The DPDP Audit Tool
Compliance for Misleading or Bundled Consent: The ₹250 Crore Trap
💸

Misleading or Bundled Consent: The ₹250 Crore Trap
Liability Check

⚠️

Misleading or bundled consent isn't just bad UX; it's a direct violation of the DPDP Act. Get it wrong, and you could face penalties up to ₹250 Crore.

Why Misleading or Bundled Consent: The ₹250 Crore Trap is at Risk

The DPDP Act, Section 6, demands **free, specific, informed, unconditional, and unambiguous consent**. Bundling consent for marketing with essential service terms, or hiding data processing details in complex legal jargon, is a direct breach. The Data Protection Board will assess the scale of impact, the sensitivity of data involved (e.g., health records, financial data), and whether your company in a tech park like Electronics City or Cyber Hub misled millions of users. **Repeated violations** amplify penalties significantly.

Common Violations

  • 1.Automatically opting users into newsletters or third-party sharing upon app signup or website registration.
  • 2.Embedding consent for multiple, unrelated data processing activities within a single, complex privacy policy or terms of service.
  • 3.Using ambiguous or overly technical language that prevents users from clearly understanding what they're agreeing to.

The Immediate Fix

Conduct an immediate audit of all your consent flows – from website cookies to app sign-ups. Ensure each distinct data processing purpose has a separate, opt-in consent mechanism, presented in clear, simple language. Separate essential service consent from optional marketing or analytics consent.

Get DPDP Updates for Misleading or Bundled Consent: The ₹250 Crore Trap

We'll send you compliance alerts and deadline reminders specific to your area. No spam — unsubscribe anytime.

Unbundled consent — the DPDP gold standard. Unsubscribe anytime. Privacy Policy

or
Start 30-Second Audit

Projected Compliance Deadline: Immediate

Next step after the audit

The audit shows the gaps. Sanctum closes them. One programme covers legal position, data map, gap analysis, implementation, tooling, training, a written readiness opinion, and breach cover, under one accountable owner. See the all-in-one programme