Digital Personal Data Protection Act, 2023 · Rules, 2025
Built for the DPDP Act. Not adapted to it.
Notice, explicit consent, withdrawal and grievance redressal — across all 22 scheduled languages, in the systems where your riskiest personal data actually lives.
- Scheduled languages
- 22
- Sec. 5(3)
- Product modules
- 7
- M1–M7
- Record per purpose
- 1
- Sec. 6(1)
Purpose
Payroll processing
Do you consent to this purpose?
- Salary disbursementREQUIRED
- Benefits sharing with insurerOPTIONAL
You can withdraw this consent at any time.
Purpose
वेतन प्रसंस्करण
क्या आप इस प्रयोजन के लिए सहमति देते हैं?
- वेतन भुगतानREQUIRED
- बीमाकर्ता के साथ लाभ साझा करनाOPTIONAL
आप यह सहमति कभी भी वापस ले सकते हैं।
Purpose
বেতন প্রক্রিয়াকরণ
আপনি কি এই উদ্দেশ্যে সম্মতি দিচ্ছেন?
- বেতন প্রদানREQUIRED
- বিমাকারীর সঙ্গে সুবিধা ভাগ করাOPTIONAL
আপনি যেকোনো সময় এই সম্মতি প্রত্যাহার করতে পারেন।
Purpose
ஊதியச் செயலாக்கம்
இந்த நோக்கத்திற்கு நீங்கள் சம்மதிக்கிறீர்களா?
- ஊதிய வழங்கல்REQUIRED
- காப்பீட்டாளருடன் சலுகைப் பகிர்வுOPTIONAL
இந்தச் சம்மதத்தை நீங்கள் எப்போது வேண்டுமானாலும் திரும்பப் பெறலாம்.
Purpose
జీతం ప్రాసెసింగ్
ఈ ప్రయోజనం కోసం మీరు సమ్మతిస్తున్నారా?
- జీతం చెల్లింపుREQUIRED
- బీమా సంస్థతో ప్రయోజనాల భాగస్వామ్యంOPTIONAL
ఈ సమ్మతిని మీరు ఎప్పుడైనా ఉపసంహరించుకోవచ్చు.
Purpose
वेतन प्रक्रिया
तुम्ही या उद्देशासाठी संमती देता का?
- वेतन अदा करणेREQUIRED
- विमा कंपनीसोबत लाभ सामायिक करणेOPTIONAL
ही संमती तुम्ही कधीही मागे घेऊ शकता.
- ArchitecturePersonal data stored in India
- Sec. 16 · Rule 15No cross-border transfer by default
- Sec. 8(5)Append-only, hash-chained ledger
- Sec. 13Grievances answered by a named officer
The statutory clock
Three doors, not one13 Nov 2025
The Board exists on paper
Rules 1, 2 and 17–21 commence, establishing the Data Protection Board. Appointments to it were still open in mid-2026, so no forum is hearing complaints yet.
13 Nov 2026
Consent Manager registration opens
Rule 4 commences, against Part A of the First Schedule: incorporation in India, a ₹2 crore net worth floor, and an interoperable platform.
13 May 2027
The duty set lands in full
Rules 3, 5–16, 22 and 23 commence together — notice, consent, rights, safeguards, breach reporting, retention, children's data and cross-border.
Seven modules, one record
M1–M7Breach Notification
Intimation to every affected principal, and the Board report, on a 72-hour clock.
Vendor Risk
Every processor you engage, the contract that permits it, and what it may process.
Capabilities
What a consent management platform has to do under the DPDP Act
Not sure the Act reaches you? Check applicability by sector.
The Act does not ask for features. It asks whether you can produce a record, in a language the person read, showing what they agreed to and when they stopped agreeing.
- Sec. 5 · Rule 3
Notice, in a language the person reads
Versioned notice templates per purpose, carrying every particular the Rules require, in English or any of the 22 scheduled languages.
