DPDP Rules 2025: Key Changes, Obligations & Implementation Guide
Read here
ONE PLATFORMEight modules · Enterprise and SaaS deployment

The complete DPDP
compliance
platform.

Consent, cookies, assessments, data discovery, grievances, breach, RoPA, and an AI layer across all of them. Eight modules on one data-blind platform, sharing one artifact store and one audit trail, so compliance is demonstrated from live evidence rather than assembled at audit time.

Built to register under Rule 4
Data-blind architecture
22+ Indian languages

ONE PLATFORM

Eight modules around a single consent core

Every module writes to the same artifact store and the same audit trail, with an AI layer reading across all of them.

DPDP compliance lifecycleOne consent core. One artifact store.One audit trail.ConsentManagerCookiemanagerDPIA &TPRMPIIdiscoveryGrievance& rightsBreachmanagementEnterpriseRoPAAIlayer

WHY ONE PLATFORM

Built as a platform, not a suite
of tools

Four architectural decisions that make every module reinforce the others.

One consent core

Every module reads the same signed consent artifact. A withdrawal captured on a cookie banner reaches the grievance desk, the RoPA register, and your downstream systems without an integration project.

Data-blind by architecture

Personal data routed through the platform stays encrypted and unreadable by IndiaConsent, and discovery agents run inside your own network over outbound-only connections.

Three-Layer Audit

Independent consent, compliance, and operational audit logs provide complete traceability across user consent, regulatory activities, and system operations.

An AI layer over all of it

Because the modules share a store, the AI layer can draft a notice, find the gap in a published one, and answer a DPO's question from your own live artifacts.

Every DPDP obligation, mapped to a module

No gaps to fill with spreadsheets, and no second vendor to integrate.

Obtain free, specific, informed, and unconditional consent

Section 6, DPDP Act 2023

Consent Manager

Serve itemised notice in English or any Eighth Schedule language

Section 5 · Rule 3

Consent Manager

Obtain verifiable parental consent for children's data

Section 9 · Rule 10

Consent Manager

Take consent for cookies and trackers, and honour rejection

Sections 4 and 6

Cookie Manager

Assess processors, third parties, and high-risk processing

Section 8(2) · Section 10

DPIA & TPRM

Know and secure the personal data you hold

Section 8(4) · Section 8(5)

PII discovery

Publish a grievance mechanism and answer rights requests

Sections 11 to 14 · Rule 13

Grievance & rights

Notify the Board and affected individuals of a breach

Section 8(6) · Rule 7

Breach management

Maintain records of processing activities and retention

Section 8 · Third Schedule

RoPA
1
CONSENT MANAGER

Capture, prove, and revoke consent end to end

Every grant, review, renewal, and withdrawal becomes a cryptographically signed artifact that propagates across your systems in real time. Withdrawal is as easy as giving consent, exactly as the Act requires, and parental consent for children's data is a first-class flow rather than a form field.

  • Signed, immutable artifacts with SHA-256 hash and ISO 8601 timestamps
  • Grant, review, renew, revoke, and expire with real-time propagation
  • Verifiable parental consent for children, bound to a guardian identity
  • Notices and preference screens in 22+ Indian languages
  • Pre-validation blocks processing that no consent covers
2
COOKIE MANAGER

Scan your sites, classify trackers, publish compliant banners

IndiaConsent's Cookie Manager scans sites, classifies trackers, and publishes branded consent banners in 22+ Indian languages — with one script tag and audit-grade compliance records.

  • Automated site scans that find and classify every tracker
  • Branded banners deployed with one script tag
  • Consent and rejection captured in 22+ Indian languages
  • Audit-grade records for every banner interaction
  • Tracker-level change alerts when a new script appears
3
PATM · DPIA & TPRM

DPIA, PIA, and third-party risk in one console

IndiaConsent's PATM unifies DPIA and third-party vendor risk assessments under the DPDP Act 2023 into one console — with evidence vaults, automated risk scoring, and audit-ready DPO reports.

  • DPIA, PIA, and third-party risk assessments on one workflow
  • Evidence vault attached to every assessment and finding
  • Automated risk scoring with configurable thresholds
  • Audit-ready DPO reports generated from live data
  • Processor questionnaires with reminders and sign-off trails
4
PII DISCOVERY & LINEAGE

Find the personal data you did not know you held

A multi-tenant scanner discovers personal data across registered hosts, files, and databases. Operators start and monitor scans from the console while outbound-only agents do the work inside your network, so nothing needs inbound access and no raw data leaves your perimeter.

  • Agent-based discovery across Linux hosts, files, and configured databases
  • Outbound-only agents — no inbound access into your network
  • Masked or full reports, verified by the backend before release
  • Live scan progress with event streaming and recovery on stall
  • Lineage mapping that traces each field to its downstream consumers
5
GRIEVANCE & RIGHTS

A grievance mechanism that survives an audit

A unified workflow manages 12 grievance categories, including all 6 Data Principal rights, with SLA-driven tracking, automated escalation, and complete status visibility. Every request follows a structured resolution process, and every action is written to a hash-chained audit log, ensuring end-to-end traceability and accountability.

  • Low-friction intake with ticket tracking for the Data Principal
  • SLA engine with published timelines, reminders, and escalation ladders
  • Rights requests modelled apart from complaints, with identity verification
  • Consent linkage shows what was permitted against what actually happened
  • Hash-chained, verifiable audit log with department and nodal-officer workflows
6
BREACH MANAGEMENT

Notify the Board and affected individuals in time

Incident intake, severity assessment, and notification run as one timed workflow against the DPDP reporting obligations, so the clock starts when the incident is logged rather than when someone remembers the rule.

