Consent withdrawal across your vendor chain
What should happen after a customer withdraws consent—and how does the business demonstrate that it happened?
Read the guideConsent, retention, Processor accountability and incident decisions, examined at the point where policy meets operations.

A privacy review begins with the processing activity: whose data is involved, who decides the purpose and means, and what each participant actually does. A Data Fiduciary and a Processor have different roles; the contract label is evidence, not the final answer. GDPR terminology should not be imported into an Indian assessment without checking the applicable statutory ground.

What should happen after a customer withdraws consent—and how does the business demonstrate that it happened?
Read the guideA deletion certificate is useful only when its scope matches the data and systems that need to be addressed.
Read the guideA practical legal review of screen capture, productivity analytics, location tracking and workplace surveillance.
Read the guideSeparate what is known, what needs investigation and which reporting obligations may already be running.
Read the guideHow to preserve relevant evidence without turning a dispute into an indefinite retention exception.
Read the guideDPDP Act, 2023: sections 4–8, 11–13 and 16, as relevant. The substantive duties discussed here form part of the phased commencement programme; distinguish readiness work from duties already in force. Existing IT, cybersecurity and sector-specific requirements need their own assessment.