DPDP Consent Withdrawal: How to Make It as Easy as Giving Consent

Short answer: DPDP consent withdrawal is a person’s right to take back consent at any time, as easily as she gave it. Section 6(4) of the Digital Personal Data Protection Act, 2023 (DPDP Act) creates the right. Section 6(6) then requires the business to stop processing within a reasonable time and to make its Data Processors stop too. In practice, that means a visible withdrawal option, fast propagation to every system, and a record that proves it happened.
Most consent projects focus on collecting consent. However, withdrawal is where many flows fail. Typically, the opt-in is one tap, while the opt-out sits behind a login, an email or a call. This guide explains what the law requires for DPDP consent withdrawal, how to design it, how it flows through your systems, and how to prove it. It sits alongside our broader guide to DPDP consent management, which covers the full consent lifecycle.
What is DPDP consent withdrawal?
DPDP consent withdrawal is the act of a Data Principal taking back consent she gave for a specified purpose. It applies wherever consent is the basis for processing. It does not apply where you rely on another ground, such as a legitimate use under Section 7.
Importantly, withdrawal is purpose-specific. For example, a customer can withdraw consent for marketing while keeping consent for order updates. Therefore, your records must hold consent per purpose, not as a single yes or no.
What the DPDP Act and Rules require
Four provisions shape DPDP consent withdrawal:
- Section 6(4): the person may withdraw consent at any time, “with the ease of doing so being comparable to the ease with which such consent was given”.
- Section 6(5): the consequences of withdrawal are borne by the person. Also, withdrawal does not make earlier processing unlawful.
- Section 6(6): the business must, within a reasonable time, cease processing and cause its Data Processors to cease. The exception is processing that the Act, the Rules or another law requires or authorises.
- Rule 3(c): every notice must give a communication link, or other means, to withdraw consent with comparable ease.
In addition, Section 8(7) links withdrawal to erasure. Unless a law requires retention, the business must erase the data when consent is withdrawn and make its processors do the same. Meanwhile, Section 6(7) lets a person withdraw through a registered Consent Manager.
Legal requirement vs recommendation: the Act does not define “reasonable time” or “comparable ease” in numbers. The design choices below are our recommendations for meeting those standards in a way you can defend.
How DPDP consent withdrawal works across your systems

A working DPDP consent withdrawal flow usually has six steps:
- Request. The person uses the same channel where she consented, such as a preference centre, app setting or message reply.
- Light verification. A one-time password confirms it is her, without adding friction beyond the opt-in.
- Record update. The consent record marks the purpose as withdrawn, with a timestamp.
- Propagation. Events reach every system and processor that relies on that consent.
- Erasure check. Data held only for that purpose is erased, unless a law requires retention.
- Confirmation. The person receives confirmation, and the record stores each system’s acknowledgement.
A practical example
A fitness app collects consent for marketing emails and for sharing workout data with a partner. A user opens settings and switches off partner sharing. First, the app confirms with an OTP. Next, the consent record marks partner sharing as withdrawn. Then an event tells the partner, as a processor, to stop and erase the shared data. Finally, the partner confirms, and the user sees “Partner sharing stopped”. Her marketing consent stays unchanged, because she withdrew only one purpose.
Designing withdrawal to be as easy as consent
In short, the test in Section 6(4) is comparison. So measure your withdrawal flow against your consent flow, step by step.
- Same place. If consent was a checkbox on sign-up, withdrawal should sit in account settings, not in a support ticket.
- Same effort. If consent took one tap, withdrawal should not need five screens.
- Same language. If she consented in Hindi, offer withdrawal in Hindi too.
- No penalties by design. Explain real consequences, as Section 6(5) allows. However, avoid dark patterns, such as guilt-trip wording or hidden buttons.
