Data Privacy & User Rights

Consent Withdrawal Under DPDP and GDPR: What Websites Must Support

What websites must build for consent withdrawal under DPDP Section 6 and GDPR Article 7: comparable ease, cease-processing pipelines, processors, and test plans.

Working summary: If consent is how you lawfully process personal data, withdrawal is not optional product polish. Under DPDP Section 6 and GDPR Article 7, people must withdraw as easily as they gave consent, and you must stop consent-based processing (and cause processors to stop) within the rules that follow.

  • Comparable ease: One-click banner consent needs one-click preference-centre withdrawal, not email-only or phone queues.
  • DPDP Section 6(6): Cease and cause processors to cease within a reasonable time unless other law still authorises processing.
  • Purpose-level controls: Let users stop marketing without wiping consent needed for an active paid service where grounds differ.
  • Cookies: Non-essential tags must stop after withdrawal until consent is given again.
  • Test: Give and withdraw in one click; confirm ESP, ad accounts, and audit logs before go-live.

If consent is how you lawfully process personal data, withdrawal is not optional product polish. Under both the Digital Personal Data Protection Act, 2023 (DPDP Act) and the GDPR, people must be able to withdraw consent as easily as they gave it, and you must stop consent-based processing within the rules that follow.

This guide focuses on what websites and apps must support in UI, backend, and vendor flows. For the wider consent and rights comparison, see GDPR vs DPDP: User Rights and Consent Compared. For notice wording that must describe withdrawal, see DPDP Act User Rights and How to Write a Privacy Policy That Covers User Rights. For fulfilment tooling after someone also asks for erasure, see How to Handle DSARs with OneTrust.

DPDP Sections 5 and 6 (notice and consent, including withdrawal) are scheduled to commence on once Rules and commencement are notified under forthcoming MeitY commencement notifications. GDPR Article 7 withdrawal duties already apply where GDPR covers your processing.

What the law requires

DPDP Act Section 6

  • Section 6(4): where consent is the basis of processing, the Data Principal may withdraw consent at any time, with ease comparable to the ease with which consent was given.
  • Section 6(5): consequences of withdrawal are borne by the Data Principal; withdrawal does not make earlier consent-based processing unlawful.
  • Section 6(6): after withdrawal, the Data Fiduciary shall, within a reasonable time, cease and cause its Data Processors to cease processing that personal data, unless processing without consent is required or authorised under the Act, the rules, or any other law in force in India.
  • Section 6(7): consent may also be given, managed, reviewed, or withdrawn through a Consent Manager.

The Act’s illustration under Section 6(5) is useful for product design: if someone consented so you could fulfil a paid order, withdrawal may let you stop new orders on the app, but you may still process data needed to complete the order already placed and paid for.

Section 5 and forthcoming Rules Rule 3 require the notice (and the link or means you publish) to explain how to withdraw consent with comparable ease, alongside rights exercise and Board complaints.

GDPR Article 7 and transparency

  • Article 7(3): the data subject may withdraw consent at any time; withdrawal does not affect the lawfulness of processing based on consent before withdrawal; the person must be informed of the right before giving consent; withdrawal must be as easy as giving consent.
  • Article 7(1): the controller must be able to demonstrate consent.
  • Articles 13(2)(c) and 14: where processing is based on consent, tell the person about the right to withdraw at any time without affecting earlier lawful processing.
  • Article 17(1)(b): when consent is withdrawn and there is no other legal ground, erasure without undue delay is one of the grounds for the right to erasure (subject to Article 17(3) exceptions).

EDPB and supervisory practice treat “as easy as” as a UI test: if consent was one click or one toggle, withdrawal should not require a posted letter, a phone queue, or a buried multi-step form.

Comparable ease: product rules of thumb

How consent was given Withdrawal path that usually matches ease Paths that usually fail the test
One banner click or toggle Same preference centre, one click or toggle off Email-only, business-hours phone, CAPTCHA maze
Account checkbox at signup Account settings toggle; confirmation optional but light Require identity documents for every marketing opt-out
In-app permission dialog In-app settings screen with the same permission Force uninstall to stop processing
Consent Manager flow Same Consent Manager review/withdraw tools (Section 6(7)) Withdraw only via a different channel than the Manager

You may still verify identity for high-risk changes that look like account takeover. Keep marketing and analytics withdrawal lighter than erasure of payment records. Do not invent friction that exists only to retain consent.

What websites must support (checklist)

1. Discoverable entry points

  1. Link “Withdraw consent” or “Privacy choices” from the privacy notice (Rule 3(c); GDPR Arts 13/14).
  2. Mirror the link in the cookie / consent preference centre footer.
  3. Offer an authenticated account path when the user has a login.
  4. Offer an email or form path for users without a session, with proportionate verification.

