Misleading or Bundled Consent: The ₹250 Crore Trap
Liability Check
Misleading or bundled consent isn't just bad UX; it's a direct violation of the DPDP Act. Get it wrong, and you could face penalties up to ₹250 Crore.
Why Misleading or Bundled Consent: The ₹250 Crore Trap is at Risk
The DPDP Act, Section 6, demands **free, specific, informed, unconditional, and unambiguous consent**. Bundling consent for marketing with essential service terms, or hiding data processing details in complex legal jargon, is a direct breach. The Data Protection Board will assess the scale of impact, the sensitivity of data involved (e.g., health records, financial data), and whether your company in a tech park like Electronics City or Cyber Hub misled millions of users. **Repeated violations** amplify penalties significantly.
Common Violations
- 1.Automatically opting users into newsletters or third-party sharing upon app signup or website registration.
- 2.Embedding consent for multiple, unrelated data processing activities within a single, complex privacy policy or terms of service.
- 3.Using ambiguous or overly technical language that prevents users from clearly understanding what they're agreeing to.
The Immediate Fix
Conduct an immediate audit of all your consent flows – from website cookies to app sign-ups. Ensure each distinct data processing purpose has a separate, opt-in consent mechanism, presented in clear, simple language. Separate essential service consent from optional marketing or analytics consent.
Get DPDP Updates for Misleading or Bundled Consent: The ₹250 Crore Trap
We'll send you compliance alerts and deadline reminders specific to your area. No spam — unsubscribe anytime.
Projected Compliance Deadline: Immediate
Next step after the audit
The audit shows the gaps. Sanctum closes them. One programme covers legal position, data map, gap analysis, implementation, tooling, training, a written readiness opinion, and breach cover, under one accountable owner. See the all-in-one programme
What Should You Do Next?