The direct answer

Consent withdrawal needs an operational response across the processing chain. Identify the affected purpose, stop processing that depends on that consent, instruct relevant Processors, and record completion or a separately justified exception. A preference-centre update alone does not establish that downstream processing has stopped.

The business situation

An illustrative scenario

A customer switches off promotional messages. The CRM records the choice, but an export already sent to a campaign agency remains active. The visible preference is correct; the processing instruction is not. The legal review needs to follow the export, not just the screen.

A privacy review begins with the processing activity: whose data is involved, who decides the purpose and means, and what each participant actually does. A Data Fiduciary and a Processor have different roles; the contract label is evidence, not the final answer. GDPR terminology should not be imported into an Indian assessment without checking the applicable statutory ground.

What needs examining

01. Separate the purpose from the customer account

Withdrawal from promotional processing does not necessarily require closing an account or deleting every transaction record. Map each purpose to its actual legal basis. Identify whether a different processing activity has an independently available basis, rather than changing labels to keep the same campaign running. A statutory retention obligation needs its own scope and record; it is not permission to continue unrelated marketing.

02. Make the Processor instruction executable

The agreement and operating procedure should identify the recipient, processing purpose, affected systems and action required. Deal explicitly with scheduled jobs, cached audiences, sub-Processors and previously exported lists. Acknowledging receipt is different from confirming cessation. If the business uses a Consent Manager, determine what that arrangement actually handles and which downstream actions remain with the Data Fiduciary.

03. Test the exceptions and the evidence

Use controlled test records to follow a withdrawal through the chain. Record when the request arrived, when instructions were issued, what action occurred and why any residual record remains. Design retries and escalation for unavailable vendors. A narrowly designed suppression record may help avoid renewed contact, but its purpose, access and retention also need justification.

Law, contract and recommended practice

DPDP Act, 2023: sections 4–8, 11–13 and 16, as relevant. The substantive duties discussed here form part of the phased commencement programme; distinguish readiness work from duties already in force. Existing IT, cybersecurity and sector-specific requirements need their own assessment.

Connect the control to the evidence

Use this table to scope the review. The legal basis and the practical control are identified separately.

Obligation or objectivePractical controlEvidence to retain
Law, on applicable commencement
Give effect to withdrawal for consent-dependent processing
Purpose-specific stop instructionsRequest, instruction and completion timestamps
Contractual control
Make downstream responsibilities clear
Processor and sub-Processor cessation termsSigned terms and vendor acknowledgements
Recommended practice
Detect an incomplete withdrawal
Controlled end-to-end test and exception queueTest result and resolved exception record

Records to prepare

Bring the complete, current record to the review. Preserve earlier versions where a change or disputed event makes them relevant.

Purpose and legal-basis register
Current notice and consent versions
Processor and sub-Processor map
System exports and withdrawal audit trail

Common questions

Does withdrawal mean every record must be deleted?

No. Assess cessation and erasure separately against the activity and applicable law. Records genuinely required for another lawful purpose may need different treatment. Document that purpose and restrict reuse; a blanket retention label is insufficient.

Is an email from the vendor enough evidence?

It may be part of the record, but the required assurance depends on the processing. Seek a sufficiently specific confirmation identifying the affected systems, sub-Processors, timing and exceptions. Higher-risk activity may justify additional verification.

The next practical step

Before changing the privacy notice, trace one withdrawal through the real architecture. The resulting gap list should identify an owner, a corrective action and the evidence needed to close each issue.

Legislation & official resources

These references identify the governing frameworks. Confirm the current text, relevant amendments and applicable judicial position for the matter.

This note is general information. The scenario is hypothetical and does not describe a client matter. The legal result depends on the facts, documents, jurisdiction and operative law. No individual lawyer review is represented by the preparation date.

Explore the AMLEGALS data privacy practice