Chapter 10 — Consent Withdrawal and Downstream Cessation
1. The button that is not a button
Chapter 9 ended with consent as a versioned, purpose-scoped, evidenced grant that the runtime enforces. This chapter begins where a principal exercises the other half of that bargain — and it begins by correcting the most natural misunderstanding in the entire regime.
To a product team, withdrawal can look like a preference toggle. Operationally it reverses an authority, starts cessation coordination and invokes a separate disposal decision. This chapter owns that coordination; Chapter 14 owns physical retention/disposal and restore, Chapter 17 contractual propagation, and Chapter 12 communication. None may turn an emitted event into proof that the remote work finished.
The law has three distinct parts. Section 6(4) permits withdrawal at any time with comparable ease; Section 6(5) preserves the legality of earlier consent-based processing and places withdrawal consequences on the principal. Its paid-order illustration says supply processing for goods already ordered and paid for may not be stopped. Section 6(6) requires the fiduciary to cease and cause processors to cease within a reasonable time unless non-consent processing is required or authorised by the Act, Rules or another Indian law (ACT:232–257).[1]
Section 8(7) separately requires erasure on withdrawal or reasonable purpose-end, whichever is earlier, unless retention is necessary for compliance with law, including processor erasure. Sections 8(8)/(11) and Rule 8 govern the relevant deemed inactivity branch; Section 12(3) is the requested-erasure route with its specified-purpose/law exception (ACT:351–385,463–476).[1] These are not one unconditional stop-and-destroy rule.
The design recommendation is prompt fail-closed denial for the withdrawn optional use, coupled to an accountable exception review and a separate retained-data state. A surviving lawful duty is not permission to ignore withdrawal or keep marketing. The paid-order example is not a general contract basis for every lending or account operation.
2. The tension: cessation is not erasure
The chapter’s tension is a single distinction, and it deserves to be held as a tension because every failure of this machine is a failure to hold it.
The first collapse: erase everything. The principal withdraws marketing, yet a person-level delete destroys application records, still-authorised servicing data and restricted statutory archives. The correct unit is the subject × purpose × data class, not the person alone. Do not insert an unsupported eight-year RBI retention rule: customer-identification records, transaction records and marketing projections need separate applicable instruments and starting events. The Act’s ten-year bank illustration is an illustration, not independent evidence of a universal current RBI period (ACT:365–368).[1]
The second collapse: stop nothing. Suppressing an email while leaving marketing scoring, queued sends and processor exports active does not achieve cessation for that purpose. A local flag can be one control, but it must reach each applicable operation. The Company cannot claim that a supplier ceased merely because its API accepted a command.
Derived data needs classification before disposal. Identifiable feature rows and training examples can be locatable personal data. A model trained on the person’s data is not automatically a collection of individually deletable weight copies. Lineage identifies a dependency; it does not demonstrate identifiability, extractability, successful unlearning or model correctness. Record those assessments and restrict disputed use rather than issuing a fictional model-erasure receipt.
The failure modes, named:
- The over-delete — lawful-retention windows destroyed; the Section 12(3) judgement never made; the audit trail erased along with the data.
- The flag-not-a-machine — withdrawal as a suppression list; processing continues everywhere the flag doesn’t reach; the orphan test (Ch.22) fails silently for years.
- The wrong-scope delete — the granularity failure: the principal withdrew marketing, the machine deleted the account. Section 6(1) makes consent purpose-scoped — which makes withdrawal purpose-scoped, and the machine must key its actions to the purpose + data element, not to the person.
- Partial propagation — local denial succeeds while a processor operation remains unknown. Retain the failed destination, retry ownership and restriction; neither a silence nor an HTTP acceptance is completion.
- Trigger inversion — purpose ends before withdrawal but the planner waits for withdrawal as a minimum. Select the earlier actual trigger, then assess lawful retention independently.
The state design is a product of three axes, not a linear three-state ladder. Authority records which operation may run; physical retention records what bytes remain and under what rule; execution records what each target has actually acknowledged. This resolves the old ambiguity in which “held” meant both quarantined and actively used.
