Consent is statutory infrastructure. It should not be imported.
Sixty years between three founders, most of it on the security and infrastructure side of exactly the systems this product sits in front of.
Who builds this, how it is designed, and what is honestly still ahead of us. Indian privacy infrastructure, built for data sovereignty.
Personal data belongs to the people it describes, not the corporations that collect it. We exist to make that principle enforceable at enterprise scale — with infrastructure built inside India, for India's regulatory framework.
Our mission
Why it matters that this is Indian
A consent record is national infrastructure, like payments and identity
Consent under the DPDP Act is not a cookie banner. It is the record a Data Fiduciary produces when the Board asks how it obtained permission to process a person's data — a poor thing to rent from a vendor built for a different statute in a different jurisdiction.
That is the sense in which this work sits alongside Atmanirbhar Bharat and Viksit Bharat 2047: not as a badge, but as three concrete choices.
- 01
Designed against Indian law first
The data model starts from Sec. 5 notice, Sec. 6 consent and Sec. 13 grievance — not from a GDPR schema with Indian fields appended. Grievance redressal with an SLA clock is a first-class surface here and an afterthought in every global suite we benchmarked.
- 02
Data that does not leave
No cross-border transfer by default, and destinations checked against the restricted list at the point of write rather than in a policy document. Sec. 16 is enforced in code.
- 03
Built and maintained here
The people who answer for this system are subject to the same law as the customers using it. When the Rules change, the change is understood at source rather than translated in from a foreign roadmap.
myconsent+ is a private company. Naming these national programmes describes the direction we build in — it is not a claim of endorsement, affiliation or government approval.
Founders
No photographs have been supplied, so nobody gets a stock portrait. Two names are still to be announced.
Manpreet Singh
Founder
Over 20 years in the IT industry.
Formerly CTO at Monster.com, and CTO to several organisations since.
Co-founder
Name to be announced
Over 20 years in cybersecurity.
Previously at Mastercard.
Profile to followCo-founder
Name to be announced
Technologist with over 20 years in the industry.
Previously at Yahoo and Oracle.
Profile to follow
What we will stand behind
Two guarantees, and the detail under each
Data stored in India
The platform is designed to process and store personal data within Indian territory, with no cross-border transfer unless a customer configures one. Region and availability-zone detail is published in the trust centre once the production estate is fixed.
- No cross-border transfer by default
- Destinations checked against the restricted list at write time
- Region: [TO BE PUBLISHED]
Encrypted, with no standing access
Consent receipts, audit entries and personal data are encrypted at rest and in transit, with keys rotated and support staff holding no standing access. Independent verification of these controls is the point of the audit programme, not a substitute for it.
- AES-256 at rest, TLS 1.3 in transit
- Envelope encryption with key rotation
- No standing operator access; elevation is time-boxed and logged
Principles
Four we would be embarrassed to break
Privacy by design
Data minimisation and purpose limitation are not afterthoughts — they are embedded in every layer of the architecture from day one.
Regulatory first
We do not adapt Western compliance tools for India. We build from the ground up for the DPDP Act, with section-level control mapping.
Prove without exposing
The goal is for a regulator to verify a consent without seeing the data behind it. Today that means encryption, least privilege and a hash-chained trail. Zero-knowledge proofs are the intended destination, and are not in the product yet.
Developer experience
A widget you can embed, a REST API, and SDKs — documented, versioned, and built to be read by the engineer who inherits them.
The statutory clock
The Act arrives in three doors, not one
These are the dates the DPDP Rules, 2025 commence on. They are the reason this product exists, and they are closer than most plans assume.
13 Nov 2025
The Board exists on paper
Rules 1, 2 and 17–21 commence, establishing the Data Protection Board. Appointments to it were still open in mid-2026, so no forum is hearing complaints yet.
13 Nov 2026
Consent Manager registration opens
Rule 4 commences, against Part A of the First Schedule: incorporation in India, a ₹2 crore net worth floor, and an interoperable platform.
13 May 2027
The duty set lands in full
Rules 3, 5–16, 22 and 23 commence together — notice, consent, rights, safeguards, breach reporting, retention, children's data and cross-border.
- 22
- Scheduled languages
- AES-256
- Encryption at rest
- India
- Data residency
- 1
- Records per purpose
Anything here you would want to test before you believed it?
Ask us directly