Consent management platform · India
Consent management platform for India's DPDP Act
Consentrio helps Data Fiduciaries meet the consent obligations of the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notices, consent capture, withdrawal, rights requests, grievances and proof, in one platform.

What a consent management platform must do under the DPDP Act
The Act puts the burden of getting consent right, and proving it, on the Data Fiduciary. This is how each obligation maps to Consentrio.
| Obligation | Where in the law | In Consentrio |
|---|---|---|
| A clear notice before or with every consent request | Section 5, Rule 3 | Versioned consent notices built from one purpose library, with translation workflows and alerts when a purpose changes after publishing. |
| Consent that is free, specific, informed and given by a clear affirmative action | Section 6(1) | Purpose-by-purpose consent captured through the cookie banner, web, Android and iOS SDKs and a Java server SDK. |
| Check consent before you use the data | Sections 4 and 6 | A consent-validation API your systems call in real time before processing a user's data for a purpose. |
| Withdrawal as easy as giving consent | Section 6(4) | A preference centre where users view, renew, update or withdraw consent in a few clicks. |
| Make processors stop after a withdrawal | Section 6(6) | HMAC-signed webhooks notify processors of every consent change, with retries, dead-lettering and SLA alerts. |
| Prove that consent was given | Section 6(10) | Cryptographically signed consent records and a SHA-256 hash-chained audit trail you can verify for any date range. |
| Rights requests and grievance redressal | Sections 11–14, Rule 14 | One inbox for access, correction, erasure and complaints, with SLA tracking, internal notes and Jira hand-off. |
| Erase data once the purpose is served or consent is withdrawn | Section 8(7), Rule 8 | Retention policies per purpose, with legal holds that pause deletion when a dispute needs it. |
| Reasonable security safeguards and logs | Section 8(5), Rule 6 | Per-record AES-256-GCM encryption, role-based access with MFA, and an audit trail of every action. |
The detail behind each obligation is in our guides to DPDP consent requirements and the consent notice checklist.
More than a cookie banner
Many consent management platforms were built for cookie consent under European rules. DPDP consent reaches further: every sign-up form, mobile app, call-centre script and partner integration that collects personal data needs a notice, valid consent, easy withdrawal and a record. Consentrio covers the cookie banner and everything behind it, with SDKs for web, Android, iOS and Java servers.
A platform, not a Consent Manager
Under the DPDP Act a Consent Manager is a company registered with the Data Protection Board that acts for individuals. Consentrio is the platform your organisation uses to meet its own obligations, whichever channel consent arrives through.
When the obligations apply
13 Nov 2025
DPDP Rules notified; the Data Protection Board provisions take effect.
13 Nov 2026
Registration and obligations of Consent Managers (Rule 4) take effect.
13 May 2027
Core Data Fiduciary obligations apply: notices, security, breach reporting, retention, children's data and rights.
Full detail: DPDP Rules 2025 timeline.
Questions
- Does the DPDP Act require a consent management platform?
- The Act does not name a tool. It requires every Data Fiduciary to give a proper notice, obtain valid consent, make withdrawal as easy as giving consent, stop processors after withdrawal and prove all of it if challenged (Sections 5 and 6). Doing that across websites, apps and back-office systems by hand is hard to evidence, which is why most organisations use a consent management platform.
- Is a cookie banner enough for DPDP compliance?
- No. DPDP consent covers every way you collect personal data, including app sign-ups, forms, call centres and partner integrations, not only cookies. You also need versioned notices, withdrawal that reaches your processors, rights and grievance handling, and a record that proves each consent.
- What is the difference between a Consent Manager and a consent management platform?
- A Consent Manager is a company registered with the Data Protection Board that acts for individuals across many organisations (Section 2(g), Rule 4). A consent management platform is software a Data Fiduciary uses to meet its own obligations. Consentrio is a consent management platform, not a registered Consent Manager.
- When do organisations need to be ready?
- The DPDP Rules, 2025 were notified on 13 November 2025 and apply in phases. Consent Manager registration starts in November 2026, and the core obligations on Data Fiduciaries, including notices, security, breach reporting and rights, apply from May 2027.
- Can the same platform handle GDPR consent?
- Yes. Purpose-based consent, easy withdrawal, rights requests and an auditable consent record are core to both the DPDP Act and the GDPR, so one setup in Consentrio supports both.
See how your notices, consents and proof would look in Consentrio.