In detail
The exact text and language shown are snapshotted into the consent record, so the notice can be reproduced years later as the person saw it.
- Sec. 6(1)
One consent record per purpose
Purpose-scoped toggles with nothing pre-ticked, and a diff trail whenever a purpose changes.
In detail
Bundled consent fails the standard. Itemising is what makes a record defensible, and it is enforced by the data model rather than by a review step.
- Sec. 6(4)–6(6)
Withdrawal that reaches your systems
One action to withdraw, propagated downstream over webhooks, with a cessation timestamp per system that acknowledged it.
In detail
The Act requires withdrawal to be as easy as granting was, and processing to stop. The second half is the part most platforms leave to your engineers.
- Sec. 8(5)
An append-only, hash-chained trail
Every consent event is appended to a chain that fails verification if a record is altered after the fact.
In detail
Encrypted at rest and in transit, keys rotated, no standing operator access. Zero-knowledge proofs are the intended destination and are not in the product yet.
- Sec. 13 · Rule 14
Grievance redressal with a clock
A rights portal with identity verification, an owner per request, and a published response window per request type.
In detail
A first-class surface here and an afterthought in every global suite we benchmarked, because the duty exists in the Indian Act and not in theirs.
- Sec. 16 · Rule 15
Cross-border, enforced at the write
Geo-fenced storage with a transfer register, checked against the restricted list at the point of write rather than in a policy document.
In detail
No cross-border transfer by default. A destination is a configuration a customer makes deliberately, not a default they inherit.
The console
Every event, with the digest that proves it has not moved
Search by principal, purpose or event. Each row carries the hash its record is chained under, so an altered entry fails verification rather than passing quietly.
Sec. 8(5) · Rule 6
The Schedule · Sec. 33
The ceiling is ₹250 crore, and it attaches to safeguards
Not to a missing cookie banner. The largest entry in the Schedule is the one for failing to take reasonable security safeguards over the personal data you already hold.
| ₹250 cr | Failure to take reasonable security safeguards | Sec. 8(5) |
|---|---|---|
| ₹200 cr | Failure to notify the Board or affected principals of a breach | Sec. 8(6) |
| ₹200 cr | Breach of the obligations on children's data | Sec. 9 |
| ₹150 cr | Breach of Significant Data Fiduciary duties | Sec. 10 |
| ₹50 cr | Residuary — any other provision | Schedule, entry 6 |
Your position
Indicative exposure ceiling
High · Schedule ceiling ₹250 crore
A heuristic, not a forecast. Penalties are imposed by the Data Protection Board under Sec. 33, and the amounts above are ceilings the Schedule sets — what the Board would actually impose turns on the facts, the mitigation and the record you can produce.
Sec. 11–14 · Rule 14
A rights request has an owner and a clock
Four states, each one written to the trail as it happens. A request that stalls is visible before the response window closes, not after.
- 01
Consent Received
- 02
Data Verified
- 03
Action Performed
- 04
Audit Logged
What changes
The left column is what most Data Fiduciaries have today. It is not negligence — it is what happens when consent lives in a spreadsheet and a support inbox.
| Area | Today | With myconsent+ |
|---|---|---|
| Consent Capture | Manual, error-prone | Automated, contextual |
| Data Mapping | Spreadsheet-based | AI-driven discovery |
| Audit Trails | Disconnected logs | Append-only, hash-chained |
| DSR Response | Days/weeks | Real-time |
Biometric attendance
Withdrawn- Granted by
- Priya Patel · EMP-2024-0847
- Notice version and language
- v1.2 · தமிழ் (Tamil)
- Data categories
- Fingerprint template, attendance timestamps
- Recipients
- Attendance system, payroll
- Withdrawn
- 06 Aug 2026, 06:45 pm · WDR-2026-0311
- Processing ceased
- Confirmed by 2 downstream systems, 06:47 pm
a3f8d2e1b7c9e4f2c1d2f3a4d4e5a6b7c8d9e0f1a2b3c4d5e6Recomputed over the notice text shown, the purpose, the language and the timestamp — it matches. Nothing in this record has changed since it was written.
