DPDP Act Best Practices For Consent Management
The Data Protection Bill (DP Bill), 2019, is a comprehensive legislation that seeks to govern the collection, use, storage, and transfer of personal data in India. The Bill is expected to be passed by the Parliament soon, and it is important for businesses to start preparing for its implementation.
One of the key aspects of the DP Bill is consent. Under the Bill, businesses must obtain consent from individuals before collecting, using, or storing their personal data. Consent must be freely given, specific, informed, and unambiguous. Businesses must also provide individuals with the option to withdraw their consent at any time.
Managing consent under the DP Bill can be challenging, but it is essential to ensure compliance with the law. Here are some best practices for managing consent:
1. Obtain consent before collecting, using, or storing personal data
Businesses must obtain consent from individuals before collecting, using, or storing their personal data. Consent must be freely given, specific, informed, and unambiguous.
To obtain consent, businesses should provide individuals with a clear and concise privacy notice that explains how their personal data will be used. The privacy notice should also inform individuals of their right to withdraw their consent at any time.
Businesses should also provide individuals with the option to give or withdraw their consent in a clear and easy way. This can be done through a variety of methods, such as checkboxes, opt-in/opt-out forms, or preference centers.
2. Make it easy for individuals to withdraw their consent
Individuals must have the right to withdraw their consent at any time. Businesses should make it easy for individuals to withdraw their consent by providing them with a clear and simple process to do so.
For example, businesses can provide individuals with the option to withdraw their consent through a link in the privacy notice, through their account settings, or by contacting customer support.
3. Keep a record of consent
Businesses must keep a record of consent for each individual whose personal data they collect, use, or store. This record should include the date and time that consent was given, the specific purpose for which consent was given, and the method by which consent was given.
Keeping a record of consent is important for demonstrating compliance with the DP Bill. It can also be helpful in resolving disputes with individuals about whether they gave consent and for what purpose.
4. Provide individuals with access to their personal data
Individuals have the right to access their personal data that is collected, used, or stored by businesses. Businesses must provide individuals with a clear and easy way to access their personal data.
For example, businesses can provide individuals with a link in the privacy notice to their account portal, where they can view and manage their personal data.
5. Protect personal data from unauthorized access, use, or disclosure
Businesses must take appropriate measures to protect personal data from unauthorized access, use, or disclosure. This includes implementing technical and organizational security measures.
Businesses should also have a process in place for responding to data breaches and other security incidents.
Conclusion
Managing consent under the DP Bill is essential to ensure compliance with the law. By following the best practices outlined above, businesses can minimize the risk of violating the law and protect the privacy of their customers.
















