Rule 4

Consent Manager registration opens13 Nov 2026

myconsent+
Compare

Adapted to the Act, or built against it

Last updated

16 September 2026

How a GDPR-first consent platform adapted to India compares with one designed against the DPDP Act, on notice languages, withdrawal parity and evidence.

The established consent platforms were built for the GDPR and the ePrivacy Directive, and they are good at what those regimes ask for. The question is not whether they are capable products. It is whether the things the DPDP Act turns on are things they were shaped around.

Where a GDPR-first platform is already strong

Cookie categorisation, banner delivery, preference centres, vendor lists and records of processing are mature, well-tested and generally better documented than anything newer. If your exposure is a website consent banner and a European user base, the incumbent is a reasonable answer and this page is not an argument against it.

Where the DPDP Act asks something else

Eighth Schedule languages. A Data Principal may demand the notice in any of 22 languages. A platform with a translation layer built for European languages can add strings; what is harder is holding an auditable record of which language version a specific person was shown.

Withdrawal parity under Sec. 6(4). Withdrawal has to be as easy as giving consent was. A preference centre reachable from a footer is not parity with a one-tap in-flow consent, and platforms designed around opt-out cookie regimes tend to treat withdrawal as a settings screen.

Consent outside the browser. Indian consent is collected at counters, over IVR, in branch, on feature phones and in regional-language apps. Tooling anchored to a web tag manager reaches none of it.

Evidence built for the Board. Sec. 8 puts the accountability on the Data Fiduciary. What matters is a record that shows the notice version, the language, the timestamp and the downstream propagation of a withdrawal — as a tamper-evident chain rather than a log line.

The honest summary

If the requirement is a cookie banner, buy the mature product. If the requirement is defending a consent record in front of the Data Protection Board, the deciding factor is whether the evidence model was designed for the Act or added to a product that already existed.

What to ask any platform, ours included

The summary above is a judgment. What follows is how to make it yourself, because a feature grid answers a question nobody will be asked in an inquiry. Each row is a provision, the question it generates, and a way to settle the answer in a trial rather than in a meeting. The same questions apply to this product; they are the ones worth arriving with.

DPDP provisions expressed as buyer questions, with a way to test each answer in a trial
ProvisionWhat to askHow to test the answer
Sec. 5(3), Sec. 6(3)Which of the 22 Eighth Schedule languages can a notice actually be published in, and can you tell me which language a named person was served?Publish one notice in three scripts, consent as a test user in one of them, then read the language back off that person's record rather than off the notice.
Sec. 6(4)How many actions does withdrawal take, against how many the consent took?Count the steps in both directions for the same purpose, on a phone. A preference centre that was not part of the consent flow is not parity with a tick that was.
Sec. 5(1), Sec. 6(1)How is consent recorded when it is taken at a counter, over IVR, on a feature phone, or by an agent in the field?Record one consent through a non-browser channel end to end, and check whether it lands in the same record as a web consent or in a second system nobody will remember at audit.
Sec. 6(10)What does an evidence export for one person look like, and what is in it?Ask for the export for a test principal. Sec. 6(10) puts the burden of proving notice and consent on the Data Fiduciary, so look for the notice version, the language, the timestamp, the channel and the outcome — and for whether any of it can be checked without trusting the vendor's own console.
Rule 7What does this give the incident team in the first hour, and what does it give them for the 72-hour report to the Board?Ask who it says was affected, and whether that list is computed from a data map or assembled by hand. Rule 7 wants an intimation to each affected person without delay, and a detailed report to the Board within 72 hours of becoming aware.
Rule 8Can a retention period be expressed as a number the product acts on, and can it warn someone 48 hours before an erasure?Set a short period on a test purpose and watch whether the warning and the erasure both fire, and whether both are recorded. Only the three Third Schedule classes are under Rule 8's three-year clock, but every Fiduciary is under Sec. 8(7).
Rule 14(3)Where does the ninety-day grievance clock live, and can anyone edit it?Open a grievance and then try to change its due date. A due date computed from the intake timestamp at read time cannot be quietly moved; a stored field can.
Rule 13, Sec. 10(2)If we are notified as a Significant Data Fiduciary, what does this do for the annual DPIA and audit, and for keeping specified personal data inside India?Ask what exists today rather than what is planned, and ask where the data is stored and who can reach it. Rule 13 also requires due diligence that algorithmic software does not put Data Principals' rights at risk, which is a question about your models as much as the vendor's.

Take these into a trial account with a test Data Principal. An answer that only exists in a roadmap is a different answer.

What has to move in a migration

Switching consent platforms is not like switching analytics, because the old platform holds evidence you remain accountable for. Four things have to survive the move.

The decisions, per purpose and per person. Not a boolean per contact. A consent that was given for three purposes and withdrawn from one is three states, and a migration that flattens them destroys the only thing that makes selective withdrawal provable.

Every notice version, not the current one. The document that matters in a dispute is the one a particular person saw on a particular date, which may have been superseded twice since. A migration that carries the live notice and drops its predecessors carries the wrong record.

The language variants, and which one was served. Under Sec. 5(3) the choice of language belongs to the Data Principal, so a consent record without the language it was taken in is incomplete in the specific way an inquiry would expose.

Withdrawal state, including the withdrawals. Sec. 6(5) preserves the lawfulness of processing done before a withdrawal, so a withdrawal is not a deletion of the consent it ended — it is a second event, with its own timestamp, and the pair is the evidence.

Two practical points sit around those. Timing: a cut-over creates a window with two systems of record, and the safest window is one that closes well before 13 May 2027 rather than one that opens near it. And Sec. 5(2): where consent was given before commencement, processing may continue until she withdraws, but a notice has to reach that base as soon as is reasonably practicable — which is easier to do once, on the platform you intend to keep, than twice.

When the incumbent is the right answer

This section is not a courtesy. There are situations where staying is the correct decision, and they are common.

Where the consent surface genuinely is one website and one cookie banner, the mature product is the lower-risk choice.

Where the platform is already the system of record for records of processing, vendor inventories and a GDPR programme that other teams depend on, the cost of a move falls on people whose work has nothing to do with the DPDP Act — and that cost is real even when the consent argument goes the other way.

Where the Indian exposure is a small part of a global estate, one evidence model for both regimes may be worth more than a better fit for one of them.

And where a move would land mid-window. Migrating a consent record is itself a risk to the record, and doing it in the last quarter before commencement converts a compliance project into a data-migration project at exactly the wrong moment.

The argument for building against the Act is strongest when the consent is collected in places a tag manager cannot see, in languages the Data Principal chooses, and has to be defended one person at a time. Where that is not the shape of the problem, it is not the deciding factor.