Rule 4

Consent Manager registration opens13 Nov 2026

myconsent+

Digital Personal Data Protection Act, 2023 · Rules, 2025

Built for the DPDP Act. Not adapted to it.

Notice, explicit consent, withdrawal and grievance redressal — across all 22 scheduled languages, in the systems where your riskiest personal data actually lives.

Scheduled languages
22
Sec. 5(3)
Product modules
7
M1–M7
Record per purpose
1
Sec. 6(1)
Notice · v1.2Sec. 5 · Rule 3
EnglishSec. 5(3)

Purpose

Payroll processing

Do you consent to this purpose?

  • Salary disbursementREQUIRED
  • Benefits sharing with insurerOPTIONAL

You can withdraw this consent at any time.

RCPT-2026-0912a3f8d2e1…9b0406 Aug 2026, 08:02 pm IST
Same notice, 6 of 22
  • ArchitecturePersonal data stored in India
  • Sec. 16 · Rule 15No cross-border transfer by default
  • Sec. 8(5)Append-only, hash-chained ledger
  • Sec. 13Grievances answered by a named officer

The statutory clock

  1. 13 Nov 2025

    The Board exists on paper

    Rules 1, 2 and 17–21 commence, establishing the Data Protection Board. Appointments to it were still open in mid-2026, so no forum is hearing complaints yet.

  2. 13 Nov 2026

    Consent Manager registration opens

    Rule 4 commences, against Part A of the First Schedule: incorporation in India, a ₹2 crore net worth floor, and an interoperable platform.

  3. 13 May 2027

    The duty set lands in full

    Rules 3, 5–16, 22 and 23 commence together — notice, consent, rights, safeguards, breach reporting, retention, children's data and cross-border.

Capabilities

What a consent management platform has to do under the DPDP Act

Not sure the Act reaches you? Check applicability by sector.

The Act does not ask for features. It asks whether you can produce a record, in a language the person read, showing what they agreed to and when they stopped agreeing.

  1. Sec. 5 · Rule 3

    Notice, in a language the person reads

    Versioned notice templates per purpose, carrying every particular the Rules require, in English or any of the 22 scheduled languages.

    In detail

    The exact text and language shown are snapshotted into the consent record, so the notice can be reproduced years later as the person saw it.

  2. Sec. 6(1)

    One consent record per purpose

    Purpose-scoped toggles with nothing pre-ticked, and a diff trail whenever a purpose changes.

    In detail

    Bundled consent fails the standard. Itemising is what makes a record defensible, and it is enforced by the data model rather than by a review step.

  3. Sec. 6(4)–6(6)

    Withdrawal that reaches your systems

    One action to withdraw, propagated downstream over webhooks, with a cessation timestamp per system that acknowledged it.

    In detail

    The Act requires withdrawal to be as easy as granting was, and processing to stop. The second half is the part most platforms leave to your engineers.

  4. Sec. 8(5)

    An append-only, hash-chained trail

    Every consent event is appended to a chain that fails verification if a record is altered after the fact.

    In detail

    Encrypted at rest and in transit, keys rotated, no standing operator access. Zero-knowledge proofs are the intended destination and are not in the product yet.

  5. Sec. 13 · Rule 14

    Grievance redressal with a clock

    A rights portal with identity verification, an owner per request, and a published response window per request type.

    In detail

    A first-class surface here and an afterthought in every global suite we benchmarked, because the duty exists in the Indian Act and not in theirs.

  6. Sec. 16 · Rule 15

    Cross-border, enforced at the write

    Geo-fenced storage with a transfer register, checked against the restricted list at the point of write rather than in a policy document.

    In detail

    No cross-border transfer by default. A destination is a configuration a customer makes deliberately, not a default they inherit.

The console

Every event, with the digest that proves it has not moved

Search by principal, purpose or event. Each row carries the hash its record is chained under, so an altered entry fails verification rather than passing quietly.

Sec. 8(5) · Rule 6

Admin Console — Evidence & Search
Export an audit pack straight from a filtered view: the notice text served, the language it was served in, the timestamp, and the chain digest.

The Schedule · Sec. 33

The ceiling is ₹250 crore, and it attaches to safeguards

Not to a missing cookie banner. The largest entry in the Schedule is the one for failing to take reasonable security safeguards over the personal data you already hold.

Penalty ceilings set by the Schedule to the DPDP Act, 2023
250 crFailure to take reasonable security safeguardsSec. 8(5)
200 crFailure to notify the Board or affected principals of a breachSec. 8(6)
200 crBreach of the obligations on children's dataSec. 9
150 crBreach of Significant Data Fiduciary dutiesSec. 10
50 crResiduary — any other provisionSchedule, entry 6

Your position

5,00050,00,000

Indicative exposure ceiling

110crore

High · Schedule ceiling ₹250 crore

A heuristic, not a forecast. Penalties are imposed by the Data Protection Board under Sec. 33, and the amounts above are ceilings the Schedule sets — what the Board would actually impose turns on the facts, the mitigation and the record you can produce.

Sec. 11–14 · Rule 14

A rights request has an owner and a clock

Four states, each one written to the trail as it happens. A request that stalls is visible before the response window closes, not after.

  1. 01

    Consent Received

  2. 02

    Data Verified

  3. 03

    Action Performed

  4. 04

    Audit Logged

What changes

The left column is what most Data Fiduciaries have today. It is not negligence — it is what happens when consent lives in a spreadsheet and a support inbox.

