Consent, cookies, assessments, data discovery, grievances, breach, RoPA, and an AI layer across all of them. Eight modules on one data-blind platform, sharing one artifact store and one audit trail, so compliance is demonstrated from live evidence rather than assembled at audit time.
ONE PLATFORM
Every module writes to the same artifact store and the same audit trail, with an AI layer reading across all of them.
WHY ONE PLATFORM
Four architectural decisions that make every module reinforce the others.
Every module reads the same signed consent artifact. A withdrawal captured on a cookie banner reaches the grievance desk, the RoPA register, and your downstream systems without an integration project.
Personal data routed through the platform stays encrypted and unreadable by IndiaConsent, and discovery agents run inside your own network over outbound-only connections.
Independent consent, compliance, and operational audit logs provide complete traceability across user consent, regulatory activities, and system operations.
Because the modules share a store, the AI layer can draft a notice, find the gap in a published one, and answer a DPO's question from your own live artifacts.
No gaps to fill with spreadsheets, and no second vendor to integrate.
Obtain free, specific, informed, and unconditional consent
Section 6, DPDP Act 2023
Serve itemised notice in English or any Eighth Schedule language
Section 5 · Rule 3
Obtain verifiable parental consent for children's data
Section 9 · Rule 10
Take consent for cookies and trackers, and honour rejection
Sections 4 and 6
Assess processors, third parties, and high-risk processing
Section 8(2) · Section 10
Know and secure the personal data you hold
Section 8(4) · Section 8(5)
Publish a grievance mechanism and answer rights requests
Sections 11 to 14 · Rule 13
Notify the Board and affected individuals of a breach
Section 8(6) · Rule 7
Maintain records of processing activities and retention
Section 8 · Third Schedule
Every grant, review, renewal, and withdrawal becomes a cryptographically signed artifact that propagates across your systems in real time. Withdrawal is as easy as giving consent, exactly as the Act requires, and parental consent for children's data is a first-class flow rather than a form field.
IndiaConsent's Cookie Manager scans sites, classifies trackers, and publishes branded consent banners in 22+ Indian languages — with one script tag and audit-grade compliance records.
IndiaConsent's PATM unifies DPIA and third-party vendor risk assessments under the DPDP Act 2023 into one console — with evidence vaults, automated risk scoring, and audit-ready DPO reports.
A multi-tenant scanner discovers personal data across registered hosts, files, and databases. Operators start and monitor scans from the console while outbound-only agents do the work inside your network, so nothing needs inbound access and no raw data leaves your perimeter.
A unified workflow manages 12 grievance categories, including all 6 Data Principal rights, with SLA-driven tracking, automated escalation, and complete status visibility. Every request follows a structured resolution process, and every action is written to a hash-chained audit log, ensuring end-to-end traceability and accountability.
Incident intake, severity assessment, and notification run as one timed workflow against the DPDP reporting obligations, so the clock starts when the incident is logged rather than when someone remembers the rule.
RoPA is populated from what the platform already knows — discovered data stores, consent purposes, processors under assessment — so the register reflects the estate rather than last year's spreadsheet.
The same AI layer serves both sides of the Act. Data Principals ask what a company holds and act on the answer; DPOs ask where the gaps are. It drafts notices, scans published notices for gaps against the Act, and flags new DPDP notifications as they land.
RULE 4 · THE CONSENT MANAGER
A Consent Manager is an entity registered with the Data Protection Board under Rule 4 of the DPDP Rules 2025. It gives Data Principals one accessible, transparent, and interoperable place to give, manage, review, and withdraw consent, and it owes duties directly to them.
IndiaConsent is built to register once Rule 4 becomes effective in November 2026. The First Schedule requirements are already in the architecture, not on a roadmap.
HOW AN ARTIFACT MOVES
DATA PRINCIPAL
Individual grants or withdraws consent
In any of 22+ Indian languages, on web, app, or IVR
DPB REGISTERED
IndiaConsent signs an immutable artifact
SHA-256 hash, ISO 8601 timestamp, purpose, data categories
FIDUCIARY
Banking
FIDUCIARY
Insurance
FIDUCIARY
Healthcare
INDUSTRIES
Purpose taxonomies, retention rules, and grievance ladders arrive pre-configured for your sector.
Consent at onboarding, credit pulls, and collections, reconciled against RBI record-keeping obligations.
Health data as a special category, intermediary chains, and long retention tails under one lineage map.
Patient consent, guardian consent for minors, and rights requests routed to the right clinical custodian.
Subscriber-scale volumes, IVR and retail-channel capture, and marketing preference enforcement.
Cookie and tracker consent, ad-tech processors, and deletion instructions that reach third parties.
Citizen-facing grievance intake with nodal-officer workflows, escalation ladders, and SLA reporting.
Student, parent, and staff consent, grievance handling, and rights requests across admissions, academics, and digital platforms.
Candidate and employee consent, background verification, assessments, and rights requests across recruitment and workforce platforms.
RESOURCES
Plain-language guides to the DPDP Act and the 2025 Rules, written for DPOs, legal teams, and engineering leads.
FAQ
The DPDP Rules 2025 were notified on 13 November 2025. Data Fiduciaries have an 18-month window that ends on 13 May 2027, by which date full compliance is required.
Consent is one obligation of several. A Data Fiduciary must also issue itemised notices, honour Data Principal rights, run a grievance redressal mechanism with published timelines, maintain a Record of Processing Activities, notify the Data Protection Board and affected individuals of breaches, assess processors and third parties, and erase personal data once its purpose is served.
IndiaConsent is built to register as a Consent Manager under Rule 4 of the DPDP Rules 2025, which becomes effective in November 2026. The First Schedule requirements are already implemented: data-blind routing, tamper-evident records retained for at least seven years, zero conflict of interest, and machine-readable export of consent records.
The Consent Manager module supports verifiable parental consent, binding a guardian's verified identity to the child's consent artifact and blocking any processing that falls outside it.
Penalties run up to ₹250 crore under Section 33 of the DPDP Act, assessed per incident. Processing personal data without valid consent attracts up to ₹50 crore per instance.
No. IndiaConsent is data-blind by architecture. Personal data routed through the platform stays encrypted and unreadable by IndiaConsent, and PII discovery agents run inside your own network over outbound-only connections.
START YOUR PILOT
Tell us which obligation is furthest behind and we will scope a pilot around it — one module or all eight. No credit card, and your data never leaves your perimeter during discovery.
From the platform team, not a queue
Your obligations mapped to modules, then a live demo
On-premise for regulated estates, cloud for everyone else