3. Transition and acknowledgement contract
| Event / condition | Authorisation decision | Physical disposition | Execution / communication |
|---|---|---|---|
| Authenticated WITHDRAW-001 for PUR-002 | withdraw CONSENT-002; recommended immediate marketing denial | assess each DS-003 copy under Rule 8/Rule 6/other-law scope | accepted is not ceased; create destination tasks |
| CONSENT-001/PUR-001 independently remains valid | that narrower application purpose can continue on its own facts | shared DS-001 field may remain for it | do not withdraw other grants by person-wide key |
| Qualified non-consent processing under Section 6(6) | document exact law, operation, actor and condition; no generic contract fallback | retain/use only that scope | explain exception, owner and review trigger |
| Rule 8(3) minimum still applies | archive access only for PUR-009; marketing remains denied | restricted retention, not immediate erasure | decision DEC-006; expiry eligibility reviewed separately |
| No minimum/other basis remains after trigger | no authority to continue expired use | issue scoped erasure task | pending until actual adapter evidence |
| Processor deadline missed | local gate remains denied; restrict new exports | remote state unknown | ACK-001 absent; escalate; no global completion |
| Older grant arrives after withdrawal | reject stale sequence; retain audit event | no restoration of active use | same-key duplicates idempotent; conflicts investigated |
| Restore requested | no production access to old state | load into SYS-014 quarantine | replay post-snapshot restrictions, then verify eligibility |
This transition contract is a recommended schema. The legal cessation standard remains reasonable time with the Section 6(6) exception, not the example’s immediate local gate or five-minute processor target (ACT:245–249).[1]
Two features of the machine carry most of its discipline:
It is keyed to subject + purpose + element, not to person alone. Because Section 6(1) makes consent granular, withdrawal arrives granular — marketing withdrawn, account retained; the machine’s every transition must be scoped to the withdrawn purpose’s data elements, or it over-deletes or under-deletes by construction. A “delete my everything” path may exist as a convenience, but it is the aggregation of many purpose-scoped withdrawals, run through the same machine, never a bypass around it.
The purpose-scoping has a subtlety worth spelling out. A principal who has two active consents — one for marketing, one for account management — withdraws marketing. The machine must identify, from Chapter 8’s matrix, which data elements are scoped to the marketing purpose (in CASE-001, the contact channel, preference and adult-eligibility projection; in other products, separately authorised segments) and which are scoped to account management (identity, transactions for the account’s own service). The purpose-blocked state applies only to the marketing-scoped elements; the account-scoped elements continue their processing undisturbed. The matrix is the machine’s map; without it, the machine cannot determine scope, and every withdrawal risks the wrong-scope delete or the wrong-scope continuation.
The derived-estate interface. Chapter 21 should return an itemised assessment: removable training rows, identifiable features/embeddings, identifiable outputs, and model artefacts whose classification or remedy is unresolved. For each target the coordinator records classification, permitted_use, action, evidence, failure and review_owner. Retraining initiated is not retraining completed; either is different from proof of personal-data erasure. In CASE-001, DEC-001 stops PUR-003 before training, so this pack does not fabricate trained weights to erase.
4. The lawful-retention assessment, honestly run
Every retention decision must distinguish the erasure trigger from the reason disposal is temporarily or permanently qualified. A legal minimum is not an authorisation to continue the withdrawn business purpose.