AreaTodayWith myconsent+
Consent CaptureManual, error-proneAutomated, contextual
Data MappingSpreadsheet-basedAI-driven discovery
Audit TrailsDisconnected logsAppend-only, hash-chained
DSR ResponseDays/weeksReal-time
Preference Centre — a receipt, opened
myconsent+PRINCIPAL
RCPT-2026-0912
Biometric attendance
Withdrawn
RCPT-2026-0088
Payroll processing
Active
RCPT-2026-0087
Wellness analytics
Expiring

Biometric attendance

Withdrawn
Granted by
Priya Patel · EMP-2024-0847
Notice version and language
v1.2 · தமிழ் (Tamil)
Data categories
Fingerprint template, attendance timestamps
Recipients
Attendance system, payroll
Withdrawn
06 Aug 2026, 06:45 pm · WDR-2026-0311
Processing ceased
Confirmed by 2 downstream systems, 06:47 pm
Digesta3f8d2e1b7c9e4f2c1d2f3a4d4e5a6b7c8d9e0f1a2b3c4d5e6

Recomputed over the notice text shown, the purpose, the language and the timestamp — it matches. Nothing in this record has changed since it was written.

This receipt stays on record. Withdrawal does not erase what was lawful before it.

What a Data Principal sees when they ask what they agreed to. The digest is recomputed in the browser, so the answer does not depend on trusting the page.

The receipt

Withdrawal does not erase what was lawful before it

A receipt records the notice version, the language, the purposes, the recipients and the moment processing stopped. It stays on record after withdrawal, because the question the Board asks is what you were entitled to do at the time.

Sec. 6(4)–6(6)

Integration

Drop the widget in, or call the API

Native SDKs for web, mobile and server. Consent capture and withdrawal are one call each; the propagation downstream is the part we do for you.

  • RESTful API

    GraphQL & REST endpoints for every consent operation

  • Multi-Platform SDKs

    React, Vue, iOS, Android, and native IoT support

  • Event Webhooks

    Real-time consent events streamed to your infrastructure

  • SDK Ready

    Zero-config deployment with automatic region routing

consent.ts@myconsent/sdk
import { MyConsent, ConsentLevel } from '@myconsent/sdk';

const client = new MyConsent({
  tenantId: 'your_tenant_id',
  region: 'IN'
});

// One record per purpose. Nothing is pre-ticked.
const receipt = await client.consent.create({
  userId: 'user_123',
  purposes: [
    ConsentLevel.GRANULAR_BIO,
    ConsentLevel.SENSITIVE_DATA,
  ],
  retention: {
    period: '1Y',
    autoDelete: true
  }
});

// Withdrawal has to reach the systems downstream.
client.events.on('consent.withdrawn', async (evt) => {
  await client.data.erase(evt.userId, { scope: 'all' });
});

The Eighth Schedule

Twenty-two languages, and the scripts they are written in

Section 5(3) permits notice in English or any language in the Eighth Schedule. Six are rendered live in the notice at the top of this page; the rest are template work, not engineering work.

Thirty minutes, screen-shared, no slides. Bring a purpose you actually collect consent for and we will build it live.

  • 01AssameseBengali–Assamese
  • 02BengaliBengali–Assamese
  • 03BodoDevanagari
  • 04DogriDevanagari
  • 05GujaratiGujarati
  • 06HindiDevanagari
  • 07KannadaKannada
  • 08KashmiriPerso-Arabic
  • 09KonkaniDevanagari
  • 10MaithiliDevanagari
  • 11MalayalamMalayalam
  • 12ManipuriMeetei Mayek
  • 13MarathiDevanagari
  • 14NepaliDevanagari
  • 15OdiaOdia
  • 16PunjabiGurmukhi
  • 17SanskritDevanagari
  • 18SantaliOl Chiki
  • 19SindhiDevanagari / Perso-Arabic
  • 20TamilTamil
  • 21TeluguTelugu
  • 22UrduPerso-Arabic

Rendered live in the notice at the top of this page

Questions people ask

What is MyConsent+?
Consent infrastructure for India's DPDP Act, 2023. It generates notices under Sec. 5, records consent per purpose under Sec. 6(1), carries withdrawal under Sec. 6(4) to the systems that hold the data, and keeps the evidence in a hash-chained ledger.
Is MyConsent+ a registered Consent Manager?
No. The register does not open until 13 November 2026 under Rule 4, so no organisation in India is a registered Consent Manager today. Any vendor claiming otherwise is describing something the Rules do not yet allow.
When does the DPDP Act apply to my business?
The Data Protection Board was constituted on 13 November 2025. Consent Manager registration opens 13 November 2026. Notice, consent, rights, safeguards, breach reporting, retention, children's data and cross-border transfer all commence on 13 May 2027.
Do I need a consent management platform to comply?
No provision requires software. The Act requires an itemised notice per purpose, consent you can evidence, withdrawal as easy as consent was, and a record you can produce to the Board. Organisations reach that with software because doing it by hand does not survive audit.
Does MyConsent+ hold a SOC 2 report or ISO certificate?
No. Neither has been issued for this platform, and the zero-knowledge proofs described elsewhere are stated intent rather than shipped product. Where a page claims a control, it cites the provision it answers to.