Building India's consent infrastructure on data sovereignty, privacy-first engineering, and an encrypted consent vault.
We believe personal data belongs to the people it describes — not the corporations that collect it. MyConsent+ was founded to make that principle enforceable at enterprise scale, with infrastructure built entirely within India, for India's regulatory framework.
Consent is statutory infrastructure. It should not be imported.
Consent under the DPDP Act is not a cookie banner. It is the record a Data Fiduciary produces when the Board asks how it obtained permission to process a person's data. That record, and the system that holds it, is national infrastructure in the same sense that payments and identity are — which is a poor thing to rent from a vendor built for a different statute in a different jurisdiction.
That is the sense in which this work sits alongside Atmanirbhar Bharat and Viksit Bharat 2047: not as a badge, but as three concrete choices.
Designed against Indian law first
The data model starts from Sec. 5 notice, Sec. 6 consent and Sec. 13 grievance — not from a GDPR schema with Indian fields appended. Grievance redressal with an SLA clock is a first-class surface here and an afterthought in every global suite we benchmarked.
Data that does not leave
No cross-border transfer by default, and destinations checked against the restricted list at the point of write rather than in a policy document. Sec. 16 is enforced in code.
Built and maintained here
The people who answer for this system are subject to the same law as the customers using it. When the Rules change, the change is understood at source rather than translated in from a foreign roadmap.
myconsent+ is a private company. Naming these national programmes describes the direction we build in — it is not a claim of endorsement, affiliation or government approval.
Founder
Manpreet Singh
Founder
Over 20 years in the IT industry, the majority of it in cybersecurity.
Heads cybersecurity at a major MNC.
Enterprise-grade trust guarantees
Data Stored in India
The platform is designed to process and store personal data within Indian territory, with no cross-border transfer unless a customer configures one. Region and availability-zone detail is published in the trust centre once the production estate is fixed.
End-to-End Encrypted
Consent receipts, audit entries and personal data are encrypted at rest and in transit, with keys rotated and support staff holding no standing access. Independent verification of these controls is the point of the audit programme below, not a substitute for it.
Principles that drive us
Privacy by Design
Data minimization and purpose limitation aren't afterthoughts — they are embedded in every layer of our architecture from day one.
Regulatory First
We don't adapt Western compliance tools for India. We build from the ground up for the DPDP Act, with Section-level control mapping.
Prove Without Exposing
The goal is for a regulator to verify a consent without seeing the data behind it. Today that means encryption, least privilege and a hash-chained trail. Zero-knowledge proofs are the intended destination, and are not in the product yet.
Developer Experience
A widget you can embed, a REST API, and SDKs — documented, versioned, and built to be read by the engineer who inherits them.
The Act arrives in three doors, not one
These are the dates the Digital Personal Data Protection Rules, 2025 actually commence on. They are the reason this product exists, and they are closer than most plans assume.
The Board exists
Rules 1, 2 and 17–21 commence. The Data Protection Board of India is constituted and complaints can be filed.
Consent Manager registration opens
Rule 4 commences. Registration runs against Part A of the First Schedule: incorporation in India, a ₹2 crore net worth floor, and an interoperable consent platform.
The duty set lands in full
Rules 3, 5–16, 22 and 23 commence together — notice, consent, rights, safeguards, breach reporting, retention, children's data and cross-border. No grace period is expected.
22
Scheduled languages
AES-256
Encryption at rest
India
Data residency
1
Records per purpose