Rule 8(3): processing retention. For any processing by the fiduciary or its processor, retain the relevant personal data, associated traffic data and other processing logs for at least one year from that processing, for Seventh Schedule purposes; afterwards cause erasure unless further retention is required by another law or Government notification. The retained e-book and cloud-processor illustrations expressly prevent treating purpose completion/account deletion as immediate destruction (RULES:1153–1166).[3] The Seventh Schedule concerns State functions/information and SDF assessment, not nominees or a commercial marketing licence (RULES:1894–1921).[3]
Rule 6(1)(e): security retention. Separately retain the covered logs and personal data for one year for unauthorised-access detection, investigation, remediation/recurrence prevention and continuity, unless law requires otherwise. Keep its security purpose PUR-008 and record categories separate from Rule 8(3)‘s PUR-009; do not deduce one common starting date from legal commencement (RULES:1101–1106).[3]
Rule 8(1)/(2): class-specific inactivity. The Third Schedule sets three years using the latest qualifying approach/rights event or its commencement anchor, for e-commerce entities and social-media intermediaries with at least two crore registered users in India and online-gaming intermediaries with at least fifty lakh. It excludes the stated account-access and virtual-token-access purposes. Its 48-hour advance warning and renewal events belong to that deemed-inactivity branch, not a blanket wait before accepting withdrawal (RULES:1142–1152,1598–1680).[3] The Company’s stipulated 100,000 customers do not establish that class coverage. A non-covered edtech cannot borrow an invented education clock; actual purpose-end can still trigger Section 8(7).
Other law and holds. Record exact instrument, field scope, start event, duration and reviewer. HOLD-001 is a fictional disputed-loan preservation request over DS-002 at EVT-008; its specific sector/court authority is unresolved in this phase and is not represented as an established compulsory hold. DEC-006’s immediate restricted-retention outcome independently rests on the retained Rule 8(3) layer. HOLD-001 never extends to DS-003 marketing, and Q04/Q06 must resolve its authority before using it as an additional legal basis.
| DEC-006 synthetic record | Value / consequence |
|---|---|
| Subject / trigger | SUB-001; WITHDRAW-001 / EVT-005, 2 June 2027 10:00 +05:30 |
| Dataset / withdrawn purpose | DS-003 / PUR-002; no marketing authority after withdrawal |
| Last processing anchor | EVT-005 control processing in the authored example; exact reset/copy interpretation remains QL-001 |
| Rule minimum / permitted use | Rule 8(3) / PUR-009 restricted archive; Rule 6 only for independently scoped DS-005 security material |
| Class / threshold / exclusion | base Company not established as Third Schedule-covered; inactivity clock not applied |
| Last qualifying request | RIGHTS-001 at EVT-009; recorded separately, not silently used as a universal disposal reset |
| Hold | HOLD-001 concerns DS-002 only; specific authority unresolved, not imported into DS-003 |
| Disposal conclusion | not eligible for blanket immediate physical erasure; no final date guaranteed; EVT-025 is an eligibility review |
| Owner / residual | Privacy + DataOps; processor cessation pending and backup/retention interpretation tracked separately |
A purpose-end-first counterexample sets an actual completed purpose before a later withdrawal: the earlier event selects assessment immediately; the minimum can still prevent disposal. A hold-release counterexample removes only its own restriction; it cannot erase while an independent minimum remains. A lawful retained subset and a failed processor are different states even when both prevent a “fully erased” message. The per-copy overlap, reset interpretation and final physical method remain explicit application questions, not reasons to omit known rule text.
5. Parity, measured rather than asserted
Section 6(4)‘s comparable-ease standard is legal; the book’s measurements are recommended proxies (ACT:232–234).[1] Record steps, discoverability, waiting, account recovery, supported channels, language and assistive access for both giving and withdrawing. Same taps with a hidden link or extra waiting is not necessarily comparable. The law does not literally prescribe an identical screen, identical channel list or a separate receipt format.
In the synthetic product specification, a signed-in user can grant or withdraw optional messages from the same choice page without a support call. A release requiring a 30-day support wait for withdrawal fails the proposed ease test even if it has one visible button. A channel or language absent from the delivered specimen remains a failed production gate, not an observed pass. Identity checks should protect the principal without making an authenticated withdrawal depend on unnecessary new documents.
Send an acceptance message promptly as an author recommendation, distinguishing acceptance, local denial, remote cessation and physical erasure. It should say that marketing consent was withdrawn and propagation is pending, rather than claiming completion before an acknowledgement exists. Chapter 12 owns the customer-facing mixed response.
