiness and DPDP notification are one capability seen from two angles.

6. Processor governance and cross-border transfer

What it is. A Data Fiduciary may engage a Data Processor — an entity processing on its behalf — only under a valid contract, and remains accountable for that processing. Cross-border transfer is permitted subject to restrictions the government may prescribe, and certain data may be required to remain in India as notified.

Why it matters. One sentence carries most of the risk: the Data Fiduciary stays liable. Appointing a processor distributes the work, not the accountability. If a marketing platform, KYC vendor or offshore support desk mishandles data you sent, the Board's counterparty is you. A signed agreement with a vendor who onward-engages three sub-processors you have never assessed is a governance illusion.

How to approach it. Inventory processors from the RoPA, not procurement records, which are always incomplete. Flow obligations down: security measures, breach-notification timelines that let you meet yours, erasure on termination, audit rights, approval for sub-processors. Maintain a transfer map. Tier vendors by sensitivity and volume and assess the top tier properly — see third-party risk management for the mechanics.

7. Children's and guardians' data

What it is. Processing a child's personal data requires verifiable consent from a parent or lawful guardian, and the same applies to persons with disabilities who have a lawful guardian. Behavioural tracking and targeted advertising directed at children are prohibited.

Why it matters. Two traps. Assuming it does not apply — if your platform is accessible to minors and you cannot show otherwise, the obligation is live, and edtech, gaming, consumer fintech and health platforms are squarely in scope. And the word verifiable: an "I am over 18" checkbox is not verification, and a self-declared date of birth is not guardian consent.

How to approach it. Determine honestly whether children can use the service, implement a guardian-consent flow proportionate to the risk, and — most often missed — audit the advertising and analytics stack to confirm no behavioural profiling reaches accounts identified as children. A technical verification of tag and SDK behaviour, not a policy statement.

8. Significant Data Fiduciary duties

What it is. The government may designate an entity a Significant Data Fiduciary on factors including the volume and sensitivity of personal data processed and the risk to Data Principals. Designation brings enhanced duties: a Data Protection Officer based in India reporting to the board, an annual Data Protection Impact Assessment, an annual independent data audit, and algorithmic due diligence to verify that algorithmic systems do not pose a risk to Data Principals' rights.

Why it matters. Long lead times. A board-reporting DPO is a hiring decision. An independent audit needs scope, an auditor and evidence. Algorithmic due diligence is novel work for most firms — explaining what your models do with personal data and showing you examined them for rights impact. Discovering you are likely designated three months before the deadline is not a problem you can buy your way out of.

How to approach it. Assess likely designation early on volume and sensitivity. If plausible, build to the enhanced standard rather than waiting for notification. A fractional DPO or vCISO arrangement can hold the role while a permanent hire is made, provided the board reporting line is real.

What a Structured DPDP Assessment Looks Like

A defensible DPDP gap assessment follows a sequence, and the sequence matters more than the artefacts.

It runs in five steps. Data mapping and RoPA comes first — interviews plus technical discovery across systems, warehouses, SaaS and backups — because everything downstream depends on it being real rather than declared. Then a gap assessment against the Act and the Rules, obligation by obligation, with each gap tied to a specific system, process or contract rather than answered from a questionnaire. Security testing follows, scoped at the systems the RoPA flagged, to produce the safeguards evidence. Maturity scoring per domain lets the board track movement between reviews instead of receiving a binary verdict. Finally a prioritised remediation roadmap, phased to 13 May 2027 and ordered by penalty exposure and lead time, with named owners rather than recommendations.

Two things distinguish an assessment that holds up. Prioritisation by exposure and lead time rather than ease: safeguards work carries the largest penalty and the longest remediation tail, so it starts first even though consent finishes faster. And the security testing is scoped from the data map — testing chosen any other way produces evidence about systems that may hold no personal data at all.

Where to Start This Quarter

Five things you can begin now
  • 01Inventory personal data in your top ten systems. Not all of them. An incomplete map that is honest beats a complete one that is aspirational.
  • 02Run one erasure end-to-end. Delete a real record, then hunt for surviving copies in the warehouse, backups and vendor platforms. What you find defines your retention workstream.
  • 03Establish whether you are likely an SDF. If plausible, start the DPO and audit conversations now — those run on hiring and procurement lead times.
  • 04List every processor touching personal data and check whether the contract flows down breach-notification timelines that let you meet your own. Most do not.
  • 05Ask what evidence you would produce if the Board asked today how you secure personal data. If the answer is a policy PDF, you have found your largest gap.

