Government of India | Ministry of Electronics & IT

Consent Management Framework

Interactive explorer for the Business Requirement Document (BRD) under the Digital Personal Data Protection (DPDP) Act, 2023

5
Lifecycle Stages
4
Key Stakeholders
13+
Functional Modules
100%
DPDP Compliant

Introduction & Objectives

The Business Requirements Document (BRD) for the Consent Management System (CMS) outlines the objectives and functionalities designed to align with the Digital Personal Data Protection (DPDP) Act, 2023.

As personal data protection becomes increasingly critical, organizations face growing challenges in managing consents transparently while maintaining regulatory compliance. The CMS addresses these challenges by enabling seamless consent management across its lifecycle.

"This document serves as a guideline for the development and deployment of a system that empowers Data Principals to exercise their rights over their personal data."

Core Objectives

Comprehensive Consent Lifecycle

Facilitate the full lifecycle: collection, validation, modification, renewal and withdrawal.

Empower Data Principals

User-centric platform for viewing, managing and controlling consent preferences.

Ensure DPDP Compliance

Strict adherence to regulations including purpose limitation and secure processing.

Key Stakeholders & Responsibilities

Understanding the roles and responsibilities of each entity in the consent ecosystem

Data Principal

The individual to whom the personal data relates.

  • Right to give consent
  • Manage consent preferences
  • Withdraw consent anytime
  • Exercise data rights

Data Fiduciary

Person/entity determining purpose and means of processing.

  • Obtain lawful consent
  • Manage consent compliance
  • Validate before processing
  • Cease on withdrawal

Data Processor

Processes personal data on behalf of the Data Fiduciary.

  • Follow fiduciary instructions
  • Secure data handling
  • Real-time sync with CMS
  • Immediate processing halt

Data Protection Officer

Primary compliance authority overseeing DPDP adherence.

  • Oversee compliance
  • Handle escalations
  • Audit trail review
  • Grievance redressal

Consent Data Flow

Data Principal
Grants/Withdraws Consent
CMS
Consent Manager
Validates & Stores
Data Fiduciary
Processes Data

Consent Management Lifecycle

The core framework comprising five critical stages from collection to withdrawal

4.1.1 Consent Collection

Enable Data Fiduciaries to explicitly collect purpose-specific and lawful consent from Data Principals.

Primary Usage DPDP Compliant
Actors
Data Principal, Data Fiduciary, CMS
Trigger
Service request requiring personal data collection
Pre-Conditions
CMS configured, User interacting with DF platform

Workflow Steps

Functional Requirements

User-Friendly Interface

Accessible, intuitive design with WCAG compliance for users with disabilities.

Purpose-Specific Consent

Separate consent for each distinct purpose. No "bundled consent" allowed.

Granular Consent

Allow users to provide or withhold consent for each purpose separately.

Explicit Action

Clear affirmative action required (e.g., "I Agree"). No pre-checked options.

Multi-Language Support

English + Eighth Schedule languages of the Constitution of India.

Metadata Logging

User ID, Timestamp, Purpose ID(s), Consent status, Language preference.

Business Rules

1.Purpose-Specific: No blanket agreements
2.Explicit Action: Affirmative user action required
3.Revocability: Consent must be revocable anytime
4.Transparency: Clear info on use, retention, rights
5.Granular: Consent/decline per purpose independently

4.3 User Dashboard

Empowering Data Principals with transparency and control

Purpose Fiduciary Date Expiry Status
Account Creation GovPortal India 2026-01-15 2027-01-15 Active
Marketing Emails GovPortal India 2026-02-20 2027-02-20 Withdrawn
Analytics DataInsights Pvt 2025-06-10 2026-06-10 Expired

4.4 Consent Notifications

Real-time alerts ensuring transparency for all stakeholders

User Notifications

Consent Approved
Confirmation when consent is successfully recorded
Email SMS In-App
Withdrawal Confirmation
Immediate confirmation with service impact details
Renewal Reminders
30 days before expiry with seamless renewal link
Processing Updates
Status on data erasure, correction requests

Fiduciary & Processor Alerts

// API Alert Payload
{
"event": "CONSENT_WITHDRAWN",
"userId": "DP_12345",
"purposeId": "MARKETING_001",
"actionRequired": "HALT_PROCESSING",
"timestamp": "2026-05-28T14:30:00Z"
}
Consent withdrawal or expiration alerts
New or updated consent notifications
System-triggered compliance checks
Auto-escalation for unacknowledged alerts

4.5 Grievance Redressal Mechanism

Efficient complaint resolution compliant with DPDP Act provisions

4.5.1 Complaint Logging

  • Simplified Complaint Form
    User-friendly with predefined categories
  • Auto-Categorization
    Consent violation, data breach, processing errors
  • Reference Number
    Unique ID generated for tracking
  • Secure Submission
    TLS 1.3 encrypted transmission

4.5.2 Resolution Tracking & Workflow

1
Initiation & Submission
User completes form with category, description, and evidence
2
Validation & Acknowledgment
System validates completeness, generates reference ID, confirms receipt
3
Routing & Processing
Routed to DPO or designated department for resolution
Escalation (if needed)
Auto-escalate to senior authority if unresolved within timeframe
Closure & Feedback
Status marked "Closed", resolution summary sent, feedback collected

4.6 System Administration

Administrative capabilities for secure and efficient CMS operations

4.6.1 User Role Management

Role View Manage Audit Admin
Administrator
DPO
Auditor
Operator
Supports MFA, SSO, real-time role revocation, and complete audit trails for role changes.

4.6.2 Data Retention Policy

Personal Data 7 Years
Consent Artifacts 10 Years
Audit Logs Indefinite
Grievance Records 5 Years
Automated Secure Deletion
Cryptographic erasure protocols for expired records. Exemptions handled for legal/regulatory requirements.

4.7 Audit Logs & Compliance

Immutable, tamper-proof documentation for regulatory verification

Audit Log Metadata Structure

Every consent-related action is recorded with the following immutable fields:

Log ID
Unique identifier
User ID
Data Principal ID
Purpose ID
Specific purpose
Action Type
grant/withdraw/update
Timestamp
ISO 8601 precise time
Consent Status
active/withdrawn/expired
Initiator
user/system/DF
Source IP
Device IP address
Audit Hash
Cryptographic hash

Sample Audit Log Entry

Tamper-Proof
[2026-05-28T14:30:00Z] CONSENT_GRANTED
UserID: DP_12345 | Purpose: MARKETING_001
Initiator: USER | IP: 203.192.12.45
Hash: sha256:a3f5c8e9d2b1...

Audit Readiness

Structured format for easy retrieval and regulatory reporting

Access Control

RBAC and MFA restricted access to audit logs

Immutability

Cryptographic hashes ensure tamper detection