← All posts

29 Sep 2026

DPDP Consent Withdrawal: How to Make It as Easy as Giving Consent

Short answer: DPDP consent withdrawal is a person’s right to take back consent at any time, as easily as she gave it. Section 6(4) of the Digital Personal Data Protection Act, 2023 (DPDP Act) creates the right. Section 6(6) then requires the business to stop processing within a reasonable time and to make its Data Processors stop too. In practice, that means a visible withdrawal option, fast propagation to every system, and a record that proves it happened.

Most consent projects focus on collecting consent. However, withdrawal is where many flows fail. Typically, the opt-in is one tap, while the opt-out sits behind a login, an email or a call. This guide explains what the law requires for DPDP consent withdrawal, how to design it, how it flows through your systems, and how to prove it. It sits alongside our broader guide to DPDP consent management, which covers the full consent lifecycle.

What is DPDP consent withdrawal?

DPDP consent withdrawal is the act of a Data Principal taking back consent she gave for a specified purpose. It applies wherever consent is the basis for processing. It does not apply where you rely on another ground, such as a legitimate use under Section 7.

Importantly, withdrawal is purpose-specific. For example, a customer can withdraw consent for marketing while keeping consent for order updates. Therefore, your records must hold consent per purpose, not as a single yes or no.

What the DPDP Act and Rules require

Four provisions shape DPDP consent withdrawal:

In addition, Section 8(7) links withdrawal to erasure. Unless a law requires retention, the business must erase the data when consent is withdrawn and make its processors do the same. Meanwhile, Section 6(7) lets a person withdraw through a registered Consent Manager.

Legal requirement vs recommendation: the Act does not define “reasonable time” or “comparable ease” in numbers. The design choices below are our recommendations for meeting those standards in a way you can defend.

How DPDP consent withdrawal works across your systems

DPDP consent withdrawal flow: withdraw request, identity check, consent record update, propagation to systems and processors, erasure where required, and confirmation to the person
A withdrawal is only complete when every system and processor has acted and the record shows it.

A working DPDP consent withdrawal flow usually has six steps:

  1. Request. The person uses the same channel where she consented, such as a preference centre, app setting or message reply.
  2. Light verification. A one-time password confirms it is her, without adding friction beyond the opt-in.
  3. Record update. The consent record marks the purpose as withdrawn, with a timestamp.
  4. Propagation. Events reach every system and processor that relies on that consent.
  5. Erasure check. Data held only for that purpose is erased, unless a law requires retention.
  6. Confirmation. The person receives confirmation, and the record stores each system’s acknowledgement.

A practical example

A fitness app collects consent for marketing emails and for sharing workout data with a partner. A user opens settings and switches off partner sharing. First, the app confirms with an OTP. Next, the consent record marks partner sharing as withdrawn. Then an event tells the partner, as a processor, to stop and erase the shared data. Finally, the partner confirms, and the user sees “Partner sharing stopped”. Her marketing consent stays unchanged, because she withdrew only one purpose.

Designing withdrawal to be as easy as consent

In short, the test in Section 6(4) is comparison. So measure your withdrawal flow against your consent flow, step by step.

Comparing approaches to DPDP consent withdrawal

Approach Strength Weakness
Email or support request No build effort Rarely “comparable ease”
Per-tool unsubscribe links Familiar to users Does not reach other systems
Central preference centre with propagation One action reaches every system Needs integration work

For most businesses, a central preference centre gives the most defensible DPDP consent withdrawal. That said, keep channel-level options, such as STOP replies, and feed them into the same central record.

Pros and cons of a central DPDP consent withdrawal flow

Pros:

Cons:

DPDP consent withdrawal by channel

Consent reaches you through many channels, so withdrawal must too. Below, you can see how comparable ease looks in each one.

In each case, the request should land in one central record. As a result, DPDP consent withdrawal from any channel reaches every system that relies on that consent.

Common mistakes

How we measure success

These indicators track DPDP consent withdrawal quality. We do not publish benchmark numbers for them.

Frequently asked questions

Can a person withdraw consent at any time?

Yes. Section 6(4) allows withdrawal at any time, with ease comparable to giving consent.

How quickly must we stop processing?

Section 6(6) says within a reasonable time. The Act does not set a number, so aim for the fastest your systems can reliably achieve, and record it.

Does withdrawal make past processing unlawful?

No. Section 6(5) says withdrawal does not affect processing done lawfully before it.

Must we delete data after withdrawal?

Usually, yes. Section 8(7) requires erasure after withdrawal unless a law requires you to keep the data.

Can we ask for verification before withdrawal?

Light verification, such as an OTP, is reasonable. However, it should not make withdrawal harder than consent was.

Can a Consent Manager withdraw on someone’s behalf?

Yes. Section 6(7) lets a person give, manage, review or withdraw consent through a registered Consent Manager.

When do these rules apply?

The core consent obligations and Rule 3 commence on 13 May 2027.

Summary and next step

In short, DPDP consent withdrawal must be easy, specific and complete. Put the option where consent was given, keep the effort equal, propagate to every system and processor, erase where required, and record every step.

ProtectComply’s consent module includes a hosted preference centre, per-purpose consent and OTP-gated withdrawal, with records that show when consent changed. See how withdrawal works, explore the product modules, or request a walkthrough of your current opt-out flow.

Published by Jupinder Singh Bedi, CEO and Co-Founder, ProtectComply. SEO: Yatin Chaudhary. Legal references: Digital Personal Data Protection Act, 2023, Sections 6(4) to 6(7), 7 and 8(7); Digital Personal Data Protection Rules, 2025, Rules 1 and 3. This article is general information, not legal advice.