Skip to main content

Step 7: Open Consent Notice

Once you have the redirectUrl, your application must open it so the user can review and act on the consent notice. If the Data Principal is a minor, their parent or guardian completes the notice on their behalf.


Where Can It Be Opened?​

🌐 Web Applications​

  • New tab
  • Popup window
  • Embedded iframe

Example:

window.open(redirectUrl);

📱 Mobile Applications​

🤖 Android​
🍎 iOS​
  • Mobile browser
  • In-app browser

On the Consent Notice page, the user can:

  • Review purpose and data details
  • Grant consent
  • Revoke consent (if applicable)

After user action:

  • Consent Manager processes the decision
  • A consent receipt is generated
  • A webhook notification is sent to the Data Fiduciary (if configured)

If you sent subjectType as MINOR in the consent request (Step 4), Consent Manager never asks the minor to log in. Instead, the parent or guardian completes the consent:

  1. A Parental Consent Required screen explains that a parent or guardian must complete the request.
  2. The parent or guardian enters their own mobile number and verifies it with an OTP.
  3. The first time they act for a child, they select their relationship to the child (Father, Mother, or Legal Guardian), enter a display label for the child, and confirm they are 18 or older. The display label is only for the parent's own dashboard and is never shared with you.
  4. They review the purposes and data categories, choose to grant or revoke, and confirm they are consenting on behalf of the child.

The consent receipt records that a parent or guardian acted for the minor, and it is included in your webhook notification. The parent's mobile number is verified by OTP, while their relationship to the child and their age are self-declared and not verified by Consent Manager.

When the child turns 18: send a new consent request for the same dpHash with subjectType as ADULT. After logging in with their own mobile number, the user is asked whether they want to take over managing their own consents. Until they do, the parent or guardian stays in control.


Important Notes​

  • Ensure the user session context is maintained before redirecting.

  • Handle cases where user closes the browser without completing action.

  • Always rely on webhook or Consent Verify API to confirm final status.

  • For a minor, make sure a parent or guardian is the one who completes the notice, for example by telling the user before you open the redirectUrl.

  • Only the parent or guardian linked to the minor's profile can act on the request. If a different account opens the link, Consent Manager refuses it and asks them to try again with a different mobile number.