Consent Management Framework
Interactive explorer for the Business Requirement Document (BRD) under the Digital Personal Data Protection (DPDP) Act, 2023
Introduction & Objectives
The Business Requirements Document (BRD) for the Consent Management System (CMS) outlines the objectives and functionalities designed to align with the Digital Personal Data Protection (DPDP) Act, 2023.
As personal data protection becomes increasingly critical, organizations face growing challenges in managing consents transparently while maintaining regulatory compliance. The CMS addresses these challenges by enabling seamless consent management across its lifecycle.
"This document serves as a guideline for the development and deployment of a system that empowers Data Principals to exercise their rights over their personal data."
Core Objectives
Comprehensive Consent Lifecycle
Facilitate the full lifecycle: collection, validation, modification, renewal and withdrawal.
- Alignment with DPDP Act and its rules
- Purpose limitation enforcement
- Data minimization principles
- Secure processing protocols
Empower Data Principals
User-centric platform for viewing, managing and controlling consent preferences.
- Transparency and trust building
- Exercise data rights effectively
- Granular control over personal data
- Easy access to consent history
Ensure DPDP Compliance
Strict adherence to regulations including purpose limitation and secure processing.
- Purpose limitation enforcement
- Data minimization checks
- Secure processing standards
- Immutable audit trails
Key Stakeholders & Responsibilities
Understanding the roles and responsibilities of each entity in the consent ecosystem
Data Principal
The individual to whom the personal data relates.
- Right to give consent
- Manage consent preferences
- Withdraw consent anytime
- Exercise data rights
Data Fiduciary
Person/entity determining purpose and means of processing.
- Obtain lawful consent
- Manage consent compliance
- Validate before processing
- Cease on withdrawal
Data Processor
Processes personal data on behalf of the Data Fiduciary.
- Follow fiduciary instructions
- Secure data handling
- Real-time sync with CMS
- Immediate processing halt
Data Protection Officer
Primary compliance authority overseeing DPDP adherence.
- Oversee compliance
- Handle escalations
- Audit trail review
- Grievance redressal
Consent Data Flow
Consent Management Lifecycle
The core framework comprising five critical stages from collection to withdrawal
4.1.1 Consent Collection
Enable Data Fiduciaries to explicitly collect purpose-specific and lawful consent from Data Principals.
Workflow Steps
Functional Requirements
User-Friendly Interface
Accessible, intuitive design with WCAG compliance for users with disabilities.
Purpose-Specific Consent
Separate consent for each distinct purpose. No "bundled consent" allowed.
Granular Consent
Allow users to provide or withhold consent for each purpose separately.
Explicit Action
Clear affirmative action required (e.g., "I Agree"). No pre-checked options.
Multi-Language Support
English + Eighth Schedule languages of the Constitution of India.
Metadata Logging
User ID, Timestamp, Purpose ID(s), Consent status, Language preference.
Business Rules
4.3 User Dashboard
Empowering Data Principals with transparency and control
| Purpose | Fiduciary | Date | Expiry | Status |
|---|---|---|---|---|
| Account Creation | GovPortal India | 2026-01-15 | 2027-01-15 | Active |
| Marketing Emails | GovPortal India | 2026-02-20 | 2027-02-20 | Withdrawn |
| Analytics | DataInsights Pvt | 2025-06-10 | 2026-06-10 | Expired |
4.4 Consent Notifications
Real-time alerts ensuring transparency for all stakeholders
User Notifications
Fiduciary & Processor Alerts
4.5 Grievance Redressal Mechanism
Efficient complaint resolution compliant with DPDP Act provisions
4.5.1 Complaint Logging
-
Simplified Complaint FormUser-friendly with predefined categories
-
Auto-CategorizationConsent violation, data breach, processing errors
-
Reference NumberUnique ID generated for tracking
-
Secure SubmissionTLS 1.3 encrypted transmission
4.5.2 Resolution Tracking & Workflow
4.6 System Administration
Administrative capabilities for secure and efficient CMS operations
4.6.1 User Role Management
| Role | View | Manage | Audit | Admin |
|---|---|---|---|---|
| Administrator | ||||
| DPO | ||||
| Auditor | ||||
| Operator |
4.6.2 Data Retention Policy
4.7 Audit Logs & Compliance
Immutable, tamper-proof documentation for regulatory verification
Audit Log Metadata Structure
Every consent-related action is recorded with the following immutable fields:
Sample Audit Log Entry
Tamper-ProofAudit Readiness
Structured format for easy retrieval and regulatory reporting
Access Control
RBAC and MFA restricted access to audit logs
Immutability
Cryptographic hashes ensure tamper detection