Surviving a DPB Consent Notice: The Evidence Trail Most Indian Companies Don’t Have

  • Loading...

Ask any privacy head in India the same question twice and you’ll usually get two different answers. Ask “do we have valid consent from our customers?” and you’ll hear a confident yes. Ask “can you show me, right now, exactly what one specific customer agreed to, when, and through which channel?” and the confidence tends to evaporate.

Get a callback

That gap — between believing you’re compliant and being able to prove it on demand — is where most organisations will actually get tested under the Digital Personal Data Protection Act. Not on whether their privacy policy reads well. On whether they can produce a receipt.

The uncomfortable truth about consent under DPDP

Consent under the DPDP Act isn’t a one-time checkbox event. It’s a claim you have to be able to substantiate for as long as you keep processing someone’s data on the strength of it. Every marketing email, every cross-sell call, every data share with a partner rests on an assumption: that this specific person, at this specific time, agreed to this specific thing.

The Data Protection Board doesn’t investigate assumptions. It investigates records. And when a complaint lands — someone says they never opted in, or that they withdrew consent and kept getting messages anyway — the Board’s questions will be pointed and specific: What did this person see? When did they act? What happened after they withdrew?

If your answer to any of those is “our policy says we handle that correctly,” you’ve already lost ground. Policy tells the Board what you intended. It says nothing about what you did.

Why “we have a privacy policy” isn’t a defence

There’s a natural instinct to treat compliance as a documentation exercise — write the right policy, get it approved by legal, publish it, done. But a privacy policy is a promise, not proof of performance. It’s the equivalent of a company saying “our safety procedures are excellent” without being able to show a single inspection log.

What actually holds up in front of a regulator is a chain of evidence that connects three very different things:

What you told people. The exact wording and design of the consent screen, call script, or form that existed on the day in question — not today’s version, the version that was live then.

What your systems actually did. How that consent choice was captured, stored, and enforced — the configuration of your CRM, your marketing tool, your call-centre software, your contracts with vendors who touch the same data.

What happened to this specific person. A dated, timestamped record of their consent, any withdrawal, and whether your systems actually stopped processing their data when they asked you to.

Most companies have fragments of all three scattered across different teams and tools. Almost none have them connected. And an inquiry doesn’t care how good your intentions were in isolation — it cares whether the three layers tell the same, consistent story.

The places evidence quietly goes missing

If you actually tried to reconstruct one customer’s consent history today, here’s where you’d likely hit walls:

  • Old versions of your consent screens are gone. Someone redesigned the sign-up flow eight months ago, and nobody archived what the previous version looked like. You can’t prove what a complainant actually saw.
  • Channels don’t talk to each other. A customer unsubscribes from email. Nobody told the SMS platform or the WhatsApp vendor, so the messages kept coming — and now that’s evidence against you, not for you.
  • Verbal consent lives in someone’s memory, or a spreadsheet. Call-centre agents follow a script, in theory. Whether they actually said the required words to this particular customer, on this particular call, may only exist as a recording nobody’s indexed.
  • Third-party leads arrive with no paper trail. A partner hands you a list of “opted-in” contacts. You have no record of what those people actually agreed to, or when.
  • Withdrawals stop at the front door. Someone opts out on your website, but the instruction never reaches the processor or Consent Manager quietly running campaigns on your behalf downstream.

Individually, each of these looks like a minor operational gap. Stacked together and viewed by a regulator investigating a specific complaint, they look like a pattern of not taking consent seriously.

Building the muscle before you need it

The organisations that will handle a DPB notice well aren’t the ones with the most elaborate policy documents. They’re the ones who’ve quietly done three unglamorous things in advance.

They know where every consent record actually lives. Not in theory — in practice. If asked to pull one customer’s full consent and withdrawal history across web, app, call centre, and any partner touching their data, someone in the organisation could do it in hours, not weeks.

They’ve assigned an owner to every piece of that trail. Not “the compliance team” in the abstract, but a named function responsible for the web consent logs, a named function for the CRM opt-in fields, a named function for call recordings, and a named function for what vendors report back. When ownership is vague, retrieval is slow, and slow retrieval reads badly to a regulator working against a clock.

They rehearse. Periodically, someone picks a real campaign or product and asks: if the Board asked about this tomorrow, could we produce a complete, defensible answer within the timeline they’d give us? Running that drill before it’s real is the difference between a controlled response and a scramble.

What actually happens in the first days of an inquiry

When a notice does arrive, speed matters — but speed without accuracy is worse than no response at all. A few principles tend to separate organisations that come through an inquiry intact from those that don’t:

  1. Stop and preserve before you explain. The instinct is to start drafting a response immediately. The better first move is to freeze the relevant systems and data so nothing gets overwritten while you investigate — a deleted log looks far worse than an incomplete one.
  2. Put one person in charge of pulling the story together. Consent evidence sits across legal, product, marketing, and vendors. Someone needs the authority to pull all of it into a single, coherent account rather than letting each team answer for its own slice.
  3. Match every claim to a specific record. “We believe consent was properly obtained” is not an answer. “Here is the consent screen shown on this date, here is the timestamped log entry, here is the withdrawal record” is an answer.
  4. Say plainly what you don’t have. Regulators respond better to organisations that identify a gap and explain how they’re fixing it than to ones who paper over uncertainty with confident language that later unravels.

The real cost of getting this wrong

The risk here isn’t only the penalty attached to a specific finding. It’s the operational chaos of discovering, mid-inquiry, that you can’t separate the customers you handled correctly from the ones you didn’t — which forces broad, disruptive halts to campaigns and processing that a cleaner evidence trail would have let you avoid entirely.

Treating consent evidence as an operational discipline — not a document you wrote once — is what turns a regulatory notice from an existential threat into a manageable, if uncomfortable, conversation. The companies that get there aren’t the ones with the fanciest policy language. They’re the ones who can answer, on any given Tuesday, exactly what one customer agreed to and prove it.

Appointment