All resources
Blog 5 min read

Consent, notice and the 72-hour breach rule under DPDP

C1The Compliance One team13 September 2026

Notice must stand on its own

Under Rule 3, the notice that precedes consent has to be understandable by itself, with an itemised description of the personal data, the specified purpose, and the means to withdraw consent, exercise rights and complain to the Board — offered in English or a scheduled Indian language. A privacy policy buried behind a link does not cut it.

Consent must be real — and easy to take back

Consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and no broader than the purpose needs. Withdrawing it must be as easy as giving it, and when someone withdraws, you must stop — and make your processors stop too. If a dispute arises, you must be able to prove valid notice and consent were obtained.

Every breach, within 72 hours

DPDP has no harm or materiality threshold. Every personal data breach is notifiable — to each affected person without delay, and to the Board with a detailed report within 72 hours.

That is a higher bar than the GDPR's risk-based trigger, and it means your detection-to-notification pipeline has to be fast, rehearsed and evidenced. A 72-hour clock is not something to assemble by hand after the fact.

See it on your own frameworks

Book a 30-minute walkthrough and we'll map Compliance One to your environment.