Comparing approaches to DPDP consent withdrawal
| Approach | Strength | Weakness |
|---|---|---|
| Email or support request | No build effort | Rarely “comparable ease” |
| Per-tool unsubscribe links | Familiar to users | Does not reach other systems |
| Central preference centre with propagation | One action reaches every system | Needs integration work |
For most businesses, a central preference centre gives the most defensible DPDP consent withdrawal. That said, keep channel-level options, such as STOP replies, and feed them into the same central record.
Pros and cons of a central DPDP consent withdrawal flow
Pros:
- First, one action reaches every system and processor.
- Also, the record proves when each system stopped.
- Per-purpose control keeps other consents intact.
Cons:
- First, each system needs a connection or a scheduled sync.
- Verification must stay light, or it breaks comparable ease.
- Finally, retention exceptions need careful legal mapping.
DPDP consent withdrawal by channel
Consent reaches you through many channels, so withdrawal must too. Below, you can see how comparable ease looks in each one.
- Website: a persistent link to the preference centre, for example in the footer and in account settings.
- Mobile app: a privacy section in settings, reachable in the same number of taps as the original consent.
- SMS and WhatsApp: a STOP-style reply that updates the central record, not just the messaging tool.
- Email: an unsubscribe link that maps to the right purpose, rather than stopping all email.
- Call centre: an agent script and a form that writes directly to the consent record.
- Offline and branch: a short withdrawal form, with the same language options as the consent form.
In each case, the request should land in one central record. As a result, DPDP consent withdrawal from any channel reaches every system that relies on that consent.
Common mistakes
- Harder exit than entry. For example, consent is one tap, but withdrawal needs an email.
- All-or-nothing withdrawal. As a result, the person cannot withdraw a single purpose.
- Stopping only one tool. For instance, the email tool stops, but WhatsApp and the partner continue.
- Forgetting processors. Section 6(6) requires them to stop as well.
- No confirmation. Consequently, neither the person nor the business can prove it happened.
How we measure success
These indicators track DPDP consent withdrawal quality. We do not publish benchmark numbers for them.
- Effort parity: steps to withdraw compared with steps to consent, per channel.
- Propagation time: time from request to the last system confirming it stopped.
- Processor confirmation: share of processor stop instructions confirmed.
- Purpose precision: share of withdrawals that affected only the chosen purpose.
- Complaints: grievances about processing after withdrawal.
Frequently asked questions
Can a person withdraw consent at any time?
Yes. Section 6(4) allows withdrawal at any time, with ease comparable to giving consent.
How quickly must we stop processing?
Section 6(6) says within a reasonable time. The Act does not set a number, so aim for the fastest your systems can reliably achieve, and record it.
Does withdrawal make past processing unlawful?
No. Section 6(5) says withdrawal does not affect processing done lawfully before it.
Must we delete data after withdrawal?
Usually, yes. Section 8(7) requires erasure after withdrawal unless a law requires you to keep the data.
Can we ask for verification before withdrawal?
Light verification, such as an OTP, is reasonable. However, it should not make withdrawal harder than consent was.
Can a Consent Manager withdraw on someone’s behalf?
Yes. Section 6(7) lets a person give, manage, review or withdraw consent through a registered Consent Manager.
When do these rules apply?
The core consent obligations and Rule 3 commence on 13 May 2027.
Summary and next step
In short, DPDP consent withdrawal must be easy, specific and complete. Put the option where consent was given, keep the effort equal, propagate to every system and processor, erase where required, and record every step.
ProtectComply’s consent module includes a hosted preference centre, per-purpose consent and OTP-gated withdrawal, with records that show when consent changed. See how withdrawal works, explore the product modules, or request a walkthrough of your current opt-out flow.
Published by Jupinder Singh Bedi, CEO and Co-Founder, ProtectComply. SEO: Yatin Chaudhary. Legal references: Digital Personal Data Protection Act, 2023, Sections 6(4) to 6(7), 7 and 8(7); Digital Personal Data Protection Rules, 2025, Rules 1 and 3. This article is general information, not legal advice.