Rule 4

Consent Manager registration opens — 13 Nov 2026

myconsent+
Company

Consent is statutory infrastructure. It should not be imported.

Sixty years between three founders, most of it on the security and infrastructure side of exactly the systems this product sits in front of.

Who builds this, how it is designed, and what is honestly still ahead of us. Indian privacy infrastructure, built for data sovereignty.

Personal data belongs to the people it describes, not the corporations that collect it. We exist to make that principle enforceable at enterprise scale — with infrastructure built inside India, for India's regulatory framework.

Our mission

Why it matters that this is Indian

A consent record is national infrastructure, like payments and identity

Consent under the DPDP Act is not a cookie banner. It is the record a Data Fiduciary produces when the Board asks how it obtained permission to process a person's data — a poor thing to rent from a vendor built for a different statute in a different jurisdiction.

That is the sense in which this work sits alongside Atmanirbhar Bharat and Viksit Bharat 2047: not as a badge, but as three concrete choices.

  1. 01

    Designed against Indian law first

    The data model starts from Sec. 5 notice, Sec. 6 consent and Sec. 13 grievance — not from a GDPR schema with Indian fields appended. Grievance redressal with an SLA clock is a first-class surface here and an afterthought in every global suite we benchmarked.

  2. 02

    Data that does not leave

    No cross-border transfer by default, and destinations checked against the restricted list at the point of write rather than in a policy document. Sec. 16 is enforced in code.

  3. 03

    Built and maintained here

    The people who answer for this system are subject to the same law as the customers using it. When the Rules change, the change is understood at source rather than translated in from a foreign roadmap.

myconsent+ is a private company. Naming these national programmes describes the direction we build in — it is not a claim of endorsement, affiliation or government approval.

Founders

No photographs have been supplied, so nobody gets a stock portrait. Two names are still to be announced.

  • Manpreet Singh

    Founder

    Over 20 years in the IT industry.

    Formerly CTO at Monster.com, and CTO to several organisations since.

  • Co-founder

    Name to be announced

    Over 20 years in cybersecurity.

    Previously at Mastercard.

    Profile to follow
  • Co-founder

    Name to be announced

    Technologist with over 20 years in the industry.

    Previously at Yahoo and Oracle.

    Profile to follow

What we will stand behind

Two guarantees, and the detail under each

Sec. 16 · Rule 15Localisation

Data stored in India

The platform is designed to process and store personal data within Indian territory, with no cross-border transfer unless a customer configures one. Region and availability-zone detail is published in the trust centre once the production estate is fixed.

  • No cross-border transfer by default
  • Destinations checked against the restricted list at write time
  • Region: [TO BE PUBLISHED]
Sec. 8(5)Encryption and access

Encrypted, with no standing access

Consent receipts, audit entries and personal data are encrypted at rest and in transit, with keys rotated and support staff holding no standing access. Independent verification of these controls is the point of the audit programme, not a substitute for it.

  • AES-256 at rest, TLS 1.3 in transit
  • Envelope encryption with key rotation
  • No standing operator access; elevation is time-boxed and logged

Principles

Four we would be embarrassed to break

Privacy by design

Data minimisation and purpose limitation are not afterthoughts — they are embedded in every layer of the architecture from day one.

Regulatory first

We do not adapt Western compliance tools for India. We build from the ground up for the DPDP Act, with section-level control mapping.

Prove without exposing

The goal is for a regulator to verify a consent without seeing the data behind it. Today that means encryption, least privilege and a hash-chained trail. Zero-knowledge proofs are the intended destination, and are not in the product yet.

Developer experience

A widget you can embed, a REST API, and SDKs — documented, versioned, and built to be read by the engineer who inherits them.

The statutory clock

The Act arrives in three doors, not one

These are the dates the DPDP Rules, 2025 commence on. They are the reason this product exists, and they are closer than most plans assume.

  1. 13 Nov 2025

    The Board exists on paper

    Rules 1, 2 and 17–21 commence, establishing the Data Protection Board. Appointments to it were still open in mid-2026, so no forum is hearing complaints yet.

  2. 13 Nov 2026

    Consent Manager registration opens

    Rule 4 commences, against Part A of the First Schedule: incorporation in India, a ₹2 crore net worth floor, and an interoperable platform.

  3. 13 May 2027

    The duty set lands in full

    Rules 3, 5–16, 22 and 23 commence together — notice, consent, rights, safeguards, breach reporting, retention, children's data and cross-border.

22
Scheduled languages
AES-256
Encryption at rest
India
Data residency
1
Records per purpose

Anything here you would want to test before you believed it?

Ask us directly