2. Purpose-level controls

  1. Store consent per purpose (and per brand or property if you operate several).
  2. Let users withdraw one purpose (for example, marketing) without wiping consent needed for an active paid service, where the grounds differ.
  3. Show which processing continues on another basis after withdrawal (contract, legal obligation, or a documented Section 7 / Article 6 basis), in plain language.

3. Backend cease-processing pipeline

  1. On withdrawal, flip consent flags and suppress consent-based jobs within a defined “reasonable time” SLA (minutes to a few days depending on system complexity; document it).
  2. Stop outbound marketing, non-essential analytics, and secondary profiling tied to that consent.
  3. Propagate cessation to Data Processors under Section 6(6) and your processor contracts (GDPR Article 28 instructions likewise).
  4. Keep an immutable audit log: who withdrew, when, which purposes, which systems acknowledged stop.

4. Interaction with erasure

  1. Withdrawal is not automatically a full erase request, but GDPR Article 17(1)(b) may require erasure when consent ends and no other ground remains.
  2. Under DPDP, Section 8(7) separately requires erasure when consent is withdrawn or the specified purpose is no longer served, unless law requires retention, and requires processors to erase data you made available.
  3. Offer a clear choice in the UI: “Stop marketing” versus “Delete my account / erase my data”, and route the second through your DSAR process.

5. Consequences messaging

  1. Before or at withdrawal, say what will stop (newsletters, personalisation) and what may continue (security logs, invoices, fulfilling open orders), matching Section 6(5) and Article 7(3).
  2. Do not threaten unrelated penalties. Consent should remain freely given; forced detriment for refusing optional processing undermines consent quality (see GDPR Article 7(4) and Recital 42 themes).

6. Cookies and similar technologies

  1. Non-essential cookies that relied on consent must stop loading after withdrawal until consent is given again.
  2. Reload or sync tags so server-side and client-side pixels respect the new state.
  3. Keep a record for demonstrations under GDPR Article 7(1) and DPDP Section 6(10).

Worked website flows

  1. User opens Settings > Privacy.
  2. Toggles “Email offers” off.
  3. API records withdrawal timestamp and purpose ID.
  4. ESP suppression list updates; journeys pause.
  5. UI confirms: “You will not get offer emails. Order and security messages may continue.”
  1. User opens cookie settings from the footer (same number of steps as accepting on the banner).
  2. Turns analytics off.
  3. CMP writes denial; tag manager blocks analytics tags.
  4. Server-side collectors drop or anonymise events for that client ID where feasible.
  1. User withdraws consent for processing needed to run the free personalised service.
  2. You explain that the personalised service will stop (Section 6(5) consequence).
  3. You cease secondary processing and, where Section 8(7) / Article 17 require, erase or anonymise data not needed for law or remaining bases.
  4. You keep data required for legal claims or tax with a documented basis.

India timing notes

  • Build and test withdrawal before once Rules and commencement are notified, when Sections 5 and 6 are scheduled to commence.
  • Section 5(2) also requires a notice for pre-commencement consent as soon as reasonably practicable after commencement, including how to withdraw and how to use grievance and Board channels.
  • Consent Manager registration under Section 6(9) follows the earlier one-year commencement track in forthcoming MeitY commencement notifications (a future Consent Manager registration date once notified).

Test plan before go-live

  1. Give consent in one click; withdraw in one click from the preference centre.
  2. Confirm processors stop within your SLA; spot-check ESP and ad accounts.
  3. Confirm essential service messages still send when a separate basis applies.
  4. Confirm audit logs show the withdrawal event.
  5. Confirm privacy notice and banner both describe the path.
  6. Confirm mobile WebView and native app settings stay in sync.

Sources

  • Digital Personal Data Protection Act, 2023, Sections 5, 6, 8(7): MeitY PDF; India Code.
  • forthcoming DPDP Rules from MeitY, Rule 3; MeitY Rules page.
  • MeitY commencement notification forthcoming MeitY commencement notifications, a future MeitY notification date.
  • Regulation (EU) 2016/679, Articles 7, 13, 14, 17: EUR-Lex.

Disclaimer

This article was prepared by Imran using publicly available information. It is for general education only and is not legal advice. Do not rely on it alone when implementing cookie compliance, DSAR handling, consent flows, privacy policies, or other privacy and data-protection controls. Consult your own legal counsel for advice that fits your business, jurisdictions, and systems.

Last updated on 6 September 2026

Share this article

Leave a Reply

Your email address will not be published. Required fields are marked *