Consent & Notice Architecture
The DPDP Act is built around consent to a degree that surprises GDPR veterans: for most commercial processing, consent is not one lawful basis among several — it is effectively the basis, and the Act specifies its qualities exactly. Notice must be clear, itemised, and available in English plus twenty-two scheduled Indian languages on request; consent must be free, specific, informed, and unambiguous; withdrawal must be as easy as the giving was; and the records proving all of this must exist when the Data Protection Board asks. A checkbox above a privacy-policy link satisfies none of it.
We build consent as product infrastructure rather than legal decoration. Notices are layered and written in plain language, engineered into the actual user journeys where data is collected; consent capture is granular by purpose, with records that timestamp what was shown and what was agreed; withdrawal flows are designed to the same standard as acquisition flows — because the Act demands symmetry; and the lifecycle mechanics — re-consent when purposes change, cessation when consent withdraws, verifiable parental consent where children's data appears — are specified at the level your engineers can build and your auditors can test.
What this covers
- Layered, plain-language notices engineered into real user journeys, with multilingual delivery strategy.
- Purpose-granular consent capture with evidentiary records.
- Withdrawal flows as frictionless as acquisition — the symmetry the Act requires.
- Verifiable parental consent design for any children's data.
- Lifecycle mechanics: re-consent, purpose change, and processing cessation, specified for engineering.
Who needs this
Product and platform companies collecting Indian user data; HR functions processing employee data on consent; and GDPR-mature teams discovering that India's consent bar sits differently.
How we deliver
- Consent flows designed with your product and engineering teams, not at them.
- Notices layered, plain-language, and multilingual by strategy.
- Lifecycle mechanics specified at build level: withdrawal, re-consent, cessation.
Why A2 Consultants
We specify consent at the level engineers implement and auditors test — because under this Act, consent is infrastructure, and infrastructure drawn only in policy documents processes nothing.
Engagement & what to expect
Architecture engagements run with your product cycle: requirements specified over three to five weeks — flows, notices, records, and lifecycle mechanics documented at build level — then implementation support through your engineering sprints, with our review at design and pre-release gates. Multilingual notice strategy and copy support are included where consumer scale demands. HR-side consent runs as a parallel, faster workstream. The engagement closes with a tested architecture and its documentation: what was built, why it satisfies the Act, and how to change it without breaking compliance.
Under this Act, consent is infrastructure — build it into the product, because policy documents do not process data.