Skip to content

Advocate Nitin Kumar Vashista

Home » Blog » Consent Withdrawal Under DPDP Act: What Businesses Are Actually Required to Do

Consent Withdrawal Under DPDP Act: What Businesses Are Actually Required to Do

Consent Withdrawal Under DPDP Act What Businesses Are Actually Required to Do

A founder running a fintech startup out of Gurugram messaged me last month with a fairly simple question. “A customer emailed us asking to withdraw consent and delete his data. Do we have to do anything, or can we just… not reply?”

I get variations of this question a lot. Businesses understand they need to collect consent. Very few have actually thought through what happens when someone wants to take it back.

Under the DPDP Act, that part isn’t optional. And it’s not something you can quietly ignore either.

Withdrawal Has to Be as Easy as Giving Consent

This is the part that catches most businesses off guard. The DPDP Act doesn’t just say users can withdraw consent — it says the process has to be roughly as simple as the process they used to give it in the first place.

So if someone signed up for your platform with a single tap on “I agree,” you can’t make them send a written letter, call a helpline, or fill out a five-page form to withdraw that same consent. If the door in was easy, the door out has to be too.

A lot of Indian businesses still get this backwards. They’ll have a one-click signup flow and then a withdrawal process that requires emailing a support address, waiting for a human to respond, and following up twice before anything actually happens. That mismatch is exactly what the law is trying to prevent.

What Happens Once Someone Withdraws Consent

Withdrawal isn’t just a formality you record somewhere and move on from. Once a user withdraws consent, you need to stop processing their data for that specific purpose going forward.

This gets tricky in practice. Say a customer withdraws consent for marketing emails but still has an active account with you for order processing. You can’t lump everything together and either keep using all their data or delete it entirely. Consent is purpose-specific, which means withdrawal is too. You stop what they’ve withdrawn consent for, and continue what’s still legitimately needed, like order fulfillment or legal record-keeping.

Past Processing Stays Valid

Here’s something that offers a bit of relief for businesses. Withdrawing consent doesn’t make everything you did with that data before the withdrawal illegal. If you processed the data lawfully while consent was active, that processing remains valid. Withdrawal only affects what happens going forward.

That said, don’t take this as a free pass to slow-walk the withdrawal request. The law expects reasonably prompt action once a request comes in, not a “we’ll get to it eventually” approach.

Build a Real Process, Not Just a Form

A lot of businesses in India think they’ve solved this problem by adding a checkbox on their website that says “withdraw consent” and calling it done. That’s a start, but it’s not the whole picture.

You need an actual internal process behind that checkbox:

A clear point of contact. Whether it’s your Grievance Officer, a dedicated privacy email, or a form on your website, users need to know exactly where to go.

A defined internal workflow. Someone on your team needs to own what happens once a withdrawal request comes in — updating databases, informing relevant vendors, stopping active campaigns.

A reasonable timeline. Set an internal SLA for how quickly withdrawal requests get processed, and actually stick to it.

Vendor coordination. If you’ve shared that person’s data with a third-party vendor (say, an email marketing platform or a CRM), you need a way to inform them too. This is exactly why your Data Processing Agreements with vendors matter — a good DPA should already cover how a vendor handles instructions like this.

Documentation. Keep a record of when the request came in, what action was taken, and when it was completed. If the Data Protection Board ever asks how you handle these requests, you’ll want a paper trail.

What This Looks Like for a Small Business

You don’t need an elaborate tech system to get this right, especially if you’re a smaller business. A simple, well-documented process — even a shared spreadsheet tracking requests and their status — is far better than no process at all. What matters is that the process actually exists, works consistently, and someone is accountable for running it.

Getting Consent Withdrawal Right

Businesses often put a lot of effort into the consent collection side — a polished signup flow, a well-worded checkbox, maybe even a consent management platform. Then they treat withdrawal as an afterthought. Under the DPDP Act, that imbalance is exactly what gets flagged.

If you’re not sure your current consent withdrawal process would hold up to scrutiny, it’s worth checking before it becomes an actual complaint. Book a free consultation and we’ll walk through your setup together.

Leave a Reply

Your email address will not be published. Required fields are marked *