infoABOUT US

Trust & Architecture

Indian privacy infrastructure — built for data sovereignty, and honest about what is shipped and what is still ahead.

OUR MISSION

Building India's consent infrastructure on data sovereignty, privacy-first engineering, and an encrypted consent vault.

We believe personal data belongs to the people it describes — not the corporations that collect it. MyConsent+ was founded to make that principle enforceable at enterprise scale, with infrastructure built entirely within India, for India's regulatory framework.

WHY IT MATTERS THAT THIS IS INDIAN

Consent is statutory infrastructure. It should not be imported.

Consent under the DPDP Act is not a cookie banner. It is the record a Data Fiduciary produces when the Board asks how it obtained permission to process a person's data. That record, and the system that holds it, is national infrastructure in the same sense that payments and identity are — which is a poor thing to rent from a vendor built for a different statute in a different jurisdiction.

That is the sense in which this work sits alongside Atmanirbhar Bharat and Viksit Bharat 2047: not as a badge, but as three concrete choices.

Designed against Indian law first

The data model starts from Sec. 5 notice, Sec. 6 consent and Sec. 13 grievance — not from a GDPR schema with Indian fields appended. Grievance redressal with an SLA clock is a first-class surface here and an afterthought in every global suite we benchmarked.

Data that does not leave

No cross-border transfer by default, and destinations checked against the restricted list at the point of write rather than in a policy document. Sec. 16 is enforced in code.

Built and maintained here

The people who answer for this system are subject to the same law as the customers using it. When the Rules change, the change is understood at source rather than translated in from a foreign roadmap.

myconsent+ is a private company. Naming these national programmes describes the direction we build in — it is not a claim of endorsement, affiliation or government approval.

Who is behind it

Founder

Manpreet Singh

Founder

Over 20 years in the IT industry, the majority of it in cybersecurity.

Heads cybersecurity at a major MNC.

Connect on LinkedIn
TRUST CERTIFICATIONS

Enterprise-grade trust guarantees

DATA LOCALIZATION

Data Stored in India

The platform is designed to process and store personal data within Indian territory, with no cross-border transfer unless a customer configures one. Region and availability-zone detail is published in the trust centre once the production estate is fixed.

No cross-border transfer by default
Destinations checked against the restricted list at write time — Sec. 16
Region: [TO BE PUBLISHED]
ENCRYPTION AND ACCESS

End-to-End Encrypted

Consent receipts, audit entries and personal data are encrypted at rest and in transit, with keys rotated and support staff holding no standing access. Independent verification of these controls is the point of the audit programme below, not a substitute for it.

AES-256 at rest, TLS 1.3 in transit
Envelope encryption with key rotation
No standing operator access; elevation is time-boxed and logged
OUR VALUES

Principles that drive us

Privacy by Design

Data minimization and purpose limitation aren't afterthoughts — they are embedded in every layer of our architecture from day one.

Regulatory First

We don't adapt Western compliance tools for India. We build from the ground up for the DPDP Act, with Section-level control mapping.

Prove Without Exposing

The goal is for a regulator to verify a consent without seeing the data behind it. Today that means encryption, least privilege and a hash-chained trail. Zero-knowledge proofs are the intended destination, and are not in the product yet.

Developer Experience

A widget you can embed, a REST API, and SDKs — documented, versioned, and built to be read by the engineer who inherits them.

THE STATUTORY CLOCK

The Act arrives in three doors, not one

These are the dates the Digital Personal Data Protection Rules, 2025 actually commence on. They are the reason this product exists, and they are closer than most plans assume.

13 Nov 2025

The Board exists

Rules 1, 2 and 17–21 commence. The Data Protection Board of India is constituted and complaints can be filed.

13 Nov 2026

Consent Manager registration opens

Rule 4 commences. Registration runs against Part A of the First Schedule: incorporation in India, a ₹2 crore net worth floor, and an interoperable consent platform.

13 May 2027

The duty set lands in full

Rules 3, 5–16, 22 and 23 commence together — notice, consent, rights, safeguards, breach reporting, retention, children's data and cross-border. No grace period is expected.

22

Scheduled languages

AES-256

Encryption at rest

India

Data residency

1

Records per purpose