The teams that reach May 2027 in good shape are not the ones that deployed a consent tool early. They are the ones that mapped their data early, and let the map tell them what to fix.

How Adayptus Helps

Our DPDP assessment runs that sequence end to end: data discovery and RoPA, an evidenced gap assessment against the Act and the Rules, maturity scoring by domain, and a remediation roadmap phased to the deadline. Because we also operate as an offensive security team, the safeguards evidence is produced by actual testing rather than asserted in a policy — which matters most in the category carrying the highest penalty.

If you want to know where you genuinely stand, tell us what you process and we will come back with scope, timeline and an indicative quote. Related reading: the DPDP Rules 2025 roadmap to May 2027 and our guide to DPDP obligations and controls. Also relevant: GRC advisory, ISO 27001 implementation and policy framework design.

Frequently Asked Questions

Click any question to expand the answer.

QIs consent management enough for DPDP compliance?

No. Consent management establishes your lawful basis — itemised notice, valid capture, easy withdrawal, consent records. It does not address reasonable security safeguards, retention and erasure, Data Principal rights fulfilment, breach detection and notification, processor governance, cross-border transfer, or Significant Data Fiduciary duties. The two highest-penalty categories in the Act — failing to take reasonable security safeguards and failing to notify a breach — sit entirely outside what a consent platform does.

QWhat is a DPDP assessment?

A structured review of your processing against the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. It begins with data discovery and a Record of Processing Activities, assesses each obligation with evidence, substantiates security safeguards through actual testing, scores maturity by domain, and produces a prioritised remediation roadmap phased to the 13 May 2027 deadline. The mark of a useful assessment is that findings are tied to specific systems, processes and contracts rather than answered from a questionnaire.

QWhat are reasonable security safeguards under DPDP?

The Rules describe them illustratively: encryption, obfuscation, masking or tokenisation of personal data; access controls over the systems holding it; logging and monitoring able to detect unauthorised access; backups enabling recovery; and log retention for a defined period. Treat these as examples of a standard of care rather than an exhaustive list. The key point is that the obligation is evidentiary — after an incident what counts is demonstrable configuration state, test results and monitoring efficacy, not a policy asserting controls were required. This category carries the Act's highest penalty, up to ₹250 crore.

QWho is a Significant Data Fiduciary?

An entity the government designates as such, based on factors including the volume and sensitivity of personal data it processes and the risk to Data Principals. Designation brings enhanced duties: a Data Protection Officer based in India who reports to the board or governing body, an annual Data Protection Impact Assessment, an annual independent data audit, and algorithmic due diligence to verify that algorithmic systems do not pose a risk to Data Principals' rights. Because a board-reporting DPO is a hiring decision and an independent audit needs scope and evidence, organisations that plausibly qualify should build to the enhanced standard before designation rather than after.

QDoes using a data processor transfer our DPDP liability?

No. A Data Fiduciary may engage a Data Processor under a valid contract but remains accountable for the processing carried out on its behalf. If a vendor mishandles personal data you provided, the Data Protection Board's counterparty is you. This is why processor governance is a core assessment pillar: contracts must flow down security measures, breach-notification timelines that allow you to meet your own, erasure on termination, audit rights and control over sub-processors — and vendors handling the most sensitive or highest-volume data should be assessed properly rather than surveyed by questionnaire.


Share this Insight
CybersecurityRegulatory ComplianceAdayptus Intelligence
Peyush Baranwal

Peyush Baranwal

Senior Delivery Manager - Cyber Security, Adayptus

Peyush Baranwal is a Senior Delivery Manager at Adayptus Consulting with 11+ years of experience designing, implementing, and managing enterprise security programmes. His core expertise spans Vulnerability Assessment & Penetration Testing (VAPT), Application Security, and Security Operations - leading web, mobile, API, and infrastructure security assessments for CISOs and security teams across BFSI, healthcare, and SaaS. He focuses on measurable risk reduction, governance maturity, and operationalising detection-and-response capability. Outside work, Peyush is a passionate biker and part-time photographer.

Connect on LinkedIn
Regulatory Compliance

Get Compliance-Ready Without the Guesswork

Knowing the requirement is the easy part; evidencing it is the work. Tell us which framework you are working toward and we will come back with a gap view, timeline, and indicative cost.

  • Aligned to ISO 27001, SOC 2, RBI, SEBI and DPDP
  • Gap analysis with a prioritised remediation plan
  • Evidence and documentation support through audit
  • Covered by NDA from the first conversation

Prefer email? [email protected]

Request a scoping call

No obligation. A senior consultant replies — not a sales sequence.

Your details stay confidential. No spam — a consultant replies, not a sales sequence.