DPDP 2023 consent (conversational) — ChatGPT Ads India glossary
DPDP 2023 consent (conversational) is how a healthcare advertiser captures valid, specific consent inside a ChatGPT Ads exchange itself, before any personal data the user shares gets processed or stored.
Definition
In plain English: before a ChatGPT Ads conversation collects a phone number, a health condition, or any other personal detail, the user needs to clearly agree to that — not through a buried disclaimer, but through a plain, purpose-specific ask they can say yes or no to, with an equally easy way to say no later.
Technically, the Digital Personal Data Protection Act, 2023 requires that consent be free, specific, informed, unconditional, and unambiguous, given through a clear affirmative action, and accompanied by a notice describing what data is collected and why. The data principal must be able to withdraw consent as easily as they gave it. None of these requirements assume a web form — they apply equally to a conversational exchange, which means a ChatGPT Ads flow needs its own built-in consent mechanism rather than relying on a website's existing privacy policy to cover it.
Why it matters for Indian healthcare marketers
Most healthcare advertisers already have DPDP-compliant consent flows on their websites — a checkbox on a contact form, a clear notice before a lead-capture field. None of that automatically covers a ChatGPT Ads conversation, because the conversation is a separate data-collection surface with its own flow, and DPDP's consent requirement attaches to each instance of data collection, not to the advertiser's website as a whole. A prompt template that asks a user for their phone number or describes their symptoms to route them to the right department is collecting personal data — potentially including inferred health information — without a DPDP-valid consent step unless one has been deliberately built into that specific conversation.
The conversational format also makes it easy to collect more than intended without a clean boundary. A user volunteering "I've had chest pain for two weeks and want to book a cardiologist" has shared health information in the course of a normal, natural exchange, before any consent notice has necessarily appeared. DPDP doesn't excuse this as incidental — data shared this way is still personal data subject to the Act's purpose-limitation and consent requirements, and a healthcare advertiser processing it (routing it to a CRM, using it to qualify a lead) needs a consent basis for doing so, captured at or before the point of collection.
The Data Protection Board of India, once fully operational under the Act, has meaningful penalty powers, and healthcare data carries reputational weight beyond the statutory penalty — a health-condition data mishandling story is the kind of consumer-trust event that outlasts a single campaign or platform. A new advertising surface without an established consent pattern is exactly where an early, avoidable misstep is most likely.
How ICG uses/measures/handles it in a live engagement
ICG inserts an explicit consent checkpoint into every healthcare client's ChatGPT Ads prompt template, positioned before the conversation asks for or processes any personal data — a plain-language statement of what will be collected and why, requiring a clear affirmative response before the flow continues. This is built as a conversation-native step, not a link out to a separate privacy policy page, since DPDP's affirmative-action standard is difficult to satisfy through an unread external document.
For flows where a user might volunteer health information before any consent step is reached — describing symptoms, naming a condition — ICG builds an interrupt pattern that pauses the flow to capture consent for that specific data before it's used for routing or lead qualification, rather than processing it first and asking afterward. Withdrawal is built as a stated, always-available option within the conversation, matching DPDP's "as easy to withdraw as to give" standard.
Every consent event — granted, declined, withdrawn — is logged with a timestamp and the specific notice text shown at that moment, giving the client an auditable consent record for each ChatGPT Ads conversation that collected personal data, reviewed as part of the same monthly compliance report used for other regulatory categories.
Related terms
Frequently asked questions
What does DPDP 2023 require for consent to be valid?
The Digital Personal Data Protection Act, 2023 requires consent to be free, specific, informed, unconditional, and unambiguous, given through a clear affirmative action, with the data principal able to withdraw it as easily as it was given — a pre-ticked box or buried clause does not qualify.
Why is consent harder to capture correctly in a ChatGPT Ads conversation than on a web form?
A web form presents a consent checkbox as a discrete, visible step; a conversational exchange has no equivalent unless the prompt template is deliberately built to pause and ask for explicit, purpose-specific consent before requesting or processing personal or health data.
Does DPDP 2023 treat health data differently from other personal data?
DPDP 2023 does not create a separate sensitive-data category the way some earlier draft frameworks did, but health information shared in a healthcare advertising conversation still falls squarely within personal data, and the Act's purpose-limitation and consent-withdrawal requirements apply in full.
How does ICG build conversational consent into ChatGPT Ads campaigns?
ICG inserts an explicit consent turn into every healthcare prompt template before any personal data collection point, states the specific purpose data will be used for, and builds an equally simple in-conversation withdrawal path, then logs each consent event for the client's compliance record.
Build DPDP-valid consent into your ChatGPT Ads conversations.
ICG designs conversation-native consent checkpoints and logs every consent event for your compliance record.