Consent withdrawal needs an operational response across the processing chain. Identify the affected purpose, stop processing that depends on that consent, instruct relevant Processors, and record completion or a separately justified exception. A preference-centre update alone does not establish that downstream processing has stopped.
The business situation
A customer switches off promotional messages. The CRM records the choice, but an export already sent to a campaign agency remains active. The visible preference is correct; the processing instruction is not. The legal review needs to follow the export, not just the screen.
A privacy review begins with the processing activity: whose data is involved, who decides the purpose and means, and what each participant actually does. A Data Fiduciary and a Processor have different roles; the contract label is evidence, not the final answer. GDPR terminology should not be imported into an Indian assessment without checking the applicable statutory ground.
What needs examining
01. Separate the purpose from the customer account
Withdrawal from promotional processing does not necessarily require closing an account or deleting every transaction record. Map each purpose to its actual legal basis. Identify whether a different processing activity has an independently available basis, rather than changing labels to keep the same campaign running. A statutory retention obligation needs its own scope and record; it is not permission to continue unrelated marketing.
02. Make the Processor instruction executable
The agreement and operating procedure should identify the recipient, processing purpose, affected systems and action required. Deal explicitly with scheduled jobs, cached audiences, sub-Processors and previously exported lists. Acknowledging receipt is different from confirming cessation. If the business uses a Consent Manager, determine what that arrangement actually handles and which downstream actions remain with the Data Fiduciary.
03. Test the exceptions and the evidence
Use controlled test records to follow a withdrawal through the chain. Record when the request arrived, when instructions were issued, what action occurred and why any residual record remains. Design retries and escalation for unavailable vendors. A narrowly designed suppression record may help avoid renewed contact, but its purpose, access and retention also need justification.
Law, contract and recommended practice
DPDP Act, 2023: sections 4–8, 11–13 and 16, as relevant. The substantive duties discussed here form part of the phased commencement programme; distinguish readiness work from duties already in force. Existing IT, cybersecurity and sector-specific requirements need their own assessment.
Connect the control to the evidence
Use this table to scope the review. The legal basis and the practical control are identified separately.
| Obligation or objective | Practical control | Evidence to retain |
|---|---|---|
| Law, on applicable commencement Give effect to withdrawal for consent-dependent processing | Purpose-specific stop instructions | Request, instruction and completion timestamps |
| Contractual control Make downstream responsibilities clear | Processor and sub-Processor cessation terms | Signed terms and vendor acknowledgements |
| Recommended practice Detect an incomplete withdrawal | Controlled end-to-end test and exception queue | Test result and resolved exception record |
Records to prepare
Bring the complete, current record to the review. Preserve earlier versions where a change or disputed event makes them relevant.
Common questions
Does withdrawal mean every record must be deleted?
No. Assess cessation and erasure separately against the activity and applicable law. Records genuinely required for another lawful purpose may need different treatment. Document that purpose and restrict reuse; a blanket retention label is insufficient.
Is an email from the vendor enough evidence?
It may be part of the record, but the required assurance depends on the processing. Seek a sufficiently specific confirmation identifying the affected systems, sub-Processors, timing and exceptions. Higher-risk activity may justify additional verification.
Before changing the privacy notice, trace one withdrawal through the real architecture. The resulting gap list should identify an owner, a corrective action and the evidence needed to close each issue.
Legislation & official resources
These references identify the governing frameworks. Confirm the current text, relevant amendments and applicable judicial position for the matter.
- Digital Personal Data Protection frameworkMinistry of Electronics and Information Technology · Official framework resource. Apply the relevant Act, Rules and commencement notifications together.
- DPDP Act commencement notification: G.S.R. 843(E)MeitY · Gazette of India · Notification dated 13 November 2025. Different provisions commence in different phases.
This note is general information. The scenario is hypothetical and does not describe a client matter. The legal result depends on the facts, documents, jurisdiction and operative law. No individual lawyer review is represented by the preparation date.
Explore the AMLEGALS data privacy practice