All insights

Sovereignty & Data Residency

Consent Architecture for Agent-Driven Services

· 10 minute read

An agent that keeps going after a citizen said stop is not innovative. It is unlawful processing with a nicer UI.

Consent is not a banner that says by continuing you agree. Under DPDP it is a specific yes that can be withdrawn as easily as it was given. Agents make that hard because they keep moving after the click. Architecture has to keep up, or the yes is a lie.

Most public-sector agents should not start with a consent screen at all. They should start with a lawful-basis decision. Consent is one basis. Section 7 is another. Mixing them so that a benefit is held hostage to a marketing yes is how you get both a legal problem and a newspaper problem.

Pick the basis before the UX

WorkflowLikely basisUX consequence
Apply for a notified subsidy via an agentSection 7 State benefit, if conditions metExplain the purpose; do not fake a marketing opt-in
Optional campus career chatbotConsentSeparate yes; no service denial on refusal if the course does not need it
Internal audit agent on employee mailEmployment legitimate use or a different legal basis, with careNot a consent screen; a policy and a union/HR note
Using grievance text to train a vendor modelUsually noneDo not do it
Voice bot that records a complaintOften Section 7 plus a notice about recordingSay it is recording before the first question

If the basis is Section 7, say so in the notice. Citizens deserve to know they are not being asked a favour. If the basis is consent, the service that does not need the data must still work. Otherwise the yes is not free.

Notice that matches the agent

The notice must describe the specified purpose. If the agent later starts calling a new tool that reads family records, the purpose has changed. Either the new tool is blocked or the notice is re-issued. Build the purpose as a machine-readable tag on every workflow, not as a PDF in a drawer.

Write the notice in the language the citizen actually uses. A Sanskritised English paragraph under a Hindi chat window is not informed. If the agent speaks two languages, the notice does too.

What the notice must make ordinary

  • Who the fiduciary is, with a working grievance address.
  • What classes of data the agent may read and write.
  • Whether a human reviews the output.
  • Whether anything leaves the perimeter.
  • How to stop, and what happens to data already collected.

Withdrawal has to stop the machine

When a Data Principal withdraws consent, downstream stores must stop. That includes the queue, the embedding index, the reviewer inbox and any scheduled tool calls. A ticket that says withdrawn while the agent still emails the citizen is a defect.

Build a stop hook. The hook cancels in-flight work, marks the purpose closed, and starts the erasure path for stores that have no independent legal basis to remain. If a statute independently requires the tax record to stay, keep the tax record. Do not keep the chat, the vector and the screenshot because it was easier.

Children and dark patterns

Processing of children's data needs verifiable parental consent except where the government provides otherwise. School and university agents that might see minors cannot hide behind a checkbox. Age gates that only ask are not verification.

Dark patterns that make withdrawal harder than consent will not survive the Board or a newspaper. Neither will an agent that hides the stop button on mobile, or that treats silence as a yes after a timeout. If the yes was a tap, the no is a tap. Same size. Same place. Same language.

Consent-manager provisions commence on 13 November 2026. Do not wait for a registered manager to invent your stop hook. Build withdrawal on a channel you already operate — the same portal, the same helpline, the same language. Then, if your programme needs a manager, plug into it. A manager cannot save an agent that cannot stop.

Purpose tags in the runtime

A notice on a website and a tag in a legal memo do not constrain an agent. The runtime has to refuse tools that do not inherit the purpose. That is software. Budget it. If the vendor cannot show a refused tool call in a log, they cannot show purpose limitation. They can only show a PDF.

Tags should be short and stable: welfare-eligibility, grievance-draft, campus-career. Do not invent a new tag per campaign. Proliferation is how tags become decoration again.

Helplines are part of withdrawal

Many Data Principals will not find a button. They will call. The helpline must be able to trigger the same stop hook as the button, in the same language, without a three-day ticket. If withdrawal is only for people who can navigate a portal, it is not as easy as the yes, which was a single tap in a chat.

Ship a stop hook before you ship another banner

Week 1: pick the basis for each live or planned workflow. Consent or a named Section 7 limb. Never both as a mush. Week 2: write the notice in the language of the chat, matching the purpose tag. Week 3: implement the stop hook so it cancels in-flight work, not only future turns. Week 4: teach the helpline to fire the same hook. Then, and only then, restyle the banner.