This receipt stays on record. Withdrawal does not erase what was lawful before it.
The receipt
Withdrawal does not erase what was lawful before it
A receipt records the notice version, the language, the purposes, the recipients and the moment processing stopped. It stays on record after withdrawal, because the question the Board asks is what you were entitled to do at the time.
Sec. 6(4)–6(6)
Integration
Drop the widget in, or call the API
Native SDKs for web, mobile and server. Consent capture and withdrawal are one call each; the propagation downstream is the part we do for you.
RESTful API
GraphQL & REST endpoints for every consent operation
Multi-Platform SDKs
React, Vue, iOS, Android, and native IoT support
Event Webhooks
Real-time consent events streamed to your infrastructure
SDK Ready
Zero-config deployment with automatic region routing
import { MyConsent, ConsentLevel } from '@myconsent/sdk';
const client = new MyConsent({
tenantId: 'your_tenant_id',
region: 'IN'
});
// One record per purpose. Nothing is pre-ticked.
const receipt = await client.consent.create({
userId: 'user_123',
purposes: [
ConsentLevel.GRANULAR_BIO,
ConsentLevel.SENSITIVE_DATA,
],
retention: {
period: '1Y',
autoDelete: true
}
});
// Withdrawal has to reach the systems downstream.
client.events.on('consent.withdrawn', async (evt) => {
await client.data.erase(evt.userId, { scope: 'all' });
});
The Eighth Schedule
Twenty-two languages, and the scripts they are written in
Section 5(3) permits notice in English or any language in the Eighth Schedule. Six are rendered live in the notice at the top of this page; the rest are template work, not engineering work.
Thirty minutes, screen-shared, no slides. Bring a purpose you actually collect consent for and we will build it live.
- 01AssameseBengali–Assamese
- 02BengaliBengali–Assamese
- 03BodoDevanagari
- 04DogriDevanagari
- 05GujaratiGujarati
- 06HindiDevanagari
- 07KannadaKannada
- 08KashmiriPerso-Arabic
- 09KonkaniDevanagari
- 10MaithiliDevanagari
- 11MalayalamMalayalam
- 12ManipuriMeetei Mayek
- 13MarathiDevanagari
- 14NepaliDevanagari
- 15OdiaOdia
- 16PunjabiGurmukhi
- 17SanskritDevanagari
- 18SantaliOl Chiki
- 19SindhiDevanagari / Perso-Arabic
- 20TamilTamil
- 21TeluguTelugu
- 22UrduPerso-Arabic
Rendered live in the notice at the top of this page
Questions people ask
- What is MyConsent+?
- Consent infrastructure for India's DPDP Act, 2023. It generates notices under Sec. 5, records consent per purpose under Sec. 6(1), carries withdrawal under Sec. 6(4) to the systems that hold the data, and keeps the evidence in a hash-chained ledger.
- Is MyConsent+ a registered Consent Manager?
- No. The register does not open until 13 November 2026 under Rule 4, so no organisation in India is a registered Consent Manager today. Any vendor claiming otherwise is describing something the Rules do not yet allow.
- When does the DPDP Act apply to my business?
- The Data Protection Board was constituted on 13 November 2025. Consent Manager registration opens 13 November 2026. Notice, consent, rights, safeguards, breach reporting, retention, children's data and cross-border transfer all commence on 13 May 2027.
- Do I need a consent management platform to comply?
- No provision requires software. The Act requires an itemised notice per purpose, consent you can evidence, withdrawal as easy as consent was, and a record you can produce to the Board. Organisations reach that with software because doing it by hand does not survive audit.
- Does MyConsent+ hold a SOC 2 report or ISO certificate?
- No. Neither has been issued for this platform, and the zero-knowledge proofs described elsewhere are stated intent rather than shipped product. Where a page claims a control, it cites the provision it answers to.