The DPDP Audit Tool
Compliance for Consent Records: What to Keep
📝

Consent Records: What to Keep

A customer turns off promotional messages. Can you show what they chose, when they chose it, and whether the messages stopped?

What to review

Keep a copy of the words the customer saw when they agreed. Link it to their account and the date. When their choice changes, check the app and every tool that sends messages.

Problems to look for

  • 1.The record is missing the privacy wording shown at signup.
  • 2.The app records a change, but the message tool still uses the old choice.
  • 3.A failed update has nobody assigned to fix it.

The Immediate Fix

Use a test account to turn off promotional messages. Check the saved choice and any messages already scheduled to send.

What to check

Words shown
Save the explanation of how you will use the data. Keep each version.
Customer choice
Save the account, date and choice each time it changes.
Message tools
Check that each tool receives the latest choice.
Failed updates
Ask someone to fix any failed update, then test again.
Saved results
Keep the test results where your team can find them.

Section 6 explains consent and the records a company may need to show. Check when its rules take effect. DPDP Act and its start dates.

Reviewed 5 September 2026.

Get DPDP Updates for Consent Records: What to Keep

We'll send you compliance alerts and deadline reminders specific to your area. No spam — unsubscribe anytime.

Unbundled consent — the DPDP gold standard. Unsubscribe anytime. Privacy Policy

or
Start 30-Second Audit

Need help checking your business?

  • Start with the free self-check to find questions for your team.
  • Our paid gap assessment takes four weeks. We check your apps, documents and records, then list what needs fixing.
  • Fixing the agreed gaps takes two to three months. A final assessment checks the completed work.
See what the assessment includes

Save your results and discuss the questions with your team.

Next step after the audit

The audit shows the gaps. Sanctum closes them. One programme covers legal position, data map, gap analysis, implementation, tooling, training, a written readiness opinion, and breach cover, under one accountable owner. See the all-in-one programme