  • Incident intake with severity and scope assessment
  • Data Protection Board notification workflow with mandated timelines
  • Affected Data Principal notices generated from the impacted record set
  • Remediation tracking with owner and due date per action
  • Complete incident audit trail for post-facto review
7
RoPA

A Record of Processing Activities that stays current

RoPA is populated from what the platform already knows — discovered data stores, consent purposes, processors under assessment — so the register reflects the estate rather than last year's spreadsheet.

  • Processing activity register with purpose, legal basis, and retention
  • Auto-populated from discovery, consent, and assessment data
  • Processor and cross-border transfer mapping per activity
  • Change history showing who altered which entry and when
  • Export formatted for Board inspection
8
AI LAYER

An AI layer that reads across every module

The same AI layer serves both sides of the Act. Data Principals ask what a company holds and act on the answer; DPOs ask where the gaps are. It drafts notices, scans published notices for gaps against the Act, and flags new DPDP notifications as they land.

  • Chat-based query and actions for Data Principals and Data Fiduciaries
  • AI notice generation from your purpose and data-category catalogue
  • Gap analysis that scans existing notices against DPDP requirements
  • Alerts on new DPDP notifications, rules, and Board directions
  • Answers grounded in your own artifacts, discovery, and audit data

RULE 4 · THE CONSENT MANAGER

A neutral intermediary that cannot read your customers' data

A Consent Manager is an entity registered with the Data Protection Board under Rule 4 of the DPDP Rules 2025. It gives Data Principals one accessible, transparent, and interoperable place to give, manage, review, and withdraw consent, and it owes duties directly to them.

IndiaConsent is built to register once Rule 4 becomes effective in November 2026. The First Schedule requirements are already in the architecture, not on a roadmap.

  • Personal data routed through the platform stays encrypted and unreadable by IndiaConsent
  • Tamper-evident, cryptographically verifiable records retained for at least seven years
  • Zero-conflict-of-interest architecture
  • Machine-readable export of consent records on request

HOW AN ARTIFACT MOVES

DATA PRINCIPAL

Individual grants or withdraws consent

In any of 22+ Indian languages, on web, app, or IVR

consent flow

DPB REGISTERED

IndiaConsent signs an immutable artifact

SHA-256 hash, ISO 8601 timestamp, purpose, data categories

artifact relay

FIDUCIARY

Banking

FIDUCIARY

Insurance

FIDUCIARY

Healthcare

INDUSTRIES

The obligation is the same. The data is not.

Purpose taxonomies, retention rules, and grievance ladders arrive pre-configured for your sector.

Banking & NBFC

Consent at onboarding, credit pulls, and collections, reconciled against RBI record-keeping obligations.

Insurance

Health data as a special category, intermediary chains, and long retention tails under one lineage map.

Healthcare

Patient consent, guardian consent for minors, and rights requests routed to the right clinical custodian.

Telecom

Subscriber-scale volumes, IVR and retail-channel capture, and marketing preference enforcement.

E-commerce

Cookie and tracker consent, ad-tech processors, and deletion instructions that reach third parties.

Government & PSU

Citizen-facing grievance intake with nodal-officer workflows, escalation ladders, and SLA reporting.

Education

Student, parent, and staff consent, grievance handling, and rights requests across admissions, academics, and digital platforms.

HRTech

Candidate and employee consent, background verification, assessments, and rights requests across recruitment and workforce platforms.

FAQ

DPDP questions, answered
directly

What is the DPDP Act compliance deadline for Indian enterprises?

The DPDP Rules 2025 were notified on 13 November 2025. Data Fiduciaries have an 18-month window that ends on 13 May 2027, by which date full compliance is required.

What does full DPDP compliance require beyond consent collection?

Consent is one obligation of several. A Data Fiduciary must also issue itemised notices, honour Data Principal rights, run a grievance redressal mechanism with published timelines, maintain a Record of Processing Activities, notify the Data Protection Board and affected individuals of breaches, assess processors and third parties, and erase personal data once its purpose is served.

Is IndiaConsent a registered Consent Manager?

IndiaConsent is built to register as a Consent Manager under Rule 4 of the DPDP Rules 2025, which becomes effective in November 2026. The First Schedule requirements are already implemented: data-blind routing, tamper-evident records retained for at least seven years, zero conflict of interest, and machine-readable export of consent records.

How does IndiaConsent handle children's data and parental consent?

The Consent Manager module supports verifiable parental consent, binding a guardian's verified identity to the child's consent artifact and blocking any processing that falls outside it.

What is the penalty for DPDP non-compliance in India?

Penalties run up to ₹250 crore under Section 33 of the DPDP Act, assessed per incident. Processing personal data without valid consent attracts up to ₹50 crore per instance.

Does IndiaConsent store our customers' personal data?

No. IndiaConsent is data-blind by architecture. Personal data routed through the platform stays encrypted and unreadable by IndiaConsent, and PII discovery agents run inside your own network over outbound-only connections.

START YOUR PILOT

See the whole platform on your own data.

Tell us which obligation is furthest behind and we will scope a pilot around it — one module or all eight. No credit card, and your data never leaves your perimeter during discovery.

Response within 24 hours

From the platform team, not a queue

A 35-minute working session

Your obligations mapped to modules, then a live demo

Enterprise or SaaS deployment

On-premise for regulated estates, cloud for everyone else