6. The backup-orphan problem
The coordinator must send the retention/disposal service a snapshot-aware instruction, not an instruction to delete every backup immediately or a declaration that backup deletion is universally infeasible. Different stores permit different mechanisms; no vendor behaviour is asserted as tested in this chapter.
For a retained backup cohort, record snapshot time, covered datasets, applicable legal basis, permitted restore uses, technical expiry/deletion mechanism and a named residual owner. deferred_backup_expiry is not proof of erasure. If a cohort remains recoverable after its approved endpoint, record failure and escalation, not a receipt inferred from configuration. The legal acceptability of delayed physical disposal requires scoped review; metadata marking alone does not settle it.
SNAP-001 is captured at EVT-004 before WITHDRAW-001. RESTORE-001 at EVT-011 loads it into SYS-014, not production. Replay withdrawal and other post-snapshot restrictions before authorising any restored marketing access. A deleted record must not resurrect; a lawfully retained record can remain present but restricted. Both cases need testing, since an absence-only test would wrongly fail lawful archives and a present-only test would miss renewed use.
Chapter 14 owns the physical adapter and restore acceptance details. This chapter’s interface requires snapshot frontier, policy frontier, missing-event detection, per-target state and evidence reference. If the latest policy cannot be fetched, quarantine remains closed. A processor receipt can attest an operation within its stated scope; it cannot prove that undeclared backups or model artefacts were also erased.
7. The control-test-evidence set
| Test specification | Input and expected observation | Failure handling |
|---|---|---|
| Purpose scoping | WITHDRAW-001; PUR-002 denied, independent PUR-001 unchanged | reject person-wide revoke/delete |
| Stale grant | EVT-007 older sequence received later | reject, no restored marketing authority |
| Same-event replay | same event ID/content twice; then changed content | idempotent same-content result; reject changed payload |
| Processor timeout | EVT-006 ACK-001 absent at hypothetical five-minute target | mark pending/escalated; never completed cessation |
| Retention laundering | archive PUR-009 requested as PUR-002 | deny despite bytes retained |
| Restore | SNAP-001 then WITHDRAW-001 then RESTORE-001 | quarantine until replay; marketing denied afterward |
| Purpose-end first | end precedes withdrawal; minimum remains | earlier assessment; retained restriction, not premature disposal |
| Hold release | scoped hold removed while another minimum remains | do not erase yet; no extension to unrelated records |
| Legacy | old consent with valid withdrawal | same purpose-scoped coordination, no invented refresh expiry |
These are executable-style specifications. The accompanying local semantic fixture tests authored states; real distributed queues, storage deletion, user journeys and supplier controls remain untested.
8. One failed branch carried through to communication
The fixed CASE-001 chronology makes the interaction concrete. At EVT-003, SUB-001 has CONSENT-001 for the loan application and CONSENT-002 for optional marketing; there is no training consent. At EVT-005, WITHDRAW-001 revokes the latter. The synthetic local gate denies new marketing requests. At EVT-006, ENT-004 has not returned ACK-001 by the five-minute internal target. The overall cessation result is therefore partial/unconfirmed; no amount of successful local denial repairs the missing remote observation.
The coordinator records an incident-to-control escalation to Supplier Manager, stops new FLOW-002 exports and preserves the same idempotency key for retries on FLOW-008. It cannot assert that messages already queued outside its control were cancelled. The next customer communication says exactly that local marketing access is stopped, remote confirmation remains outstanding, and restricted retention prevents a blanket erased-everywhere claim. The execution status remains pending until scoped evidence returns; a service-response timestamp is not a deletion timestamp.
At EVT-007, an older grant arrives after the withdrawal. Processing receipt time alone would wrongly reactivate marketing. The proposed ledger instead orders the subject/purpose stream by a trusted monotonic revision and preserves occurred/received times separately. A multi-channel implementation needs one sequencer or a reconciliation protocol; it cannot compare unrelated counters from two issuers as though they shared an order. A gap or ambiguous revision restricts new grants and raises reconciliation, without making direct authenticated withdrawal unavailable.
