← All posts

17 Aug 2026 · 4 min read

What Is a Consent Artefact Under the DPDP Act?

What Is a Consent Artefact Under the DPDP Act?

A consent artefact is a machine-readable, verifiable record of a consent: who gave it, to whom, for which data, for which purpose, and for how long.

Think of it as the receipt for consent — one that software can read, verify, and act on, rather than a checkbox log a human has to interpret.


Where the Idea Comes From

The consent artefact pattern was popularised in India by DEPA — the Data Empowerment and Protection Architecture — where it powers the Account Aggregator ecosystem in financial services. Every data-sharing event is authorised by a signed, structured artefact instead of an ad-hoc permission.

The DPDP Act brings the same philosophy to all personal data. It defines the Consent Manager in §6 read with §2(g): an entity registered with the Data Protection Board that lets a Data Principal give, manage, review, and withdraw consent through an accessible, transparent, interoperable platform.

Interoperable is the key word — and interoperability between consent systems is exactly what the artefact format exists to provide.


What a Consent Artefact Typically Contains


Why It Matters for Your Compliance Programme

Section 6 requires consent that is free, specific, informed, unconditional and unambiguous — and as easy to withdraw as it was to give. When an inquiry or audit comes, “we had a checkbox” is a claim. An artefact is evidence.

Structured consent records also make withdrawal propagation practical: revoke the artefact, and every downstream system keyed to it knows to stop processing.


How ProtectComply Handles It

ProtectComply records every consent as a structured, immutable, purpose-linked record — and speaks DEPA Rule 4 consent-as-a-service interoperability for ecosystems that exchange artefacts.

Related reading: what a Consent Manager is under the DPDP Act · DPDP consent management: what Indian companies must build · the best DPDP platforms in India.