DPDP Glossary

Consent Artefact

Not a defined statutory term in the Act or Rules; in operational systems it usually means the structured record of a consent decision and its context.

Operational term (not defined in the Act/Rules)

What it means

“Consent artefact” is industry language, not a Section 2 definition. Teams use it for the structured record that shows who consented, to which purpose, when, under which notice version, and through which channel — the evidence you need when consent is the processing basis and accountability is tested.

Worked example

After a customer opts in to email offers on a checkout form, the artefact might store Principal identifier (or token), purpose code “email-offers”, timestamp, notice version ID, channel “web-checkout”, and later a withdrawal timestamp if they opt out. That is an operational record of Section 6 consent — not a statutory form prescribed by the Act.

In practice

Define minimum fields for consent records, version notices, and how withdrawal updates the artefact and downstream systems. Do not invent a legal requirement to use the words “consent artefact” in policies — focus on being able to prove consent qualities and purpose linkage.

Source

Operational term (not defined in the Act/Rules) · Official text (PDF)

Educational summary based on the Digital Personal Data Protection Act, 2023 and Rules, 2025. Not legal advice.

Further reading

← Back to glossary