REM-001 at EVT-010 represents a proposed stale-cache remedy: final-send authority must be rechecked rather than relying on audience-selection time. RETEST-001 is a local model observation only if the accompanying run output exists. That retest does not manufacture ACK-001 from ENT-004; supplier completion remains unknown in the scenario. At EVT-011 the restore path likewise replays the newer withdrawal before access. These are different seams in the same obligation chain, not several names for one successful toggle.
For a workshop, remove the final-send check while keeping the source-of-truth consent record correct. The defective fixture allows a cached grant; the corrected fixture denies it. Retain both outcomes. This demonstrates why accurate records and effective enforcement need separate tests, without pretending that a toy model proves atomic revocation across a deployed estate.
9. The Section 5(2) legacy path
Section 5(2) requires notice as soon as reasonably practicable for qualifying pre-commencement consent and permits continued processing until and unless withdrawal. It supplies no prescribed refresh period or automatic sunset (ACT:182–205).[1]
The legacy inventory records original consent evidence, historical purpose, applicable notice, delivery result and the reachable withdrawal path. If original authority is uncertain, record that uncertainty; do not create a new grant merely by sending a notice. A valid legacy withdrawal enters the same purpose-scoped state model, including lawful exceptions, restricted retention, failed processor work and honest communication. Neither an undelivered notice nor an old channel should silently produce a false completed migration.
10. What remains for the reader and the reviewer
The open items, each <residual>:
- Resolve Rule 6/Rule 8 overlap, processing-date resets and backup-copy scope through QL-001; the known one-year provisions are incorporated, not deferred as unread.
- Supply actual sector instrument/start-event mappings for identification and transaction records; HOLD-001 remains a disputed-loan request, not a fabricated legal order.
- Determine processor acknowledgement evidence adequate for each actual operation, and test actual queue/adapter behaviour.
- Assess model identifiability and remedy effectiveness separately from lineage; this pack does not certify unlearning or physical erasure.
- Evaluate comparable ease and complete the actual language/channel estate. The example’s timings are design targets, never universal legal SLAs.
The question that hands the book its next chapter
The machine’s every state transition reaches outward — to processors whose acknowledgements must return, to a consent record that must be reconstructible, to channels where the consent may not even live in the enterprise’s own systems. That last reach raises the book’s most structural third-party question: is there a statutory actor whose entire role is to hold and manage the principal’s consents across many fiduciaries — and how does the enterprise’s machine interoperate with it? Chapter 11 takes up Consent Managers and Consent-Management Software.
Evidence and reusable artifacts
The primary-text line keys ACT, COMM, RULES and CORR resolve to the retained files below. Line numbers count physical newlines, not PDF form feeds. The canonical provision register supplies actor, trigger, conditions, exceptions and effective dates; chapter recommendations and synthetic examples are not statutory forms. The Q03 source manifest preserves URL, retained retrieval metadata and recalculated hashes.
ACT:research/legal/evidence/01_dpdp_act_2023_gazette.txtCOMM:research/legal/evidence/02_gsr_843e_commencement.txtRULES:research/legal/evidence/05_gsr_846e_dpdp_rules_2025.txtCORR:research/legal/evidence/06_gsr_892e_corrigendum.txt
Completed chapter fragments, before/after evidence and actual local checks: out/remediation/Q03/. Blank operating templates remain under research/operations/templates/; The reconciled integrated dossier is the reader working copy; these chapter fragments preserve the earlier bounded examples and their run evidence.
Blank companion: research/operations/templates/withdrawal-workflow-template.md; completed Q03 fragments retain the same decision boundaries.
Sources
[1] https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf — ACT [2] https://www.meity.gov.in/static/uploads/2025/11/c56ceae6c383460ca69577428d36828b.pdf — COMM [3] https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf — RULES [4] https://www.meity.gov.in/static/uploads/2025/12/3c7ebbae0e5456f493f486e6845df86b.pdf — CORR
Contents · Reader guide and citation conventions · Artifact index