21. STEP4 :Map Legal Grounds Consent vs Legal Notice
ISSUE #104Published: 10/1/2026

21. STEP4 :Map Legal Grounds Consent vs Legal Notice

Ankur Srivastava

Ankur Srivastava

Deputy-CISO / CISSP

Cyber Security & Business Continuity Expert with over 15 years of experience orchestrating InfoSec Governance, risk mitigation frameworks, and disaster recovery architectures. CISSP | M.S. in Cyber Laws & Information Security (IIIT).

Access Price

₹40
Preview

Description

Step 4 of DPDPA compliance is mapping your legal grounds—consent must be free, specific, informed, unconditional, unambiguous, and given through clear affirmative action in plain language.

DPDPA consent has three core parameters: withdraw consent as easily as giving it, exercise user rights (access, correction, deletion) without obstacles, and complain to the Data Protection Board if unhappy.

Rule 10 requires verifiable parental consent for processing children's data—using technical authentication to confirm the person is an identifiable adult, such as DigiLocker authorization or specialized tokens.

Ankur Technology implemented three notices (Website Marketing, Learner, Employee/Trainer), added unsubscribe links in all emails, offered privacy@ankurtechnology.com for consent withdrawal, and maintained a request log for auditability.