Add the allow-list that binds tools to tags. A notice that the runtime cannot enforce is a poster. Posters do not stop a family-record fetch.

If minors can appear, stop the workflow until verifiable parental consent exists or the workflow is redesignated away from children. Age gates that only ask are not verification. Do not hide that gap behind a checkbox.

Objections you will hear — and what to do with them

Product managers will say a stop hook that cancels in-flight work is expensive. Leaving in-flight work running after withdrawal is processing without a basis. Expensive is the honest price of a chat that takes sale deeds. If you cannot pay it, do not take the deed.

Legal will want consent plus Section 7 for belt and braces. Belt and braces that hold a benefit hostage to a marketing yes are unlawful in spirit and often in letter. Pick a basis. Write it. Design the UX for that basis only.

Communications teams will want a short banner. Short is fine if the long notice is one tap away in the same language. Short that hides transfer or recording is not a notice. It is a dark pattern with a legal footer.

Helpline vendors will say they cannot trigger backend deletes. Then they are not a withdrawal channel. Either integrate them or stop advertising the number as a way to withdraw. Advertising a dead stop is worse than advertising no stop.

Someone will wait for consent managers in November 2026 before building anything. Managers will not invent your hook. Build the hook. Plug in the manager later if you need one.

How this shows up in the file

Banners are the last thing you design, not the first. Basis, tag, notice, stop hook, helpline, then paint. The opposite order produces a pretty yes that cannot be withdrawn. Pretty yeses are how agents become unlawful with a nicer UI.

If you cannot cancel in-flight work, do not collect sale deeds, medical notes or identity images. The Act does not contain an exception for in-flight. Engineering cost is the price of those documents. If you will not pay it, do not take them.

Children's workflows stay red until verification exists. Class-12 outreach, sports hostels and first-year campus bots are the usual surprises. Find them before a campaign poster does.

What the next noting must contain

“Consent Architecture for Agent-Driven Services” belongs in a file, not only in a search result. A P6 Compliance/DPO should be able to point at one artefact that proves “consent management AI services”: a packet capture, a processing schedule, a scored evaluation row, a dated notice, or a refusal rule. If the only evidence is a slide, you have a heading.

An agent that keeps going after a citizen said stop is not innovative. It is unlawful processing with a nicer UI. DPDP 2023 does not define sovereign AI and does not write a blanket localisation rule for every model hop. CERT-In’s 28 April 2022 directions still set specified incident clocks and 180-day log retention in India for in-scope events. The November 2025 AI governance text is guidance, not a statute. A Proprietary Article Certificate, when it is lawful, lives in GFR Rule 166 — not Rule 161.

Write three dated sentences under C1 Sovereignty & Data Residency: what was decided, which designation owns it after the next posting order, and when it will be re-checked. Unsigned sentences are souvenirs. Dated sentences are controls.

  • Name the designation that owns “consent management AI services”, plus a deputy.
  • Attach one artefact a stranger can open next year.
  • Name the instrument you are actually using — Act, direction, GFR clause, GeM term, or guideline paragraph.
  • Leave unsourced percentages, GMV slides and house forecasts out of the noting.
  • Revisit when the model, the SI, the notice, the region or the posting changes.

Questions this usually raises

Do government services always need fresh consent?
Not always. Section 7 provides legitimate uses for certain State benefits and legal functions. You still need a recorded basis, a notice where required, and purpose limitation.
When do consent managers matter?
Consent-manager provisions commence on 13 November 2026. Design so a citizen can withdraw through a channel you already control, then plug into a registered consent manager if your programme needs one.
Can we use one consent for the website and the agent?
Only if the specified purpose is the same. An agent that starts calling new tools has left that purpose. Bundle less. Tag more.
Why not collect consent and also rely on Section 7?
Because a benefit held hostage to a marketing yes is not a free yes. Pick one basis per workflow and design the UX for that basis. Belt-and-braces mixing is how notices become dishonest.
Is a 1800 number enough for withdrawal if it only logs a ticket?
No. The helpline must fire the same stop hook as the button, including in-flight cancels and store deletes, while the person is still on the call or immediately after. A ticket is not a stop.

Sources