Skip to content

Guide

Rule 3 consent notices: standalone, not a banner tick

Last verified 16 July 2026

Rule 3 requires standalone, plain-language, purpose-specific consent notices. The proof artifact is a decision record tied to notice facts, not a banner tick screenshot.

01

What Rule 3 requires

Under the DPDP Rules, consent notices must be standalone, plain-language, and purpose-specific. The notice is where the person understands what they are deciding; the decision is what every system must obey afterward.

Core operational notice duties sit with the Phase 3 calendar (13 May 2027 under the gazetted Rules). Treat that date as enacted only as it appears in the gazette.

02

What a banner tick is not

A banner tick can record that someone clicked. It does not, by itself, prove purpose, notice version, systems affected, or whether a later withdrawal reached every surface that still held the purpose.

When a Board, auditor, or rights request asks what governed a use of personal data, the useful artifact is a decision record: purpose, state, timestamp, systems, and a stable decision id.

03

What Consentry records

Consentry records the purpose, decision state, notice facts that matter to proof, and which systems later enforce that decision. The ledger is the retention artifact for that decision, not a screenshot of a banner.

For the full statute mapping across Rule 3, retention, rights, erasure, and Consent Managers, read the DPDPA page.

Request access

Early access for teams mapping notices, retention, and rights work to a decision record under the DPDP Rules.